1
1

00:00:00,330  -->  00:00:02,823
<v Instructor>Open Source Intelligence or OSINT.</v>
2

2

00:00:03,840  -->  00:00:05,520
What is OSINT?
3

3

00:00:05,520  -->  00:00:08,640
OSINT is the ability to use publicly available information,
4

4

00:00:08,640  -->  00:00:10,440
plus the tools used to aggregate
5

5

00:00:10,440  -->  00:00:12,300
and search that information.
6

6

00:00:12,300  -->  00:00:13,680
Now, there's a lot of different ways
7

7

00:00:13,680  -->  00:00:16,650
to collect open source intelligence out there.
8

8

00:00:16,650  -->  00:00:19,140
Now, many companies and individuals work
9

9

00:00:19,140  -->  00:00:21,780
in organizations that have a ton of information
10

10

00:00:21,780  -->  00:00:24,060
that's published on the internet about them.
11

11

00:00:24,060  -->  00:00:26,610
For instance, my small little company has a lot
12

12

00:00:26,610  -->  00:00:28,140
of information about us.
13

13

00:00:28,140  -->  00:00:30,750
You can go online into the web or social media sites
14

14

00:00:30,750  -->  00:00:32,910
and find lots of information about us.
15

15

00:00:32,910  -->  00:00:35,070
This is all open source intelligence,
16

16

00:00:35,070  -->  00:00:37,170
and if you were trying to target and attack us
17

17

00:00:37,170  -->  00:00:40,200
you could use this to cyber stalk us and determine all sorts
18

18

00:00:40,200  -->  00:00:42,960
of information about us using things like Google
19

19

00:00:42,960  -->  00:00:46,560
and Bing and Duck, Duck, Go, and many other tools out there
20

20

00:00:46,560  -->  00:00:49,110
all over the web to collect this data
21

21

00:00:49,110  -->  00:00:52,350
and build a whole dossier on me or my company.
22

22

00:00:52,350  -->  00:00:54,810
Now, attackers use OSINT all the time
23

23

00:00:54,810  -->  00:00:57,420
because OSINT can allow an attacker to develop a number
24

24

00:00:57,420  -->  00:00:59,670
of strategies for compromising a target.
25

25

00:00:59,670  -->  00:01:01,680
For instance, if you are an attacker
26

26

00:01:01,680  -->  00:01:04,080
you might find an employee that works for a company
27

27

00:01:04,080  -->  00:01:07,440
on a dating website and strike up a conversation with them,
28

28

00:01:07,440  -->  00:01:09,930
get them interested in you, and then start asking them
29

29

00:01:09,930  -->  00:01:13,050
for details about their company's security procedures maybe.
30

30

00:01:13,050  -->  00:01:14,940
This is a great way to start getting information
31

31

00:01:14,940  -->  00:01:16,860
out of them using social engineering.
32

32

00:01:16,860  -->  00:01:19,680
Or you might put them in a compromising situation
33

33

00:01:19,680  -->  00:01:22,290
and then use that for blackmail or entrapment.
34

34

00:01:22,290  -->  00:01:24,660
There's lots of different ways that OSINT can be used
35

35

00:01:24,660  -->  00:01:27,780
out in the real world as an attacker going after people
36

36

00:01:27,780  -->  00:01:30,630
in your company, so it's something to keep in mind.
37

37

00:01:30,630  -->  00:01:31,890
Now, when we talk about OSINT,
38

38

00:01:31,890  -->  00:01:33,900
what are some of the sources of OSINT?
39

39

00:01:33,900  -->  00:01:36,180
Well, we have publicly available information.
40

40

00:01:36,180  -->  00:01:39,060
This is information that any attacker can harvest out there
41

41

00:01:39,060  -->  00:01:41,850
from public repositories or web searches.
42

42

00:01:41,850  -->  00:01:43,560
For instance, if you wanted to find
43

43

00:01:43,560  -->  00:01:46,050
my company's physical address, you could Google that
44

44

00:01:46,050  -->  00:01:48,750
and figure out where we are in San Juan, Puerto Rico.
45

45

00:01:48,750  -->  00:01:51,150
This data is publicly available.
46

46

00:01:51,150  -->  00:01:53,220
Also, you can use social media.
47

47

00:01:53,220  -->  00:01:56,190
Social media is great because you can go on Facebook
48

48

00:01:56,190  -->  00:01:59,100
or LinkedIn and start friending and liking people
49

49

00:01:59,100  -->  00:02:01,440
and making a connection, and then use that
50

50

00:02:01,440  -->  00:02:04,290
for additional attacks such as social engineering.
51

51

00:02:04,290  -->  00:02:06,090
You might also use HTML code.
52

52

00:02:06,090  -->  00:02:09,360
If you search the HTML code of an organization's webpage,
53

53

00:02:09,360  -->  00:02:12,570
you can find lots of information in there like IP addresses,
54

54

00:02:12,570  -->  00:02:15,420
names of web servers, what operating system version
55

55

00:02:15,420  -->  00:02:17,460
they're using, what file paths there are,
56

56

00:02:17,460  -->  00:02:19,470
names of people who work there and developers
57

57

00:02:19,470  -->  00:02:22,380
and admin and all sorts of other stuff.
58

58

00:02:22,380  -->  00:02:25,020
Again, by looking through code, you can find a lot
59

59

00:02:25,020  -->  00:02:28,050
of information about an organization, their capabilities,
60

60

00:02:28,050  -->  00:02:30,720
their practices, and their security posture.
61

61

00:02:30,720  -->  00:02:32,670
And finally, you can also look at metadata
62

62

00:02:32,670  -->  00:02:35,430
because metadata is open source intelligence.
63

63

00:02:35,430  -->  00:02:38,010
If you publish a Word document or an Excel spreadsheet
64

64

00:02:38,010  -->  00:02:40,890
to your website, there's metadata inside of that,
65

65

00:02:40,890  -->  00:02:43,650
and by going through that metadata, we can start collecting
66

66

00:02:43,650  -->  00:02:46,260
a lot of information and start fingerprinting you
67

67

00:02:46,260  -->  00:02:48,990
and understanding exactly what documents belong
68

68

00:02:48,990  -->  00:02:52,620
to your company as we do a wider search across the internet.
69

69

00:02:52,620  -->  00:02:57,210
Now, one quick tip about OSINT for the C-Y-S-A plus exam.
70

70

00:02:57,210  -->  00:02:59,670
On the older version of the C-Y-S-A plus exam,
71

71

00:02:59,670  -->  00:03:01,440
they actually asked you to do a lot more
72

72

00:03:01,440  -->  00:03:03,870
with OSINT and be able to search for information
73

73

00:03:03,870  -->  00:03:07,680
on your own company, but that doesn't exist anymore.
74

74

00:03:07,680  -->  00:03:09,720
Instead, when they talk about OSINT,
75

75

00:03:09,720  -->  00:03:12,720
they're referring specifically to open source threat data
76

76

00:03:12,720  -->  00:03:15,270
and intelligence sources, and it's not going to be focused
77

77

00:03:15,270  -->  00:03:17,820
on your ability to actually conduct OSINT.
78

78

00:03:17,820  -->  00:03:20,100
Now in this course, we are going to do a little bit
79

79

00:03:20,100  -->  00:03:21,900
of OSINT and we are going to play a little bit
80

80

00:03:21,900  -->  00:03:24,030
in that reconnaissance world as we go through
81

81

00:03:24,030  -->  00:03:26,160
and learn about Google hacking and search tools
82

82

00:03:26,160  -->  00:03:27,630
and things like Shodan.
83

83

00:03:27,630  -->  00:03:29,160
And this is all good information to know
84

84

00:03:29,160  -->  00:03:32,550
and understand as a cybersecurity analyst in the real world
85

85

00:03:32,550  -->  00:03:35,150
but you won't have to know it in depth for the exam.
