SlideShare une entreprise Scribd logo
1  sur  27
OSINT
Testcases for Pentesters
@upgoingstar | shubham@shubhammittal.net
Who Am I?
• Shubham Mittal
• 4+ years of experience ~ Offensive & Defensive roles.
• InfoSec Consultant. Trainer @ Nullcon.
• Interests in PT, OSINT, Infrastructure Security.
• Projects: Datasploit
• Biker, Beat Boxer, Blogger.
@upgoingstar | shubhammittal.net | shubham@shubhammittal.net
Internet gives you RAW Data. Harvest it.
OSINT – Open Source Intelligence
(Intelligence on Information publicly available)
WhoIs Records – First things first.
• Reveals Email ID
• Reveals Contact Person
• Some Other Basic information.
DNS Records
• CNAME Records – Gives you subdomains
• MX Records – Check for attacks on Mail Server.
• A records – IP Addresses
Domain History
• Abc.com uses Cloudflare / Incapsula / Sucuri.
• All DNS Traffic is routed.
• Domain History reveals earlier IP Addresses.
• If IP still hosts the website, Bypass all rate limiting, firewall rules, etc.
Wappalyzer
• Profiles the technologies a website is using.
• Vulnerabilities associated with these technologies can also be listed
via CVEDetails.com.
• Have fun. ;)
• Buildwith is also a good option, though automating Wappalyzer is
easy.
• Both available as Firefox Addons as well.
PunkSpider, OpenVuln, SSl labs, etc.
• Pass domain and check for vulnerabilities found by scanners / other
researchers.
• SSL Labs scans all the SSL / TLS related issue. You get niche testing
done without hitting from your own IP.
Search Engines
• Shodan | Censys | ZoomEye – Computer Search Engines
• NerdyData | GitRob | MeanPath – Code Search Engines
• Pipl | Yasni – People Search Engines
• TrueCaller - Phone number Search Engine
• Google | Yandex | Bing – General Search Engines
• DuckDuckGo – Combines multiple search engine
• WolfRamAlpha – Computational Search Engine
• Computer Search Engine
• Locate exposed portals / legacy dashboards.
• Code Search Engines
• Look for vulnerable codes. Juicy targets. Wow.
• People Search Engines
• Profiling specific User
• TrueCaller / ThatsThem
• Phone number lookup.
Enumerate Subdomains
• Trickiest part.
• Knock.py type scripts available for brute-forcing the subdomains.
• Too much noise, not that effective. Can’t brute force longer
subdomain names.
• WolfRamAlpha - Advanced Data
• DNSDumpster
• Netcraft
• Automate! Hit It!
Extract files, Extract meta data from them.
• Filetype search via Google /
Yandex / Bing / etc.
• Spider the site.
• Extract all files, eg. PDF, SWF, etc.
• Extract Metadata
• Run Exif Tool ~ Application
version, author, etc.
Enumerate Emails Associated.
• Emailhunter
• SimplyEmail.py
Breach Status?
• Have I Been Pwned?
• Breach or Clear?
• If email is found to be a part of breach? Is the breach data public?
• Quite often, people use same password for more than one account.
Osint on Email
• Find Gravatar
• Tinyeye.com / Google Reverse Image Search / FindFace
• Information from Facebook / Google Plus / Blog / Linkedin
• Harvest username.
• ClearBit
Osint on Username
• UserSherlock / NameCheck / Knowem
• Tweets. Woah! Woah! Woah!
• Instagram Check-ins / Facebook Check-ins
• Github repos > Employees don’t give a shit to Security.
• ApiKeys? Access Tokens? Passwords? DB Creds? What not?
• Secret keys once committed, cannot be deleted, Unless the whole repo is
deleted.
• Gravatar / Profile Image > Reverse Image Search.
Create list of targeted passwords ~ username
Search domain in Github
• https://github.com/search?q=“example.com”&type=Code
• Specifically check Server side codes, .php, .py, .asp, .jsp, etc.
• No High Sev bug > Get creds from Git. w00t w00t. :D
Trace check-ins from Instagram / Facebook
Facebook Stuff.
• http://graph.tips/
• https://inteltechniques.com/intel/OSINT/facebook.html
Check S3 buckets / Windows blobs for access
controls.
• bucketfinder.rb < searches s3 buckets based on keywords.
• Bucket name nomenclature:
• https://bucketname.s3.amazonaws.com
• https://s3.amazonaws.com/bucketname
• Install aws-cli, configure it. Free credits from AWS will get you aws secret keys and api keys.
• By default AWS buckets are private. But devs are too smart sometimes ;)
• Simple checks
• aws s3 ls s3://bucketname
• aws s3 mv ../../Downloads/filename.txt s3://bucketname
Obtain Government Data [Pan Card / Voter
Card Information]
• Name + DoB = Pan Card Information
• Name + DoB + Native Place = Voter card Information
• http://electoralsearch.in/##resultArea
• DoB : Username Osint / Social media.
• DD/MM is public. YYYY can be enumerated from Linkedin profile.
Visualize Data
• Maltego
• Various python Libraries
• Lumio
• ElasticSearch / Kibana
Monitoring and Alerting
• Use streaming APIs if possible
• Dump data in ES / MongoDb / Db of your choice.
• Calculates hashes. Alerting on top of it.
• For Elasticsearch, ElastAlert is cool. (Frequency / Spike / Negation /
etc.) http://nullcon.net/website/nullcon-2016/training/attack-monitoring-using-elasticsearch-logstash-kibana.php
• Facilitates alerts on Jira, Hipcha, Slack, Email, Bash Commands ~
(Perform an action).
Null Humla on OSINT
https://bitbucket.org/null0x00/null-blr-humla-osint-
dec-
2015/src/5fdef0599552b46d632e57a7c2dc00d65e27d
613/HumlaSummary.txt?at=master&fileviewer=file-
view-default
Quick Basic Demo?
https://github.com/upgoingstar/datasploit
Open Source Intelligence (OSINT)- Testcases for Pentesters

Contenu connexe

Dernier

Lecture_2_Deep_Learning_Overview-newone1
Lecture_2_Deep_Learning_Overview-newone1Lecture_2_Deep_Learning_Overview-newone1
Lecture_2_Deep_Learning_Overview-newone1
ranjankumarbehera14
 
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
nirzagarg
 
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Klinik kandungan
 
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi ArabiaIn Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
ahmedjiabur940
 
Gartner's Data Analytics Maturity Model.pptx
Gartner's Data Analytics Maturity Model.pptxGartner's Data Analytics Maturity Model.pptx
Gartner's Data Analytics Maturity Model.pptx
chadhar227
 
Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
HyderabadDolls
 
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...
gajnagarg
 
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
nirzagarg
 
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
gajnagarg
 

Dernier (20)

Charbagh + Female Escorts Service in Lucknow | Starting ₹,5K To @25k with A/C...
Charbagh + Female Escorts Service in Lucknow | Starting ₹,5K To @25k with A/C...Charbagh + Female Escorts Service in Lucknow | Starting ₹,5K To @25k with A/C...
Charbagh + Female Escorts Service in Lucknow | Starting ₹,5K To @25k with A/C...
 
RESEARCH-FINAL-DEFENSE-PPT-TEMPLATE.pptx
RESEARCH-FINAL-DEFENSE-PPT-TEMPLATE.pptxRESEARCH-FINAL-DEFENSE-PPT-TEMPLATE.pptx
RESEARCH-FINAL-DEFENSE-PPT-TEMPLATE.pptx
 
Statistics notes ,it includes mean to index numbers
Statistics notes ,it includes mean to index numbersStatistics notes ,it includes mean to index numbers
Statistics notes ,it includes mean to index numbers
 
Lecture_2_Deep_Learning_Overview-newone1
Lecture_2_Deep_Learning_Overview-newone1Lecture_2_Deep_Learning_Overview-newone1
Lecture_2_Deep_Learning_Overview-newone1
 
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
 
Gomti Nagar & best call girls in Lucknow | 9548273370 Independent Escorts & D...
Gomti Nagar & best call girls in Lucknow | 9548273370 Independent Escorts & D...Gomti Nagar & best call girls in Lucknow | 9548273370 Independent Escorts & D...
Gomti Nagar & best call girls in Lucknow | 9548273370 Independent Escorts & D...
 
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
 
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi ArabiaIn Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
 
High Profile Call Girls Service in Jalore { 9332606886 } VVIP NISHA Call Girl...
High Profile Call Girls Service in Jalore { 9332606886 } VVIP NISHA Call Girl...High Profile Call Girls Service in Jalore { 9332606886 } VVIP NISHA Call Girl...
High Profile Call Girls Service in Jalore { 9332606886 } VVIP NISHA Call Girl...
 
SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...
SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...
SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...
 
Gartner's Data Analytics Maturity Model.pptx
Gartner's Data Analytics Maturity Model.pptxGartner's Data Analytics Maturity Model.pptx
Gartner's Data Analytics Maturity Model.pptx
 
5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed
5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed
5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed
 
Top Call Girls in Balaghat 9332606886Call Girls Advance Cash On Delivery Ser...
Top Call Girls in Balaghat  9332606886Call Girls Advance Cash On Delivery Ser...Top Call Girls in Balaghat  9332606886Call Girls Advance Cash On Delivery Ser...
Top Call Girls in Balaghat 9332606886Call Girls Advance Cash On Delivery Ser...
 
Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
 
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...
 
7. Epi of Chronic respiratory diseases.ppt
7. Epi of Chronic respiratory diseases.ppt7. Epi of Chronic respiratory diseases.ppt
7. Epi of Chronic respiratory diseases.ppt
 
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
 
20240412-SmartCityIndex-2024-Full-Report.pdf
20240412-SmartCityIndex-2024-Full-Report.pdf20240412-SmartCityIndex-2024-Full-Report.pdf
20240412-SmartCityIndex-2024-Full-Report.pdf
 
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
 
Discover Why Less is More in B2B Research
Discover Why Less is More in B2B ResearchDiscover Why Less is More in B2B Research
Discover Why Less is More in B2B Research
 

En vedette

How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
ThinkNow
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

En vedette (20)

Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 

Open Source Intelligence (OSINT)- Testcases for Pentesters

  • 1. OSINT Testcases for Pentesters @upgoingstar | shubham@shubhammittal.net
  • 2. Who Am I? • Shubham Mittal • 4+ years of experience ~ Offensive & Defensive roles. • InfoSec Consultant. Trainer @ Nullcon. • Interests in PT, OSINT, Infrastructure Security. • Projects: Datasploit • Biker, Beat Boxer, Blogger. @upgoingstar | shubhammittal.net | shubham@shubhammittal.net
  • 3. Internet gives you RAW Data. Harvest it. OSINT – Open Source Intelligence (Intelligence on Information publicly available)
  • 4. WhoIs Records – First things first. • Reveals Email ID • Reveals Contact Person • Some Other Basic information.
  • 5. DNS Records • CNAME Records – Gives you subdomains • MX Records – Check for attacks on Mail Server. • A records – IP Addresses
  • 6. Domain History • Abc.com uses Cloudflare / Incapsula / Sucuri. • All DNS Traffic is routed. • Domain History reveals earlier IP Addresses. • If IP still hosts the website, Bypass all rate limiting, firewall rules, etc.
  • 7. Wappalyzer • Profiles the technologies a website is using. • Vulnerabilities associated with these technologies can also be listed via CVEDetails.com. • Have fun. ;) • Buildwith is also a good option, though automating Wappalyzer is easy. • Both available as Firefox Addons as well.
  • 8. PunkSpider, OpenVuln, SSl labs, etc. • Pass domain and check for vulnerabilities found by scanners / other researchers. • SSL Labs scans all the SSL / TLS related issue. You get niche testing done without hitting from your own IP.
  • 9. Search Engines • Shodan | Censys | ZoomEye – Computer Search Engines • NerdyData | GitRob | MeanPath – Code Search Engines • Pipl | Yasni – People Search Engines • TrueCaller - Phone number Search Engine • Google | Yandex | Bing – General Search Engines • DuckDuckGo – Combines multiple search engine • WolfRamAlpha – Computational Search Engine
  • 10. • Computer Search Engine • Locate exposed portals / legacy dashboards. • Code Search Engines • Look for vulnerable codes. Juicy targets. Wow. • People Search Engines • Profiling specific User • TrueCaller / ThatsThem • Phone number lookup.
  • 11. Enumerate Subdomains • Trickiest part. • Knock.py type scripts available for brute-forcing the subdomains. • Too much noise, not that effective. Can’t brute force longer subdomain names. • WolfRamAlpha - Advanced Data • DNSDumpster • Netcraft • Automate! Hit It!
  • 12. Extract files, Extract meta data from them. • Filetype search via Google / Yandex / Bing / etc. • Spider the site. • Extract all files, eg. PDF, SWF, etc. • Extract Metadata • Run Exif Tool ~ Application version, author, etc.
  • 13. Enumerate Emails Associated. • Emailhunter • SimplyEmail.py
  • 14. Breach Status? • Have I Been Pwned? • Breach or Clear? • If email is found to be a part of breach? Is the breach data public? • Quite often, people use same password for more than one account.
  • 15. Osint on Email • Find Gravatar • Tinyeye.com / Google Reverse Image Search / FindFace • Information from Facebook / Google Plus / Blog / Linkedin • Harvest username. • ClearBit
  • 16. Osint on Username • UserSherlock / NameCheck / Knowem • Tweets. Woah! Woah! Woah! • Instagram Check-ins / Facebook Check-ins • Github repos > Employees don’t give a shit to Security. • ApiKeys? Access Tokens? Passwords? DB Creds? What not? • Secret keys once committed, cannot be deleted, Unless the whole repo is deleted. • Gravatar / Profile Image > Reverse Image Search.
  • 17. Create list of targeted passwords ~ username
  • 18. Search domain in Github • https://github.com/search?q=“example.com”&type=Code • Specifically check Server side codes, .php, .py, .asp, .jsp, etc. • No High Sev bug > Get creds from Git. w00t w00t. :D
  • 19. Trace check-ins from Instagram / Facebook
  • 20. Facebook Stuff. • http://graph.tips/ • https://inteltechniques.com/intel/OSINT/facebook.html
  • 21. Check S3 buckets / Windows blobs for access controls. • bucketfinder.rb < searches s3 buckets based on keywords. • Bucket name nomenclature: • https://bucketname.s3.amazonaws.com • https://s3.amazonaws.com/bucketname • Install aws-cli, configure it. Free credits from AWS will get you aws secret keys and api keys. • By default AWS buckets are private. But devs are too smart sometimes ;) • Simple checks • aws s3 ls s3://bucketname • aws s3 mv ../../Downloads/filename.txt s3://bucketname
  • 22. Obtain Government Data [Pan Card / Voter Card Information] • Name + DoB = Pan Card Information • Name + DoB + Native Place = Voter card Information • http://electoralsearch.in/##resultArea • DoB : Username Osint / Social media. • DD/MM is public. YYYY can be enumerated from Linkedin profile.
  • 23. Visualize Data • Maltego • Various python Libraries • Lumio • ElasticSearch / Kibana
  • 24. Monitoring and Alerting • Use streaming APIs if possible • Dump data in ES / MongoDb / Db of your choice. • Calculates hashes. Alerting on top of it. • For Elasticsearch, ElastAlert is cool. (Frequency / Spike / Negation / etc.) http://nullcon.net/website/nullcon-2016/training/attack-monitoring-using-elasticsearch-logstash-kibana.php • Facilitates alerts on Jira, Hipcha, Slack, Email, Bash Commands ~ (Perform an action).
  • 25. Null Humla on OSINT https://bitbucket.org/null0x00/null-blr-humla-osint- dec- 2015/src/5fdef0599552b46d632e57a7c2dc00d65e27d 613/HumlaSummary.txt?at=master&fileviewer=file- view-default