home.social

#informationgathering — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #informationgathering, aggregated by home.social.

fetched live
  1. with the new Search Engine .

    The goal was to find as much information as possible about myself, my family members, and partners, using only my callsign (SV1SJP) as the starting point.

    ChatGPT Search Engine seems promising :))
    sv1sjp.github.io/articles/chat

  2. Continuing the tour of my @github projects, the #TacticalExploitation toolkit deserves to be mentioned. It's now a bit old, but I believe the concept still applies, and very much so.

    github.com/0xdea/tactical-expl

    "The Other Way to Pen-Test" -- @hdm & @Valsmith

    I've always been a big proponent of a tactical approach to #PenetrationTesting that doesn't focus on exploiting known software #vulnerabilities, but relies on #OldSchool techniques such as #InformationGathering and #BruteForce. While being able to appreciate the occasional usefulness of a well-timed 0day, as a veteran penetration tester I favor an exploit-less approach. Tactical exploitation provides a smoother and more reliable way of compromising targets by leveraging process vulnerabilities, while minimizing attack detection and other undesired side effects.

    Since a few years, I've meant to give a talk on this very subject, with the working title of "Empty Phist Style - Hacking Without Tooling" (inspired by @thegrugq). Sooner or later it will happen.

  3. Continuing the tour of my @github projects, the #TacticalExploitation toolkit deserves to be mentioned. It's now a bit old, but I believe the concept still applies, and very much so.

    github.com/0xdea/tactical-expl

    "The Other Way to Pen-Test" -- @hdm & @Valsmith

    I've always been a big proponent of a tactical approach to #PenetrationTesting that doesn't focus on exploiting known software #vulnerabilities, but relies on #OldSchool techniques such as #InformationGathering and #BruteForce. While being able to appreciate the occasional usefulness of a well-timed 0day, as a veteran penetration tester I favor an exploit-less approach. Tactical exploitation provides a smoother and more reliable way of compromising targets by leveraging process vulnerabilities, while minimizing attack detection and other undesired side effects.

    Since a few years, I've meant to give a talk on this very subject, with the working title of "Empty Phist Style - Hacking Without Tooling" (inspired by @thegrugq). Sooner or later it will happen.

  4. Теги та ключові слова: OSINT, інформаційний збір, автоматизація, аналітика візуального змісту, геопросторові дані, соціальні мережі, кібер OSINT, технології, джерела даних.

    Гештеги в Twitter:
    1. #OSINT
    2. #InformationGathering
    3. #Automation
    4. #VisualContentAnalytics
    5. #GeospatialData
    6. #SocialMedia
    7. #CyberOSINT
    8. #Technology
    9. #DataSources
    10. #DigitalIntelligence
    11. #MachineLearning
    12. #OpenSourceIntelligence
    13. #BigData
    14. #DigitalForensics
    15. #ResearchTools

  5. #CEOs should map their #collaboration process out to see where they’re short of ideas — most likely in the #InformationGathering stage — then treat that part of #StrategyMaking as a process of #exploring and #discovering what they don’t know, and embrace the volume and complexity of the #ideas they receive. hbr.org/2023/03/leaders-need-t #DesignStrategy #BusinessStrategy #DecisionMaking #innovation via @HarvardBiz

  6. #CEOs should map their #collaboration process out to see where they’re short of ideas — most likely in the #InformationGathering stage — then treat that part of #StrategyMaking as a process of #exploring and #discovering what they don’t know, and embrace the volume and complexity of the #ideas they receive. hbr.org/2023/03/leaders-need-t #DesignStrategy #BusinessStrategy #DecisionMaking #innovation via @HarvardBiz

  7. Need a quick way to find related domains?

    I did, so I wrote a quick #OSINT tool that abuses the SecurityTrails domain search suggestion API to grab a list of domains that start with [string].

    I call it DomainDouche, since it's clearly using their API in a very unintended way and they probably wouldn't like it.

    Grab it while it still works :)

    github.com/n0kovo/DomainDouche

    #infosec #tool #domains #enumeration #recon #reconnaissance #InformationGathering #attacksurface #pentesting #redteam

  8. Need a quick way to find related domains?

    I did, so I wrote a quick #OSINT tool that abuses the SecurityTrails domain search suggestion API to grab a list of domains that start with [string].

    I call it DomainDouche, since it's clearly using their API in a very unintended way and they probably wouldn't like it.

    Grab it while it still works :)

    github.com/n0kovo/DomainDouche

    #infosec #tool #domains #enumeration #recon #reconnaissance #InformationGathering #attacksurface #pentesting #redteam

  9. heise+ | Wie Angreifer dank psychologischer Tricks in Unternehmen eindringen

    Mit Social Engineering dringt unser Autor seit Jahren durch geschicktes Manipulieren von Menschen in Firmengebäude ein. Natürlich nur zu Testzwecken.
    Wie Angreifer dank psychologischer Tricks in Unternehmen eindringen