Compass Security OSINT Cheat Sheet
OSINT Cheat Sheet
Google dorking, also known as Google hacking, can return information
that is difficult to locate through simple search queries. Using this
technique, information not intended for public access can be discovered.
The Google Hacking Database (GHDB) is an authoritative source for
querying the ever-widening reach of the Google search engine.
Its contents are search terms, which allow to find usernames, passwords,
and even files containing sensitive information. The GHDB is located here:
https://www.exploit-db.com/google-hacking-database/
Google and Bing Search Operators
Search for the exact phrase within " "
Remove pages that mention a given term from the
search results
Force Google to return common words that might
ordinarily be discarded
Search for a given search term OR another term
Search within a given domain
Search for a certain file type
Search for sites with the given word(s) in the page title
Search for sites with the given word(s) in the URL
Search for sites with the given word(s) in the text of
the page
Search for sites that have the given word(s) in links
pointing to them
Show most recent cache of a webpage
Bing only: Finds results based on a given IP address
Bing only: Search for links on the given domain
Additional Google Features
Search Tools: The "Tools" button present a new row of options, which
allows narrowing downs the search results. One of the most interesting
options of this feature is "Custom Range", which can be used to search
within a given time frame.
Google Images: The most powerful reverse image search service.
https://images.google.com/
Searching for Archived Information
Google and Bing: both search engines offer a cached view of results
The Wayback Machine: http://archive.org/web/
Archive Today: http://archive.is/
Yandex operates the largest search engine in Russia with about 65%
market shares.
Find all results with any word where the
asterisk (*) is located
Cheshire cat | hatter | Alice
Search for any word in query. This query
works for Google as well
This query would mandate that the page
has the word flamingo, but not croquet
Search for specific file type
!Curiouser !and !curiouser
Search for multiple identical words
Twinkle twinkle little -star
Exclude “star” from search results
Narrow search by language
date:200712*,
date:20071215..20080101,
date:>20091231
Narrow search by date or date range
Search Engines: Other Alternatives
carrot2.org: Carrot2 is a clustering search engine that groups search
results into sets of topics
www.exalead.com/search: Exalead works well in finding documents that
contain the search term
millionshort.com: Million Short allows removing results, which link to the
one million most popular websites
globalfilesearch.com: the site claims to have indexed 243 terabytes of
files stored on public FTP servers
Shodan - https://www.shodan.io
Shodan is a search engine for finding Internet-connected devices and
device types. It allows searching for webcams, routers, IoT/SCADA
devices, and more.
Search for results in a given city
Search for results in a given country (2-letter code)
Search for a specific port or ports
Search for values that match the hostname
Search a given IP or subnet (e.g.: 192.168.1.0/24)
Search for the name of the software identified in the
banner
Search for the version of the product
Search for a specific operating system name
Search in the content scraped from the HTML tag
Search in the full HTML contents of the returned
page