- Joined
- Dec 30, 2024
- Messages
- 381
- Reaction score
- 206
- Points
- 62
- Website
- blackhatpakistan.net
- Points
- 1,033
- USD
- 1,033
An OSINT tools for beginners guide covers the open-source intelligence stack: gathering target data from public sources - usernames, emails, domains, infrastructure, people - using tools that query what is already exposed instead of touching the target's systems. This guide runs the full beginner workflow: username enumeration across platforms, email and domain recon, infrastructure mapping, people search, and the note-taking discipline that keeps findings usable when the report is due.
TL;DR - The three questions every OSINT engagement starts with: who is this person/entity, what infrastructure do they own, where have their credentials appeared. The toolset that answers them: Sherlock and Maigret for usernames, theHarvester for emails and subdomains, holehe for email account mapping, Shodan and Censys for infrastructure, and SpiderFoot or Maltego to chain it all. Everything below is passive until you decide otherwise - passive first, active only with scope.
CORE TOOLSET - INSTALL ONCE
STAGE 1 - USERNAME ENUMERATION
One username, hundreds of sites:
What comes back: profile URLs that exist. Visit each manually and read what the bio, join date, and post history expose - the tool finds the door, you read the room. Cross-reference usernames across platforms to stitch identities: same handle on GitHub (real name in commits), Reddit (opinions), and Instagram (face) is a full picture from three public pages.
STAGE 2 - EMAIL RECON
holehe deserves special mention: it probes registration endpoints of hundreds of services and tells you where an email has an account - Spotify plus a niche forum plus a dev platform maps a person's digital life without touching them.
STAGE 3 - DOMAIN AND INFRASTRUCTURE
Certificate transparency logs (crt.sh) are the beginner's favorite: every TLS cert ever issued for a domain is public, including staging and internal hostnames admins forgot - a single query often doubles the attack surface you knew about.
STAGE 4 - PEOPLE AND GEO
Yandex reverse image consistently beats Google for faces - a known asymmetry in face-search quality worth remembering.
STAGE 5 - CHAINING - SPIDERFOOT AND MALTEGO
Manual CLI runs give fragments; automation connects them:
SpiderFoot on default settings pulls everything passive - run it first, read the event list, then decide which findings deserve active follow-up.
RECON THAT FEEDS TESTING
That chain - OSINT to live host list to scan - is how scoped engagements actually start. The targets came from public logs, not guessing.
OPSEC AND LEGAL LINES
- Passive first: DNS, cert logs, search engines, archived pages - no packets to the target
- Active checks (direct connection, port scans) need written scope, same as every other tool here
- Archiving: web.archive.org snapshots catch pages deleted after the fact - check dates
- Accounts you create for research are themselves an OPSEC surface: clean browser profile, dedicated email, no personal data
NOTE TAKING - THE DISCIPLINE NOBODY TEACHES
The report writes itself from structured notes; from screenshots and memory it takes a week.
FAQ
Q: What is the first tool to run on a username?
A: Sherlock (fast, clean output), then Maigret if you want breadth, then manual review of the found profiles. Tools find URLs; the intelligence comes from reading what is on them.
Q: OSINT versus hacking?
A: OSINT reads what is public - search engines, DNS, certificates, posted content, breach corpora. No system of the target is accessed. The moment you touch their infrastructure directly, you are in pentest territory and need scope.
Q: How do I stay anonymous while doing OSINT?
A: Dedicated browser profile, no personal accounts logged in, Tor or a clean VPS for collection, and never interact (no follows, no logins to target-adjacent services) during passive phases.
Q: Where do beginners usually waste time?
A: Collecting everything instead of answering one question. Pick the entity, pick the three questions, run the four stages above, stop when the questions are answered.
RELATED ON BLACKHAT PAKISTAN
Nmap Cheat Sheet 2026 - OSINT found the hosts, nmap maps the services.
Simple Dork Generator - search dorks at scale for stage-1 discovery.
Kali Linux Tools List 2026 - recon tools in the full attack-phase stack.
Burp Suite Tutorial for Beginners - when passive collection ends and testing begins.
TL;DR - The three questions every OSINT engagement starts with: who is this person/entity, what infrastructure do they own, where have their credentials appeared. The toolset that answers them: Sherlock and Maigret for usernames, theHarvester for emails and subdomains, holehe for email account mapping, Shodan and Censys for infrastructure, and SpiderFoot or Maltego to chain it all. Everything below is passive until you decide otherwise - passive first, active only with scope.
CORE TOOLSET - INSTALL ONCE
Code:
pip install sherlock-holehe
sudo apt install theharvester
git clone https://github.com/saeeddhqan/miqdb || true # username enum
# Shodan: account + API key from shodan.io
# SpiderFoot: sudo apt install spiderfoot, web UI on 5001
STAGE 1 - USERNAME ENUMERATION
One username, hundreds of sites:
Code:
sherlock username --print-found
maigret username -o maigret_report.txt # bigger site list, json output
namechk, instantusername # web fallbacks when CLIs rate-limit
What comes back: profile URLs that exist. Visit each manually and read what the bio, join date, and post history expose - the tool finds the door, you read the room. Cross-reference usernames across platforms to stitch identities: same handle on GitHub (real name in commits), Reddit (opinions), and Instagram (face) is a full picture from three public pages.
STAGE 2 - EMAIL RECON
Code:
theHarvester -d target.com -b all emails + subdomains + hosts
holehe email@gmail.com which services this email registered with
mailcat email@domain.com client-side footprint (outlook headers, etc.)
haveibeenpwned API breach exposure per email
holehe deserves special mention: it probes registration endpoints of hundreds of services and tells you where an email has an account - Spotify plus a niche forum plus a dev platform maps a person's digital life without touching them.
STAGE 3 - DOMAIN AND INFRASTRUCTURE
Code:
whois target.com registration, nameservers, dates
dnsrecon -d target.com -a full record sweep (A, MX, TXT, SPF, NS)
subfinder -d target.com passive subdomain enumeration
amass enum -d target.com deeper subdomain graph
crt.sh query: %.target.com certificate transparency log mining
shodan search org:"Target Inc" exposed services, banners, ports
censys search target.com certificate + service inventory
wappalyzer / whatweb https://target.com technology stack fingerprint
Certificate transparency logs (crt.sh) are the beginner's favorite: every TLS cert ever issued for a domain is public, including staging and internal hostnames admins forgot - a single query often doubles the attack surface you knew about.
STAGE 4 - PEOPLE AND GEO
Code:
Google Dorks: "firstname lastname" target.com filetype:pdf
Social searcher: social-searcher.com, mention.com for name mentions
Wiki / filings: company officers via corporate registries
Images: reverse image search (Google, Yandex for faces)
Geo: EXIF on posted photos (exiftool), geohints in backgrounds
Yandex reverse image consistently beats Google for faces - a known asymmetry in face-search quality worth remembering.
STAGE 5 - CHAINING - SPIDERFOOT AND MALTEGO
Manual CLI runs give fragments; automation connects them:
Code:
spiderfoot -l 127.0.0.1:5001 web UI, 200+ modules
# feed an email or domain -> it runs subdomain, DNS, breach, netblock, and social modules
# review the graph, export the event chain
Maltego (community edition) visual graph, transforms between entity types
# email -> accounts -> usernames -> linked profiles -> other emails
SpiderFoot on default settings pulls everything passive - run it first, read the event list, then decide which findings deserve active follow-up.
RECON THAT FEEDS TESTING
Code:
subfinder -d target.com -o subs.txt subdomains
amass enum -d target.com >> subs.txt
httpx -l subs.txt -sc -title -td live hosts with status + title
nmap -iL live.txt -sV -T4 -oA osint_pass service scan of OSINT-derived hosts
That chain - OSINT to live host list to scan - is how scoped engagements actually start. The targets came from public logs, not guessing.
OPSEC AND LEGAL LINES
- Passive first: DNS, cert logs, search engines, archived pages - no packets to the target
- Active checks (direct connection, port scans) need written scope, same as every other tool here
- Archiving: web.archive.org snapshots catch pages deleted after the fact - check dates
- Accounts you create for research are themselves an OPSEC surface: clean browser profile, dedicated email, no personal data
NOTE TAKING - THE DISCIPLINE NOBODY TEACHES
Code:
One note per entity, fields kept consistent:
Identifier | Source | Date observed | Confidence | Raw quote/link
Timelines beat lists - join dates and post dates construct sequences
Confidence tags: confirmed (direct source), likely (inference), unverified (single weak source)
The report writes itself from structured notes; from screenshots and memory it takes a week.
FAQ
Q: What is the first tool to run on a username?
A: Sherlock (fast, clean output), then Maigret if you want breadth, then manual review of the found profiles. Tools find URLs; the intelligence comes from reading what is on them.
Q: OSINT versus hacking?
A: OSINT reads what is public - search engines, DNS, certificates, posted content, breach corpora. No system of the target is accessed. The moment you touch their infrastructure directly, you are in pentest territory and need scope.
Q: How do I stay anonymous while doing OSINT?
A: Dedicated browser profile, no personal accounts logged in, Tor or a clean VPS for collection, and never interact (no follows, no logins to target-adjacent services) during passive phases.
Q: Where do beginners usually waste time?
A: Collecting everything instead of answering one question. Pick the entity, pick the three questions, run the four stages above, stop when the questions are answered.
RELATED ON BLACKHAT PAKISTAN
Nmap Cheat Sheet 2026 - OSINT found the hosts, nmap maps the services.
Simple Dork Generator - search dorks at scale for stage-1 discovery.
Kali Linux Tools List 2026 - recon tools in the full attack-phase stack.
Burp Suite Tutorial for Beginners - when passive collection ends and testing begins.
Code:
0. entity decided, three questions written down
1. sherlock + maigret usernames across platforms
2. theHarvester + holehe emails, registrations, subdomains
3. crt.sh + subfinder hidden infrastructure
4. shodan (org search) exposed services, banners
5. spiderfoot chain everything passive in one run
6. structured notes with source + date + confidence