Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Presenter: One of the best sources
of open source intelligence these days is social media.
Many people tend to lift their guard
down when they're posting on social media
whether it's Twitter, Facebook, LinkedIn, YouTube,
Instagram, Reddit, or even TikTok.
By analyzing what the organization
or its employees are posting on social media,
you're gonna be able to find a lot
of information that can really help in your engagements.
When you're using social media to search for information,
you should start
with the organization's own social media profiles
and their accounts.
The organization is usually gonna post marketing information
on their social media profiles,
but often companies are now providing some sort of
behind the scenes type of pictures and videos.
These more candid posts can often capture things
in the background that the organization didn't realize
was there when they recorded that video
or took that picture.
For example, I've seen an organization who had one
of their employees making a post
to their Instagram account showing
what an average day looked like,
and when the employees snapped
that picture with their front facing camera,
they didn't realize that people could actually read
the computer screen that was located behind them.
By zooming in on that picture,
people were able to read the contents
of a sensitive corporate document that was being drafted
by the employee at the desk next to the posters.
These days, it seems that everybody is on social media
and that means you can scour
and scrape social media sites for details
about an organization's employees from the CEO,
all the way down to the person working
in the proverbial mail room.
Now, some employees are gonna have
multiple social media accounts as well,
and this is to divide their professional
or work accounts from their personal account.
For example, all of my employees have
a personal Facebook account and a work Facebook account,
and they're gonna use that work account
whenever they're posting on behalf of our company.
While they're personal, one is used
for everything else they do on Facebook.
Now, that means that most employees will be proper
and professional on their work accounts,
but if you find their personal account,
you can find the real person
behind that employee, including their interests, habits,
behaviors, friends, spouses, children, and much more.
Now, some employees even publish their own personally
identifiable information online,
including things like their full name,
their birthdate, their address their phone number,
and much more.
When it comes to social media sites, my personal favorite
for open source intelligence research is LinkedIn.
And this is because I can find out so much
about an organization by reviewing their pages there.
First, you can find the company's own page on LinkedIn.
Let's take for example Udemy,
the massively popular e-learning company.
From their LinkedIn page,
I can see they have 5,562 that have claimed a relationship
with Udemy on LinkedIn.
Now, if I go to the post tab, I'm gonna find a lot
of marketing things in press releases and things like that.
Now, this could be helpful,
but usually it isn't really what I'm focused
on when I'm looking
at LinkedIn for open-source intelligence.
Instead, I like to focus on the insights tab,
the life tab, the people tab, and the jobs tab.
First, let's look at the insights tab.
Under this tab, we can see some key data about the company
including its total number of employees and the growth
of that employee number over the past two years.
Now, in this case, I can see
in the last two years that the company has grown 62%,
but in the last six months, they've only grown 5%.
Now, why is that important to understand?
Well, if the company is rapidly growing
that's usually a time when they have worse security,
especially, due to the number
of new users who aren't fully or properly trained.
Additionally, if they have a very high growth rate
that means it's common
that new people are joining the team all the time.
And this could be a good chance
for you to conduct a social engineering campaign that relies
on impersonation where you might pretend to be a new hire
at the company.
As you continue to look through the insights tab,
there's other valuable information here for you to see too.
For example, we can look
at the distribution of their workforce, and I can see here
that the majority of their employees are in education
and the next highest area is engineering.
This could indicate that they're spending a lot of money
on their technical employees who might be better trained
and less likely to fall for things like a fishing attempt.
Next, I'm gonna move on to the life tab.
Now, this tab is used by the company to tell their own story
about why somebody would wanna work for them
what their culture is like, and even some
of the employee testimonials and company photos.
Next, I'll move over to the people tab.
From here, I can find
out the breakdown of where people live,
what colleges they went to, and more importantly
a list of the people who are currently working for Udemy.
This can be your springboard into a deeper dive
on an individual that you might wanna target
as part of your engagement
or you might try to identify their system administrators,
their engineers, and their security professionals
and see if they regularly post to LinkedIn.
Now, many people in technical careers like to post
to LinkedIn about the challenges they're facing at work,
and if they're having a work-related project
that's challenging
or they overcame it, they may go ahead and post
about that to celebrate how they overcame that challenge
and maybe even detail the solution they used.
This can be great information
for a penetration tester to have, especially when it comes
from the technical personnel of that targeted organization.
Finally, I'm gonna move into the jobs tab
and this is my favorite tab.
As we look at the jobs tab,
we can see every job posted by this organization.
Currently, there are 307 job openings available
and I can search through all of them
with a few keywords to find what I'm looking for.
For example, let's say I want to determine
which cloud service provider
Udemy is relying on to provide their infrastructure.
I can simply type in the word cloud
and see that it filters down from 307 postings
down to a more reasonable number of 29 postings.
Next, I wanna start clicking through some of the positions.
The first position is listed as a senior systems engineer.
As I look at that job description,
I don't see anything that mentions
whether they're using AWS, Azure or Google Cloud,
but I do see that they're using JAMF and Intune
for Windows OS patching
and that they're seeking somebody who has experience
in Mac OSX device management.
And this tells me they're not just a Windows only company,
so, we're gonna have to conduct some vulnerability scanning
and exploitations against their Mac systems too.
All right, let's move on to another position.
Let's say, for example,
we look at the security architect position.
In this position description,
I can see they're focused on programming
and development experience, but they're not very specific
in which single language they're using.
Instead, they list out things like Python,
Go, Ruby, Java, JavaScript, et cetera.
Now, this isn't as helpful unfortunately
because it's really too vague
for me to know exactly what they're using
in their system development.
As we keep looking though,
we're also gonna see they want experience
with cloud service provider platforms
such as AWS, GCP, Azure, and automation tools.
Now, again, this is really vague as well,
so, it's not that helpful.
Now, there's really two reasons a company would be
this broad on their job description.
The first is that they are very security conscious
and they don't wanna let attackers
and penetration testers know
what type of tech stack they have,
and what all their different languages look like
that they're using in their software development,
and so, they're trying to prevent us
from gaining enough information
by looking at these job postings.
Now, personally, I don't think that's the reason
because most companies aren't that smart,
and so, as we continue to look at other job postings,
we can probably find one that tells us a little more
about what we're looking for.
Now, the second reason that they're gonna be this broad
and vague, and this is probably the more accurate one
in the case of Udemy,
is that finding security architects and programmers
in the San Francisco California area is really challenging.
So, the company is probably being very open
to anybody who has the basic skill set needed.
Since once you learn a language like Java or Ruby,
you can pick up another one and it's not too difficult.
The same holds true for cloud platforms.
Once you use AWS or Azure,
learning the other one isn't too bad,
and I think that's more likely
why this post is being so vague.
It's because of a talent crunch
and they're having difficulty hiring for this position
if they're very specific on what their needs actually are.
All right, so we're gonna go ahead
and click around until we find one that helps us.
I'm gonna go and jump down to the senior cloud engineer.
This is probably a good one because we're talking
about cloud, and that was what I was looking for.
Now, I bet here we're gonna be a little bit more specific
in their requirements as well.
Now, in this position, we see some generic information
about a cloud engineer,
and then, in the second paragraph it says,
"Our primary environments and tools
include AWS, GCP,, VMware, Dell computer slash storage,
VSAN, Terraform, Cloud Formation,
Atlantic, Ansible, Datadog, and GitHub."
That's a pretty good list
of their tech stack and their different development tools
and one of the things I noticed
in there that wasn't listed is Microsoft Azure.
So, we know Azure is not one of the cloud tools
they're really focused on,
and this tells me
they are using a multi-cloud infrastructure though
because I did see AWS and Google Cloud being listed.
Now, based on my reading of that,
it seems that they're primarily on Amazon Web Services,
and they're using Google Cloud for a backup,
but that's just my guess at this point.
Now, if we look
down a little bit further at the requirement section,
you're gonna see that it states a good level of experience
with AWS and cost management experience a plus.
This confirms my suspicion
that they're probably using AWS primarily.
So, now that I gather this intelligence,
what does it tell me?
Well, I'm have to think
about how I'm gonna test things during the engagement
and I'm gonna wanna make sure that I have someone
on the team who's familiar with AWS penetration testing
and we need to make sure to get AWS's permission
before we start doing those tests.
Also, since they're using AWS for their cloud,
that means I can use something like PACU
which is an open-source AWS exploitation framework
during my engagement against their AWS technical stack.
I think you can see now why I love job posting so much
during the reconnaissance phase
because you can find so much great information
that's open source within them.
This includes things like the personnel who are making
up the departments or teams, including the hiring managers.
You might be able to find the lack
of qualified personnel and critical positions.
For example, we saw this organization needs
a new security architect and a cloud engineer,
and that means they either lost those people
and they're looking for replacements
or they're growing rapidly,
and either those are things we can take advantage of.
We can also find the level
of technical capability they have.
Again, this is based off those job postings.
What level of education are they posting as requirements?
We can also figure
out what software architecture and services are used.
We can figure out what programming languages are used.
We can figure out the types of hardware they use.
We can find out the types
of security systems they've fielded.
All of this is stuff we can find inside
of these job postings if we just go out and look for it.
In addition to LinkedIn,
there's lots of other places to gather information
about the people who work
at that company and the positions they're hiring for.
Sites like Monster, ZipRecruiter, Indeed, Glassdoor
and many others are a great place
for you to look as you're looking for more information
on your targeted organization.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.