appsec.fyi

OSINT — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

OSINT: A Practical Guide

Curated and synthesized by . Last updated 2026-10-01. Synthesized from 124 of 124 curated resources. Browse all 124 OSINT resources →

The Evolving Landscape of OSINT for Application Security Professionals

As application security professionals, our remit is broad. We secure code, infrastructure, and data, but increasingly, our responsibilities extend to understanding the intelligence an adversary might gather before they even attempt a technical exploit. Open-Source Intelligence (OSINT) is no longer just a tool for law enforcement or intelligence agencies; it's a critical component of a robust application security program. Adversaries are leveraging publicly available information to map attack surfaces, identify vulnerabilities, and even conduct social engineering attacks against development teams and users. Understanding OSINT from an attacker's perspective allows us to proactively identify and mitigate risks. This guide will delve into the core mechanics, notable techniques, and practical applications of OSINT relevant to appsec practitioners.

Core Mechanics of OSINT

At its heart, OSINT is the collection and analysis of information from publicly accessible sources to produce actionable intelligence [1]. The "open source" aspect refers not to open-source software, but to the overt and publicly available nature of the information itself [1][2]. This data can originate from a vast array of sources, including:

The process generally follows a lifecycle: defining objectives, discovering and collecting sources, processing and organizing data, analyzing and correlating findings, and finally, reporting and disseminating intelligence [11][12][13]. It is crucial to emphasize that ethical OSINT operates within legal boundaries and does not involve hacking or unauthorized access [1][12][14].

Notable OSINT Techniques for AppSec

For application security professionals, OSINT can illuminate potential vulnerabilities and expose an organization's digital footprint in ways that traditional security assessments might miss. Here are several key techniques:

1. Advanced Search Engine Operators (Google Dorking)

Google Dorking, or Google Hacking, leverages advanced search operators to refine search results and uncover information that might not be easily discoverable through standard queries [15][16][17][13]. This can include identifying exposed files, login pages, directory listings, or configuration files [16][17].

For example, searching site:yourcompany.com filetype:config inurl:web.config could reveal exposed configuration files [18]. Similarly, site:yourcompany.com intitle:"index of" can uncover directory listings [16][17]. Automated tools like DorkEye and DorkGenius can assist in generating and managing these queries [19].

2. Certificate Transparency (CT) Logs

Certificate Transparency logs are publicly accessible records of SSL/TLS certificates issued for domains [20]. By querying these logs, one can discover hostnames, including those for internal applications or codenamed projects that might not be intended for public visibility [20]. Tools like Certspotter (with a throttled free tier) and Gungnir can monitor CT logs for new certificates [20].

This technique can reveal internal tools, staging environments, or even development projects that have been inadvertently exposed on the public internet [20]. For an appsec professional, this is a direct way to discover potentially vulnerable internal applications that might be accessible from the outside.

3. Internet-Wide Scanning (Shodan, Censys, Netlas)

Services like Shodan, Censys, and Netlas scan the internet for connected devices and services, indexing open ports, service banners, SSL certificates, and device metadata [2][6][21][22][23][24][25][26][27]. They allow you to search for specific technologies, vulnerabilities, or even devices associated with an organization's IP ranges [2][6][21][23].

For appsec, searching for an organization's IP range on Shodan or Censys can reveal exposed services, outdated software versions, misconfigured ports, or insecure certificates that could be entry points for attacks [5][28][25][27]. For instance, identifying open RDP ports or unsecured MongoDB instances associated with an organization's infrastructure is a critical first step in assessing its external attack surface [29].

4. Metadata Analysis (ExifTool, FOCA, Metagoofil)

Documents (PDFs, Office files, images) often contain embedded metadata that can reveal sensitive information such as author names, internal usernames, file paths, software versions, and even geolocation data [30][2][31][24][32][33]. Tools like ExifTool can extract this data from a wide variety of file types [30][31][34]. FOCA and Metagoofil are specifically designed to extract metadata from publicly available documents, often found through search engines [2][24][25][26].

An appsec team might use this to understand the software stack used by an organization based on version information in embedded documents, or to discover internal file paths that might hint at directory structures.

5. Social Media Intelligence (SOCMINT)

SOCMINT is a subset of OSINT specifically focused on data from social media platforms [4][5]. It involves analyzing profiles, posts, connections, and metadata to understand individuals, groups, and trends [4]. Techniques include profile analysis, network mapping, hashtag tracking, and geolocation inference from images or posts [35][36][13].

For appsec, understanding how developers or team members discuss projects, technologies, or potential vulnerabilities on social media can provide critical intelligence. This can also be a vector for social engineering, where an attacker leverages this information to craft targeted phishing attacks [1].

6. Username Enumeration (Sherlock, User-Scanner)

Many individuals and organizations reuse usernames across multiple platforms. Tools like Sherlock and user-scanner can search for a given username across hundreds of social media, developer, and creator platforms, revealing associated accounts [37][38][29][39].

This can help in identifying an individual's broader digital footprint, uncovering associated accounts that might hold sensitive information, or linking a seemingly innocuous username to a developer who might have access to code repositories or internal systems.

7. Data Breach and Leak Site Monitoring (Have I Been Pwned, Intelligence X)

Services like Have I Been Pwned (HIBP) allow users to check if their email addresses or phone numbers appear in known data breaches [2][40][11]. Intelligence X and DarkSearch.io are search engines that index data from leak sites, dark web forums, and other underground sources, making it possible to search for compromised credentials or leaked information [8][41][42][43].

For appsec, this is vital for understanding if employee credentials or customer data might have been exposed in past breaches, which could be leveraged for credential stuffing attacks or social engineering. Searching for leaked API keys or tokens related to an organization's services is also a critical discovery path [44].

8. Passive DNS and Infrastructure Analysis (Security Trails, DNSDumpster)

Passive DNS databases store historical DNS records, mapping domains to IP addresses and vice-versa over time [7]. Tools like Security Trails and DNSDumpster provide access to this data, allowing for infrastructure pivoting [2][7][34][14].

This can help in identifying historical infrastructure that might still be connected to an organization, finding other domains hosted on the same IP address (indicating shared hosting or infrastructure), or discovering domains associated with specific name servers, potentially revealing clusters of related entities [7]. For appsec, this can uncover forgotten subdomains, legacy systems, or potentially malicious infrastructure linked to the organization.

9. Git Repository Forensics

When investigating suspicious commits in version control systems like Git, understanding the commit history is crucial [45]. While commit metadata (author, committer, timestamps) can be spoofed, analyzing it in conjunction with platform-specific information (e.g., account profiles, verification status) and looking for anomalies can reveal malicious activity [45].

This is relevant for appsec when investigating insider threats, compromised developer accounts, or the introduction of malicious code into the codebase. Examining commit author/committer discrepancies, backdated commits, or unsigned commits can be indicators of compromise [45].

Tooling for OSINT in AppSec

A robust OSINT toolkit is essential for appsec professionals. Here are some key tools and categories:

Frameworks and Aggregators

Specific Data Source Tools

Automation and Scripting

Python is a dominant language in OSINT due to its extensive libraries for web scraping, API interaction, and data analysis [60]. Tools like theHarvester, Recon-ng, and SpiderFoot are often written in Python [24][25][26][27]. Building custom scripts can also be highly effective for automating specific OSINT tasks, especially when dealing with large datasets or unique data sources [61].

Recent Developments and Emerging Trends

The OSINT landscape is dynamic, with new tools and techniques emerging rapidly. Several trends are particularly relevant to appsec:

Where to Go Deeper

For those looking to expand their OSINT capabilities, several resources offer structured learning and continuous development:

Sources cited in this guide

  1. OSINT Techniques & Tools (Imperva) — imperva.com
  2. OSINT Tools for Cybersecurity: A Practical Guide for Security Teams — socradar.io
  3. Complete OSINT Guide 2025: Find Anyone Online — projectosint.com
  4. Social Media Intelligence (SOCMINT) in Modern Investigations — osint.industries
  5. OWASP OSINT Resources — welivesecurity.com
  6. OSINT Gathering Using Censys (Hackers Arise) — hackers-arise.com
  7. Domain and IP Investigation with OSINT: Complete Guide (OSINTBench) — osintbench.com
  8. Top OSINT Tools For Dark Web (Brandefense) — brandefense.io
  9. OSINT Basics: What is Dark Web Intelligence (DARKInt)? — osint.industries
  10. Python for Dark Web OSINT: Automate Threat Monitoring — publication.osintambition.org
  11. How to Use the OSINT Framework: Sources, Tools, Steps (BitSight) — bitsight.com
  12. OSINT Tools And Techniques (Neotas) — neotas.com
  13. Trace Labs OSINT Educational Series — tracelabs.org
  14. Top 15 OSINT Tools For Cybersecurity In 2026 — cyble.com
  15. Hacking With Google — infosecwriteups.com
  16. Master Google Dorking: Advanced Techniques for OSINT and Ethical Hacking — neospl0it.github.io
  17. Automating Google Dorking: From Manual OSINT Technique to Continuous Monitoring — digitalstakeout.com
  18. Google dork cheatsheet — gist.github.com
  19. Awesome OSINT - A Curated List of OSINT Resources — github.com
  20. Finding Hidden Internal Apps Through Public Certificate Logs — naveensrinivasan.com
  21. Top 5 OSINT Sources for Pentesting and Bug Bounties (Intel 471) — intel471.com
  22. sarenka: OSINT tool (Shodan/Censys) (GitHub) — github.com
  23. Top 10 OSINT Tools 2026 - DevOpsSchool — devopsschool.com
  24. Top 10 OSINT Tools Everyone Should Know | SMIIT CyberAI — smiit-cyberai.com
  25. 10 Best Open Source Intelligence (OSINT) Tools Of 2025 — wbcomdesigns.com
  26. Open Source Intelligence Tools and Resources Collection — github.com
  27. Top 15 Free OSINT Tools To Collect Data From Open Sources — recordedfuture.com
  28. Bug Bounty 101: Top 10 Reconnaissance Tools | Netlas — netlas.io
  29. Top 10 OSINT Tools in 2025 Cyber Analysts Trust — axis-intelligence.com
  30. Beyond Canarytokens: Building a DIY Document Tripwire with Passive OS Fingerprinting — infosecwriteups.com
  31. OSINT Tools Security Analysts Should Know for 2025 — liferaftlabs.com
  32. kargisimos/offensive-bookmarks — github.com
  33. hashlookup-forensic-analyser version 0.8 released including a report functionality — github.com
  34. Best OSINT Tools for Intelligence Gathering (2026) — shadowdragon.io
  35. OSINT Techniques: Complete List for Investigators — shadowdragon.io
  36. OSINT Challenge in 30: Social Media Geolocation — medium.com
  37. GhostTrack Explained: Track IPs Phones and Usernames Easily — techshali.com
  38. OSINT Framework: How to Build a Custom Maltego Transform — netragard.com
  39. GitHub - kaifcodec/user-scanner: Scan a username across multiple social, developer, and creator platforms to see if it’s available. Perfect for finding a unique username across GitHub, Twitter, Reddit, Instagram, Telegram and more, all in one command. — github.com
  40. Email-Username-OSINT Toolbox — github.com
  41. 9 Top OSINT Tools & How to Evaluate Them — wiz.io
  42. 15 Best OSINT Tools in 2026 | Lampyre — lampyre.io
  43. 10 Rare and Worthy Websites and Services for Security Professionals — osintteam.blog
  44. Thousands of Corporate Secrets Were Left Exposed. This Guy Found Them All — wired.com
  45. Git repo forensics: a seven-phase process for investigating suspicious commits — root-security.eu
  46. The Top 10 OSINT Software Tools for Research and Investigation (2026) — technology.org
  47. OSINT Framework — osintframework.com
  48. Top 15 OSINT Tools in 2025 (OSINT BYLE) — osintbyle.medium.com
  49. A Beginner's Guide to OSINT Investigation with Maltego — wondersmithrae.medium.com
  50. 8 Best OSINT Tools (Paid & Free) in 2025 — comparitech.com
  51. OSINT for Threat Enrichment: Deep Dive with Maltego, SpiderFoot, IntelX, Recon-ng — medium.com
  52. spiderfoot: OSINT automation for threat intel (GitHub) — github.com
  53. Spiderfoot vs Maltego for OSINT Research Cases — osintteam.blog
  54. DataSploit/datasploit: An #OSINT Framework to perform various recon techniq — github.com
  55. Dorks collections list — github.com
  56. Beyond Google: Navigating the Hidden Internet with Shodan and Censys — medium.com
  57. Useful OSINT Browser Extensions — medium.com
  58. Phone Number Lookup — github.com
  59. Hunchly - Better Online Investigations — hunch.ly
  60. Python Cybersecurity — vinsloev.medium.com
  61. Build Your Own OSINT APIs for Pen Testers — claconnect.com
  62. Open Source Intelligence (OSINT): AI-Powered Image Geo-Location — hackers-arise.com
  63. Recon Village - OSINT and Reconnaissance Village at DEF CON 33 — reconvillage.org
  64. AI-enabled Workflows and Deeper Intelligence — trmlabs.com
  65. Automated OSINT Techniques for Digital Asset Discovery and Cyber Risk Assessment — mdpi.com
  66. 6 Ways to Delete Yourself From the Internet — wired.com
  67. Remove Personal Info from Google - DeleteMe — joindeleteme.com
  68. Dark Web Monitoring Using Python - Code With C — codewithc.com
  69. OSINT Framework — osintframework.com
  70. Awesome OSINT for Everything — github.com
  71. Open Source Intelligence GitHub Topics — github.com
  72. ljagiello/ctf-skills: Claude Code skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more — github.com
  73. reconurge/flowsint: A graph manager to help you save time in your cyber investigations. — github.com
  74. IVMachiavelli/OSINT_Team_Links: Links for the OSINT Team — github.com
  75. I Participated in a Trace Labs CTF - Now I'm Hooked on OSINT — dfirdiva.com
  76. OSINT Investigation Techniques for Missing Person Cases (Trace Labs) — alexislingad.medium.com
  77. Open-Source Intelligence (OSINT) in 5 Hours - Full Course - Learn OSINT! — youtube.com
  78. IntelTechniques Books (Michael Bazzell) — inteltechniques.com
  79. The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy — blog.includesecurity.com
  80. Phone Numbers and Emails to Hidden Subdomains: The OSINT Acquisition Pipeline That Uncovered a… — infosecwriteups.com
  81. Unmasking Phishing: Strategies for identifying 0ktapus domains and beyond — wiz.io
  82. PrizeBuzz phishing network analysis — phisheye.com
  83. Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered — unit42.paloaltonetworks.com
  84. Lessons from Building an Online Toolkit to Aid Open-Source Investigations — niemanreports.org
  85. Epieos: The Ultimate OSINT Tool — epieos.com
  86. Bellingcat's Online Investigation Toolkit — bellingcat.gitbook.io
  87. mosint: An automated e-mail OSINT tool — github.com
  88. Telegram-OSINT: In-depth repository of Telegram OSINT resources — github.com
  89. Top 10 OSINT Tools, Products & Solutions — SocialLinks — blog.sociallinks.io
  90. OSINT Industries — Online Investigations Platform — osint.industries
  91. Geolocation 101: image-based OSINT tips — authentic8.com
  92. Image Analysis and Geolocation with OSINT (OSINT Combine) — osintcombine.com
  93. OSINT Framework: The Ultimate Guide for Ethical Hackers — medium.com
  94. Operational Technology Discovery: ICS OSINT — medium.com
  95. OSINT 2025: New and updated digital investigative tools — indicator.media
  96. Top 10 OSINT Tools and Software for 2026 — streetinsider.com
  97. How to Conduct Investigations Using OSINT & Maltego — maltego.com
  98. Best Open Source Windows OSINT Tools 2026 — sourceforge.net
  99. 13 Best OSINT Tools for 2025 — talkwalker.com
  100. OSINT Bible: Comprehensive 2026 Guide — github.com
  101. 10 Best Threat Intelligence Tools In 2026 — cloudsek.com
  102. What is OSINT? Tools, Techniques and Framework Explained — medium.com
  103. AI vs dirty money: Using opensource intelligence to expose illicit financial flows — retailbankerinternational.com
  104. WebRecon from @D4rk_Intel is another OSINT multi-tool worth knowing about. 🧠 — x.com
  105. Hunchly - Better Online Investigations — hunch.ly
  106. Automating OSINT Blog — automatingosint.com
  107. Thingful - a search engine for the Internet of Things — thingful.net
  108. ‘Dogequest’ Site Claims to Dox Tesla Owners Across the U.S. — 404media.co
  109. Favorite tweet by @JasonFord — twitter.com
  110. Favorite tweet by @0xAsm0d3us — twitter.com
  111. Favorite tweet by @harshbothra_ — twitter.com
  112. Favorite tweet by @Insharamin — twitter.com
  113. Track any IP Address’s Exact Location like a Pro Hacker — medium.com
  114. OSINT: How to find information on anyone? — usersearch.org
  115. OSINT Treasure Trove — bib.opensourceintelligence.biz
  116. How To Track Phone Number Location With Python — python.plainenglish.io
  117. Open-source information gathering tool — medium.com
  118. How to search URLs exposed by Shortener services — grayhatwarfare.medium.com
  119. Gathering Open Source Intelligence — link.medium.com
  120. Thingful - a search engine for the Internet of Things — thingful.net
  121. Automating OSINT Blog — automatingosint.com
📚 This guide is synthesized from the full text of resources curated in the OSINT library, and refreshed as new material is added.