• Blackhat Pakistan — Ethical Hacking, Hacking Tools & Cybersecurity Tutorials

OSINT Tools for Beginners

Blackhatpakistan

Administrator
Staff member
Joined
Dec 30, 2024
Messages
388
Reaction score
206
Points
62
Website
blackhatpakistan.net
Points
1,068
USD
1,068
An OSINT tools for beginners guide covers the open-source intelligence stack: gathering target data from public sources - usernames, emails, domains, infrastructure, people - using tools that query what is already exposed instead of touching the target's systems. This guide runs the full beginner workflow: username enumeration across platforms, email and domain recon, infrastructure mapping, people search, and the note-taking discipline that keeps findings usable when the report is due.

TL;DR - The three questions every OSINT engagement starts with: who is this person/entity, what infrastructure do they own, where have their credentials appeared. The toolset that answers them: Sherlock and Maigret for usernames, theHarvester for emails and subdomains, holehe for email account mapping, Shodan and Censys for infrastructure, and SpiderFoot or Maltego to chain it all. Everything below is passive until you decide otherwise - passive first, active only with scope.

CORE TOOLSET - INSTALL ONCE

Code:
pip install sherlock-holehe
sudo apt install theharvester
git clone https://github.com/saeeddhqan/miqdb || true     # username enum
# Shodan: account + API key from shodan.io
# SpiderFoot: sudo apt install spiderfoot, web UI on 5001

STAGE 1 - USERNAME ENUMERATION

One username, hundreds of sites:

Code:
sherlock username --print-found
maigret username -o maigret_report.txt       # bigger site list, json output
namechk, instantusername                      # web fallbacks when CLIs rate-limit

What comes back: profile URLs that exist. Visit each manually and read what the bio, join date, and post history expose - the tool finds the door, you read the room. Cross-reference usernames across platforms to stitch identities: same handle on GitHub (real name in commits), Reddit (opinions), and Instagram (face) is a full picture from three public pages.

STAGE 2 - EMAIL RECON

Code:
theHarvester -d target.com -b all              emails + subdomains + hosts
holehe email@gmail.com                          which services this email registered with
mailcat email@domain.com                        client-side footprint (outlook headers, etc.)
haveibeenpwned API                              breach exposure per email

holehe deserves special mention: it probes registration endpoints of hundreds of services and tells you where an email has an account - Spotify plus a niche forum plus a dev platform maps a person's digital life without touching them.

STAGE 3 - DOMAIN AND INFRASTRUCTURE

Code:
whois target.com                                registration, nameservers, dates
dnsrecon -d target.com -a                       full record sweep (A, MX, TXT, SPF, NS)
subfinder -d target.com                         passive subdomain enumeration
amass enum -d target.com                        deeper subdomain graph
crt.sh query: %.target.com                      certificate transparency log mining
shodan search org:"Target Inc"                  exposed services, banners, ports
censys search target.com                        certificate + service inventory
wappalyzer / whatweb https://target.com         technology stack fingerprint

Certificate transparency logs (crt.sh) are the beginner's favorite: every TLS cert ever issued for a domain is public, including staging and internal hostnames admins forgot - a single query often doubles the attack surface you knew about.

STAGE 4 - PEOPLE AND GEO

Code:
Google Dorks:      "firstname lastname" target.com filetype:pdf
Social searcher:   social-searcher.com, mention.com for name mentions
Wiki / filings:    company officers via corporate registries
Images:            reverse image search (Google, Yandex for faces)
Geo:               EXIF on posted photos (exiftool), geohints in backgrounds

Yandex reverse image consistently beats Google for faces - a known asymmetry in face-search quality worth remembering.

STAGE 5 - CHAINING - SPIDERFOOT AND MALTEGO

Manual CLI runs give fragments; automation connects them:

Code:
spiderfoot -l 127.0.0.1:5001                  web UI, 200+ modules
# feed an email or domain -> it runs subdomain, DNS, breach, netblock, and social modules
# review the graph, export the event chain

Maltego (community edition)                     visual graph, transforms between entity types
# email -> accounts -> usernames -> linked profiles -> other emails

SpiderFoot on default settings pulls everything passive - run it first, read the event list, then decide which findings deserve active follow-up.

RECON THAT FEEDS TESTING

Code:
subfinder -d target.com -o subs.txt             subdomains
amass enum -d target.com >> subs.txt
httpx -l subs.txt -sc -title -td                  live hosts with status + title
nmap -iL live.txt -sV -T4 -oA osint_pass          service scan of OSINT-derived hosts

That chain - OSINT to live host list to scan - is how scoped engagements actually start. The targets came from public logs, not guessing.

OPSEC AND LEGAL LINES

- Passive first: DNS, cert logs, search engines, archived pages - no packets to the target
- Active checks (direct connection, port scans) need written scope, same as every other tool here
- Archiving: web.archive.org snapshots catch pages deleted after the fact - check dates
- Accounts you create for research are themselves an OPSEC surface: clean browser profile, dedicated email, no personal data

NOTE TAKING - THE DISCIPLINE NOBODY TEACHES

Code:
One note per entity, fields kept consistent:
  Identifier | Source | Date observed | Confidence | Raw quote/link
Timelines beat lists - join dates and post dates construct sequences
Confidence tags: confirmed (direct source), likely (inference), unverified (single weak source)

The report writes itself from structured notes; from screenshots and memory it takes a week.

FAQ

Q: What is the first tool to run on a username?
A: Sherlock (fast, clean output), then Maigret if you want breadth, then manual review of the found profiles. Tools find URLs; the intelligence comes from reading what is on them.

Q: OSINT versus hacking?
A: OSINT reads what is public - search engines, DNS, certificates, posted content, breach corpora. No system of the target is accessed. The moment you touch their infrastructure directly, you are in pentest territory and need scope.

Q: How do I stay anonymous while doing OSINT?
A: Dedicated browser profile, no personal accounts logged in, Tor or a clean VPS for collection, and never interact (no follows, no logins to target-adjacent services) during passive phases.

Q: Where do beginners usually waste time?
A: Collecting everything instead of answering one question. Pick the entity, pick the three questions, run the four stages above, stop when the questions are answered.

RELATED ON BLACKHAT PAKISTAN

Nmap Cheat Sheet 2026 - OSINT found the hosts, nmap maps the services.
Simple Dork Generator - search dorks at scale for stage-1 discovery.
Kali Linux Tools List 2026 - recon tools in the full attack-phase stack.
Burp Suite Tutorial for Beginners - when passive collection ends and testing begins.

Code:
0. entity decided, three questions written down
1. sherlock + maigret       usernames across platforms
2. theHarvester + holehe    emails, registrations, subdomains
3. crt.sh + subfinder       hidden infrastructure
4. shodan (org search)      exposed services, banners
5. spiderfoot               chain everything passive in one run
6. structured notes with source + date + confidence
 
Threads
1,073Threads
Messages
2,132Messages
Members
3,704Members
Latest member
AlaricalaraLatest member
Top