Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Speaker: There is a lot of great information
available online for free that can help you understand
how a business or organization is operating.
This information is just sitting out there
waiting for you to find it.
This information is considered open-source
in the world of information and intelligence gathering
if it comes from publicly available sources.
Now, Open-Source Intelligence, also known as OSINT,
is the collection and analysis of data gathered
from publicly available sources
to produce actionable intelligence.
Open-source intelligence tools are often used
to collect and analyze information
that's already publicly available on the open web
such as social media, blogs,
newspapers, governmental records
and academic and professional publications
during your passive reconnaissance phase.
For example, if the company puts out a new press release
about an upcoming merger
between themselves and another company,
this information could become actionable intelligence
in the hands of a penetration tester
because they could use it to craft
various social engineering attacks
against those targeted organizations.
Let's pretend that a physical penetration test
was part of our engagement.
Knowing that a company named SodaCo
is about to undergo a merger with DrinkCo,
that means that SodaCo might be seeing a lot of new faces
in the offices as DrinkCo starts sending over people
to learn all about SodaCo's operations.
If you happen to put on a suit
and print up some business cards
that say you work for DrinkCo,
well, you could probably walk right
in the front door of SodaCo
and have some helpful employees walk you
directly into the data center if you play your cards right.
Now similarly, this same press release
might give you the names, phone numbers,
emails, and positions of all the different people
who are expecting to get questions from the press
about this merger.
So you could call it the person listed
and start asking them questions
about how SodaCo and DrinkCo's merger
might affect their technical infrastructure.
Are you going to be using SodaCo's network,
DrinkCo's network, or a combination of both of these
after the merger?
Will there be any downsizing of redundant IT personnel?
Are you already using the cloud
or are you going to migrate your data centers into the cloud
during the merger over the next few months?
Most companies that put out press releases
will be able to answer questions about them and their future
so you can leverage this open-source intelligence
to your advantage during your reconnaissance phase.
Now, other types of open-source information
includes things like job listings,
metadata and website information.
For example, simply reviewing the Companies About Us page
on their website can give you some detailed information
about executives at the company.
If you really want to grab some important names,
numbers and emails though,
you should also check out the website
that a company creates for its investors.
These websites or pages off their main website
are usually termed the investor relations site
or investor relations portal.
Now, for example, let's say you're going to conduct
a penetration test against Udemy,
the online educational platform.
And you might want to go and visit investors.udemy.com
as part of your open-source intelligence collection efforts.
Here, you're going to see tabs
with the latest press releases,
event information, financial information,
stock information, corporate governance,
and shareholder resources.
Now going to the corporate governance tab,
you're going to find pages dedicated
to their management team
which consists of all of their executives,
presidents and vice presidents
as well as their board of directors.
For each of these people, you can click on their photos
and get additional profile information about them
such as where they went to college,
what degrees they earned,
former companies they've worked for,
and their focus area within the current organization.
And in this case, that's Udemy.
Now, using this information,
you can really craft some detailed whaling emails
against these executives and board members
if that's within the engagement scope.
Something I've learned over the years
is that executives and board members
tend to be extremely busy people.
And because of this, they tend to fall for whaling,
spear phishing and phishing emails at a much higher rate
than a normal or regular employee would.
At least that's what I've seen
in my own real world engagements.
Your mileage may vary.
Now, blogs and social media
are another great source of information too,
especially when you're trying to understand
the workplace culture or tempo of an organization
that you're targeting.
For example, is everyone working remotely from home?
Or is everyone back in the office every single day?
This is valuable information for a penetration tester,
especially one who has to conduct
a physical penetration test.
Are the employees unhappy
because they have a bad work-life balance?
Do they hate their managers?
And do they feel they're dumb or incompetent?
Does the company focus on training
and building up their employees?
Or do they overlook training
in favor of additional work output?
All of these things can give you valuable information
that you're going to be able to use
during your engagement as well.
Maybe you find out where people like to go
to blow off steam after work.
And you can find that the system administrators
are the local bar right next to the office
every Friday at 5:00 PM.
This could be a great opportunity
to go clone one of their proximity badges
as part of your physical penetration test
because they would be tired after a long week of work
and distracted while they're getting a drink at the bar.
Or maybe you start chatting up
one of the technical team members at the bar,
flirting and asking them what they do at their job,
how they like it
what kind of tech they get to work on and things like that.
This is a form of social engineering
where you're up close and personal
with some of the employees
and trying to gather as much information
as you can from them without raising their suspicions.
I know, I know.
This sounds kind of like a spy movie here.
But again, if this was agreed upon
in the rules of the engagement
and it's within scope of the engagement, then guess what?
It's fair game.
Once you gather all this open-source information,
it's going to be time to put that information to work
as actionable intelligence.
At this point, you should be able to identify
a couple of key details about your target organization
such as the roles that different employees have
in the organization, including their job titles,
level in the organizational hierarchy,
and their day-to-day tasks and responsibilities.
You'll also find out the different teams
and departments that exist in the organization
as well as the phone numbers,
email addresses and office locations of these teams
and the employees within them.
You might find out the technical aptitude
of the organization and if they have
a good security training program.
And finally, you can start to understand the mindset
of the employees and the managers inside that organization
including how they perceive their coworkers,
subordinates and managers.
Now, all of this data can be put to work in different ways.
I've already talked about how we can use it
to conduct social engineering either by email or in person.
But there's other ways to leverage all this data too.
For example, if you've identified that Harriet
over in the human resources department
has a dog named Yoda,
graduated from Rutgers University in 2003,
her birthday is August 5th
and her favorite singer is Celine Dion.
And you can use all those names and dates
to create a word list that you can use
to conduct a hybrid password cracking attempt.
Because most people use their date of birth,
names of people or animals
that they have a relationship with, interests,
and other things like that to create their passwords.
So as you're gathering this information,
think about how can it be useful to you
and how can you turn it into actionable intelligence.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.