Transcription
Someone gives you just a name and a photo and then asks, where does this person live? What do they do? Are they really who they claim to be? If you are a professional OSINT investigator, you can find all these answers in just 10 minutes. No hacking, no illegal activity, only publicly available data. In today's video, I'll show you the exact method step by step. You'll learn 50 plus professional tools, all free, all legal. After watching this one video, you can become your own digital investigator.
Disclaimer: This video is for educational purposes only. All methods use publicly available data OSINT. No hacking or illegal activity is involved. Use this knowledge ethically and legally.
First, we'll understand what OSINT is and why it's important to learn. Then, we'll see how professional investigators think, their exact mental framework, and we'll break down how each method actually works.
OSINT means open source intelligence. In simple terms, it's the art of turning publicly available information into useful intelligence. Everything you can find freely on the internet, social media posts, domain records, news articles, public databases. OSINT is about collecting this data, analyzing it, and turning it into actionable insights. This is not hacking. It's not illegal. It's digital investigation. Organizations like the FBI, CIA, and journalists from BBC use these techniques, and now you can do it too.
Now, the question is, who actually uses OSINT? Only investigators? No. The use cases are much bigger. Journalists use it to expose corruption. HR departments use it to verify new employees. Cyber security analysts use it to trace threat actors. And regular people use it to protect themselves from online fraud. The truth is, anyone can learn OSINT. It's a skill that anyone can develop.
Before showing the tools, let me say one important thing. The difference between an amateur and an expert is this: An amateur opens tools and searches randomly. An expert knows which tool to use, when to use it, and how to pivot from one result to the next. This is called the OSINT chain. Let's get started.
Image investigation is just like magic. You can give it a photo and find out who the person is or where that picture was taken. Yandex Images is actually much more powerful than Google Images for facial recognition. Next is EXIF tool. It finds the hidden metadata inside a picture like the exact location, GPS coordinates, the camera model used, and the time it was taken. Geospy.ai uses artificial intelligence to guess the location just by looking at the background of the image. Google Images standard search to find where a photo appears online. Geo hints, a useful reference database to help identify locations, like in Geogesser. Finally, TNI helps you find the oldest copy of an image. This is useful for finding the original source.
First category: Finding a person. Let's say you only have a name, but you don't know where they live. Spokio is a public records aggregator. It collects data like address history, employment details, and more, all in one place. True People Search and Fast People Search both are completely free for the US. Important: These tools are mostly US-centric, but the technique is the same. Find local databases for your own country and use those instead. That's them.com works surprisingly well for US data sets. Whitepages.com people phone address lookup, limited free tier but still useful.
Now, let's talk about username tracking. Most people use the same username across multiple platforms, and that's their weakness. Sherlock is one of my favorite tools. Just enter a username in the command line, and it will automatically search across 400 plus platforms. What's my name.app and Instant Username. Both are browser-based, so no coding is needed. From a single username, you can discover their gaming profiles, forum posts, even dating accounts. And from there, you may find their real email address. Then, you pivot into email investigation. Enumerate accounts by username across hundreds of sites. Nameich.com. Check username availability across social and domain platforms. Instantusername.com. Real-time search across 100 plus social networks. Users.org. Find profiles by username, email, phone, or real name. pq.com. Username plus social footprint correlation. Good for digital identity mapping.
Email investigation. This is one of the most powerful entry points in OSINT because almost every online account is created using an email address. Have I Been Pwned? Enter an email here and see which data breaches it has appeared in. You can also check if the password has been exposed in a breach or not. Hunter.io. Find and verify corporate email addresses by domain. Free version has some limitations, so you won't see everything, but if you create an account, you can access more details. For full access and deeper information, you'll need the paid version. Epio. This is one of the most underrated tools. Just enter an email, and it can tell you whether a Google account is linked to it or not. Email Rep. With a free plan, you can make 10 queries per day and up to 250 per month. To use it, you'll need their API. Create an account, get your API key, log in, and then you can start testing. And Hlehei, a Python tool. It checks 120 websites to see if an email is registered. It comes with the installation command, but if that doesn't work, you can install it using PIPX and then test it.
Now, let's talk about domain and network investigation. These tools are necessary if you want to investigate any website. First is WHOIS lookup. It tells you everything like when a domain was registered and who registered it. You can use websites like whois.com, mxtoolbox.com, and whois.domaintools.com for this. There are many other tools, but these are the most popular ones. Also, you can use Mxtoolbox to analyze email headers as well. Shodan.io is a search engine for devices connected to the internet. Just enter an IP address, a service, or a port. Here you can see which ports are open, what services are running, and even the location. Censys is another powerful option. It helps you find domains using SSL certificates. For example, if you search for Nginx in the software section, it will only show you Nginx servers. ViewDNS.info is an all-in-one toolkit. Here you can perform over 25 different types of lookups on a single website or IP address. DNS Dumpster is a specialized tool for domain research. Its main job is to help you create a map of a company's entire digital infrastructure. Ipinfo.io and ipgeolocation.io mainly focus on IP intelligence. They provide all the details such as where an IP address is located, which ISP, internet service provider it belongs to, and whether it is using a VPN or a proxy. When we scan a web server or any server, we use these tools to make sure it is actually our target. This helps us avoid scanning the wrong server by mistake. VirusTotal is like a gold mine for OSINT and information gathering. For a security researcher or a bug bounty hunter, it is an incredibly important tool. When you search for a domain like hackerone.com, VirusTotal shows you a map of all connected subdomains, IP addresses, and certificates under its relations tab. It is also used to analyze whether there is anything harmful or malicious there.
SOCMINT stands for social media intelligence. With Social Searcher, you can monitor any keyword or name in real time across social media. Intelx is a powerful tool that searches the dark web, Telegram leaks, and paste sites all in one place. OSINT Combine is excellent for searching TikTok and Instagram posts by their location. The three tools here are now working for free: What's my name.app, OSINT Combine.tools, Sur.ly.com. Facebook Graph Search still works. You can find people by combining their location, name, and a specific time. Search by time. This is where most of the work happens. You can get information about your target. You can also use various Twitter intelligence tools available on GitHub for deeper analysis. With these tools, it is possible to track all of a person's online activity.
Our final category is just as important as the others. First is the Wayback Machine at web.archive.org. Even if a website or page is deleted, you can still find it here. They have archives dating all the way back to 1996. Archive.today lets you take an instant snapshot of any page during your investigation. If your target deletes the post later, you will still have the proof. You can also search all public Pastebin posts for leaked data. Use Dehashed to search through billions of leaked credentials like passwords and emails. These tools are absolutely necessary for collecting evidence.
Google Dorking is a secret weapon for investigators. It uses advanced operators to find hidden pages, expose files, and even leaked data. Dorking shows you things that a normal search cannot find. Learning this is like mastering 10 different tools at once. These Google Dorkings are very important.
Operational security. First, here are the things you must never do: Never search for your target using your real IP address. Do not stay logged into your personal accounts during an investigation. Never click on suspicious links directly. Do not keep your investigation files unencrypted. Do not contact the target directly until the investigation is completely finished. Always use a VPN. The Tor browser is also very safe for anonymous browsing. In Tor, your traffic passes through three different encrypted layers of relays to keep you hidden. Use a virtual machine (VM). Always browse suspicious websites inside a VM to protect your main computer.
Operational security toolkit. Remember one thing: When you are investigating someone, you are also being investigated. Every click you make leaves a digital fingerprint. A professional OSINT operator never leaves those fingerprints behind. How to stay invisible? You can do it with the tools here.
So, we learned today OSINT is the science of creating intelligence from publicly available data. Professional investigators follow five main phases: recon, enumeration, analysis, pivoting, and reporting. There are over 50 free tools available, and each one has its own specialty. Remember, Google Dorking alone can do the work of 10 different tools. And most importantly, use this power only for ethical and legal purposes.
If you like the video, don't forget to like and comment. If you are new, don't forget to subscribe. Thanks for watching.