https://osintframework.com/https://i-intelligence.eu/uploads/public-documents/OSINT_Handbook_2020.pdfhttps://start.me/p/DPYPMz/the-ultimate-osint-collection
# Multipurposehttps://shodan.io/https://www.zoomeye.org/https://leakix.net/https://www.yougetsignal.com/https://intelx.io/https://pentest-tools.com/​# DNS Reconhttps://domainbigdata.com/https://viewdns.info/http://bgp.he.net/https://rapiddns.io/https://dnsdumpster.com/https://www.whoxy.com/​# Mailserver blacklistshttp://multirbl.valli.org/​# Dark web exposurehttps://immuniweb.com/radar/​# New acquisitionshttps://crunchbase.com/​https://hunter.io/
# Google Dorks Cli# https://github.com/six2dez/degoogle_hunterdegoogle_hunter.sh company.com​# Google dorks helperhttps://dorks.faisalahmed.me/​# Code share sitessite:http://ideone.com | site:http://codebeautify.org | site:http://codeshare.io | site:http://codepen.io | site:http://repl.it | site:http://jsfiddle.net "company"# GitLab/GitHub/Bitbucketsite:github.com | site:gitlab.com | site:bitbucket.org "company"# Stackoverflowsite:stackoverflow.com "target.com"# Project management sitessite:http://trello.com | site:*.atlassian.net "company"# Pastebin-like sitessite:http://justpaste.it | site:http://pastebin.com "company"# Config filessite:target.com ext:xml | ext:conf | ext:cnf | ext:reg | ext:inf | ext:rdp | ext:cfg | ext:txt | ext:ora | ext:env | ext:ini# Database filessite:target.com ext:sql | ext:dbf | ext:mdb# Backup filessite:target.com ext:bkf | ext:bkp | ext:bak | ext:old | ext:backup# .git folderinurl:"/.git" target.com -github# Exposed documentssite:target.com ext:doc | ext:docx | ext:odt | ext:pdf | ext:rtf | ext:sxw | ext:psw | ext:ppt | ext:pptx | ext:pps | ext:csv# Other filessite:target.com intitle:index.of | ext:log | ext:php intitle:phpinfo "published by the PHP Group" | inurl:shell | inurl:backdoor | inurl:wso | inurl:cmd | shadow | passwd | boot.ini | inurl:backdoor | inurl:readme | inurl:license | inurl:install | inurl:setup | inurl:config | inurl:"/phpinfo.php" | inurl:".htaccess" | ext:swf# SQL errorssite:target.com intext:"sql syntax near" | intext:"syntax error has occurred" | intext:"incorrect syntax near" | intext:"unexpected end of SQL command" | intext:"Warning: mysql_connect()" | intext:"Warning: mysql_query()" | intext:"Warning: pg_connect()"# PHP errorssite:target.com "PHP Parse error" | "PHP Warning" | "PHP Error"# Login pagessite:target.com inurl:signup | inurl:register | intitle:Signup# Open redirectssite:target.com inurl:redir | inurl:url | inurl:redirect | inurl:return | inurl:src=http | inurl:r=http# Apache Struts RCEsite:target.com ext:action | ext:struts | ext:do# Search in pastebinsite:pastebin.com target.com# Linkedin employeessite:linkedin.com employees target.com# Wordpress filessite:target.com inurl:wp-content | inurl:wp-includes# Subdomainssite:*.target.com# Sub-subdomainssite:*.*.target.com#Find S3 Bucketssite:.s3.amazonaws.com | site:http://storage.googleapis.com | site:http://amazonaws.com "target"# Traefikintitle:traefik inurl:8080/dashboard "target"# Jenkinsintitle:"Dashboard [Jenkins]"
".mlab.com password""access_key""access_token""amazonaws""api.googlemaps AIza""api_key""api_secret""apidocs""apikey""apiSecret""app_key""app_secret""appkey""appkeysecret""application_key""appsecret""appspot""auth""auth_token""authorizationToken""aws_access""aws_access_key_id""aws_key""aws_secret""aws_token""AWSSecretKey""bashrc password""bucket_password""client_secret""cloudfront""codecov_token""config""conn.login""connectionstring""consumer_key""credentials""database_password""db_password""db_username""dbpasswd""dbpassword""dbuser""dot-files""dotfiles""encryption_key""fabricApiSecret""fb_secret""firebase""ftp""gh_token""github_key""github_token""gitlab""gmail_password""gmail_username""herokuapp""internal""irc_pass""JEKYLL_GITHUB_TOKEN""key""keyPassword""ldap_password""ldap_username""login""mailchimp""mailgun""master_key""mydotfiles""mysql""node_env""npmrc _auth""oauth_token""pass""passwd""password""passwords""pem private""preprod""private_key""prod""pwd""pwds""rds.amazonaws.com password""redis_password""root_password""secret""secret.password""secret_access_key""secret_key""secret_token""secrets""secure""security_credentials""send.keys""send_keys""sendkeys""SF_USERNAME salesforce""sf_username""site.com" FIREBASE_API_JSON="site.com" vim_settings.xml"slack_api""slack_token""sql_password""ssh""ssh2_auth_password""sshpass""staging""stg""storePassword""stripe""swagger""testuser""token""x-api-key""xoxb ""xoxp"[WFClient] Password= extension:icaaccess_keybucket_passworddbpassworddbuserextension:avastlic "support.avast.com"extension:batextension:cfgextension:envextension:exsextension:iniextension:json api.forecast.ioextension:json googleusercontent client_secretextension:json mongolab.comextension:pemextension:pem privateextension:ppkextension:ppk privateextension:propertiesextension:shextension:slsextension:sqlextension:sql mysql dumpextension:sql mysql dump passwordextension:yaml mongolab.comextension:zshfilename:.bash_historyfilename:.bash_history DOMAIN-NAMEfilename:.bash_profile awsfilename:.bashrc mailchimpfilename:.bashrc passwordfilename:.cshrcfilename:.dockercfg authfilename:.env DB_USERNAME NOT homesteadfilename:.env MAIL_HOST=smtp.gmail.comfilename:.esmtprc passwordfilename:.ftpconfigfilename:.git-credentialsfilename:.historyfilename:.htpasswdfilename:.netrc passwordfilename:.npmrc _authfilename:.pgpassfilename:.remote-sync.jsonfilename:.s3cfgfilename:.sh_historyfilename:.tugboat NOT _tugboatfilename:_netrc passwordfilename:apikeyfilename:bashfilename:bash_historyfilename:bash_profilefilename:bashrcfilename:beanstalkd.ymlfilename:CCCam.cfgfilename:composer.jsonfilename:configfilename:config irc_passfilename:config.json authsfilename:config.php dbpasswdfilename:configuration.php JConfig passwordfilename:connectionsfilename:connections.xmlfilename:constantsfilename:credentialsfilename:credentials aws_access_key_idfilename:cshrcfilename:databasefilename:dbeaver-data-sources.xmlfilename:deployment-config.jsonfilename:dhcpd.conffilename:dockercfgfilename:environmentfilename:express.conffilename:express.conf path:.openshiftfilename:filezilla.xmlfilename:filezilla.xml Passfilename:git-credentialsfilename:gitconfigfilename:globalfilename:historyfilename:htpasswdfilename:hub oauth_tokenfilename:id_dsafilename:id_rsafilename:id_rsa or filename:id_dsafilename:idea14.keyfilename:known_hostsfilename:logins.jsonfilename:makefilefilename:master.key path:configfilename:netrcfilename:npmrcfilename:passfilename:passwd path:etcfilename:pgpassfilename:prod.exsfilename:prod.exs NOT prod.secret.exsfilename:prod.secret.exsfilename:proftpdpasswdfilename:recentservers.xmlfilename:recentservers.xml Passfilename:robomongo.jsonfilename:s3cfgfilename:secrets.yml passwordfilename:server.cfgfilename:server.cfg rcon passwordfilename:settingsfilename:settings.py SECRET_KEYfilename:sftp-config.jsonfilename:sftp-config.json passwordfilename:sftp.json path:.vscodefilename:shadowfilename:shadow path:etcfilename:specfilename:sshd_configfilename:tokenfilename:tugboatfilename:ventrilo_srv.inifilename:WebServers.xmlfilename:wp-configfilename:wp-config.phpfilename:zhrcHEROKU_API_KEY language:jsonHEROKU_API_KEY language:shellHOMEBREW_GITHUB_API_TOKEN language:shelljsforce extension:js conn.loginlanguage:yaml -filename:travismsg nickserv identify filename:configorg:Target "AWS_ACCESS_KEY_ID"org:Target "list_aws_accounts"org:Target "aws_access_key"org:Target "aws_secret_key"org:Target "bucket_name"org:Target "S3_ACCESS_KEY_ID"org:Target "S3_BUCKET"org:Target "S3_ENDPOINT"org:Target "S3_SECRET_ACCESS_KEY"passwordpath:sites databases passwordprivate -language:javaPT_TOKEN language:bashredis_passwordroot_passwordsecret_access_keySECRET_KEY_BASE=shodan_api_key language:pythonWORDPRESS_DB_PASSWORD=xoxp OR xoxb OR xoxas3.yml.exsbeanstalkd.ymldeploy.rake.sls
port:"9200" elasticproduct:"docker"product:"kubernetes"hostname:"target.com"host:"10.10.10.10"# Spring boot servers, look for /env or /heapdumporg:YOUR_TAGET http.favicon.hash:116323821
# https://github.com/nitefood/asnasn -n 8.8.8.8​# https://github.com/j3ssie/metabigorecho "company" | metabigor net --orgecho "ASN1111" | metabigor net --asn​# https://github.com/yassineaboukir/Asnlookuppython asnlookup.py -m -o <Organization>​# https://github.com/harleo/asnipasnip -t domain.com -p​# https://github.com/projectdiscovery/mapcidrecho 10.10.10.0/24 | mapcidr​# https://github.com/eslam3kl/3klectorpython 3klector.py -t company​# https://github.com/SpiderLabs/HostHunterpython3 hosthunter.py targets.txt
# Get ASN and do amass intel# Get ASNamass intel -org "whatever"# Reverse whoisamass intel -active -asn NUMBER -whois -d domain.com# SSL Cert Grabbingamass enum -active -d example.com -cidr IF.YOU.GOT.THIS/24 -asn NUMBER
spiderfoot -s domain.com
# theHarvestertheHarvester -d domain.com -b all
recon-ng
# https://github.com/lc/gaugau example.com​# https://github.com/utkusen/urlhunterurlhunter -keywords keywords.txt -date latest​# https://github.com/tomnomnom/waybackurlsgo get github.com/tomnomnom/waybackurls​# Wayback machine dorkshttps://web.archive.org/web/*/website.com/*​https://gist.githubusercontent.com/mhmdiaa/adf6bff70142e5091792841d4b372050/raw/56366e6f58f98a1788dfec31c68f77b04513519d/waybackurls.pyhttps://gist.githubusercontent.com/mhmdiaa/2742c5e147d49a804b408bfed3d32d07/raw/5dd007667a5b5400521761df931098220c387551/waybackrobots.py
# https://github.com/devanshbatham/FavFreakcat urls.txt | python3 favfreak.py# https://github.com/pielco11/fav-upfavUp.py -k SHODANKEY -w website.com
# https://opendata.rapid7.com/sonar.fdns_v2/# https://github.com/cgboal/sonarsearch​go get -u github.com/cgboal/sonarsearch/crobatcrobat -s site.com
# https://github.com/m8r0wn/pymetapymeta -d example.com
# https://github.com/davidtavarez/pwndbpython3 pwndb.py --target [email protected]
https://hunter.io/https://link-base.org/index.phphttp://xjypo5vzgmo7jca6b322dnqbsdnp3amd24ybx26x5nxbusccjkm4pwid.onion/http://pwndb2am4tzkvold.onionhttps://rslookup.comhttps://leakcheck.nethttps://snusbase.comhttps://haveibeenpwned.comhttps://leakpeek.comhttps://breachchecker.comhttps://leak-lookup.comhttps://weleakinfo.tohttps://leakcheck.iohttp://scylla.shhttp://scatteredsecrets.comhttps://joe.black/leakengine.htmlhttps://services.normshield.com/data-breachhttps://www.dehashed.com/search?query=https://leakedsource.ru/main/https://leaked.site/https://ghostproject.fr/https://haveibeensold.app/https://vigilante.pw/https://nuclearleaks.com/https://hashes.org/https://leak.sx/https://leakcorp.com/loginhttps://private-base.info/https://4iq.com/https://intelx.iohttps://leakprobe.net
# https://github.com/SimplySecurity/SimplyEmail./SimplyEmail.py​pip3 install mailspoofsudo mailspoof -d domain.com​# Test email spoofhttps://emkei.cz/​# https://github.com/sham00n/busterbuster -e [email protected]​# https://github.com/m4ll0k/Infogapython infoga.py​# https://github.com/martinvigo/email2phonenumberpython email2phonenumber.py scrape -e [email protected]​# https://github.com/jkakavas/creepy/
# https://github.com/obheda12/GitDorkerpython3 GitDorker.py -tf TOKENSFILE -q tesla.com -d dorks/DORKFILE -o target​# https://github.com/dxa4481/truffleHogtrufflehog https://github.com/Plazmaz/leaky-repotrufflehog --regex --entropy=False https://github.com/Plazmaz/leaky-repo​# https://github.com/eth0izzle/shhgitshhgit --search-query AWS_ACCESS_KEY_ID=AKIA​# https://github.com/d1vious/git-wild-huntpython git-wild-hunt.py -s "extension:json filename:creds language:JSON"​# https://shhgit.darkport.co.uk/​# GitLab (API token required)# https://github.com/codeEmitter/token-hunter./token-hunter.py -g 123456
# https://github.com/twintproject/twinttwint -u username​# Google account# https://github.com/mxrch/ghuntpython hunt.py [email protected]​# https://github.com/th3unkn0n/osi.igpython3 main.py -u username​# Websitesemailrep.io # Accounts registered by emailtinfoleak.com # Twittermostwantedhf.info # Skypesearchmy.bio # Instagramsearch.carrot2.org # Results grouped by topicboardreader.com # forumssearchcode.com # search by code in repositoriesswisscows.com # semantic search enginepublicwww.com # search by source page codepsbdmp.ws # search in pastebinkribrum.io # social-media search enginewhatsmyname.app