1 of 54

NCDPI K-12 Cybersecurity Program ��Open Source Intelligence for PSUs

Digital Leaders Exchange 2024 �Data Privacy and Cybersecurity

Tim Wease, NCDPI

Samuel Carter, Friday Institute

September 2024

2 of 54

Open Source Intelligence for PSUs

In today's PSU digital environments, information is everywhere, waiting to be discovered and analyzed. Open Source Intelligence (OSINT) is the practice of collecting, analyzing, and interpreting information gathered from publicly available sources. From social media platforms to online databases, OSINT offers a wealth of data that can be leveraged for various purposes, including research, investigation, and decision-making. In this session, we will explore the fascinating world of OSINT and its relevance in the K-12 education landscape. We will focus on what OSINT is, its significance in the digital age, the types of information that can be obtained through OSINT, and demonstrate some real-world examples showcasing how OSINT can be applied in educational settings.

2

3 of 54

About Tim Wease

  • PSU IT Security Specialist at NCDPI�
  • One of the original founding members of the K-12 Cybersecurity Advisory Council (CAC) in 2021�
  • Leading NCDPI K-12 Cybersecurity Program and the core teams/partners who provide the various cybersecurity services and resources to the PSUs

  • 19 years experience (15 in PSU and 4 at DPI)�

3

4 of 54

About Samuel Carter

  • Systems Architect, Friday Institute
  • College of Education, N.C. State University
    • 13 years (10+3)�
  • Adjunct Professor, Computer Science
  • College of Engineering, N.C. State University
    • 19 years�
  • Planning, design, procure, implement, and support of large statewide technology services
    • e.g. NCVPS, NCEdCloud, K-12 Cybersecurity�
  • Extensive background in Cybersecurity with a specialization in Identity and Access management

4

5 of 54

Agenda

  • Introduction and Program Background�
  • OSINT Background and Overview�
  • Select OSINT Tools and Resource�
  • Resources�
  • Q&A

5

6 of 54

Disclaimer Statement

The information and tools provided in this session are intended for educational purposes only. Any demonstration of information collection and penetration testing tools is conducted in a controlled, ethical, and responsible manner. PSUs are advised to use these tools only in authorized environments, with proper permissions, and with caution to prevent malicious activity. Unauthorized use or application of these tools outside of the educational context may be illegal and is strictly discouraged. Always adhere to legal and ethical standards when working with cybersecurity tools.

6

7 of 54

OSINT Background �and Overview

7

8 of 54

Data as a Currency

  • Data is a form of currency, as it holds significant value for cybercriminals who trade, sell, or exploit it for financial gain and other malicious purposes. �
  • Personal identifiable information (PII), financial details, medical records, intellectual property, and corporate secrets are all highly sought-after commodities in the underground cybercriminal economy.�
  • Hackers and cybercriminals leverage stolen data in several ways such as monetization, ransom, exploitation, and espionage.

8

9 of 54

What is OSINT?

Open Source Intelligence (OSINT) generally refers to the process of collecting, analyzing, and disseminating information that is publicly available from various open sources.

9

10 of 54

What is OSINT?

  • Threat actors use OSINT to uncover sensitive information they can leverage to exploit vulnerabilities in technical systems as well as individuals�
  • PSUs can use OSINT as a cybersecurity tool to gain awareness of information available to minimize the exposure and detect some of the reconnaissance activities. �

The goal is to minimize how much of your personal and organizational information is publicly available.

10

11 of 54

Data Control and Reconnaissance

11

12 of 54

Data Control

  • Controlled information refers to data that is actively managed, protected, and restricted by policies, procedures, and technologies to ensure its confidentiality, integrity, and availability.
    • This includes sensitive data such as key employee and student personal information, academic records, special education records, health information, parent/guardian Information, etc.�
  • Not-Controlled information refers to data that is not subject to stringent management or protection measures.
    • This can include required public information, general business data, website, board policies, and other non-sensitive content

12

13 of 54

Reconnaissance

  • The reconnaissance phase of hacking/intrusions, also known as the information-gathering or footprinting phase, is the initial stage in the cyber attack lifecycle where the attacker collects as much information as possible about the target.
  • This phase is crucial for planning and executing subsequent stages of an attack. �
  • The main objective of reconnaissance is to understand the target’s systems, networks, and potential vulnerabilities.
  • Reconnaissance can be divided into two main types: Passive and Active

13

14 of 54

Passive Reconnaissance

  • In Passive Reconnaissance approach, attackers gather information without directly interacting with the target systems to avoid detection. �
  • This includes activities such as
    • analyzing public records and databases,
    • collecting information from social media, websites, and public forums, and
    • using other open-source intelligence (OSINT) tools and techniques to gather data.�
  • Using established intermediary services creates a level of anonymity between the attack and victim (e.g. shodan.io, search.censys.io)

14

15 of 54

Passive Recon with Shodan and Censys

Demo

15

16 of 54

Active Reconnaissance

  • Active Reconnaissance involves directly interacting with the target systems to obtain more detailed information, which may increase the risk of detection. �
  • Techniques include actions such as
    • Scanning the target network with Nmap to identify open ports and services.
    • Sending phishing emails to gather credentials or other sensitive information.
    • Probing the target’s infrastructure for configuration details.
    • Dialing the org phone tree for names and extensions

16

17 of 54

Active Recon with Nmap

Demo

17

18 of 54

Reconnaissance

  • By meticulously gathering this information, attackers can build a detailed profile of the target, identify potential weaknesses, and plan an effective attack strategy with minimal risk of detection. �
  • For defenders, understanding the reconnaissance phase is crucial for implementing effective countermeasures, such as monitoring for unusual activity, using honeypots, and employing robust security practices to minimize exposed information.

18

19 of 54

Reconnaissance Approach

  • OSINT DOJO has a rich set of OSINT resources including a set of OSINT Attack Surface Diagrams that provides a general framework how to proceed from different data point perspectives. �
  • Attack Surface Diagrams

19

20 of 54

OSINT Attack Surface Diagrams

Demo

20

21 of 54

Select OSINT Tools and Resource

21

22 of 54

DNS OSINT

  • DNS (Domain Name System) is a hierarchical system that translates human-readable domain names like www.example.com into numerical IP addresses like 93.184.215.14, enabling users to access websites and other resources on the Internet.�
  • In addition to basic IP/Hostname translations, DNS provides a variety of other functions such as email routing, load balancing, service discovery, reverse dns lookup and security enhancements.

22

23 of 54

DNS OSINT

  • DNS is a rich resource for OSINT (Open Source Intelligence) because it provides valuable information about domain ownership/registrar, DNS provider, web hosting provider, IP address mappings, email server details, marketing/sales tools, subdomains, service configurations, and sometimes sensitive information.
  • Enumerating and analyzing DNS records can reveal insights into an organization's infrastructure, identify potential vulnerabilities, and uncover associations between different entities, making it a crucial tool for cybersecurity investigations and intelligence gathering (think attack surface).

DNSDumpster.com and DNSTwist.it are online tool used for performing network reconnaissance, specifically focusing on DNS (Domain Name System) information

23

24 of 54

DNS OSINT

dnsdumpster.com

dnstwist.it

Demo

24

25 of 54

Metadata

  • Metadata in the context of files and images refers to the additional information that describes and provides context for the primary data.
  • This information helps users and systems understand, organize, and manage the files and images more effectively. �
  • Metadata can include a wide range of details, from basic file attributes to more complex descriptive information.

EXIF.tools is a multimedia file metadata tool that runs exiftool to extract all metadata about an uploaded or internet-located object.

25

26 of 54

EXIF Metadata

Demo

26

27 of 54

Whois OSINT

  • WHOIS is a query and response protocol widely used for querying databases that store the registered users or assignees of an Internet resource, such as a domain name, an IP address block, or an autonomous system. �
  • WHOIS information is a rich resource for OSINT because it contains detailed data about domain ownership, including registrant names, contact information, registration dates, and domain status. �

whoisfreaks.com provides a platform to access detailed information about any domain on the internet.

27

28 of 54

whoisfreaks

Demo

28

29 of 54

Google Alerts

  • Google Alerts is a free online tool provided by Google that allows users to monitor the web for new content that matches specific search queries. �
  • When new content is indexed by Google that matches the criteria set in a Google Alert, the user receives an email notification with links to the content.

29

30 of 54

Google Alerts

Demo

30

31 of 54

Netcraft Site Report

“Netcraft is the global leader in cybercrime detection and disruption. We’re a trusted partner for three of the four largest companies in the world, twelve of the fifty largest banks, and five country governments. We’ve blocked almost 200 million malicious sites and perform takedowns on around one-third of the world’s phishing sites. ”

Netcraft

31

32 of 54

Netcraft Site Report

Demo

32

33 of 54

IntelTechniques Search Tools

  • These tools were created as a supplement to the book OSINT Techniques, 10th Edition by Michael Bazzell and the IntelTechniques online OSINT training by Jason Edison.

IntelTechniques

33

34 of 54

IntelTechniques

Demo

34

35 of 54

ThatsThem

  • ThatsThem was launched in 2014 to give users a free tool to easily find people using the information you know about them.
    • Search database of over a billion public records for US states
    • Access contact information associated with an address, IP address, email address, phone number, VIN.
    • Find out what network a phone number is associated with.
    • Geo locate about the person currently associated with an IP address.
    • Find people associated to the individual you are looking for.

https://thatsthem.com/

35

36 of 54

ThatsThem

Demo

36

37 of 54

whatsmyname.app

  • This tool allows you to enumerate usernames across many websites�
  • Website version of WhatsMyName proudly developed by OSINT Combine (https://www.osintcombine.com) in collaboration with Micah Hoffman.

https://whatsmyname.app/

37

38 of 54

WhatsMyName

Demo

38

39 of 54

Internet Archive

  • The Wayback Machine is an initiative of the Internet Archive, a 501(c)(3) non-profit, building a digital library of Internet sites and other cultural artifacts in digital form.�

https://web.archive.org/

39

40 of 54

Internet Archive�Wayback Machine

Demo

40

41 of 54

theHarvester

  • theHarvester is a simple to use, yet powerful tool designed to be used during the reconnaissance stage of a red team assessment or penetration test. �
  • It performs open source intelligence (OSINT) gathering to help determine a domain's external threat landscape. �
  • The tool gathers names, emails, IPs, subdomains, and URLs by using multiple public resources such as anubis, certspotter, dnsdumpter, otx, rapiddns, sitedossier, etc.�
  • https://github.com/laramies/theHarvester (native in Kali)

41

42 of 54

theHarvester

Demo

42

43 of 54

Open Source Intelligence Framework

  • OSINT framework focused on gathering information from free tools or resources. �
  • The intention is to help people find free OSINT resources. �
  • Some of the sites included might require registration or offer more data for $$$, but you should be able to get at least a portion of the available information for no cost.�
  • Example: Default Password DB from Exploits and Advisories

43

44 of 54

OSINT Framework

Demo

44

45 of 54

Awesome OSINT

  • Awesome OSINT is a curated list of amazingly awesome open source intelligence tools and resources. �
  • This list is to help all of those who are into Cyber Threat Intelligence (CTI), threat hunting, or OSINT. From beginners to advanced.�
  • https://github.com/jivoi/awesome-osint

45

46 of 54

Awesome OSINT

Demo

46

47 of 54

Countermeasures

47

48 of 54

Potential Techniques and Methods ($)

  • Incogni: ($) removes data from 175+ people search sites and data brokers.�
  • One Rep: ($) discovers and removes personal data from sites such as MyLife, WhitePages, Spokeo, Beenverified, and over 200 more�
  • DeleteMe: ($) scans and removes personal information off of websites every three months

48

49 of 54

Potential Techniques and Methods (Free)

  • Stuff Off Search (S.O.S): helps to reduce Internet attack surfaces for organizations by reducing what is visible to anyone on a web based search platform�
  • Permission Slip by Consumer Reports: Ask for companies to delete your accounts and associated data right in Permission Slip.�
  • Google Results about You: Take control of results about you. Google helps you find personal info you see provides utility to ask to remove any results.

49

50 of 54

Stuff Off Search, Google

Demo

50

51 of 54

Resources

51

52 of 54

Index of Select Tools Presented

52

53 of 54

Resources

53

54 of 54

Questions?

Samuel Carter

North Carolina State University

swcarter@ncsu.edu

Timothy Wease

NCDPI

timothy.wease@dpi.nc.us