OSINT and Dorks
PowerMeta
Powershell > Invoke-PowerMeta sans.org -download -extractDorks
OSINT
Maltego
Amazon S3 Bucket
Azure Blobs
Image Reverse Search
Last updated
Scrape all ppt/doc/xls/etc files and pull metadata from a Website/Domain
Powershell > Invoke-PowerMeta sans.org -download -extractGooglediggity & Searchdiggi - tool for Windows to multi-search
Combo tools for Google Dorks
Dork Scan
Example: > goohak domain.com
LinkedIn - user may have resume, or cover-letter posted - or activity
Instagram - user may have photo with a Badge posted
Twitter - Found favorite song, dog name, hometown from a CTF
Great tool.. but free version is limited
Buckets can be searched. And data is often leaked here
Put your keyword domains in file 'myDict'
REF: SANS Holiday Hack 2020
REF: Images/Exit/Steg
Last updated
> curl https://raw.githubusercontent.com/mattweidner/bucket_finder/master/bucket_finder.rb -o bucket_finder.rb
> bucket_finder --download myDict
package ..found!!
http://s3.amazonaws.com/wrapper3000/package