Wiki Review - OSINT

 OSINT Wiki Review

https://wiki.itcollege.ee/index.php/OSINT_%E2%80%93_theory_and_practice

 

    For the end of our course, I decided to review one Wiki article that sparked my interest. There were many papers on social media, cryptocurrencies, malware - the usual "big" topics. But, I found OSINT, which is a theme that is very interesting for me. 

    In my opinion, if everyone from our course had to read one article, it would be this one. Not because it has been written well, but because it is such an important one. I would even say that 95% of our population has no idea how much data and information they share by default online.

    Now, about the paper itself. The first thing that I noticed was the correct buildup of the paragraphs. Everything was logical and the subparagraphs made it quick to find the needed information. 

    It started off with the theoretical part and a list of tools that can be used for collecting OSINT information. It went on to the social media part, which had lots of information (really great because social media is one of the biggest ways to gather the needed intel).

    Another great aspect was the data one, which was completely unknown to me. I hadn't even thought about it, but in retrospect, it's crucial when scaling your operations and being in need of visualization of bigger information sets.

    It ended with details on how to gather intelligence via usernames, e-mails and phone numbers, which were also great and needed topics.

     But, there are some things that they failed to mention, at least in my opinion:

  • Usage of other search engines for technical queries (like Shodan ands Spyse).
  • Usage of automated tools, not by searching manually (like TheHarvester and SpiderFoot).
  • Usage of other reverse image search engines, that give better results than Google (like TinEye).
  • How one could protect him- or herself from OSINT searches and gathering, which steps are needed and how should one even start when lowering their digital footprint available in the public.

     Also, in my opinion, they could have used more sources and fixed the formatting of the current ones (different bullet points, random "APA" etc.). But, in conclusion it was a really good read. They showed great knowledge and taught me very much in the theoretical part, which is crucial even when running automated OSINT tools.

Comments