SlideShare a Scribd company logo
http://datasploit.info | @datasploit
https://github.com/datasploit/datasploit
• Just another Pen-tester.
• Security Consultant @ NotSoSecure
• 5+ Years of Experience
• Twitter - @upgoingstar
• Email - upgoingstaar@gmail.com
What’s DataSploit?
• Automated OSINT Tool for Domain / Email / Username / IP Addresses
• Fetches information from multiple HIDDEN sources.
• Works in passive mode.
• Written in Python.
• Multiple report formats available.
• Customized for Pen-testers / Product Security Guys / Cyber
Investigators.
Why DataSploit?
• So much data.
• Server’s Username / Passwords
• Address
• Email Id
• Phone Number
• Credentials
• Interests
• Friends
• Preferences
• Legacy Machines
• Unnecessary Ports Information
• Technologies in use, and blah blah..
Lets talk real time? History?
Components
• Domain Osint
• Email Osint
• IP Osint
• Username Osint
• WIP
• Company Scoping
• Phone Number OSINT
• Active Modules
Sources and Flow
Email:
Basic Email Checks
Work History
Social profiles
Enumerated Usernames 
Location Information
Slides
Scribd Documents
Related Websites
HaveIBeenPwned
Domain:
WhoIS
DNS Records
PunkSpider
Wappalyzer
Github
Email Harvestor 
Domain IP History
Paste(s) Search
Pagelinks
Wikileaks
Links from Forums
Passive SSL Scan
ZoomEye
Shodan
Censys
Subdomains 
Username:
Git Details
Check username on various sites.
Profile Pics –Output saved in
$username directory
Frequent Hashtags
Interaction on Twitter.
Active Modules
Setting it up..
• Manual
• Download from git (git clone or download)
git clone https://github.com/DataSploit/datasploit.git
• pip install –r requirements.txt
• config.py holds API keys
• domain_xyz.py – running stand alone scripts.
• domainOsint / emailOsint / ipOsint – automated OSINT
• active_scan.py
• Automated
• https://hub.docker.com/r/appsecco/datasploit/
• https://hub.docker.com/r/ftorn/datasploit/
Documentation.
https://datasploit.github.io/datasploit/
What’s in there?
Output Formats
• HTML
• JSON
• Emails List (txt file)
• Subdomains List (txt file)
DataSploit - BlackHat Asia 2017
Twitter:
@datasploit
https://twitter.com/datasploit
Facebook:
/datasploit
https://www.facebook.co
m/datasploit/
Roadmap
• Allows to set up periodic scans and alerting for product security companies.
• Intelligence on co-relation and identity verification.
• Reports in CSV.
• Reverse Image Search and profile validation.
• Works closely with various social network APIs.
• Refine Pastebin and Github Searches.
• IP Threat Intelligence.
• Organization Scoping.
• Integration with SE other tools.
• Cloud related OSINT and active modules.
• pip install datasploit (to be installed as both library as well as script)
Coverage
How to Contribute
• Help us in testing the tool
• Expand : Write/Suggest modules
• Give Feedback: raise issues, tweet, drop an email.
• Use / Promote / Write about the tool.
• Write OSINT blogs / tool walkthrough(s) / etc.
• Report issues at https://github.com/datasploit/datasploit/issues
Core Contributors.
• Shubham Mittal (@upgoingstar)
• Nutan Kumar Panda (@nutankumarpanda)
• Sudhanshu (@sudhanshu_c)
• Kunal (@KunalAggarwal92)
• Kudos to
• @anantshri for mentoring.
• @ bnchandrapal for feedbacks, suggestions and other help around issues.
Thanks. g0t questions?
https://github.com/DataSploit/datasploit
Follow @datasploit for OSINT news and latest updates.
Tweet / DM to @datasploit
upgoingstaar@gmail.com

More Related Content

PPTX
Datasploit - An Open Source Intelligence Tool
Shubham Mittal
 
PPTX
Tools for Open Source Intelligence (OSINT)
Sudhanshu Chauhan
 
PPTX
DataSploit - Tool Demo at Null Bangalore - March Meet.
Shubham Mittal
 
PDF
Rv defcon25 osint tactics on source code intelligence - simon roses
reconvillage
 
PPTX
OSINT using Twitter & Python
37point2
 
PPTX
Let’s hunt the target using OSINT
Chandrapal Badshah
 
PDF
Osint ashish mistry
n|u - The Open Security Community
 
PDF
OSINT x UCCU Workshop on Open Source Intelligence
Philippe Lin
 
Datasploit - An Open Source Intelligence Tool
Shubham Mittal
 
Tools for Open Source Intelligence (OSINT)
Sudhanshu Chauhan
 
DataSploit - Tool Demo at Null Bangalore - March Meet.
Shubham Mittal
 
Rv defcon25 osint tactics on source code intelligence - simon roses
reconvillage
 
OSINT using Twitter & Python
37point2
 
Let’s hunt the target using OSINT
Chandrapal Badshah
 
OSINT x UCCU Workshop on Open Source Intelligence
Philippe Lin
 

What's hot (20)

PDF
Web application penetration testing lab setup guide
Sudhanshu Chauhan
 
PPTX
OSINT for Proactive Defense - RootConf 2019
RedHunt Labs
 
KEY
Enterprise Open Source Intelligence Gathering
Tom Eston
 
PDF
Open Source Information Gathering Brucon Edition
Chris Gates
 
PPTX
OSINT mindset to protect your organization - Null monthly meet version
Chandrapal Badshah
 
PPTX
Dark Arts Of Social Engineering
Nutan Kumar Panda
 
PPT
Open source intelligence
balakumaran779
 
PDF
Practical White Hat Hacker Training - Passive Information Gathering(OSINT)
PRISMA CSI
 
PDF
OSINT- Leveraging data into intelligence
Deep Shankar Yadav
 
PDF
Stop pulling the plug
Kamal Rathaur
 
PPTX
Getting started with using the Dark Web for OSINT investigations
Olakanmi Oluwole
 
PPTX
Hacker tool talk: maltego
Chris Hammond-Thrasher
 
PDF
What you need to know about OSINT
Jerod Brennen
 
PDF
Offensive OSINT
Christian Martorella
 
PPTX
Empowering red and blue teams with osint c0c0n 2017
reconvillage
 
PDF
Osint presentation nov 2019
Priyanka Aash
 
PPTX
osint - open source Intelligence
Osama Ellahi
 
PPTX
Maltego
penetration Tester
 
PPTX
OSINT Black Magic: Listen who whispers your name in the dark!!!
Nutan Kumar Panda
 
PPTX
Maltego Magic Workshop - BSides London 2015
Adam Maxwell
 
Web application penetration testing lab setup guide
Sudhanshu Chauhan
 
OSINT for Proactive Defense - RootConf 2019
RedHunt Labs
 
Enterprise Open Source Intelligence Gathering
Tom Eston
 
Open Source Information Gathering Brucon Edition
Chris Gates
 
OSINT mindset to protect your organization - Null monthly meet version
Chandrapal Badshah
 
Dark Arts Of Social Engineering
Nutan Kumar Panda
 
Open source intelligence
balakumaran779
 
Practical White Hat Hacker Training - Passive Information Gathering(OSINT)
PRISMA CSI
 
OSINT- Leveraging data into intelligence
Deep Shankar Yadav
 
Stop pulling the plug
Kamal Rathaur
 
Getting started with using the Dark Web for OSINT investigations
Olakanmi Oluwole
 
Hacker tool talk: maltego
Chris Hammond-Thrasher
 
What you need to know about OSINT
Jerod Brennen
 
Offensive OSINT
Christian Martorella
 
Empowering red and blue teams with osint c0c0n 2017
reconvillage
 
Osint presentation nov 2019
Priyanka Aash
 
osint - open source Intelligence
Osama Ellahi
 
OSINT Black Magic: Listen who whispers your name in the dark!!!
Nutan Kumar Panda
 
Maltego Magic Workshop - BSides London 2015
Adam Maxwell
 
Ad

Similar to DataSploit - BlackHat Asia 2017 (20)

PPTX
Social Media Data Collection & Analysis
Scott Sanders
 
PPTX
The Hacking Game - Think Like a Hacker Meetup 12072023.pptx
lior mazor
 
PPTX
Defending the Enterprise with Evernote at SourceBoston on May 27, 2015
grecsl
 
PPTX
Blue Teaming On A Budget
KevinRiley83
 
PDF
DEVNET-2002 Coding 201: Coding Skills 201: Going Further with REST and Python...
Cisco DevNet
 
PDF
Open Data and Web API
Sammy Fung
 
PPTX
Dutch Information Worker User Group - January 2022 - eDiscovery and Microsoft...
Albert Hoitingh
 
PDF
OSINT for Attack and Defense
Andrew McNicol
 
PDF
Continuum Analytics and Python
Travis Oliphant
 
PDF
Reproducibility and automation of machine learning process
Denis Dus
 
PDF
SharePoint goes Microsoft Graph
Markus Moeller
 
PDF
How a Tweet Went Viral - BIWA Summit 2017
Rittman Analytics
 
PDF
CNIT 121: 14 Investigating Applications
Sam Bowne
 
PPTX
how to connect your app to the activity stream with x-pages
Frank van der Linden
 
PDF
Searching Chinese Patents Presentation at Enterprise Data World
OpenSource Connections
 
PPTX
Muhammad Sarfaraz(Presentation) Final.pptx
sarfarazkhanwattoo
 
PDF
Advanced Research Investigations for SIU Investigators
Sloan Carne
 
PDF
Building APIs in an easy way using API Platform
Antonio Peric-Mazar
 
PDF
IT Systems for Knowledge Management used in Software Engineering (2010)
Peter Kofler
 
PDF
NotaCon 2011 - Networking for Pentesters
Rob Fuller
 
Social Media Data Collection & Analysis
Scott Sanders
 
The Hacking Game - Think Like a Hacker Meetup 12072023.pptx
lior mazor
 
Defending the Enterprise with Evernote at SourceBoston on May 27, 2015
grecsl
 
Blue Teaming On A Budget
KevinRiley83
 
DEVNET-2002 Coding 201: Coding Skills 201: Going Further with REST and Python...
Cisco DevNet
 
Open Data and Web API
Sammy Fung
 
Dutch Information Worker User Group - January 2022 - eDiscovery and Microsoft...
Albert Hoitingh
 
OSINT for Attack and Defense
Andrew McNicol
 
Continuum Analytics and Python
Travis Oliphant
 
Reproducibility and automation of machine learning process
Denis Dus
 
SharePoint goes Microsoft Graph
Markus Moeller
 
How a Tweet Went Viral - BIWA Summit 2017
Rittman Analytics
 
CNIT 121: 14 Investigating Applications
Sam Bowne
 
how to connect your app to the activity stream with x-pages
Frank van der Linden
 
Searching Chinese Patents Presentation at Enterprise Data World
OpenSource Connections
 
Muhammad Sarfaraz(Presentation) Final.pptx
sarfarazkhanwattoo
 
Advanced Research Investigations for SIU Investigators
Sloan Carne
 
Building APIs in an easy way using API Platform
Antonio Peric-Mazar
 
IT Systems for Knowledge Management used in Software Engineering (2010)
Peter Kofler
 
NotaCon 2011 - Networking for Pentesters
Rob Fuller
 
Ad

Recently uploaded (20)

PPTX
The Internet of Things (IoT) refers to a vast network of interconnected devic...
chethana8182
 
PPTX
The Latest Scam Shocking the USA in 2025.pptx
onlinescamreport4
 
PDF
Latest Scam Shocking the USA in 2025.pdf
onlinescamreport4
 
PDF
PDF document: World Game (s) Great Redesign.pdf
Steven McGee
 
PPTX
原版北不列颠哥伦比亚大学毕业证文凭UNBC成绩单2025年新版在线制作学位证书
e7nw4o4
 
PPTX
Parallel & Concurrent ...
yashpavasiya892
 
PDF
KIPER4D situs Exclusive Game dari server Star Gaming Asia
hokimamad0
 
PDF
The Internet of Things (IoT) refers to a vast network of interconnected devic...
chethana8182
 
PDF
DNSSEC Made Easy, presented at PHNOG 2025
APNIC
 
PPTX
办理方法西班牙假毕业证蒙德拉贡大学成绩单MULetter文凭样本
xxxihn4u
 
PPTX
Generics jehfkhkshfhskjghkshhhhlshluhueheuhuhhlhkhk.pptx
yashpavasiya892
 
PPTX
谢尔丹学院毕业证购买|Sheridan文凭不见了怎么办谢尔丹学院成绩单
mookxk3
 
PDF
Project English Paja Jara Alejandro.jpdf
AlejandroAlonsoPajaJ
 
PPTX
EthicalHack{aksdladlsfsamnookfmnakoasjd}.pptx
dagarabull
 
PPT
1965 INDO PAK WAR which Pak will never forget.ppt
sanjaychief112
 
PPT
Transformaciones de las funciones elementales.ppt
rirosel211
 
PDF
LB# 820-1889_051-7370_C000.schematic.pdf
matheusalbuquerqueco3
 
PPTX
Perkembangan Perangkat jaringan komputer dan telekomunikasi 3.pptx
Prayudha3
 
PPTX
AI ad its imp i military life read it ag
ShwetaBharti31
 
PPTX
Black Yellow Modern Minimalist Elegant Presentation.pptx
nothisispatrickduhh
 
The Internet of Things (IoT) refers to a vast network of interconnected devic...
chethana8182
 
The Latest Scam Shocking the USA in 2025.pptx
onlinescamreport4
 
Latest Scam Shocking the USA in 2025.pdf
onlinescamreport4
 
PDF document: World Game (s) Great Redesign.pdf
Steven McGee
 
原版北不列颠哥伦比亚大学毕业证文凭UNBC成绩单2025年新版在线制作学位证书
e7nw4o4
 
Parallel & Concurrent ...
yashpavasiya892
 
KIPER4D situs Exclusive Game dari server Star Gaming Asia
hokimamad0
 
The Internet of Things (IoT) refers to a vast network of interconnected devic...
chethana8182
 
DNSSEC Made Easy, presented at PHNOG 2025
APNIC
 
办理方法西班牙假毕业证蒙德拉贡大学成绩单MULetter文凭样本
xxxihn4u
 
Generics jehfkhkshfhskjghkshhhhlshluhueheuhuhhlhkhk.pptx
yashpavasiya892
 
谢尔丹学院毕业证购买|Sheridan文凭不见了怎么办谢尔丹学院成绩单
mookxk3
 
Project English Paja Jara Alejandro.jpdf
AlejandroAlonsoPajaJ
 
EthicalHack{aksdladlsfsamnookfmnakoasjd}.pptx
dagarabull
 
1965 INDO PAK WAR which Pak will never forget.ppt
sanjaychief112
 
Transformaciones de las funciones elementales.ppt
rirosel211
 
LB# 820-1889_051-7370_C000.schematic.pdf
matheusalbuquerqueco3
 
Perkembangan Perangkat jaringan komputer dan telekomunikasi 3.pptx
Prayudha3
 
AI ad its imp i military life read it ag
ShwetaBharti31
 
Black Yellow Modern Minimalist Elegant Presentation.pptx
nothisispatrickduhh
 

DataSploit - BlackHat Asia 2017