Skip to main content

45. CTF Reconnaissance: Mastering OSINT Techniques

OSINT (open-source intelligence) is a core skill in CTF competitions, penetration testing, and security research. This guide covers practical OSINT techniques that help gather information before and during challenge solving.

What is OSINT?

OSINT is the collection of publicly available information from open sources. In a CTF context, it means finding hidden clues in web pages, metadata, social media, DNS records, and public databases.

Why OSINT matters in CTFs:

  • Discover flags hidden in metadata
  • Uncover usernames, email addresses, and credentials
  • Map infrastructure and relationships
  • Discover historical data and deleted content

Essential OSINT tools

Web reconnaissance

Wayback Machine (archive.org) — view historical versions of websites. Deleted pages often retain flags or sensitive information removed from the current version.

Google dorking — discover hidden content with advanced search operators:

  • site:example.com filetype:pdf — find a particular file type
  • inurl:admin — find admin panels
  • intitle:"index of" — find directory listings

Shodan (shodan.io) — a search engine for internet-connected devices. It can discover exposed services, default credentials, and vulnerable systems.

Metadata analysis

ExifTool — extract metadata from images, documents, and files:

exiftool image.jpg
exiftool -all= image.jpg # Remove all metadata

GPS coordinates, software versions, and usernames are often hidden in EXIF data.

Strings — a simple but effective technique for binary files:

strings file.bin | grep -i flag

DNS and domain intelligence

dig — query DNS records:

dig example.com ANY
dig -x 192.168.1.1 # Reverse lookup

whois — inspect domain registration data to identify owners, email addresses, and registration dates.

Certificate Transparency (crt.sh) — discover subdomains through SSL certificates:

%.example.com

Social-media intelligence

Username OSINT — find accounts across platforms with tools such as sherlock or namechk:

sherlock username123

Twitter advanced search — filter by date, location, user, and keyword. Useful for reconstructing timelines.

LinkedIn — use employee information to understand organizational structures, technologies in use, and potential social-engineering targets.

Practical CTF techniques

Detecting image steganography

Check images for hidden data:

binwalk image.png
steghide extract -sf image.jpg
zsteg image.png # Analyze a PNG

Archive and file analysis

Recursively extract archives:

binwalk -e firmware.bin
foremost disk.img # Carve files from a disk image

Network traces

Analyze packet captures with Wireshark filters:

  • http.request.method == "POST" — find form submissions
  • ftp-data — extract files from FTP traffic
  • dns — inspect accessed domains

Mining Git repositories

Extract secrets from Git history:

git log --all --full-history -- "*password*"
trufflehog --regex --entropy=False .

Deleted commits and branches often retain flags or credentials.

Building an OSINT workflow

1. Start broad — use search engines and public databases 2. Dig deeper — trace links, subdomains, and related accounts 3. Automate — script repetitive work with Python or Bash 4. Document — record findings and relationship notes

Quick reconnaissance script

#!/bin/bash
TARGET=$1
echo "[+] DNS records"
dig $TARGET ANY
echo "[+] Subdomains (crt.sh)"
curl -s "https://crt.sh/?q=%.$TARGET&output=json" | jq -r '.[].name_value' | sort -u
echo "[+] Historical snapshots"
curl -s "http://archive.org/wayback/available?url=$TARGET" | jq -r '.archived_snapshots.closest.url'

Common CTF OSINT scenarios

Flag in metadata — always inspect the EXIF data of downloaded images Deleted social-media post — search cached and archived versions Subdomain enumeration — flags are often hidden on forgotten subdomains Historical leak — credentials remain in old Pastebin or Gist posts QR code — decode it with zbarimg instead of scanning manually

OSINT uses public information, but context matters. In a CTF competition, act only within the challenge scope. In real research, comply with privacy laws and terms of service.

Rules to always follow:

  • Obtain authorization before testing a production system
  • Do not social-engineer real people without consent
  • Document the methodology
  • Report vulnerabilities responsibly

Practice resources

CTF platforms — TryHackMe and HackTheBox offer OSINT challenges Trace Labs — an OSINT CTF for missing persons with real-world impact OSINT Framework (osintframework.com) — a comprehensive tool directory

Closing thoughts

OSINT is reconnaissance without exploitation. Mastering these techniques helps you find flags faster, understand attack surfaces better, and develop a security researcher's mindset. The information is already public—you only need to know where to look.

Start with Google, dig deeper with specialized tools, and always inspect the metadata. Happy hunting!