9

Click here to load reader

Open Source Intelligence (OSINT) with Maltego

Embed Size (px)

Citation preview

Page 1: Open Source Intelligence (OSINT) with Maltego
Page 2: Open Source Intelligence (OSINT) with Maltego

define:OSINT A form of intelligence

collection management thatinvolves finding, selecting,and acquiring informationfrom publicly available sourcesand analyzing it to produceactionable intelligence.

Page 3: Open Source Intelligence (OSINT) with Maltego

What is Maltego?

Maltego is an Open SourceIntelligence application, whichprovides a platform to not onlyextract data but also torepresent that data in a formatwhich is easy to understand aswell as analyze.

Page 4: Open Source Intelligence (OSINT) with Maltego

Basic Blocks Entity: An entity is a piece of data which is taken as an input to extract

further information. E.g. domain name xyz.com

Transform: A piece of code which takes an entity (or a group of entities) as an input and extracts data in the form of entity (or entities) based upon the relationship. E.g. DomainToDNSNameSchema: this transform will try to test various name schemas against a domain (entity).

Machine: A machine is basically a set of transforms linked programmatically. E.g. Footprint L1: a transform which takes a domain as an input and generates various types of information related to the organization such as emails, AS number etc.

Page 5: Open Source Intelligence (OSINT) with Maltego

Maltego Interface

Page 6: Open Source Intelligence (OSINT) with Maltego

DEMO TIME

Page 7: Open Source Intelligence (OSINT) with Maltego

Special Mention Sudhashu Chauhan (@Sudhanshu_C)

The official osintguy https://github.com/SudhanshuC/Maltego-Transforms

Author: Hacking Web Inteligence

Troy Hunt (@troyhunt)

Software architect

http://www.troyhunt.com/

https://haveibeenpwned.com/

Page 8: Open Source Intelligence (OSINT) with Maltego

Reference https://www.paterva.com/web6/documentation/devel

oper.php

http://resources.infosecinstitute.com/doxing-the-dark-side-of-reconnaissance/

http://resources.infosecinstitute.com/information-gathering-maltego/

http://blog.kaffenews.com/2012/12/02/sploitego-maltego-local-transforms/

Page 9: Open Source Intelligence (OSINT) with Maltego

Q/A