{"id":2087,"date":"2023-06-21T21:54:23","date_gmt":"2023-06-22T01:54:23","guid":{"rendered":"https:\/\/increasec.com\/?p=2087"},"modified":"2024-07-04T13:01:06","modified_gmt":"2024-07-04T17:01:06","slug":"osint-tips","status":"publish","type":"post","link":"https:\/\/increasec.com\/?p=2087","title":{"rendered":"OSInt Tips"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">OSInt; Operational Security Intelligence refers to limiting the amount of information that a company makes known on the internet.  You likely arn&#8217;t aware of the amount of info anyone tech savvy can gather about your organization.  whois gives domain registrar and name servers.  SOA gives their start of authority and responsible email address.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A lot of info can be found using <a href=\"https:\/\/mxtoolbox.com\/\">mxtoolbox.com<\/a>   MX records lists their mail server and possibly their spam filter.  SPF record gives clues as to spam filtering and public IP addresses.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Google search to find the company website and the domain name (the part after www).  we will use this later.  Record their Facebook and LinkedIn profile names, Street Address, any email addresses, News report with a CEO name.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Visit their website, record &#8220;Contact Us&#8221; info, employee names<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">pentest-tools.com<br>use &#8220;Discover Attack Surface&#8221; to find endpoints<br>use &#8220;website scanner&#8221; on their public website, and their firewall if you know the ip already.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">shodan.io<br>enter each unique IP Addresses from &#8220;Discover Attack Surface&#8221; (above) and record the results<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Social Media:<br>visit Facebook.com and LinkedIn.com and record names of C level management and any email addresses.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">External IP of office;<br>This is a little intrusive so make sure you have a written agreement from management.  use <a href=\"https:\/\/canarytokens.org\/\">CanaryTools<\/a> to generate a Canary Web token.  Generate an email to someone that is in the office with the canary token link.  Make up a juicy reason to click the link.   It may be possible to embed an image in an email with a webbug image, but I havent&#8217; found a site that will do this for free. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/dnsdumpster.com\/\">dnsdumpster.com<\/a>  find subdomains, and nice diagram of how dns and sites fit together<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">dnsspy.io<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>OSInt; Operational Security Intelligence refers to limiting the amount of information that a company makes known on the internet. You likely arn&#8217;t aware of the amount of info anyone tech&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2087","post","type-post","status-publish","format-standard","hentry","category-uncategorised"],"_links":{"self":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/2087","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2087"}],"version-history":[{"count":7,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/2087\/revisions"}],"predecessor-version":[{"id":2989,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/2087\/revisions\/2989"}],"wp:attachment":[{"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2087"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2087"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2087"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}