
Explore open source intelligence and dark web exploration, gaining hands-on experience with Osint tools like Maltego, The Harvester, Shodan, SpiderFoot, and Recon-ng to uncover public data.
Learn how osint turns public data into intelligence by defining targets, gathering and analyzing information, and verifying results within ethical, legal bounds using the harvester, Shodan, Maltego, and OSINT framework.
Explore the osint framework, navigate categories like email searches and breach data, and use haveibeenpwned to verify if an email has been breached.
Use Google dorking to uncover non-public information through targeted searches, combining operators like site:github.com and quoted terms to aid passive reconnaissance within legal and authorized bounds.
Explore how the OSINT framework and open source tools enable passive reconnaissance, using search engines, social media, image and video analysis, geospatial intelligence, and data correlation to verify information.
Explore the harvester tool to collect emails, subdomains, IPs, and other entity information via command line across macOS, Windows, and Linux, with installation options via Homebrew, GitHub, or apt.
Install the harvester on mac with brew, then run domain reconnaissance using Bing; github.com yields no results, while google.com reveals several hosts like accounts.google.com and maps.google.com.
Learn how to use the harvester tool for OSINT, selecting a target and domain, querying Google, Bing, or Yahoo, and saving emails, domains, hostnames, and IPs to a file.
Complete the assignment by using the harvester on a public domain to uncover email addresses, domain information, and IP details, practicing osint discovery beyond high-profile sites.
Install the harvester on a Mac, run it to extract domains, IP addresses, and email addresses for recon, while following legal authorization and anticipating the Shodan module.
Learn how Shodan, a search engine for internet connected devices, extends basic domain intel by revealing devices through web interface or CLI, using queries for ports, countries, products, and SSL.
Set up Shodan for osint by creating a free account, verifying email, and obtaining an api key; install the cli and run queries to reveal services, ports, and locations.
Utilize Shodan as a powerful tool for passive recon, exploring domains, ports, locations, and webcams via the search bar. Interpret results, using its filters, while applying legal and ethical cautions.
Participate in module three's quick quiz to search for apache products in Great Britain, examine related ports, and try ssl to uncover relevant findings.
Explore Shodan to map open ports, server locations, and product types, beyond Harvester and Google dorking; note unsecured webcams and metadata tools ExifTool and Fossa.
Learn metadata extraction from documents and domains using Forza and Exiftool, revealing emails, subdomains, servers, devices, and IoT cameras, with browser-based alternatives and legal sample files.
Install FOCA and ExifTool, prepare the demo with Windows as the recommended system, then run a scan via Google Doc or FOCA as shown.
Discover how FOCA searches domains for files, downloads documents, and analyzes results, then use ExifTool to extract metadata and GPS coordinates, while staying within legal limits.
Explore how metadata in downloaded documents can reveal sensitive information, signaling security gaps in an organization and guiding authorized penetration testing; consider why people remove metadata before sharing images.
Extract metadata and useful information from documents, pdfs, and images using the fossa tool, Google docking, and Exiftool to reveal online details and connections.
Learn visual link analysis with Maltego, mapping domains, IPs, and services like DNS; understand metadata removal as a security practice and use the community edition for reconnaissance.
Build and explore a simple maltego investigation graph by creating a new graph, adding domains, running transforms, and visualizing the web of connections from dns records to ips and emails.
Complete a true/false quiz on whether Maltego can automatically locate social media profiles from an email, then preview the upcoming topics on OSINT best practices and the dark web.
Explore osint best practices and how Maltego can reveal a person’s social media presence and profiles from an email address, illustrating the tool’s power to gather information on an entity.
Identify OSINT best practices as the first step for penetration testers, document findings, respect privacy, and collect only publicly available data with OSINT framework, Maltego, Fosa, and Exiftool.
Explore OSINT tools and the OSINT framework for passive recon. Use harvester, Shodan, Forza, Exiftool, and Maltego to analyze metadata, DNS, and open resources for organizational protection.
Explore the dark web as a deep web subset, apply security tips to stay anonymous and legal during OSINT research, and grasp foundational internet mechanics.
Explore how internet routing works with ping and traceroute, revealing hops, public IPs, and how Tor supports anonymity and privacy, countering crime on the dark web.
Safely navigate the dark web with operational security and anonymity practices, using Tor and onion addresses, while understanding legal, ethical, and data protection boundaries and risk management.
End module seven with a quiz on understanding the dark web, including the tor browser's role in anonymous access and the upcoming focus on setting up tor browser.
Set up tor browser for anonymous browsing on mac and windows. Understand onion router encryption and install a pre-configured firefox variant from the Tor Project with safe default settings.
Install and configure the Tor browser, enable automatic connection, and test tau three onion addresses for anonymous, safe browsing with no scripts or plugins.
Participate in a quiz on the Tor browser and onion sites, evaluate which statement about Tor and onion addresses is true, and prepare for Tor-based searches.
Explore Tor Browser for anonymous browsing, access onion sites, and learn Amaya Search to perform searches on the dark web that aren't available through normal search engines.
In module nine, learn about dark web search engines, focusing on safe tools like Ahmia. Use the Tor browser to access onion sites and perform simple searches.
Open Tor Browser and connect to Ahmia to access onion addresses for safe, legal recon and data analysis, reviewing email addresses from leaks within legal limits.
Complete the final module quiz by evaluating Ahmia’s use for searching onion sites and identifying true statements about its indexing and accessibility.
Explore data leak discovery with Intelligence X, a combined search engine and data archive for surface and dark web leaks, enabling recon across emails, domains, IP addresses, and Bitcoin addresses.
Learn to use Intelligence X in clearnet or Tor, log in, and search domains and identifiers for data leaks, using filters while respecting legal boundaries.
Answer the quiz on intelligent X for dark web discovery in osint investigations; the primary purpose is mapping tor hidden services and clustering related onion domains.
This 2-part course takes you deep into the worlds of OSINT (Open-Source Intelligence) and the Dark Web, teaching you how to gather intelligence safely and effectively using free, open-source tools for real-world applications.
In Part 1 (OSINT), you’ll master the art of uncovering valuable public data often hidden in plain sight. We’ll set up an OSINT toolkit on macOS and work hands-on with tools like Maltego CE for link analysis, theHarvester for emails and hosts, Shodan for device discovery, and SpiderFoot and Recon-ng for automated recon. Through guided demos and exercises, you’ll learn to transform raw data into meaningful, actionable intelligence.
In Part 2 (Dark Web Exploration), we’ll navigate the hidden parts of the internet accessible only via Tor. You'll learn how to safely set up the Tor Browser, use dark web search engines like Ahmia, and leverage platforms like Intelligence X to uncover leaked information and hidden services. We'll cover best practices for staying anonymous and discuss responsible, ethical exploration of the dark web.
By the end of the course, you’ll have real-world skills in OSINT and dark web research. Each section includes short assignments to reinforce your learning, leading up to a capstone project that ties everything together in a realistic investigative challenge.