27
a civilian approach to fight cyberwar introducing OSINT

OSINT - Open Source Intelligence

Embed Size (px)

DESCRIPTION

OSINT - Open Source Intelligence by Rohit Srivastwa at c0c0n - International Cyber Security and Policing Conference http://is-ra.org/c0c0n/speakers.htm

Citation preview

Page 1: OSINT - Open Source Intelligence

a civilian approach to fight cyberwar

introducing

OSINT

Page 2: OSINT - Open Source Intelligence

Founder, ClubHack

Mentor, ClubHack Magazine

Awarded as Microsoft Most Valuable Professional 2012 in Enterprise Security.

Advisor eGov - Science & Technology park, DST

Ex- Head of Technology, Commonwealth Game(s)

Shameless Self Promotion

Page 3: OSINT - Open Source Intelligence

rohit11

Page 4: OSINT - Open Source Intelligence

Agenda for next 30min

Remember, it can save a lot of pain in future

What is OSINT

Tools & Tricks Case Study

Page 5: OSINT - Open Source Intelligence

Open Source Intelligence

Nothing to do with Open Source Software though

Page 6: OSINT - Open Source Intelligence

OSINT: Open Source INTelligence

“Is an information processing

discipline that involves finding,

selecting, and acquiring

information from publicly available

sources and analyzing it to produce

actionable intelligence.”

What is it?

Page 7: OSINT - Open Source Intelligence

A lo

t o

f in

form

atio

n o

ut

the

re

Page 8: OSINT - Open Source Intelligence

Sou

rce

s Too much information everywhere !

Page 9: OSINT - Open Source Intelligence

Cable Gating is not OSINT, its crime. But wiki leaks is a OS info :D

Never Cross boundaries

Page 10: OSINT - Open Source Intelligence

Tools & Tricks

Again not a rocket science

Page 11: OSINT - Open Source Intelligence

Too

ls

Maltego

Page 12: OSINT - Open Source Intelligence

Too

ls

LeakedIn

The primary purpose of leakedin.com is to make visitors aware about the risks of loosing data. This blog just compiles samples of data lost or disclosed on sites like pastebin.com.

Page 13: OSINT - Open Source Intelligence

Too

ls

LeakedIn

Page 14: OSINT - Open Source Intelligence

Too

ls

AnonPaste Monitor

Page 15: OSINT - Open Source Intelligence

Too

ls

Tweeter Monitoring

Page 16: OSINT - Open Source Intelligence

Too

ls

Facebook Monitoring

Page 17: OSINT - Open Source Intelligence

Too

ls

http://talkback.volvent.org/items.html

Page 18: OSINT - Open Source Intelligence

Too

ls

More Tools

Metadata : – Foca , metagoofil , exiftool Online sites : – Shodanhq, Serversniff, netcraft, centralops, FF extensions :– wappalyzer, Passive recon, Our Own Mantra

Page 19: OSINT - Open Source Intelligence
Page 20: OSINT - Open Source Intelligence

Too

ls

Nostradamus

Nostradamus Police reports, recorded at the

regional police departments

Mass media articles and other public sources (including the

web)

Communication records

Databases of security services and other law enforcement

authorities

Information from the field on: accidents, incidents, interviews,

etc

Life scan systems

Geographically spread sources of

different types and formats

Page 21: OSINT - Open Source Intelligence

Too

ls

Nostradamus

Nostradamus A complete, powerful analytical tool

Analysis of Relationships, Graphical visualization of Relationships

Detection of Direct and Hidden networks, patterns, trends

GIS Analysis, Space-Time Analysis

Telephone Call Analysis, Contacts Analysis

GIS enabled Analysis; Movement & Location Analysis

Crime Pattern Analysis, Proactive Analysis

Multi-lingual Phonetic & Semantic Search & Query

Intelligence Accumulation

Completely web-based; includes online & real-time capabilities

Automated data capture. IP, GPRS, SMS enabled

Structured information access privileges

Client side Platform independent. No special requirement w.r.t. the User PC

Efficient operations even with low communication capabilities

Page 22: OSINT - Open Source Intelligence

Too

ls

Nostradamus

Nostradamus Criminal Intelligence Analytical System

Page 23: OSINT - Open Source Intelligence

Case Study

“Lord of Dharamaraja”

Page 24: OSINT - Open Source Intelligence

Lord

s o

f D

har

mar

aja

Page 25: OSINT - Open Source Intelligence

Lord

s o

f D

har

mar

aja

Page 26: OSINT - Open Source Intelligence

If we have the will...

Page 27: OSINT - Open Source Intelligence

Thanks

[email protected] +91-92-CLUBHACK