N’avez-vous jamais eu envie de jouer à Sherlock Homes, d’incarner le colonel « moutarde » dans la cuisine avec le chandelier, adepte du Cluedo je vous salue ! Fort de constater que les méthodes des attaquants (cyber, concurrentiels, recruteurs, officines…) sont basées sur une phase importante de collecte d’information tant humaine que cyber, Il peut être intéressant de se mettre en mode Sherlock » afin d’évaluer son empreinte numérique et pourquoi pas en déterminer des chemins d’attaques.
Thus, like a chess player, to be a few moves ahead. This is the whole art of open-source information-gathering techniques which, when applied with method, patience and perseverance, add depth to digital investigations. This is what this modest article will endeavour to survey, both in terms of method and of the tools used to collect information of interest and of cyber origin.
The first part will be devoted to a definition of so-called "open-source" information, as well as the iterative process used during digital investigations. We will also define the spaces in which one must operate to collect this intelligence, commonly called the Clear, Deep or dark web. This first part will finally define the regulatory framework for investigations and the possible use of avatars.
La deuxième partie tentera au travers des graphes d’expliquer, de façon non exhaustive, comment on peut élaborer un chemin d’approche, d’attaque. Elle permettra de rappeler la menace qui pèse sur les organismes de type OIV (organisme d’importance vital), OSE (organisme stratégique de l’état), via la compromission de sous-traitant de rang N-x, par exemple. Cette partie permettra ainsi d’enrichir la notion « d’empreinte numérique » et d’y associer des graphes méthodologies à partir d’un surnom, d’un Mail…
The third part will finally give an overview of the open-source tools at our disposal and of the value of building a technical watch around tools and publications on 'open-source intelligence'. I will thus talk about the following families of tools:
- Note-taking • OSINT frameworks (Buscador – IntelTechniques)
- Search engines (classic ones, people search, etc.)
- Specialised engines (Shodan, Censys, etc.)
- Specific queries
- Crawlers – Scrapers (BeautifulSoup, Selenium, etc.)
- Applications (Recon-ng, GoCa – Foca, Spiderfoot, etc.)
- Visualisation tools (CaseFile, Gephi.)
- Software-defined radio (SDR) tools
- Keeping a watch on the tools
David Le Goff has worked in government circles for thirty years and is currently a cybersecurity engineer at a French critical-infrastructure operator (OIV). A reserve captain within the Cyber ops reserve. Passionate about technology – a geek of all kinds.