For the complete documentation index, see llms.txt. This page is also available as Markdown.

Files/Media/Breach/Paste/Code

Files and Documents

Files and media are among the most valuable targets to investigate when planning a penetration test. Companies that regularly publish content to the web frequently overlook sensitive information that should never have left the organization. Common discoveries include email distribution lists, internal-only email addresses perfect for phishing campaigns, personnel information, client communications, and more. Don't forget to check public-facing FTP servers—they often contain sensitive data hidden in plain sight.

Documents.html

Documents.html is a tool that enables you to search for various file types associated with a target-related search term. Choose terms that are as unique as possible while remaining relevant to the target, such as company names, platform identifiers, application names, or client references. For optimal coverage, perform multiple searches using different search terms.

Document Search Tools
  • PowerMeta - PowerMeta searches for publicly available files hosted on various websites for a particular domain by using specially crafted Google, and Bing searches. It then allows for the download of those files from the target domain. After retrieving the files, the metadata associated with them can be analyzed by PowerMeta. Some interesting things commonly found in metadata are usernames, domains, software titles, and computer names.

  • goofile - Use this tool to search for a specific file type in a given domain.

  • FilePhish - A simple OSINT Google query builder for fast and easy document and file discovery.

  • MetaFinder - Search for documents in a domain through Search Engines (Google, Bing and Baidu). The objective is to extract metadata

  • Archive.org Wayback Machine - Access historical versions of websites and documents that may no longer be publicly available. Essential for finding deleted or modified content.

  • FOCA - Fingerprinting Organizations with Collected Archives. Extracts metadata and hidden information from documents.

Local helper copy: Documents.html

Public Directory, FTP, and Cloud
Article, Presentation, and Book search
  • https://libgen.rs/ - This is the largest free library in human history. Giving the world free access to over 84 million scholarly journals, over 6.6 million academic and general-interest books, over 2.2 million comics, and over 381 thousand magazines. Commonly referred to as "Libgen" for short. Libgen has zero regard for copyright.

  • Sci-Hub - A "shadow library" that provides free access to millions of research papers and books by bypassing paywalls. Note: Domain frequently changes due to legal actions. Current mirrors can be found via search engines. Sci-Hub has zero regard for copyright.

  • https://the-eye.eu/public - An open directory data archive dedicated to the long-term preservation of any and all data including websites, books, games, software, video, audio, other digital-obscura and ideas. Currently hosts over 140TB of data for free.

    • https://eyedex.org - A searchable index of the-eye.eu. Much faster than manually digging through subfolders or using Google dorks.

  • https://doaj.org - Search over 16,000 journals, over 6.5 million articles in 80 different languages from 129 different countries.

  • https://www.slideshare.net/ - Allows users to upload content including presentations, infographics, documents, and videos. Users can upload files privately or publicly in PowerPoint, Word, PDF, or OpenDocument format. Note: SlideShare is now part of Scribd.

Images/Videos

Michael Bazzell's Images.html and Videos.html tools help search for visual content across multiple platforms. Whether you're looking for employee faces, photos of security badges that could be replicated, or images containing extractable metadata, starting with a comprehensive image search is essential. While Google's image search is highly effective, alternative platforms can yield unique and valuable discoveries.

Note: These tools are designed to find images associated with search terms. If you already have an image and need to extract information from it, refer to the Image Analysis and Forensics section below or the dedicated Forensics section of this guide.

Image Analysis and Forensics
Facial Recognition
  • PimEyes - Powerful facial recognition and reverse image search engine. Requires paid subscription for detailed results and alerts.

  • FindFace - Russian face search engine. Searches VK and other Russian social networks.

  • Face Recognition — facial recognition api for Python and the command line

  • Search4faces.com — search people in VK, Odnoklassniki, TikTok and ClubHouse by photo or identikit

Misc Utility

Clothing/Shopping

Local helper copy: Images.html

Local helper copy: Videos.html

Breach/Leak/Paste data

Data breaches provide a treasure trove of information including credentials, linked data, and password hashes. These breaches often expose individuals and organizations with poor cybersecurity hygiene. Credentials from major breaches frequently become the basis for password lists used in attacks, such as the infamous rockyou.txt wordlist originating from a 2009 breach.

The tools and resources below can be used to search known data breaches and leaks, as well as to monitor and receive alerts when credentials appear in newly reported breach data. Paste sites like Pastebin have recently restricted their search capabilities. Pastebin itself has removed the ability to directly search its pastes. However, you can still search for breach data using Google dorks by including "site:pastebin.com" in your search query.

Breach Report and Search Tools
  • DeHashed - Premium breach search engine (paid subscription required). Search by email, username, IP address, physical address, phone, domain, VIN, and more. One of the most comprehensive breach databases available.

  • Have I Been Pwned - Free service to check if your email or phone has been compromised in a data breach. Created by Troy Hunt. Includes Pwned Passwords API.

  • Scylla - Community-driven breach data search platform. Free to use with registration.

  • https://leak-lookup.com/ - Leak-Lookup allows you to search across thousands of data breaches to stay on top of credentials that may have been compromised, allowing you to proactively stay on top of the latest data leaks with ease. AKA Citadel

  • https://breachdirectory.org - Search via email address, username or phone number to see censored passwords. They also provide the full password as a SHA-1 hash, which can easily be cracked.

  • https://leaked.site/ - Leaked database search with extensive coverage. Requires paid subscription.

  • Snusbase - Breach database search with frequent updates and large collection. Paid subscription required.

  • LeakCheck.io - Breach database search service. Offers both API access and web interface. Paid plans available.

  • Intelligence X - Search engine and data archive with breach data, darknet sources, pastes, and historical internet data. Offers free searches with limitations and paid plans.

  • Pwndb - Tor-based breach database search (requires Tor browser)

  • h8mail - Email OSINT and breach hunting tool that queries multiple breach data sources via API

  • http://4wbwa6vcpvcr3vvf4qkhppgy56urmjcj2vagu2iqgp3z656xcmfdbiqd.onion/ - An .onion site that allows you to search through the full 2019 Facebook data breach.

Local helper copy: Breaches.html

Paste Search Tools
  • https://psbdmp.ws/ - Pastebin dump search and monitoring service. Indexes pastes in real-time.

  • Pastebin.com - Popular paste hosting site. Direct search functionality removed; use Google dorks with site:pastebin.com to search.

  • https://redhuntlabs.com/online-ide-search - Search and find strings across multiple IDEs, code aggregators and paste sites.

  • https://doxbin.org - A document sharing and publishing website which invites users to contribute personally identifiable information (PII), or a "dox" of any person of interest. It previously operated on the darknet as a TOR hidden service.

    • Search for Doxbin/Databin in TOR

  • https://cipher387.github.io/pastebinsearchengines/ - 5 Google Custom Search Engine for search 48 pastebin sites

  • Rentry.co - Markdown-based pastebin gaining popularity as an alternative to traditional paste sites

  • Justpaste.it - Popular paste site frequently used for leak distribution

  • Telegram - Many data leaks and breach discussions now occur in Telegram channels. Search for relevant channels using keywords.

  • Discord - Discord servers frequently host breach discussions and data sharing. Use server discovery tools to find relevant communities.

Misc Tools and Resources
  • Cryptome - Archive of publicly leaked documents since 1996. Usually government and intelligence-related.

  • Breach Alarm Sources - Comprehensive, easy-to-read list tracking known data breaches.

  • Firefox Monitor - Mozilla's free breach monitoring service. Checks if your accounts appear in known data breaches and provides alerts for new breaches. Powered by Have I Been Pwned data.

  • Analysis Information Leak framework - AIL is a modular framework to analyze potential information leaks from unstructured data sources like pastes from Pastebin or similar services or unstructured data streams.

  • breach-parse - A tool for parsing breached passwords by The Cyber Mentor. Repo also contains large breach data collections.

  • https://www.reddit.com/r/DataHoarder/ - This is a sub that aims at bringing data hoarders together to share their passion with like minded people.

  • https://www.reddit.com/r/DHExchange/ - Exchange and Sharing sub for /r/DataHoarder

Code Repositories

Code repositories represent a goldmine for security reconnaissance. Despite growing awareness, many organizations still lack mature DevSecOps practices. Software engineers frequently commit sensitive information to public repositories—whether storing code snippets for later use or posting configuration files on forums when seeking help. Often, these seemingly innocent posts inadvertently expose credentials and other sensitive data. Repository searches are particularly valuable during penetration tests against organizations with active software development teams.

While numerous code repository platforms exist, the following are considered essential for security reconnaissance:

You can manually parse these by user or subject but there are some handy tools that can help search and keep track.

Important Search Techniques:

  • Certificate Transparency Logs - Use crt.sh to find subdomains that may host development servers or exposed repositories

  • Archive.org for Deleted Content - Check archived versions of repository pages or organization profiles for deleted repos or commits

  • GitHub Gist Search - Don't forget GitHub Gists, which often contain sensitive snippets: site:gist.github.com "company-name"

  • Docker Hub Search - hub.docker.com may reveal organization repositories with embedded secrets in container images

  • NPM/PyPI Package Search - Check package registries for organization-published packages that may contain sensitive configuration

Code Repo Search Tools
  • TruffleHog - Actively maintained and recommended. Searches git repositories for secrets across commit history and branches. Features 700+ credential detectors, high-entropy string detection, and verification of findings.

  • Gitleaks - Fast SAST tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repos. Supports custom rules and integrates with CI/CD pipelines.

  • GitDorker - Python tool to scrape secrets from GitHub using an extensive dork repository. Useful for automated GitHub reconnaissance.

  • Repo Supervisor - Find secrets and passwords in your code

  • Watchman - Git change monitor

  • https://grep.app/ - A search engine for contents of Git Repos

  • gitoops - GitOops is a tool to help attackers and defenders identify lateral movement and privilege escalation paths in GitHub organizations by abusing CI/CD pipelines and GitHub access controls.

  • https://searchcode.com/ - Search 75 billion lines of code from 40 million projects

  • Sourcegraph - Universal code search across multiple repositories with powerful search syntax

  • GitHub Advanced Search - GitHub's native advanced search with extensive filters and operators

  • Semgrep - Static analysis tool for finding code patterns, useful for identifying security issues across repositories

  • https://publicwww.com/ - Source code search engine that lets you find any alphanumeric snippet in web page HTML, JS, and CSS code

Github Dorking
Dorking Word List

​ ".mlab.com password" "access_key" "access_token" "amazonaws" "api.googlemaps AIza" "api_key" "api_secret" "apidocs" "apikey" "apiSecret" "app_key" "app_secret" "appkey" "appkeysecret" "application_key" "appsecret" "appspot" "auth" "auth_token" "authorizationToken" "aws_access" "aws_access_key_id" "aws_key" "aws_secret" "aws_token" "AWSSecretKey" "bashrc password" "bucket_password" "client_secret" "cloudfront" "codecov_token" "config" "conn.login" "connectionstring" "consumer_key" "credentials" "database_password" "db_password" "db_username" "dbpasswd" "dbpassword" "dbuser" "dot-files" "dotfiles" "encryption_key" "fabricApiSecret" "fb_secret" "firebase" "ftp" "gh_token" "github_key" "github_token" "gitlab" "gmail_password" "gmail_username" "herokuapp" "internal" "irc_pass" "JEKYLL_GITHUB_TOKEN" "key" "keyPassword" "ldap_password" "ldap_username" "login" "mailchimp" "mailgun" "master_key" "mydotfiles" "mysql" "node_env" "npmrc _auth" "oauth_token" "pass" "passwd" "password" "passwords" "pem private" "preprod" "private_key" "prod" "pwd" "pwds" "rds.amazonaws.com password" "redis_password" "root_password" "secret" "secret.password" "secret_access_key" "secret_key" "secret_token" "secrets" "secure" "security_credentials" "send.keys" "send_keys" "sendkeys" "SF_USERNAME salesforce" "sf_username" "site.com" FIREBASE_API_JSON= "site.com" vim_settings.xml "slack_api" "slack_token" "sql_password" "ssh" "ssh2_auth_password" "sshpass" "staging" "stg" "storePassword" "stripe" "swagger" "testuser" "token" "x-api-key" "xoxb " "xoxp" [WFClient] Password= extension:ica access_key bucket_password dbpassword dbuser extension:avastlic "support.avast.com" extension:bat extension:cfg extension:env extension:exs extension:ini extension:json api.forecast.io extension:json googleusercontent client_secret extension:json mongolab.com extension:pem extension:pem private extension:ppk extension:ppk private extension:properties extension:sh extension:sls extension:sql extension:sql mysql dump extension:sql mysql dump password extension:yaml mongolab.com extension:zsh filename:.bash_history filename:.bash_history DOMAIN-NAME filename:.bash_profile aws filename:.bashrc mailchimp filename:.bashrc password filename:.cshrc filename:.dockercfg auth filename:.env DB_USERNAME NOT homestead filename:.env MAIL_HOST=smtp.gmail.com filename:.esmtprc password filename:.ftpconfig filename:.git-credentials filename:.history filename:.htpasswd filename:.netrc password filename:.npmrc _auth filename:.pgpass filename:.remote-sync.json filename:.s3cfg filename:.sh_history filename:.tugboat NOT _tugboat filename:_netrc password filename:apikey filename:bash filename:bash_history filename:bash_profile filename:bashrc filename:beanstalkd.yml filename:CCCam.cfg filename:composer.json filename:config filename:config irc_pass filename:config.json auths filename:config.php dbpasswd filename:configuration.php JConfig password filename:connections filename:connections.xml filename:constants filename:credentials filename:credentials aws_access_key_id filename:cshrc filename:database filename:dbeaver-data-sources.xml filename:deployment-config.json filename:dhcpd.conf filename:dockercfg filename:environment filename:express.conf filename:express.conf path:.openshift filename:filezilla.xml filename:filezilla.xml Pass filename:git-credentials filename:gitconfig filename:global filename:history filename:htpasswd filename:hub oauth_token filename:id_dsa filename:id_rsa filename:id_rsa or filename:id_dsa filename:idea14.key filename:known_hosts filename:logins.json filename:makefile filename:master.key path:config filename:netrc filename:npmrc filename:pass filename:passwd path:etc filename:pgpass filename:prod.exs filename:prod.exs NOT prod.secret.exs filename:prod.secret.exs filename:proftpdpasswd filename:recentservers.xml filename:recentservers.xml Pass filename:robomongo.json filename:s3cfg filename:secrets.yml password filename:server.cfg filename:server.cfg rcon password filename:settings filename:settings.py SECRET_KEY filename:sftp-config.json filename:sftp-config.json password filename:sftp.json path:.vscode filename:shadow filename:shadow path:etc filename:spec filename:sshd_config filename:token filename:tugboat filename:ventrilo_srv.ini filename:WebServers.xml filename:wp-config filename:wp-config.php filename:zhrc HEROKU_API_KEY language:json HEROKU_API_KEY language:shell HOMEBREW_GITHUB_API_TOKEN language:shell jsforce extension:js conn.login language:yaml -filename:travis msg nickserv identify filename:config org:Target "AWS_ACCESS_KEY_ID" org:Target "list_aws_accounts" org:Target "aws_access_key" org:Target "aws_secret_key" org:Target "bucket_name" org:Target "S3_ACCESS_KEY_ID" org:Target "S3_BUCKET" org:Target "S3_ENDPOINT" org:Target "S3_SECRET_ACCESS_KEY" password path:sites databases password private -language:java PT_TOKEN language:bash redis_password root_password secret_access_key SECRET_KEY_BASE= shodan_api_key language:python WORDPRESS_DB_PASSWORD= xoxp OR xoxb OR xoxa s3.yml .exs beanstalkd.yml deploy.rake .sls

Training

Hands-on OSINT labs have been moved to the Training section.

Training and Resources

Deprecated/Legacy Tools

The following tools are no longer maintained, have been shut down, or have better alternatives. They are listed here for historical reference and in case they become available again.

Deprecated Document Search Tools
  • UVRX.com - File storage search engine (Site defunct/unreliable)

  • Palined.com - Open directory search (Site defunct)

Deprecated Image/Video Tools
  • Portrait Matcher - Face to painting matcher (Service no longer available)

  • Pictriev - Face search engine (Service frequently unavailable/unreliable)

Deprecated Breach Search Tools
  • WeLeakInfo.to - Seized by law enforcement in 2020. Was a major breach database search site.

  • BreachForums at breached.to - Seized/disrupted and no longer a stable source. Breach forums frequently rebrand or move domains; verify current legal and safety implications before researching any successor.

  • GhostProject.fr - Free breach database search (Site frequently unavailable/unreliable)

  • MyPwd.io - Password leak monitoring (Service status unreliable)

  • pwd query - Password breach checking (Site frequently down)

Deprecated Paste Search Tools
  • Pastebin.ga - Multi-paste site search (Site defunct)

  • PasteLert - Paste monitoring service (Service no longer maintained)

Deprecated Code Repository Tools
  • Gitrob - No longer maintained. Use TruffleHog or GitLeaks instead.

  • Git-all-secrets - No longer actively maintained. Consider alternatives like TruffleHog.

  • TruffleHog Legacy - Original version, superseded by TruffleHog v3+

  • trufflehog3 - Enhanced fork, but official TruffleHog now incorporates similar features

Deprecated Presentation Tools

Last updated