
An introduction to the course, myself, and expectations for OSINT
Explore open source intelligence (osint) using data from publicly available sources to build a broader picture, including emails, social media, background checks, and users like law enforcement and journalists.
Develop mental preparation for investigations by staying calm, setting goals, and pacing through emotionally challenging findings. Stay organized, decompress, and remain objective when facing disturbing content from the dark web.
Learn osint steps from defining the goal and starting evidence to a checklist-driven process that begins with a social media post and includes credibility checks, domain lookups, and reporting.
What will you need for this course?
Osint tools and websites will break as platforms change; stay flexible by using alternative tools or fall back on solid methodology to continue open-source investigations.
Ask what information the client already has before beginning an investigation to save time, avoid redundancy, and tailor findings to what they need.
Navigate ethical and legal boundaries in osint, recognizing investigators must stay lawful and avoid phishing or illegal scans; follow local laws and client guidelines to do everything by the book.
Maintain objectivity by recognizing personal biases, resisting outside influence, and verifying evidence to uncover the truth in investigations, while avoiding misleading sources and conclusions.
Explore how to structure an OSINT investigation with templates and client intake, defining scope, data handling, and reporting, using CSI Linux case tools for open-source and dark web investigations.
Learn to craft clear osint reports by drafting a pre-investigation contract, defining scope and milestones, and using a data collection matrix with reliability ratings to explain findings.
Demonstrates OSINT templates and intake forms for documenting investigations, including subject profiles, digital footprints, social media, assets, and evidence logs, plus client intake and scoping essentials.
What is virtualization? We discuss what virtualization is and why you would want to use it.
Install CSI Linux, a Linux distro based off of Buntu for open source intelligence, and set up a virtualization workflow with VirtualBox and snapshots for a clean investigation environment.
In this video we will be going over some basic Linux terminal commands. While knowing terminal commands is not necessary for OSINT per se, it is useful o have a basic understanding of them.
Learn how to create and use sock puppets, burner accounts with fake identities, to protect investigators in OSINT and pen testing while avoiding links to real information.
Learn how to create Gmail sock puppet accounts without a real phone number by using burner smartphones, with typical limits around three accounts per day.
There may be times where we need to conceal our real identity or just need a burner telephone number, text message, and/or email. Sudo to the rescue! This is currently a iOS only app.
Using a temporary email solution instead of your burner email.
Compare free text apps such as text free and Textnow, and learn how to create sockpuppet texting accounts using disposable numbers or pseudo services to protect your real number.
Explore CSI Linux's built-in sock puppet builder for open-source intelligence. Generate a complete sock puppet dossier with demographic details, contact info, map coordinates, hashes, and a ready-to-use profile template.
In this video we talk about handling data and some tips on how not to become overwhelmed.
Open Cherry Tree templates for OSINT reports. Learn to embed images, create nodes, and export to PDF or HTML while preserving file hashes such as MD5 and SHA256.
These are a couple templates for a OSINT report. There is a technical report and a executive report template. Feel free to modify them to fit your needs.
Explore Obsidian, a cross-platform notation and note-taking tool, with canvas workflows, linking notes, graphs, and attachments, plus pricing, sync, and basic use cases across Windows, Linux, macOS, iOS, and Android.
In this video we look at some options to keep your data and yourself secure.
In this video we will be looking at some advanced search techniques using Google.
In this video we will be looking at Google maps and how it can be used in OSINT
In this video we talk about doing a reverse image search with Google.
Learn to perform a reverse image search with Google Images by uploading a file or URL, using exact image match to identify sources and dates, and speed up OSINT investigations.
Google and Twitter alerts
In this video we explore other reverse image options
Learn to extract geolocation from photo metadata, including latitude and longitude, using tools like geo imager. Double-check with reverse image search and Google Maps street view to verify.
Explore Greynoise to analyze IP addresses, tags, and malicious activity, viewing trends, alerts, and suggested actions to assess and respond to potential threats.
In this video we will be looking at some techniques to perform reverse email searches on our target.
Currently Behindemail is no longer in service.
Explore how phone numbers unlock osint insights—from area and country codes to voicemail clues, reverse lookups, and voip or burner number nuances.
Explore reverse phone lookup tools for the US and Europe, including search yellow directory.com/reverse-phone, comfy.com/book/reverse, and phi.com/a/book/reverse, with tips on country codes and cross-tool results.
In this video we will be looking at reverse number lookups.
Explore Minerva, a web-based email tool for OSINT, sign up for a free account, run a search to view breach histories and linked accounts, and export results as JSON.
In this video we look at some techniques and websites to perform OSINT on businesses.
Explore Black Book Online, a free public record lookup hub for jail inmate searches, death records, maps and satellite imagery, court and corporation lookups, and more, with privacy considerations noted.
Cibib is now xlek, thank you Everand for the heads up.
In this video we take a look at the breach site Dehashed.
In this video we learn about have i been pwned and how it can help in OSINT
Explore WebMe, a browser-based OSINT tool that lets you search for people, view visibility scores, and access biographies, social profiles, and news to audit online presence and privacy.
In this video we look at some resume finders and how they can be applied to OSINT
In this video we talk a look at how family trees can be applied to OSINT and some sites.
Discover how to verify whether someone is admitted to a hospital and what unit they are in, while adhering to HIPAA and GDPR and avoiding impersonation.
Explore how Instant Checkmate, a people search engine, helps generate leads and verify information, with timelines, reports, emails, phones, and licenses, while noting data may be old or missing.
Unmask Google users by sharing a blank Google doc and inspecting who has access to reveal the name tied to a Gmail account, an osint technique.
In this section we will be looking at Spiderfoot, a program designed to crawl websites and harvest information.
Clone websites with wget and HTTrack for offline research on CSI Linux, enabling investigators to inspect mirrored site structure and preserve offline copies.
Learn metagoofil, a command-line tool that searches websites for documents by domain and file type, such as pdf and xlsx, with usage options and download limits demonstrated.
The internet never forgets... In this video we will be looking at some options to retrieve lost pages from the internet.
learn how to use the internet archive to manually save web pages and media, initiate archiving with the wayback machine, and understand indexing delays.
Discover meta r, a beta OSINT tool that analyzes a full URL, fetching pages, detecting language, and inspecting HTTP headers, robots.txt, sitemaps, and SSL data.
Dot db is a global domain search tool that scans registered domains across languages. It enables keyword searches, shows active, parked, or inactive domains, and compares free versus paid tiers.
In this course you will be learning about OSINT (Open-source intelligence) from a hacker's point of view. Tools, techniques, setting up a virtual lab, and how to protect yourself. This is a comprehensive course that will be using free open source tools to investigate people and companies. No matter if you are totally new to the fascinating world of OSINT and hacking or have some experience, this course will walk you through how both hackers and investigators use these tools and why.
This course is designed to be beginner friendly and also help educate experienced individuals alike with a easy to follow and practical approach. Your safety is also important as we explore the use of sock puppets, a Linux virtual machine and more.
Worried about out of date content? I have gone through updating the content as things change, become obsolete, I find new cool tools, or techniques. These updates are free along with the bonus content.
Get stuck or have a question? Always feel free to send me a message and I will do my best to help you out!
FYI, a reminder: I not anyone that is a part of DGS has any affiliation with any of the vendors, software manufactures, or programmers in this course.