On the occasion of the Postgraduate Degree in Cybersecurity that we direct from onBRANDING, Selva Orejón has written this post for all those professionals who wish to dedicate themselves to OSINT within the field of Cyber-investigation.
Just as fishing is an art, searching for information on the Internet also has its methods, tools and, above all, the experience of the “fisherman” who knows where to look, what to look for, what to look with, and how to find it. The acronym OSINT (Open Source Intelligence) is already part of most police and private investigations, including those carried out for marketing purposes, market research, and studies on clients and business competition.
We are going to focus on how to obtain that information. The first step is to have a proven methodology based on experience, which is why the human factor is very important: it is the “trackers” who apply their knowledge and tools to achieve the collection of information. These trackers are often also responsible for analyzing all the information obtained, becoming intelligence analysts; this directly conflicts with the traditional intelligence cycle, in which these two functions (collection and analysis) should be performed by different people with different technical profiles.
Returning to the methodology, the first thing to do is understand the objective of the investigation: it is not the same to try to find information about a multinational to identify its weak points in the market as it is to look for information about a person who is harassing another through social networks. Once the objective is set, we will choose which sources we are going to search, which tools are the most suitable, and what strategy we will follow in the investigation. With all the results we obtain, we will have to validate the information so that, once filtered, it can be given the appropriate processing and presentation for dissemination—dissemination being understood as communicating the results to the client or, otherwise, delivering the relevant report to whoever requested it.
Information gathering
When searching for information, we must not make the mistake of thinking that everything is on the Internet, nor that everything we find will be of value to our investigation; therefore, the use of specific tools becomes necessary, which will sometimes be free and—in most cases—not. However, there is something that tools, to this day, are not capable of doing: discriminating between false information and duplicate results. This is why I insist on the figure of the analyst, capable of filtering the results and choosing the correct ones. This serves to reduce uncertainty for the consumer of our investigation.
In any investigation, a trail is usually left that any other investigator or “bad actor” can follow to discover that someone is interested in the information they possess or publish. This happens with connections from the same IP when visiting websites, forums, or blogs to obtain information, where administrators can check the addresses of users who have accessed their content and obtain the investigator’s identity.
Security plays a very important role when it comes to monitoring or obtaining data from entities on the Internet; browsing with a VPN or proxy, using exclusive profiles for each case, and avoiding routine connection times can prevent us from being discovered.
So, as a first conclusion, we can say: go fishing, but with a good rod and good boots so that the fish we want to catch don’t bite us. The search in open sources, that is, in publicly accessible sites, will provide intelligence to our organization or our clients, as used at strategic, operational, and tactical levels, it provides alerts, information, and decision-making support, respectively. One of the main advantages of obtaining information from open sources is the low economic, technical (without neglecting security), and human cost, since a single experienced tracker/analyst can obtain a vast amount of information.
