In this week’s episode I’m going to cover OSINT or Open Source Intelligence. I’ll share with you some tools and apps you can use to scrub the internet for data, and how to use these common tools to your advantage while you’re at the office or mobile.
Now I’m no expert in data mining. I’ve been learning as I go so I’m not going to be talking about hacks and some super serious tools and super secret squirrels with black hats. But I think the information that I’ll provide you will be very useful for the security practitioner to protect people, data, and property.
What is OSINT? Open Source Intelligence involves, finding, selecting, and acquiring information from publicly available sources and analyzing it to produce actionable intelligence.
The internet has become the place get answers to your problems. Gone are the days of thumbing through the yellow pages. When someone needs a plumber, find a bank, a gas station to fix the car, whatever the issue we look to the internet for our answers. With the proliferation of social media networks such as Facebook and Twitter, more and more people are posting and sharing information about themselves, their families, their pets, jobs, vacations, etc publicly – for all the world to see. The old Monday morning water cooler, gossip, gripes, and groans has transitioned to social media networks. If you are on social media it isn’t private – you might think so, but you are still sharing information with your friends – and your friends can share your information with the world.
The advantage of this information for the security practitioner is that the bad guys use social media networks too. From Al qaida to the Occupy protesters – all are using some form of social media to organize and communicate.
Open Source Intelligence Tools Mentioned:
Twitter search: http://search.twitter.comTwitter trends map: http://www.trendsmap.comGoogle advanced search: http://google.com/advanced_searchGoogle blog search: http://google.com/blogsearchGoogle Reader: http://google.com/readerGoogle Alerts: http://google.com/alertsIf This, then that: http://ifttt.comYahoo pipes: http://pipes.yahoo.comWatching content changes: http://watchthatpage.comBan.jo App: http://ban.joCreepy – Geolocation aggregator: http://ilektrojohn.github.com/creepy/MetaGoofil: http://www.edge-security.com/metagoofil.phphttp://whostalkin.comhttp://socialmention.comComplex search examples for searching the big 3 (Google, Bing and Yahoo):
Search LinkedIn profiles – site:linkedin.com inurl:pub ( “Fidelity Investments”)Search LinkedIn updates – site:linkedin.com inurl:updates (bofa | “Bank of America”)Search LinkedIn companies – site:linkedin.com inurl:companies ( “Novartis”)Search Facebook groups – site:facebook.com inurl:groups (“militia”)Search Facebook pages – site:facebook.com inurl:pages (“bank of america sucks”)Search Profiles – allinurl:people “Jane Doe” site:facebook.comReplace what’s in the parentheses and quotes with your specific keywords and phrases and replace site with your websites.
What are some of your favorite open source tools that you use? Post in the comment below.
The post Open Source Intelligence Tools appeared first on Strategic Marketing Solutions.