From Photo to Passport Number With Maltego OSINT Tools

Sdílet
Vložit
  • čas přidán 26. 06. 2024
  • OSINT is an essential tool for any investigator or ethical hacker. Today, we'll start with only a photo of an unknown subject, and string together OSINT tools to locate them on a US sanctions list.
    Sign up for our e-mail alerts to stay updated when we go live & register to win free swag: info.varonis.com/securityfwd
    Chapters:
    0:00 Countdown
    0:48 Intro
    9:05 Starting With an Image
    13:25 Pimeyes Facial Recognition Search
    19:00 TinEye Image Search
    21:17 Maltego
    25:07 Starting Entity and Transforms
    29:20 Aleph Search
    36:00 Finding the Passport
    40:29 Finding Diplomatic Papers
    42:21 Closing Thoughts
  • Věda a technologie

Komentáře • 109

  • @portia-assamensis
    @portia-assamensis Před 2 lety +25

    This is awesome. I'm big into OSINT but I've always struggled with Maltego. Subbed. Short of buying a book on it, I think I could learn a lot from you guys

  • @iyeetsecurity922
    @iyeetsecurity922 Před 2 lety +46

    Uploaded a picture of my dog to PimEyes. Got a lot of pics back of pregnant women diddling themselves and three pics of guys doing the same thing.
    Fascinating.

    • @Rust_Rust_Rust
      @Rust_Rust_Rust Před 2 lety +1

      Were u diddling ur dog?

    • @iyeetsecurity922
      @iyeetsecurity922 Před 2 lety +7

      @@Rust_Rust_Rust Dolan Duck, I am but a simple tugboat moonlighting as a cruise ship. I am unable to diddle anything.

    • @gothicherie6691
      @gothicherie6691 Před 2 lety

      omg same, i was like wtf, it was cropped just to the dogs face too

    • @smudgepost
      @smudgepost Před 2 lety

      As foreshadowed in Ted 2

  • @seanfaherty
    @seanfaherty Před 2 lety +1

    Nice to see you again .

  • @jacobsan
    @jacobsan Před 3 lety +70

    As a Mexican, I can unfortunately tell you that the one at minute 36 is not a passport number. It's a CURP, which is sort of a national id number but it's mostly useless on its own. You need it mostly for some government processes like healthcare, etc

    • @Kas_Styles
      @Kas_Styles Před 3 lety +9

      OSINT is about finding, collecting and analyzing different types of data to get a bigger look at someone/something. That data is one more thing a bad person could use to their advantage, either for social engineering or otherwise.

    • @ko-Daegu
      @ko-Daegu Před 2 lety +16

      @@Kas_Styles did you read what he said so ??

    • @pabloalfaro2595
      @pabloalfaro2595 Před 2 lety +9

      @@Kas_Styles This literally has nothing to do with what he said

    • @Kas_Styles
      @Kas_Styles Před 2 lety +1

      @@pabloalfaro2595 there was another comment that I wrote (idk where it went. I know that sometimes Google/CZcams can be annoying with letting perfectly fine comments be hidden or something like that) which was related to the comment above.

    • @tr0llol677
      @tr0llol677 Před 2 lety +4

      @@Kas_Styles r/sheesh

  • @SuperHtownswag
    @SuperHtownswag Před 2 lety

    nice stuff. Thanks guys

  • @juanizabal6812
    @juanizabal6812 Před 2 lety +27

    Super cool video, I'm new to OSINT. Just to correct some information about the info you found. In 36:08 the "passport number" you found actually is the national ID number (C.U.R.P Clave Unica de Registro Poblacional -> Unique Code of Poblational Registry), which is a a mix of letters from the subject's name.

  • @sotecluxan4221
    @sotecluxan4221 Před 3 lety +1

    Bright!

  • @newold1093
    @newold1093 Před 3 lety +1

    Great video

  • @Sch00lbu5
    @Sch00lbu5 Před 2 lety

    excellent

  • @mrtransmogrify
    @mrtransmogrify Před 2 lety +4

    7:44
    OMG just start OSINT-ing already

  • @JCtheMusicMan_
    @JCtheMusicMan_ Před 2 lety +5

    Did you guys ever do a video on security for researchers?

  • @channelroot
    @channelroot Před 2 lety

    Amazing

  • @warrior3d27
    @warrior3d27 Před 2 lety +4

    wow.. so does maltego tell you where those data leaks originate? if you have a video on more of these kind of tools i'd be interested. looking to get into security related IT jobs.

  • @springchickena1
    @springchickena1 Před 2 lety +6

    ah, how to stop microsoft from spying on you was a question raised in the chat.
    I recommend you fully delete system32 or any part of it that says "windows" that'll do it.

  • @crumb7059
    @crumb7059 Před 3 lety

    Cool.

  • @radomaleshkov6144
    @radomaleshkov6144 Před 2 lety +1

    Hah love y guys :D

  • @alonemusket7246
    @alonemusket7246 Před 2 lety +4

    Inspect element trick no longer works on pimeyes. Guessed they upped their game! Any ideas on how to surpass that now?

  • @mranaumar8015
    @mranaumar8015 Před 2 lety

    Nice

  • @stalkeractual
    @stalkeractual Před rokem +1

    You get more accurate results when you add quotes to the phrase.

  • @johndawson6484
    @johndawson6484 Před rokem

    Interesting

  • @MisterK-YT
    @MisterK-YT Před 2 lety +7

    Aren’t you the brilliant dude that never blinks from Null Byte?

  • @the_whi13_rabbit
    @the_whi13_rabbit Před 2 lety +1

    OSINT!!

  • @creedyacosta
    @creedyacosta Před 2 lety +1

    Great content. Any chance you guys can cover VPNs?

  • @randomdudefpv4927
    @randomdudefpv4927 Před 2 lety

    varonis in latvian means HERO

  • @AjarnSpencer
    @AjarnSpencer Před 24 dny

    Maltego is like Supersleuth

  • @robin-bird
    @robin-bird Před rokem +1

    the essence of this video could have been boiled down to a 5-10min video

  • @Brett_S_420
    @Brett_S_420 Před 3 lety +2

    KODI ROCKS!

  • @OrigMaelstrom
    @OrigMaelstrom Před rokem

    35 minutes and seeing some great content, but I do have one question releated to the specific example case you are using. Why are you searching just a partial name for the subject and not the full given name? Did I miss that reasoning?

  • @D_Tech_And_Trek
    @D_Tech_And_Trek Před 3 lety +7

    There is no OCCRP Aleph Transform in my CE Maltego?? Is that only available for paid version?

  • @Sam-hq4jl
    @Sam-hq4jl Před 2 lety +19

    Is Maltego basically MS Power BI for shady underworld data?

    • @MartianV2GG
      @MartianV2GG Před měsícem

      Maltego just compiles a bunch of ONIST tools into one place

  • @jetsetjourneysofficial

    so transform means search a source?

  • @eldanicarvajal
    @eldanicarvajal Před 2 lety +2

    I am from Nayarit, he was the gobernor of this state.

  • @TankCatIntoMordor
    @TankCatIntoMordor Před 2 lety +1

    *Stares blankly intensifies*

  • @nicatshare6103
    @nicatshare6103 Před 6 měsíci

    Are we exposed when we investigate any person or company? Can the person or company we are looking for find us or not?

  • @victortorres1585
    @victortorres1585 Před 6 měsíci

    What is the diff between this and truecallerpy and phoneinfoga

  • @stvlley
    @stvlley Před rokem

    update* they now blur the background so u can no longer reverse search the image on google

  • @shashwattewarishaz12
    @shashwattewarishaz12 Před 2 lety +6

    Any other alternatives for pimeyes as its paid only now

  • @s14turbo2
    @s14turbo2 Před 2 lety +2

    Where can I find a freelancer who can do this type of work on a contract basis?

  • @artfactory4529
    @artfactory4529 Před 3 lety +1

    Maltego classic has been discontinued, how can i use aleph then

    • @SecurityFWD
      @SecurityFWD  Před 3 lety +2

      Congratulations we answered your question in the livestream! czcams.com/video/mM_8cY_G5wA/video.html

  • @briancreech9990
    @briancreech9990 Před 2 lety

    My favorite is WMD. makes me laugh.

  • @andrempsc
    @andrempsc Před 2 lety +3

    I'm no hacker, but why not search for the full name? It seems to me that theres gotta be a ton of Roberto Sandovals worlwide.

    • @cvspvr
      @cvspvr Před rokem +1

      i'm no hacker either, but people often don't include their middle name online

  • @blubblab5201
    @blubblab5201 Před 2 lety +1

    why do they have german stickers on ther laptops?

  • @user-gy4yz1jq5l
    @user-gy4yz1jq5l Před 11 měsíci

    Is this still a think?

  • @leonmunro2168
    @leonmunro2168 Před rokem

    Do you have an email address pls also. Can you use multego by inputting a mobile number? And can it give you the phone ip and IMEI?

  • @aldrineuri122
    @aldrineuri122 Před 2 lety +4

    I never signed up on many websites and I always dissable the location and I never put too much of my real info and my accounts are privatised.

    • @GiFiGinaisCZ
      @GiFiGinaisCZ Před 2 lety +7

      But you have your real name on your CZcams account?

    • @vincenthuaweitien
      @vincenthuaweitien Před 2 lety

      But you signed up for Google and CZcams.

    • @aldrineuri122
      @aldrineuri122 Před 2 lety +1

      @@vincenthuaweitien do you think that's my real name? I didn't put any of my real details when I filled up,

    • @aldrineuri122
      @aldrineuri122 Před 2 lety

      What would you do with data that doesn't exist?

    • @vincenthuaweitien
      @vincenthuaweitien Před 2 lety

      ​@@aldrineuri122It doesn't matter whether you used your real name or fake name.
      Google is interested in your ISP, location, region, language, favorite CZcams video, search history, subscribed CZcams channels, chat history, time spent on CZcams, wifi/mobile/landline internet connection, and whether you used a laptop or smartphone to access CZcams, etc.
      That's how Google advertisers can custom-made their advertisements for you and for me.

  • @Gobillion160
    @Gobillion160 Před 3 lety +3

    yandex reverse image search is even better

    • @VoltageLP
      @VoltageLP Před 2 lety +1

      Yandex is owned by what used to be KGB, so no wonder

    • @Gobillion160
      @Gobillion160 Před 2 lety

      @@VoltageLP yea its great

  • @voochun44
    @voochun44 Před rokem

    Can you help me please 🙏

  • @British_loyalist
    @British_loyalist Před rokem

    Not enough stickers on your laptop, mate.

  • @Vuyccbvuj
    @Vuyccbvuj Před rokem

    You have to pay for maltego $500!

  • @demonEyenj
    @demonEyenj Před 2 lety +8

    I know this is going to be odd and can come off as rude cause I can be wrong, but if these two are part of the LGBTQ that's crazy. You never get that kinda representation, I love it.

    • @cvspvr
      @cvspvr Před rokem

      what makes you think that? i'm not hating; i haven't watched the video yet
      edit: i guess the guy on the left sounds a bit gay but i don't know
      edit edit: nevermind, he's 100% gay. that's cool

  • @allencompassingevil
    @allencompassingevil Před rokem

    8:25 - *Heavy Breathing* Muhahahahahaha

  • @kenhedges
    @kenhedges Před 2 lety +3

    What do you do with your stickers when you get a new laptop. Suddenly, you have none.

  • @belvederebaileycambodia

    There kinda feels like there should be a rainbow somewhere in this vid...

  • @cyber_ukraine
    @cyber_ukraine Před 2 lety +4

    I see people blinking! The video is fake 😂😂😂😂😂😂😂

  • @darioxbrow9223
    @darioxbrow9223 Před 2 lety +1

    Get into the trap of doing

  • @jacobsan
    @jacobsan Před 3 lety +5

    My 5 second solution? Ask a mexican

  • @OurSouthAfrica
    @OurSouthAfrica Před rokem +1

    So much fluff in the video

  • @Markersman
    @Markersman Před rokem

    So so so so so......

  • @blbreptiles4126
    @blbreptiles4126 Před 2 lety +8

    Y'all talk a lot

  • @Chinu-gw7ko
    @Chinu-gw7ko Před 3 lety +1

    Can you make a video on how to hack a phone over wifi. Please.

  • @srishti2k22-iw5dh
    @srishti2k22-iw5dh Před rokem

    I want to help ukrane

  • @deity6119
    @deity6119 Před 2 lety +1

    SecurityFWD​ These are some pretty serious hacks guys
    SecurityFWD​ try to keep u
    SecurityFWD​ up*
    i just shit my self reading that bullshit lmao