From Photo to Passport Number With Maltego OSINT Tools

แชร์
ฝัง
  • เผยแพร่เมื่อ 8 ก.ค. 2024
  • OSINT is an essential tool for any investigator or ethical hacker. Today, we'll start with only a photo of an unknown subject, and string together OSINT tools to locate them on a US sanctions list.
    Sign up for our e-mail alerts to stay updated when we go live & register to win free swag: info.varonis.com/securityfwd
    Chapters:
    0:00 Countdown
    0:48 Intro
    9:05 Starting With an Image
    13:25 Pimeyes Facial Recognition Search
    19:00 TinEye Image Search
    21:17 Maltego
    25:07 Starting Entity and Transforms
    29:20 Aleph Search
    36:00 Finding the Passport
    40:29 Finding Diplomatic Papers
    42:21 Closing Thoughts
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 109

  • @iyeetsecurity922
    @iyeetsecurity922 2 ปีที่แล้ว +46

    Uploaded a picture of my dog to PimEyes. Got a lot of pics back of pregnant women diddling themselves and three pics of guys doing the same thing.
    Fascinating.

    • @Rust_Rust_Rust
      @Rust_Rust_Rust 2 ปีที่แล้ว +1

      Were u diddling ur dog?

    • @iyeetsecurity922
      @iyeetsecurity922 2 ปีที่แล้ว +7

      @@Rust_Rust_Rust Dolan Duck, I am but a simple tugboat moonlighting as a cruise ship. I am unable to diddle anything.

    • @gothicherie6691
      @gothicherie6691 2 ปีที่แล้ว

      omg same, i was like wtf, it was cropped just to the dogs face too

    • @smudgepost
      @smudgepost 2 ปีที่แล้ว

      As foreshadowed in Ted 2

  • @seanfaherty
    @seanfaherty 2 ปีที่แล้ว +1

    Nice to see you again .

  • @portia-assamensis
    @portia-assamensis 2 ปีที่แล้ว +25

    This is awesome. I'm big into OSINT but I've always struggled with Maltego. Subbed. Short of buying a book on it, I think I could learn a lot from you guys

  • @jacobsan
    @jacobsan 3 ปีที่แล้ว +70

    As a Mexican, I can unfortunately tell you that the one at minute 36 is not a passport number. It's a CURP, which is sort of a national id number but it's mostly useless on its own. You need it mostly for some government processes like healthcare, etc

    • @Kas_Styles
      @Kas_Styles 3 ปีที่แล้ว +9

      OSINT is about finding, collecting and analyzing different types of data to get a bigger look at someone/something. That data is one more thing a bad person could use to their advantage, either for social engineering or otherwise.

    • @ko-Daegu
      @ko-Daegu 2 ปีที่แล้ว +16

      @@Kas_Styles did you read what he said so ??

    • @pabloalfaro2595
      @pabloalfaro2595 2 ปีที่แล้ว +9

      @@Kas_Styles This literally has nothing to do with what he said

    • @Kas_Styles
      @Kas_Styles 2 ปีที่แล้ว +1

      @@pabloalfaro2595 there was another comment that I wrote (idk where it went. I know that sometimes Google/TH-cam can be annoying with letting perfectly fine comments be hidden or something like that) which was related to the comment above.

    • @tr0llol677
      @tr0llol677 2 ปีที่แล้ว +4

      @@Kas_Styles r/sheesh

  • @SuperHtownswag
    @SuperHtownswag 2 ปีที่แล้ว

    nice stuff. Thanks guys

  • @mrtransmogrify
    @mrtransmogrify 2 ปีที่แล้ว +4

    7:44
    OMG just start OSINT-ing already

  • @newold1093
    @newold1093 3 ปีที่แล้ว +1

    Great video

    • @SecurityFWD
      @SecurityFWD  3 ปีที่แล้ว +2

      Thanks for watching!

  • @sotecluxan4221
    @sotecluxan4221 3 ปีที่แล้ว +1

    Bright!

  • @Sch00lbu5
    @Sch00lbu5 2 ปีที่แล้ว

    excellent

  • @juanizabal6812
    @juanizabal6812 2 ปีที่แล้ว +27

    Super cool video, I'm new to OSINT. Just to correct some information about the info you found. In 36:08 the "passport number" you found actually is the national ID number (C.U.R.P Clave Unica de Registro Poblacional -> Unique Code of Poblational Registry), which is a a mix of letters from the subject's name.

    • @user-ht5dr3wc6i
      @user-ht5dr3wc6i 2 ปีที่แล้ว +1

      Subject's name anda birth of date

    • @sky.the.infinite
      @sky.the.infinite 2 ปีที่แล้ว +1

      @@user-ht5dr3wc6i a date of birth

  • @channelroot
    @channelroot 2 ปีที่แล้ว

    Amazing

  • @JCtheMusicMan_
    @JCtheMusicMan_ 2 ปีที่แล้ว +5

    Did you guys ever do a video on security for researchers?

  • @springchickena1
    @springchickena1 2 ปีที่แล้ว +6

    ah, how to stop microsoft from spying on you was a question raised in the chat.
    I recommend you fully delete system32 or any part of it that says "windows" that'll do it.

  • @alonemusket7246
    @alonemusket7246 2 ปีที่แล้ว +4

    Inspect element trick no longer works on pimeyes. Guessed they upped their game! Any ideas on how to surpass that now?

  • @crumb7059
    @crumb7059 3 ปีที่แล้ว

    Cool.

  • @stalkeractual
    @stalkeractual ปีที่แล้ว +1

    You get more accurate results when you add quotes to the phrase.

  • @randomdudefpv4927
    @randomdudefpv4927 2 ปีที่แล้ว

    varonis in latvian means HERO

  • @radomaleshkov6144
    @radomaleshkov6144 2 ปีที่แล้ว +1

    Hah love y guys :D

  • @warrior3d27
    @warrior3d27 2 ปีที่แล้ว +4

    wow.. so does maltego tell you where those data leaks originate? if you have a video on more of these kind of tools i'd be interested. looking to get into security related IT jobs.

  • @mranaumar8015
    @mranaumar8015 2 ปีที่แล้ว

    Nice

  • @MisterK-YT
    @MisterK-YT 2 ปีที่แล้ว +7

    Aren’t you the brilliant dude that never blinks from Null Byte?

  • @johndawson6484
    @johndawson6484 2 ปีที่แล้ว

    Interesting

  • @the_whi13_rabbit
    @the_whi13_rabbit 2 ปีที่แล้ว +1

    OSINT!!

  • @AjarnSpencer
    @AjarnSpencer หลายเดือนก่อน

    Maltego is like Supersleuth

  • @eldanicarvajal
    @eldanicarvajal 2 ปีที่แล้ว +2

    I am from Nayarit, he was the gobernor of this state.

  • @Brett_S_420
    @Brett_S_420 3 ปีที่แล้ว +2

    KODI ROCKS!

    • @SecurityFWD
      @SecurityFWD  3 ปีที่แล้ว +1

      Thanks for watching!

    • @Brett_S_420
      @Brett_S_420 2 ปีที่แล้ว +1

      @@SecurityFWD Anytime!

  • @D_Tech_And_Trek
    @D_Tech_And_Trek 3 ปีที่แล้ว +7

    There is no OCCRP Aleph Transform in my CE Maltego?? Is that only available for paid version?

  • @creedyacosta
    @creedyacosta 2 ปีที่แล้ว +1

    Great content. Any chance you guys can cover VPNs?

  • @jetsetjourneysofficial
    @jetsetjourneysofficial 2 ปีที่แล้ว

    so transform means search a source?

  • @OrigMaelstrom
    @OrigMaelstrom ปีที่แล้ว

    35 minutes and seeing some great content, but I do have one question releated to the specific example case you are using. Why are you searching just a partial name for the subject and not the full given name? Did I miss that reasoning?

  • @robin-bird
    @robin-bird ปีที่แล้ว +1

    the essence of this video could have been boiled down to a 5-10min video

  • @Sam-hq4jl
    @Sam-hq4jl 2 ปีที่แล้ว +19

    Is Maltego basically MS Power BI for shady underworld data?

    • @MartianV2GG
      @MartianV2GG 2 หลายเดือนก่อน

      Maltego just compiles a bunch of ONIST tools into one place

  • @nicatshare6103
    @nicatshare6103 6 หลายเดือนก่อน

    Are we exposed when we investigate any person or company? Can the person or company we are looking for find us or not?

  • @victortorres1585
    @victortorres1585 6 หลายเดือนก่อน

    What is the diff between this and truecallerpy and phoneinfoga

  • @TankCatIntoMordor
    @TankCatIntoMordor 2 ปีที่แล้ว +1

    *Stares blankly intensifies*

  • @artfactory4529
    @artfactory4529 3 ปีที่แล้ว +1

    Maltego classic has been discontinued, how can i use aleph then

    • @SecurityFWD
      @SecurityFWD  3 ปีที่แล้ว +2

      Congratulations we answered your question in the livestream! th-cam.com/video/mM_8cY_G5wA/w-d-xo.html

  • @shashwattewarishaz12
    @shashwattewarishaz12 2 ปีที่แล้ว +6

    Any other alternatives for pimeyes as its paid only now

    • @luciferMorningstar-ko9qc
      @luciferMorningstar-ko9qc 2 ปีที่แล้ว +1

      Tineye

    • @nikhilgawde
      @nikhilgawde 2 ปีที่แล้ว

      @@luciferMorningstar-ko9qc it's not as advance as Pimeyes but really good alternative.

  • @s14turbo2
    @s14turbo2 2 ปีที่แล้ว +2

    Where can I find a freelancer who can do this type of work on a contract basis?

  • @stvlley
    @stvlley ปีที่แล้ว

    update* they now blur the background so u can no longer reverse search the image on google

  • @briancreech9990
    @briancreech9990 2 ปีที่แล้ว

    My favorite is WMD. makes me laugh.

  • @andrempsc
    @andrempsc 2 ปีที่แล้ว +3

    I'm no hacker, but why not search for the full name? It seems to me that theres gotta be a ton of Roberto Sandovals worlwide.

    • @cvspvr
      @cvspvr ปีที่แล้ว +1

      i'm no hacker either, but people often don't include their middle name online

  • @leonmunro2168
    @leonmunro2168 ปีที่แล้ว

    Do you have an email address pls also. Can you use multego by inputting a mobile number? And can it give you the phone ip and IMEI?

    • @willa5551
      @willa5551 ปีที่แล้ว

      It will not.

  • @blubblab5201
    @blubblab5201 2 ปีที่แล้ว +1

    why do they have german stickers on ther laptops?

  • @Gobillion160
    @Gobillion160 3 ปีที่แล้ว +3

    yandex reverse image search is even better

    • @VoltageLP
      @VoltageLP 2 ปีที่แล้ว +1

      Yandex is owned by what used to be KGB, so no wonder

    • @Gobillion160
      @Gobillion160 2 ปีที่แล้ว

      @@VoltageLP yea its great

  • @aldrineuri122
    @aldrineuri122 2 ปีที่แล้ว +4

    I never signed up on many websites and I always dissable the location and I never put too much of my real info and my accounts are privatised.

    • @GiFiGinaisCZ
      @GiFiGinaisCZ 2 ปีที่แล้ว +7

      But you have your real name on your TH-cam account?

    • @vincenthuaweitien
      @vincenthuaweitien 2 ปีที่แล้ว

      But you signed up for Google and TH-cam.

    • @aldrineuri122
      @aldrineuri122 2 ปีที่แล้ว +1

      @@vincenthuaweitien do you think that's my real name? I didn't put any of my real details when I filled up,

    • @aldrineuri122
      @aldrineuri122 2 ปีที่แล้ว

      What would you do with data that doesn't exist?

    • @vincenthuaweitien
      @vincenthuaweitien 2 ปีที่แล้ว

      ​@@aldrineuri122It doesn't matter whether you used your real name or fake name.
      Google is interested in your ISP, location, region, language, favorite TH-cam video, search history, subscribed TH-cam channels, chat history, time spent on TH-cam, wifi/mobile/landline internet connection, and whether you used a laptop or smartphone to access TH-cam, etc.
      That's how Google advertisers can custom-made their advertisements for you and for me.

  • @user-gy4yz1jq5l
    @user-gy4yz1jq5l ปีที่แล้ว

    Is this still a think?

  • @voochun44
    @voochun44 ปีที่แล้ว

    Can you help me please 🙏

  • @demonEyenj
    @demonEyenj 2 ปีที่แล้ว +8

    I know this is going to be odd and can come off as rude cause I can be wrong, but if these two are part of the LGBTQ that's crazy. You never get that kinda representation, I love it.

    • @cvspvr
      @cvspvr ปีที่แล้ว

      what makes you think that? i'm not hating; i haven't watched the video yet
      edit: i guess the guy on the left sounds a bit gay but i don't know
      edit edit: nevermind, he's 100% gay. that's cool

  • @British_loyalist
    @British_loyalist ปีที่แล้ว

    Not enough stickers on your laptop, mate.

  • @Vuyccbvuj
    @Vuyccbvuj ปีที่แล้ว

    You have to pay for maltego $500!

  • @allencompassingevil
    @allencompassingevil 2 ปีที่แล้ว

    8:25 - *Heavy Breathing* Muhahahahahaha

  • @kenhedges
    @kenhedges 2 ปีที่แล้ว +3

    What do you do with your stickers when you get a new laptop. Suddenly, you have none.

    • @MNaeem5
      @MNaeem5 2 ปีที่แล้ว

      LOLOL!

    • @gothicherie6691
      @gothicherie6691 2 ปีที่แล้ว +1

      trace where you got all of them from and get new ones

    • @ivans.935
      @ivans.935 ปีที่แล้ว

      New laptop? Why??

  • @belvederebaileycambodia
    @belvederebaileycambodia 26 วันที่ผ่านมา

    There kinda feels like there should be a rainbow somewhere in this vid...

  • @cyber_ukraine
    @cyber_ukraine 2 ปีที่แล้ว +4

    I see people blinking! The video is fake 😂😂😂😂😂😂😂

  • @darioxbrow9223
    @darioxbrow9223 2 ปีที่แล้ว +1

    Get into the trap of doing

  • @jacobsan
    @jacobsan 3 ปีที่แล้ว +5

    My 5 second solution? Ask a mexican

  • @OurSouthAfrica
    @OurSouthAfrica ปีที่แล้ว +1

    So much fluff in the video

  • @Markersman
    @Markersman ปีที่แล้ว

    So so so so so......

  • @blbreptiles4126
    @blbreptiles4126 2 ปีที่แล้ว +8

    Y'all talk a lot

  • @Chinu-gw7ko
    @Chinu-gw7ko 3 ปีที่แล้ว +1

    Can you make a video on how to hack a phone over wifi. Please.

  • @srishti2k22-iw5dh
    @srishti2k22-iw5dh ปีที่แล้ว

    I want to help ukrane

  • @deity6119
    @deity6119 2 ปีที่แล้ว +1

    SecurityFWD​ These are some pretty serious hacks guys
    SecurityFWD​ try to keep u
    SecurityFWD​ up*
    i just shit my self reading that bullshit lmao