OSINT Course 2026 | OSINT Tutorial For Beginners | OSINT Tools | OSINT Tutorial | Simplilearn
Key Takeaways
This video introduces the OSINT course, covering OSINT tools and techniques for beginners in cybersecurity
Full Transcript
Imagine [music] you're a detective, but instead of combining through physical evidence, you're diving deep into the world of publicly available data, social media profiles, news stories, public records, and even company websites. This is the power of opensource intelligent, which is OSENT. Just like how a detective pieces together the clues to solve a case, OENT allows you to gather valuable insights from a open web and make informed decision. But not all the information is created equal. Some pieces of data are easy to find and harmless while others carry much more weight and risk. This is where the OENT utility and risk pyramid comes into play. Think of it as a map for navigating the vast ocean of open-source data. As you move up the pyramid, the information becomes more specific, sensitive, and potentially more dangerous if misused. In this session, we'll walk you through the layers of OSEN pyramid and helping you understand how each level of data can reveal more than just one surface and how to handle that intelligence responsibly. By the end, you'll also see how OSENT is not just about collecting data, but understanding its potential impact, whether it's harmless or high-risk. We will start by understanding what OSENT is and why it's such a critical tool in today's information-driven world. Touching on its use and everything from security to business intelligence. From there, we'll dive into the OENT utility and risk pyramid, a framework that breaks down the evolution of intelligence from basic accessible data to high-risk sensitive information. Each level of pyramid uncovers a different layers of intelligence, revealing insights that become more impactful as you move higher. We'll then look at how data changes from a low risk to high risk at each stage using real world examples and illustrate the shift. And finally, we'll discuss how to access and manage the risk associated with each layer, ensuring that you handle OSENT responsibility and ethically. This session will wrap up with actionable key takeaways to apply in your own OSENT work. Now, before we dive in, here's a quick question for you. What's the main benefit of opensource intelligence? It's legal, it acts as private information or it predicts the future. Let me know your answers in the comment section below. And for more such content, do subscribe to simply learn. As we dive into this topic, let's start by exploring what open-source intelligence or OSENT actually means. Opensource intelligence is a process of collection and analyzing publicly available information to produce actionable intelligence. Think of it as gathering valuable insights from publicly accessible data sources like news outlets, social media or even public records all to help inform decision. Now that you have an understanding of what OSENT, let's look at some key characteristics. The first characteristics of OSENT is that it is only publicly available. This means that the intelligence you gather must come from open source. Nothing hidden or private. It could be any kind of websites, social media post, forums, public databases or anything that is accessible to the public. Next is that OSEN follows structured process. While the sources may be varied, there is a clear methodology to how information is gathered, analyzed and used. This ensures that the intelligence produced is relevant and reliable. And finally, OSENT leads to actionable output. The whole purpose of gathering this intelligence is to create insights that can inform decision, strategies or operation. It's not just about collecting data. It's about using the data effectively to take actions. Now let's address a common issue which is OSENT is not hacking. Some people may confuse OSENT with illegal activities but it's important to draw a clear line between OSENT and hacking. Then follows legal and ethical guidelines and it strictly involves the use of publicly available data. Let's break down the difference between OSENT and hacking. Here's a simple comparison. Uses publicly available data gathering through transparent and lawful means. It's about finding insights from accessible sources like website, public records or even social media platforms. Whereas hacking on the other hand involves breaching private systems without permission. It's a violation of privacy and often illegal with unethical practices at its core. So to clarify, OSENT is not about breaking the law. It's about ethically gathering intelligence from open-source to inform decisions. Now let's walk through open-source intelligence process. This process involves gathering information from a variety of open sources and we'll go step by step through the key categories of data collection. The first step is the process of media. This includes television, radio, newspapers and magazines. These traditional media sources are still very relevant when it comes to gathering publicly available intelligence. Next we move on to the internet. The internet is a gold mine for Osent with search engines like Google, Bing and Yahoo offering vast amount of data. It also includes user generated content from blogs, forums, social media and more. Geographic data is also a crucial part of the process. This could involve maps, environmental data or even maritime data that helps in understanding specific regions or locations in details. It's vital for intelligence in geographical context. Next we have observation. This steps involves using various tools like cameras, videos or even reports. It can be about observing physical environments or analyzing footage that have been recorded. Especially useful in surveillance or fieldwork scenarios. And finally we have academia. Academia refers to the wealth of research conferences and expert insights that can be accessed for intelligence purpose. This includes journals, research papers and academic discussions that offer indepth knowledge on specific topics. So as you can see the OSEN process involves multiple diverse sources each contributing valuable insights. These steps helps create a comprehensive view of the information allowing for accurate analysis and actionable intelligence. As we all know by now, the open-source intelligence cycle is a structured process that helps organization effectively gather, analyze, and use publicly available information. Let's walk through each phase of the cycle. The first phase is direction and planning. This is where you define your objectives and scope of your intelligence gathering. You plan out what type of information you need and the sources that will best provide the data. It's about setting clear goals of the intelligence process. Next, we move on to collection. This phase involves gathering the information from identified sources. It's about collecting data from publicly available sources such as websites, news articles, social media, and academic publications. After collection comes the processing and exploitation. In this phase, the collected data is organized and formatted so that it can be analyzed effectively. It involves cleaning and refining the data to extract meaningful insights making it ready for further analysis. Next, we have analysis and integration. The processed data is analyzed and insights are integrated to create actionable intelligence. This phase is all about interpreting the data, identifying patterns and combining it with existing knowledge to form a comprehensive understanding. Finally, the production and dissemination phase. The intelligence produced is shared with stakeholders. This involves presenting the findings in a way that easily understandable and actionable whether through reports, presentation or dashboards. The goal is to ensure that the intelligence is communicated effectively to the right audience. This cycle is iterative meaning after dissemination feedback may be further need collection of data and analysis creating a continuous loop of intelligence gathering and refinement. In the direction and the planning phase, we establish the foundation of the entire OSEN process. And here's a breakdown of the key steps involved. The first one is objectives and requirements. This is where you outline what you want to achieve with OSENT. It involves identifying the specific goals of intelligence process such as understanding a particular threat, gathering market insights or tracking political movements. You must be clear on what data is needed to meet those objectives. Next, you must identify the target. Here you specify what or who you are collecting intelligence on. This could be a person, organization, event or even a geographical area. Understanding your target helps you focus on collection process and make sure you gather most of the relevant information. It's also essential to establish legal and ethical boundaries. OSEN must be conducted with legal and ethical frameworks. This step ensures that you are only collecting data from publicly accessible sources and that respect privacy laws, intellectual property rights and even boundaries set by the target. It's about adhering to regulations and ethical standards while collecting data. Afterwards, we move on to resource allocation. Here you determine what resources such as tools, technology or even personal which are necessary to carry out OSEN process effectively. This could include setting up data collection platforms, choosing softwares and even assigning roles to team members. And finally, we have operational security setup which is crucial. This step involves ensuring that your OSENT activities remain secure and that the operations are not compromised. It includes setting up secure communication channels, protecting the identities of your team and ensuring your methods cannot be tracked back to your own organization. This phase lays the groundwork for successful and ethical OSENT operation ensuring that all the steps are aligned with your objectives while maintaining security and compliance. In this phase, we use several tools and techniques to ensure that our onset process is efficient and follows ethical guidelines. Below are the tools and technology commonly used in direction and planning stage. For the documentation, a text editor which is like wiki is typically used. For example, you can use notion, obsidian or even MSWord. This helps in maintaining records of the objectives, requirements and plans for OSENT. Proper documentation ensures that the process is well organized and you have a return reference for each step of the process. When preparing for the ethical or legal aspects, a privacy focused browser or a VPN service is crucial. Using a privacy focused browser or VPN ensures that all your online activities are secure and anonymous and helps protect the integrity of OSEN process by maintaining privacy and preventing tracking. For the tool index, we commonly use the OSEN framework which is found at osenframeworks.com. This framework is a comprehensive resource for identifying and accessing various open-source intelligent tools. It categorizes tools based on the type of intelligence they help gather making it easier to find the right tool for the job. So we'll discuss about this tool later in detail. Lastly for account creation which is sock puppet accounts may be used. These are fake or anonymous accounts created to protect the identity of a person performing the oent. Sock puppets are useful for researching and gathering information within revealing your true identity or affiliations. These tools and techniques are essential to ensure that OSEN process is efficient, secure and ethically sound. The collection phase is critical to gather all the data needed for further analysis. In this stage, we focus on identify gathering data, filtering out irrelevant information, and documenting everything. Here's a breakdown of each step. The first step is source identification. This involves identifying the various sources from which you can collect relevant data. These could be websites, social media platforms, forms, public records or any publicly accessible information that could provide valuable intelligence. Next we move on to data gather. Data can be collected from different parts of the web and one of them surface web. This includes all the publicly accessible websites which are the easiest and most common source of OSENT. Next, if you talk about deep web data found in the deep web like academic papers or data sets which aren't indexed by standard search engines. And then we have social media. Social media intelligence focuses on gathering intelligence from social platforms such as Twitter, Facebook, Instagram and others. Social media can be a rich source of real-time information and sentiment. Once data is gathered, the next step is initial filtering. This phase involves sifting through the collected data to remove irrelevant or lowquality information. It's about narrowing down the vast amount of data to only what is meaningful and relevant to the intelligence objectives. All collected data needs to be documented systematically. This includes noting down the source of information, time of collection, and any other relevant details to ensure transparency and traceability. In the collection phase, it's essential to focus on identifying the right sources, gathering meaningful data, filtering out noise, and keep track of everything collected for further analysis. In the collection phase, various tools and techniques are used to gather data effectively from different sources. For general search, we have Google talking which is advanced operators is a powerful technique. This involves using advanced search operators in Google to find specific information that's not readily accessible through basic search queries. It can help locate hidden or specific data across the web such as documents, login portals, or even any other indexed pages. When gathering data related to infrastructure tools like who is lookup example domain tools who is.com DNS dumpster and security trails are invaluable. These tools allow you to gather details about domain names, IP addresses and other network related data which are essential for mapping out the structure of organization online presence. Tools like shoddan and census are also used to scan and find devices connected to the internet. Additionally, we have recong and the harvest are widely used for gathering the information related to email address and others online details for people or ID collection. Social media sites such as LinkedIn formally Twitter and other platforms are commonly used. These platforms help identify personal information and professional connection. Additionally to can be used to extract valuable data from public profiles. In the archief's category, wayback machines such as archief.org is a vital tool. It allows you to explore historical snapshots of websites which is useful for seeing how a website or a web page looked at its previous point in time. This is important for tracking changes, uncovering past versions of websites or retrieving deleted content. These tools and techniques are crucial for effectively gathering open-source intelligence across various domains from general web searchs to more specific infrastructure and peoplebased data collection. The next phase which is the processing and exploitation phase is where collected data is refined, verified and organized to prepare it for analysis. So let's break down those steps. The first step is filtering and cleaning. Once data is collected, it's essential to filter out irrelevant, incomplete or lowquality information. This steps involves cleaning the data to ensure it's accurate, relevant, and ready for analysis. For example, if you're removing duplicates, correcting errors, and eliminating unnecessary data point. Next, we move on to verification. In this step, the data is cross-ch checked to ensure its authenticity and reliability. Verification helps identify any false or misleading information, ensuring that only trustworthy sources and data are used for further analysis. After verification, we focused on data structuring. Data structuring involves organizing the data in a way that makes it easier to analyze. This could mean converting raw data into formats like spreadsheets, databases or structured text that can be easily interpreted and processed by analyst. Metadata extraction is another critical step. Metadata refers to the underlying details of the collected data such as time it is collected, the source and other contextual information. Extracting this metadata adds an additional layer of insights helping analyst better understand the context and relevance of the data. In cases where data is collected in multiple languages, language translation becomes essential. This step involves translating non-native language content into common language for analysis. It ensures that the intelligence gathered from different sources is accessible and can be evaluated in the same context. And finally, we have file analysis. This step involves analyzing specific files such as documents, images, videos or others formats to extract actionable insights. It includes techniques like examining file properties, extracting text from documents or performing image analysis to find hidden information. This phase refineses the raw data into structured, verified and usable intelligence, preparing it for deeper analysis and decision making. In the processing and exploitation phase, a variety of tools are used to refine and analyze the collected data. Below are the key tools used for each step. For metadata extractions, tools like XF tool or FOCA which is fingerprint organization with collected art chiefs are used. These tools allow you to extract metadata from files and documents. XF tool is commonly used for image and video metadata while FOCA is used to gather metadata from collected documents and files providing insights into a file sources and history. For a file forensics, spreadsheets such as Excel or Google Sheets are commonly used. These tools helps in analyzing and organizing data into structured formats making it easier to search, filter and manipulate data for further insights. They are essential for checking file integrity and investigating the context systematically. When it comes to data cleaning, tools like Open Refine, Tableau Prep, and Trafaca are highly effective. Open refine is used to clean messy data, transform it into structured formats and explore relationships within the data. Whereas Tableau prep and event trifactor are also used for preparing and cleaning large data sets making them ready for further analysis and visualizations. For timeline creation, timeline creation software is used. These tools help to create visual timelines that represents the sequence of events. They're essential for understanding the context of data, especially in scenarios where time plays a critical role in analysis. These tools are key to turning collected data into structured, verified and meaningful intelligence, enabling accurate analysis in the next phases of the OSEN process. Next we have the analysis and integration phase where collected and processed data is analyzed. Patterns are identified and insights are integrated to form actionable intelligence. Here's a breakdown of the steps. The first step is pattern recognition. In this phase, the goal is to identify recurring patterns, trends or anomalies in the data. These patterns could be related to specific behaviors, events or connection and spotting them is crucial for making sense of large data sets. This step helps reveal meaningful information that may not be immediately obvious. Next, we perform link analysis. This involves examining the relationships and connections between different pieces of the data. For example, in OSEN, this could mean linking social media profiles, IP address, or even geographical location to uncover networks, relationships or influence patterns. Link analysis is essential for connecting the dots in complex intelligence gathering. Next, we focus on contextualization. The data means understanding the circumferences surrounding the data and placing it in the border context. This helps determine its significance, relevance and how it fits into a bigger picture. Without contextualization, data might be misunderstood or misinterpreted. Once this step is done, we move on to hypothesis generation. Once this step is done, we move on to hypothesis generation. This step involves developing possible explanations or theories based on a platform and relationships identified. A hypothesis provides a framework for testing and further analysis, helping direct and investigation into areas that require more focus or verification. In bias mitigation, the goal is to reduce influence of personal or systemic biases that could destroy the analysis. This ensures that the conclusion raw are based on objective analysis not skewed by preconceived notions or biases. Bias mitigation is crucial for maintaining the integrity of intelligence process. And finally, we perform the risk assessment. Risk assessment involves evaluating the potential risk or implications of intelligence gathered. This could include assessing the accuracy of the information, its potential impact or likelihood of being used maliciously. It's about understanding the potential consequences of intelligence before taking action. This phase is essential for transforming raw data into reliable and actionable intelligence that can guide decisions and actions. In analysis and integration phase, specific tools are used to analyze, map, and query data effectively. Here's a breakdown of the tools commonly used in this phase. For link analysis, tools like Multiggo or I2 analyst notebook, which is IBM, are widely used. Multigo allows users to visualize relationships and connections in large data set making it ideal for uncovering networks and understanding complex relationships. Whereas I analyst notebook is an IBM tool that also focuses on visualizing and analyzing data relationships especially in investigate scenarios. For automation, Spiderford is a powerful tool. Spider automates the process of gathering intelligence from different open sources including IP address, domain names and social media. It's particularly useful for automating the collection of vast amount of data saving time in analysis process. In the mappm category, tools like Google Earth Pro and QIS are commonly used. Google Earth Pro allows for visualizing of geographical data including mapping physical location and analyzing the geographical context of collected intelligence. Whereas QGIS which is quantum gist is an open-source mapping tool that provides more advanced features for the geospatial data analysis helping with the creation of custom maps and spatial analysis. For data query, custom scripts using languages like Python or SQL are essential. Python scripts are often used for automating data queries, analyzing data structures and extracting insights. We can use SQL which is structured query language critical for quering databases and extracting specific information stored in relational database system. These tools and techniques enable a thought and efficient analysis and integration of open-source intelligence allowing for deeper insights and actionable intelligence. The production and dissemination phase is where the intelligence that has been analyzed and integrated is formally compiled and communicated. This step ensures that the findings are organized, documented and shared with appropriate stakeholders. Here are the breakdown of the steps. The first step is to report generation. In this phase, all the findings and the insights gathered from the Osen process are compiled into comprehensive report. The report should include key findings, methods used, data sources and conclusion drawn from the intelligence gathered. This ensures transparency and clarity in how the intelligence was derived. Next, we move on to evidence compilation. This step involves gathering all the evidence and support documents related to the findings. This could include the screenshots, URLs, data sets, or any other forms of evidence that supports the conclusions made in the report. Compiling the evidence ensures that the intelligence is grounded in verbify facts. Once the report and the evidence are in place, in in this phase, data is presented in visual formats like graphs, charts, maps, and timelines. This helps make the intelligence more accessible and easier to understand, especially when presenting complex relationships or patterns. After visualizing the data, recommendations are made based on the intelligence collected, processed or analyzed actionable recommendations. These recommendations help decision makers understand what step should be taken next or how to respond to the intelligence. And finally we move on to the dissemination phase. This step involves sharing the report, evidence, visualization and recommendations with the intent audience. Dissimilation could be done through presentation, email, secure portals or any other appropriate channel to ensure that the relevant stakeholders receive the intelligence and can act on accordingly. This phase ensures the intelligence gathered is effectively communicated to those who can use it. help drive informed decision and actions. And in this phase we use tools such as word processor which is MSWord, Google Docs for report generation. Whereas for visualization again we use multigo, I2 exports or even Tableau and for storage we use secure data repository. The OSENT utility and risk pyramid visual represents the different levels of information that the open-source intelligence which is the OSEN can reveal ranging from lowrisk information to more sensitive high-risk intelligence. Each level of pyramid corresponds to how OSEN reveals specific details for the most general to the most sensitive. Let's break down each layer of the pyramid. The base layer OSEN gives ad rehearsal process a starting point and additional resources necessary to leverage further attacks or exploitation. At the base of the pyramid, we have foundation of OSENT. This layer includes publicly accessible information that's generally available to anyone. Information that can serve as a starting point for further intelligence gathering. for example, information for public websites, social media posts, and news outlets. While this is the least sensitive data, it can still be crucial as it provides a foundation for understanding a subject or entity that can lead to further exploitation or exploration. OSENT is at the level of generally low risk, but it can be valuable for adversely looking to build a broader profile. In the second layer, we can see generally only selected information meets the criteria for classification with unclassified sources of information filling in the gaps. The next level is where the selected information meets the criteria for classification. This includes pieces of information that are sensitive but still publicly available. The information could be from a variety of unclassified sources like government reports, academic papers, or even leaks that provide more in-depth context or details about the subject. This type of OENT helps researchers or intelligence offers piece together details about subject, but it's often fragmented. Unclassified information helps fill in the gaps to give more complete picture. Then we move on to the third layer. OENT reveals current status, capabilities and other contemporary information. At this level, it reveals the current status, capabilities and contemporary information. This level is more specific revealing the current state of a target including their operational capabilities, goals and resources. For example, information might include details about organization assets, workforce, technology capabilities or even operational focus. This layer is more sensitive and typical involves tracking activity statements or public profiles that gives a realtime snapshot of the subject while still publicly accessible is kind of OSENT can provide valuable intelligence that currently and actionable. Next we have the top layer. Oent the most sensitive form of OSENT involves revealing the intent of friendly or adversal forces. This level provides insights into the intention and strategic goals of an individual organization or government. Information from this layer might could form a intelligence about groups political or military objectives, their future plans or even their strategies for giving the objective. It's the most sensitive and high-risk information as understanding a target's intent can lead to predicting actions or formulating the counter measures. This layer of OSENT is highly valuable but carries a higher level of risk as it can be used for malicious purposes if it falls into the wrong hands. The OSENT and risk pyramid provides a structured view of how open-source intelligence can reveal different levels of informations from general knowledge to sensitive intelligence. It shows how information evolves in importance and sensitivity with each layer providing increasingly detailed insight. As OSEN moves up the pyramid, the value of the intelligence increases but so does the risk involved in exploiting it. Now let's look into tools that actually help in performing OSENT. So in the first place we have direction and planning. The first step is documentation. For documentation either you can use any text editor like notion, obsidian or MSWord. So let's go one by one. So firstly we have notion. Now, Notion is a flexible all-in-one workspace that uses customizable pages and databases to centralize the diverse oent findings, logs, and process into a structured collaborative knowledge base. So to open notion, you just need to type notion in Google. The first thing that appears which is notion the AI workspace. Just open it and there's a free version of it and you can request a demo of it and just click on the free notion you'll automatically logged in by your Google. So here you can see you can search few things if you want to uh search for your previous things home meetings there's also a new feature of notion AI where you can ask anything and it will um make sure to autocorrect it or research regarding research papers etc. And uh you have a to-do list where you can just add your to-do list etc. And also the mailing is also done. Now how to start with here is you can just click on the new page and start documenting your observations or what procedure happens when your maybe your people's name their identity their uh services information everything you can just chart it down. So this is the notion part. Coming to obsidian, it's a local first knowledge graph that uses plain markdown files and birectional linking to create a highly interconnected private and customizable network for complex oset case nodes and data relationship. So for um obsidian you just need to install this particular software. So here get Obsidian for Windows. You can just click on it. It'll get downloaded and you can install. After installing you will be able to see Obsidian here and if you open it here this is the interface. Now what's the specialtity about Obsidian is you can interconnect each document whatever you have created and these are the data points. So every document will be linked to this data point. So you can um start with one data point and you can write entire their um identity and then next they you can write their IP address what are the systems they work on and then they can go on to the next dot which is connected which might be personal details. It's easy for us to just take a look and know which information is there in which folder. So this is about obsidian and you have multiple other option like graphing and other documents insert templates calendar is also given in this apart from this you can use MS word this is a very standard processor so it's almost it's inbuilt in every system again it's a standard word processor So primarily used for producing formal static and final oent reports and even eventually documents lacking built-in tools for live data linking or complex relational analysis. So here again it's a very basic app that saves all your documents you can link it etc. Now coming to the second step which is a legal prep or even ethical prep. You need to be careful about two things. One is the VPN services that you're using. Make sure you have a VPN service so you cannot be tracked and also any kind of browser that cannot be tracked. So here my suggestion will be use any kind of VPN service but make sure the paid ones have more features to hide your details whereas a free version are very limited access. So I have a extension here. So here one of the VPN that I have I've added it as a extension so it connects India Pune there are multiple free versions you can see which one works for you but if you want to get no track backs for yourself do have a good VPN so that you won't be able to track back yourself and coming to browsers I highly recommend Brave browser so you just need to type in Brave save and uh you'll get the website. You need to download it. So here are the features. It's a private search built-in assistant. It has a powerful VPN also inbuilt. So here you can uh get Brave download and install it. And after installing you'll get something like this window where it's similar to Google has the features of Google browser but um it's a private brow browsing tool. So any kind of Google search you do regarding informations that you want or any kind of profiles that you want to create. You can use this browser to create all kind of stuff so that you cannot be tracked back since this has a inbuilt and it's a free version also. Now coming to the tool index we have OENT framework which is there in osentframework.com. Now this is the biggest cheat code I would say for the entire tools which is present. As you can see it is showing this sign can't be reached. It might be. So, we'll go to our Brave browser and type in awesomeframework.com. So as you can see this website comes up. So here the Osin framework is present and all kind of data that you might want is been present here including from usernames, email address, domain, IP address, even MAC IP address, images, videos, documents, social networking, instant messaging, what kind of message, telephone numbers, dating history, location tools, search engines and so much more including meta data is also provided. Now, how do you get the tool names from here? Just click, if you want any person's username, just click on username and you will have user search engines or specific sites. So, if you go on user search engines, you'll have multiple websites that can give you information of username, search engines. Now, let's say what's in my name. If you click on it, it'll directly take you to the particular page. Here are some of the cookies. This is one of the tools that was mentioned in the awesome. We can try it out. So here we can search for a particular person's name. Let's say John Williams. So let's say it's John Williams and search and confirm if you're not a human. Here you can see the processor processing the data and it'll give us the data. This name wherever it is linked to a authentic category it will be displayed here. So here you can see found one which is username is John Williams categories are achieved account found and here you can see where so actually in um dosecs.com John Williams account is there the second one also you can see in social media also we have found one now after searching every site possible we found seven accounts which is related to this name. So here you can see all the site names the usernames which we have given and which category have they signed up on. So Archie means which is created and deleted. So you can go out it's given in the link also you just can click on it and view his or her profile. So if you want to know something about a person this is pretty much very useful tool that you can go and see what kind of accounts he's having etc. So let's go back to the awesome framework and again these are similar kind of tools which gives you information based on the information that you are having. So let's say email address um breach data we can breach data and um I have I prawn is also another website that has been used so you can just enter your email id and just check it you have it'll give us like two data breaches are there notify me and all those things so you will know if this particular email address is breached or Not. Now coming back here we can see other things such as email verification, commonal email formats, email search, what is the email history of that person etc. There are multiple tools for each category. Do try it whichever works the best you can stick with that. And then we have domain name also here. Who is records? We'll come to who is let's explain in the next steps. Before that we have other tools, URL expandations, blacklist and all. So here you can see another thing is geolocation tools. So you can actually see the location of a person with these tools and there are tools for meta data exploitation as well. So as you can see here we have XF tool metag goif and foca and also code to outlook expert. So if you open this awesome framework website you will have everything under one roof. You can try different tools for different purposes based on whatever information that you're having whether it's your email information that you're having a phone number also you can just enter the phone number and get the details within few seconds. Some of the website might not open on normal Google browser. So make sure to try them out in Brave so that it will accept all kinds of breaching properties etc. Coming on to the next step is account creation as sock puppet accounts. So here's the thing. If you want to recruit a person for a secret agency report and you need to do a backstory analysis of that person account creation in a fake profiles creations like creating a entirely new person's account just for knowing the information of other people. These fake accounts which is created but looks to be a normal person's accounts are called sock puppet accounts. Now here's the thing about sock puppet accounts. You need a fake name. You need a fake photo which look realistic. And to create a LinkedIn profile or suppose some any other social media accounts you need few information that you can fake it but make it look real. So that there are rules and regulation. Suppose in LinkedIn if they identify this account is fake they're going to remove the account. So keep in mind the pictures the data that you're providing should look real. The next step is for collection of the data. Now here for general search we can use Google docking. Now what is Google docking? Google docking is a process of using advanced search operators in your Google query to drastically narrow results and uncover specific often hidden or sensitively publicly index information that a normal search wouldn't reveal. The format involves combining your search keywords with these special operators. Suppose if you want to know about a site, you just type in site and give the site name. And next one is to write the file type to search for a specific file extension. If you want an Excel file or a word file or any kind of document, you can mention it here. So next go with file type. Let's say I need an Excel file. And then finally, you have in URL. This is to find the keywords in the URLs. So, whatever keyword that you want to find in that site, you can mention it here. So, you can type in in URL and give the name. Suppose I need a document which says index of. So any document which has this keyword will be shortlisted and shown here. So in this format you can search for documents which are hidden also. Often these results won't be showing much. So try it with different types of file types, different URLs, different kind of keywords. Experiment with your Google docking. Now next for infrastructure we have who is lookup. Who is is a query and a response protocol used to retrieve the publicly registration and contract details suppose like owner name, address, email, registration, date etc. for a specific domain name or even any kind of IP address from its corresponding registry databases. So let's first open this. So again I'm opening it in Brave since it's a safer version. So this is the interface of who is. So you can see you can enter an IP address and you can check. So let's do an example. Let's find a great domain name and um let's look out for the IP address. So I need the information of Amazon. Let's say so let's click on Amazon.com. That's the IP address that I'm going to give him. So here you can see entire domain information is there which includes the domain is Amazon registered on so and so on date expires on so and so on date updated status is client delete prohibited then we have register information under whose name is it registered email address of that particular person phone number is also provided registrant contact is also provided and technical contact this usually discovers and visualizes maps and entire public facing infrastructure of a target domain including subdomain host records and associated IP address. So let's just check in that. So here let's check for Microsoft and you can start the test. So here you can see the location is updated. So [snorts] as you can see the location mostly is in United States and we have all the working capitals. The host name is provided with open services ASN name and IP address also is provided is being tracked. There's also service and banners hosting networks hosting from USA, Canada as well as some other countries such as Netherlands. Next, for people's ID, we have obviously social media sites such as LinkedIn, X, Twitter, etc. And we have Gi Hunt also. So here um we can search for the name, check with their background, check if they match your requirement status. If there is anything fishy, you can just document it back. Next, we have Archiefs, which is basically the internet at which is a massive digital library that takes historical snapshots of websites over time. It is an indispensable osite tool for recovering deleted content, tracking changes in website structure like old employees list, hidden subdomains or even forgotten files are generally viewing a website past version to find information no longer present on the current live page. Now again open archiefs.org in the brave browser.org. Now this is a misleading website. So here you can see best cell phone deals, latest Samsung phone but you have opened art chiefs. So you can just randomly click on some option and it will take you to the actual website. Now here whatever you search in all the old information is going to appear. Now suppose I search for the same person here. if he has any profile that was created and deleted and it will still appear here. Next, moving on to the next step which is processing and collection. The first tool for metadata extraction is X if tool or even you can consider fingerprinting organization. So for the next step which is processing and collection the first step is to extract the metadata which can be done by XF tools or FOCA. So let's see about XF tool. Both XF tool and FOCA are essential OENT tools specializing in metadata extraction which is data embedded within files that can reveal hidden clues. XF tool is a powerful cross-platform command line utility that supports nearly 180 file formats, especially images and videos to write, read, and edit metadata, often revealing GPS coordinates, camera models, or even timestamps. You can just type in XF tool. It's by Phil Harvey. Again it's a software so you need to download it and run it in your system. It'll ask you a few security questions. Do fulfill it and then you can breach your entire meta data. Similarly, we have FOCA which is fingerprinting organization with collected Archie which is a primarily Windowsbased GUI tool that automates the OSEN process by using search engines to find public documents like whether it's PDF, Docs, Excel or a targeted domain downloading them and extracting collecting metadases such as username, internal network parts and software version. Now for file 4 and six which is Excel or spreadsheet which includes Excel, your normal Microsoft Excel and even you can use Google Sheets. Again same purpose is storing information storing the metabase that we have collected from the previous step. You can use it for data cleaning as well. As you know Excel is a great tool for data cleaning. And then timeline creation software. There are multiple softwares which is paid which will give you the exact timeline creation. So you don't need to worry about all the timeline analysis which can be done. Let me know what are the tools that you found regarding the timeline in the comment section below. The fourth step is analysis and integration and in that the first thing that you have to do is link analysis. You can use Multigo or I2 analyst notebook by IBM. Again, these are the softwares that you need to install. So you can just open Multigu and there is a free demo. So let's just sign in. I'll explain the interface. So again, enter your email address and password. Now after logging in there are few information that you need to provide. So suppose your company name etc. So you can just give a fake name and you can proceed with it. So here's the interface after login with the details and for a free version you cannot do much but for a paid version you can actually create the graph. Here there are multiple options of your admin evidences etc. So it's a nice place to organize it and keep for link analysis also. Similarly is analyst notebook. It's by IBM also it has a paid version. So do check it out. Also for automating these task we can use spider foot which you don't need to everyday keep analyzing keep receiving metadata etc. For that you can use spider food and for mapping which is the locations and all Google Earth Pro is a excellent website that you can go and check it out. it also QGIS is also a great tool that you can use for location purpose. And for the last step which is production and dissimulation again for report generation we can use word processor which we already have gone through it which is MS world or Google docs any presentation software would work great again for visualization you can use multigo and tableau again tableau is also good if you're a student it's a free version you can download it up to a certain point system for a working professional you can buy it it's a great tool to do all the analysis this part, visualization part as well and storage also. There are multiple storage options you can choose from whichever is comfortable for you to use but make sure it is a secure data repository. So these are the tools that are generally used for Osent. All the tools that you need are present in the frameworks.com which is osenframeworks.com. Do go and check out each one of them so that you'll have an idea what each website can do. How to get information, how to track your metadata, how to track geoloc, phone numbers, email address, etc. which might help you in your research work. As we wrap up this session, remember that OSENT is more than just gathering data. It's about understanding the layers of intelligence and associated risk. From public social media posts to more sensitive high-risk intelligence, every level of OSENT reveals a different piece of the puzzle. The OSENT utility and risk pyramid has shown has highly informative moves from low-risk accessible data to highly sensitive insights that can have a profound impact on decisions or actions. Understanding this pyramid helps you not only gather intelligence but also manage the risk that comes with it. Whether you're a cyber security expert, journalist, researcher or even a business analyst, the way you handle OSENT will directly affect the quality and safety of the intelligence you work with. So if you move forward with your OSI practices, keep the pyramid in mind and always approach your work ethically, responsibly and with an awareness of potential risks. Thank you for joining for this session and I hope you are now equipped with the knowledge to navigate the complexities of OSENT in a thoughtful and impactful way. Until next time, keep learning with Simply Learn.
Original Description
🔥Professional Certificate Program in Cybersecurity: https://www.simplilearn.com/ai-cybersecurity-course?utm_campaign=luk-9Ld-NPs&utm_medium=DescriptionFirstFold&utm_source=Youtube
🔥IIIT Bangalore Advanced Executive Program In Cybersecurity (India Only): https://www.simplilearn.com/pgp-advanced-executive-program-in-cyber-security?utm_campaign=luk-9Ld-NPs&utm_medium=DescriptionFirstFold&utm_source=Youtube
🔥Cyber Security Masters Program (Discount Code - YTBE15): https://www.simplilearn.com/cyber-security-expert-master-program-training-course?utm_campaign=luk-9Ld-NPs&utm_medium=DescriptionFirstFold&utm_source=Youtube
In this course, you’ll learn how to uncover powerful insights hiding in plain sight using Open-Source Intelligence (OSINT). From understanding what OSINT really is to mastering the complete intelligence cycle, this training walks you through every phase—Direction & Planning, Collection, Processing, Analysis, and Dissemination. You’ll explore real-world OSINT tools like Google Dorking, Maltego, Shodan, SpiderFoot, ExifTool, and the OSINT Framework, while learning how to ethically gather, clean, verify, and interpret publicly available data. Through practical explanations, tool breakdowns, and detailed walkthroughs of the OSINT Utility and Risk Pyramid, you’ll see how data progresses from harmless, open-web information to sensitive intelligence that carries real-world implications. By the end of the course, you’ll be equipped to apply ethical OSINT techniques for cybersecurity, investigations, journalism, threat intelligence, business research, and more while understanding how to responsibly manage the risks that come with powerful information.
00:00:07 Introduction to OSINT
00:07:45 OSINT Intelligence Cycle
00:29:23 The OSINT Utility and Risk Pyramid
00:33:45 Tools used
Open-Source Intelligence (OSINT) is the practice of collecting, analysing, and interpreting information that is publicly available—such as social media posts,
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from Simplilearn · Simplilearn · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Ethical Hacking Full Course 2026 | Ethical Hacking Course for Beginners | Simplilearn
Simplilearn
AWS Full Course 2026 | AWS Cloud Computing Tutorial for Beginners | AWS Training | Simplilearn
Simplilearn
Data Structures And Algorithms Full Course | Data Structures and Algorithms Tutorial | Simplilearn
Simplilearn
SQL Full Course 2026 | SQL Tutorial for Beginners | SQL Beginner to Advanced Training | Simplilearn
Simplilearn
Microsoft Azure Full Course 2026 | Azure Tutorial for Beginners | Azure Training | Simplilearn
Simplilearn
Shopify Tutorial For Beginners 2026 | Shopify Course | shopify dropshipping | Simplilearn
Simplilearn
Six Sigma Full Course 2026 | Six Sigma Green Belt Training | Six Sigma Training | Simplilearn
Simplilearn
🔥Feeling Stuck? How Upskilling Can Boost Your Career! #shorts #simplilearn
Simplilearn
Growth Hacking In Marketing | Learn Growth Hacking Marketing Strategies | Simplilearn
Simplilearn
🔥Cracked 3 Job Offers with One AIML Course! | 20–30% Salary Hike #shorts #simplilearn
Simplilearn
Top 10 Must-Have Figma Plugins for UI/UX Designers in 2026 | Figma Plugins | Simplilearn
Simplilearn
Business Analytics Full Course 2026 | Business Analytics Tutorial For Beginners | Simplilearn
Simplilearn
Simplilearn Reviews | Getting future-ready with course in Artificial Intelligence | Roopam’s story
Simplilearn
Generative AI Full Course 2026 | Gen AI Tutorial for Beginners | Gen AI Explained | Simplilearn
Simplilearn
Full Stack Developer Course 2026 | Full Stack Java Developer Tutorial for Beginners | Simplilearn
Simplilearn
Simplilearn Reviews | How David Went From Seasoned Engineer to AI Innovator #GetCertifiedGetAhead
Simplilearn
Complete Social Media Marketing Strategy for 2026 | Social Media Marketing Strategy | Simplilearn
Simplilearn
🔥Top 4 Cybersecurity Certifications You Need! #simplilearn #shorts
Simplilearn
🔥Cloud Engineer Salary in India 2026 | City-Wise Breakdown #shorts #simplilearn
Simplilearn
Digital Marketing Full Course 2026 | Digital Marketing Tutorial For Beginners | Simplilearn
Simplilearn
Full Stack Java Developer Course | Full Stack Java Developer Tutorial for Beginners | Simplilearn
Simplilearn
Social Media Marketing Full Course | Social Media Marketing Tutorial For Beginners | Simplilearn
Simplilearn
How To Create LLM Chatbot Demo 2026 | Build a LLM Chatbot From Scratch | Simplilearn
Simplilearn
Digital Supply Chain Management Certification | Supply Chain Management Course | Simplilearn
Simplilearn
AI Agents Full Course 2026 | AI Agents Tutorial for Beginners | How to Build AI Agents | Simplilearn
Simplilearn
ITIL Full Course 2026 | ITIL 4 Foundation Course | ITIL Tutorial For Beginners | Simplilearn
Simplilearn
Generative AI Full Course 2026 | Gen AI Tutorial for Beginners | Gen AI Explained | Simplilearn
Simplilearn
ITIL Full Course 2026 | ITIL 4 Foundation Course | ITIL Tutorial For Beginners | Simplilearn
Simplilearn
Simplilearn Reviews | Integrating AI & Music | Diego's Story
Simplilearn
Digital Marketing Full Course 2026 | Digital Marketing Tutorial For Beginners | Simplilearn
Simplilearn
SEO Full Course 2026 | SEO Tutorial for Beginners | SEO Training | SEO Explained | Simplilearn
Simplilearn
PMP Vs CAPM: Which Certification Should You Choose? | PMP Vs CAPM | Simplilearn
Simplilearn
Complete Data Analyst Roadmap 2026 | How To Become A Data Analayst In 2026 | Simplilearn
Simplilearn
Generative AI Full Course 2026 | Gen AI Tutorial for Beginners | Gen AI Explained | Simplilearn
Simplilearn
🔥5 Jobs That Are Most Likely Safe from Layoffs in Today’s Market #shorts #simplilearn
Simplilearn
🔥Git vs GitHub – What's the Difference?
Simplilearn
What Goes Behind Building the Likes of Uber and Netflix? | Product Management Tutorial | Simplilearn
Simplilearn
AI Agents Full Course 2026 | AI Agents Tutorial for Beginners | How to Build AI Agents | Simplilearn
Simplilearn
Full Stack Developer Course 2026 | Full Stack Java Developer Tutorial for Beginners | Simplilearn
Simplilearn
Product Life Cycle 2025 | Stages Of Product Life Cycle | Product Life Cycle Tutorial | Simplilearn
Simplilearn
Project Management Full Course 2026 | Project Management Tutorial | PMP Course | Simplilearn
Simplilearn
PCB Design Course 2025 | PCB Designing Explained | How To Make PCBs | Simplilearn
Simplilearn
Python Full Course 2026 | Python Data Analytics Tutorial For Beginners | Simplilearn
Simplilearn
🔥Top Product Management Skills You Need to Succeed in 2026 #shorts #simplilearn
Simplilearn
SQL For Data Analytics 2026 | Essential SQL Commands | SQL Tutorial For Beginners | Simplilearn
Simplilearn
Simplilearn Reviews | Paving Way To Success With AI & ML Course | Soumik’s Upskilling Journey
Simplilearn
Six Sigma Full Course 2026 | Six Sigma Green Belt Training | Six Sigma Training | Simplilearn
Simplilearn
Learn Snowflake In 45 Mins | Snowflake Tutorial | What Is Snowflake | Snowflake Explained
Simplilearn
🔥ML Career Tip – How to Start Learning Machine Learning in 60 Seconds! #shorts#simplilearn
Simplilearn
🔥Agile vs Waterfall in 60 Seconds #shorts #simplilearn
Simplilearn
Excel Full Course 2026 | Excel Tutorial For Beginners | Microsoft Excel Course | Simplilearn
Simplilearn
What Are AI Agents? | Types Of AI Agents | AI Agents Explained | AI Agents Tutorial | Simplilearn
Simplilearn
How To Create a Product Roadmap In 2026 | Product Roadmap | What Is Product Roadmap | Simplilearn
Simplilearn
SQL Full Course 2026 | SQL Tutorial for Beginners | SQL Beginner to Advanced Training | Simplilearn
Simplilearn
🔥What Is Phishing? #shorts #simplilearn
Simplilearn
Cloud Computing Full Course 2026 | Cloud Computing Tutorial | Cloud Computing Course | Simplilearn
Simplilearn
Simplilearn Reviews | Overcoming Rejection & career plateau to finding a New Job : Bhaskar Banerji
Simplilearn
Six Sigma Full Course 2026 | Six Sigma Green Belt Training | Six Sigma Training | Simplilearn
Simplilearn
Generative AI Full Course 2026 | Gen AI Tutorial for Beginners | Gen AI Explained | Simplilearn
Simplilearn
VLSI Design Course 2026 | VLSI Tutorial For Beginners | VLSI Physical Design | Simplilearn
Simplilearn
Related Reads
📰
📰
📰
📰
Lab: SQL injection UNION attack, retrieving multiple values in a single column
Medium · Cybersecurity
Tuesday Morning Threat Report: Jul 21, 2026
Medium · Cybersecurity
GHSA-H95V-H523-3MW8: GHSA-H95V-H523-3MW8: Sensitive URI Fragment Disclosure via Referer Headers in Guzzle HTTP Client
Dev.to · CVE Reports
If you can’t answer who accessed this patient’s data, you have a problem
Medium · Cybersecurity
Chapters (4)
0:07
Introduction to OSINT
7:45
OSINT Intelligence Cycle
29:23
The OSINT Utility and Risk Pyramid
33:45
Tools used
🎓
Tutor Explanation
DeepCamp AI