Files/Media/Breach/Paste/Code
Files and Documents
Files and media are among the most valuable targets to investigate when planning a penetration test. Companies that regularly publish content to the web frequently overlook sensitive information that should never have left the organization. Common discoveries include email distribution lists, internal-only email addresses perfect for phishing campaigns, personnel information, client communications, and more. Don't forget to check public-facing FTP servers—they often contain sensitive data hidden in plain sight.
Documents.html
Documents.html is a tool that enables you to search for various file types associated with a target-related search term. Choose terms that are as unique as possible while remaining relevant to the target, such as company names, platform identifiers, application names, or client references. For optimal coverage, perform multiple searches using different search terms.
Document Search Tools
PowerMeta - PowerMeta searches for publicly available files hosted on various websites for a particular domain by using specially crafted Google, and Bing searches. It then allows for the download of those files from the target domain. After retrieving the files, the metadata associated with them can be analyzed by PowerMeta. Some interesting things commonly found in metadata are usernames, domains, software titles, and computer names.
goofile - Use this tool to search for a specific file type in a given domain.
FilePhish - A simple OSINT Google query builder for fast and easy document and file discovery.
MetaFinder - Search for documents in a domain through Search Engines (Google, Bing and Baidu). The objective is to extract metadata
Archive.org Wayback Machine - Access historical versions of websites and documents that may no longer be publicly available. Essential for finding deleted or modified content.
FOCA - Fingerprinting Organizations with Collected Archives. Extracts metadata and hidden information from documents.
Local helper copy: Documents.html
Public Directory, FTP, and Cloud
https://www.filechef.com - Search for open directories and files on the web or in Google Drives via keywords. Including document, video, audio, image and executable files. Uses Google dorks.
Napalm FTP Indexer - Search for documents in public FTP servers
MMNT - Russian FTP indexer
GrayHatWarfare - Search for publicly accessible AWS S3 buckets, Azure blobs, and Google Cloud Storage buckets.
MS Azure Portal - Search for public blobs
https://osint.sh/buckets/ - Find public AWS and Azure buckets and documents via keyword.
https://www.gdrivesearch.com/ - A simple and fast tool that allows you to search Google Drive for files.
https://www.reddit.com/r/opendirectories/ - Unprotected directories of pics, vids, music, software and otherwise interesting files.
Article, Presentation, and Book search
https://libgen.rs/ - This is the largest free library in human history. Giving the world free access to over 84 million scholarly journals, over 6.6 million academic and general-interest books, over 2.2 million comics, and over 381 thousand magazines. Commonly referred to as "Libgen" for short. Libgen has zero regard for copyright.
Sci-Hub - A "shadow library" that provides free access to millions of research papers and books by bypassing paywalls. Note: Domain frequently changes due to legal actions. Current mirrors can be found via search engines. Sci-Hub has zero regard for copyright.
https://the-eye.eu/public - An open directory data archive dedicated to the long-term preservation of any and all data including websites, books, games, software, video, audio, other digital-obscura and ideas. Currently hosts over 140TB of data for free.
https://eyedex.org - A searchable index of the-eye.eu. Much faster than manually digging through subfolders or using Google dorks.
https://doaj.org - Search over 16,000 journals, over 6.5 million articles in 80 different languages from 129 different countries.
https://www.slideshare.net/ - Allows users to upload content including presentations, infographics, documents, and videos. Users can upload files privately or publicly in PowerPoint, Word, PDF, or OpenDocument format. Note: SlideShare is now part of Scribd.
Images/Videos
Michael Bazzell's Images.html and Videos.html tools help search for visual content across multiple platforms. Whether you're looking for employee faces, photos of security badges that could be replicated, or images containing extractable metadata, starting with a comprehensive image search is essential. While Google's image search is highly effective, alternative platforms can yield unique and valuable discoveries.
Note: These tools are designed to find images associated with search terms. If you already have an image and need to extract information from it, refer to the Image Analysis and Forensics section below or the dedicated Forensics section of this guide.
Image Analysis and Forensics
FotoForensics - Free and public photo forensics tools.
https://www.imageforensic.org/ - Image Metadata Analysis tool
https://github.com/GuidoBartoli/sherloq - An open-source digital image forensic toolset
https://www.peteyvid.com/ - A video and audio search engine that searches over 70 different platforms.
CameraTrace - Trace the location a camera has been by the metadata it embeds in photos that end up on the internet.
ExifTool - Platform-independent library and command-line application for reading, writing and editing metadata in a wide variety of files.
Jeffrey's Image Metadata Viewer - Online tool for viewing and analyzing image metadata.
InVID/WeVerify - Browser plugin for video and image verification, useful for detecting manipulated media.
Reverse Image Search
Yandex Images — Often superior to Google for reverse image search, particularly for non-Western content
Bing Visual Search — Microsoft's reverse image search with strong results for product identification
pic.sogou.com — chinese reverse image search engine
Image So Search — Qihoo 360 Reverse Images Search
Revesearch.com — allows to upload an image once and immediately search for it in #Google, #Yandex, and #Bing.
Pixsy — allows to upload pictures from computer, social networks or cloud storages, and then search for their duplicates and check if they are copyrighted
Image Search Assistant — searches for a picture, screenshot or fragment of a screenshot in several search engines and stores at once
openi.nlm.nih.gov — Reverse image search engine for scientific and medical images
DepositPhotos Reverse Image Search — tool for reverse image search (strictly from DepositPhoto's collection of 222 million files).
EveryPixel — Reverse image search engine. Search across 50 leading stock images agencies. It's possible to filter only free or only paid images.
https://tineye.com/ - Image search engine.
Facial Recognition
PimEyes - Powerful facial recognition and reverse image search engine. Requires paid subscription for detailed results and alerts.
FindFace - Russian face search engine. Searches VK and other Russian social networks.
Face Recognition — facial recognition api for Python and the command line
Search4faces.com — search people in VK, Odnoklassniki, TikTok and ClubHouse by photo or identikit
Misc Utility
Clothing/Shopping
Searchbyimage.app — search clothes in online shops
Aliseeks.com — search items by photo in AliExpress and Ebay
lykdat.com — clothing reverse image search services
Local helper copy: Images.html
Local helper copy: Videos.html
Breach/Leak/Paste data
Data breaches provide a treasure trove of information including credentials, linked data, and password hashes. These breaches often expose individuals and organizations with poor cybersecurity hygiene. Credentials from major breaches frequently become the basis for password lists used in attacks, such as the infamous rockyou.txt wordlist originating from a 2009 breach.
The tools and resources below can be used to search known data breaches and leaks, as well as to monitor and receive alerts when credentials appear in newly reported breach data. Paste sites like Pastebin have recently restricted their search capabilities. Pastebin itself has removed the ability to directly search its pastes. However, you can still search for breach data using Google dorks by including "site:pastebin.com" in your search query.
Breach Report and Search Tools
DeHashed - Premium breach search engine (paid subscription required). Search by email, username, IP address, physical address, phone, domain, VIN, and more. One of the most comprehensive breach databases available.
Have I Been Pwned - Free service to check if your email or phone has been compromised in a data breach. Created by Troy Hunt. Includes Pwned Passwords API.
Scylla - Community-driven breach data search platform. Free to use with registration.
https://leak-lookup.com/ - Leak-Lookup allows you to search across thousands of data breaches to stay on top of credentials that may have been compromised, allowing you to proactively stay on top of the latest data leaks with ease. AKA Citadel
https://breachdirectory.org - Search via email address, username or phone number to see censored passwords. They also provide the full password as a SHA-1 hash, which can easily be cracked.
https://leaked.site/ - Leaked database search with extensive coverage. Requires paid subscription.
Snusbase - Breach database search with frequent updates and large collection. Paid subscription required.
LeakCheck.io - Breach database search service. Offers both API access and web interface. Paid plans available.
Intelligence X - Search engine and data archive with breach data, darknet sources, pastes, and historical internet data. Offers free searches with limitations and paid plans.
Pwndb - Tor-based breach database search (requires Tor browser)
h8mail - Email OSINT and breach hunting tool that queries multiple breach data sources via API
http://4wbwa6vcpvcr3vvf4qkhppgy56urmjcj2vagu2iqgp3z656xcmfdbiqd.onion/ - An .onion site that allows you to search through the full 2019 Facebook data breach.
Local helper copy: Breaches.html
Paste Search Tools
https://psbdmp.ws/ - Pastebin dump search and monitoring service. Indexes pastes in real-time.
Pastebin.com - Popular paste hosting site. Direct search functionality removed; use Google dorks with
site:pastebin.comto search.https://redhuntlabs.com/online-ide-search - Search and find strings across multiple IDEs, code aggregators and paste sites.
https://doxbin.org - A document sharing and publishing website which invites users to contribute personally identifiable information (PII), or a "dox" of any person of interest. It previously operated on the darknet as a TOR hidden service.
Search for Doxbin/Databin in TOR
https://cipher387.github.io/pastebinsearchengines/ - 5 Google Custom Search Engine for search 48 pastebin sites
Rentry.co - Markdown-based pastebin gaining popularity as an alternative to traditional paste sites
Justpaste.it - Popular paste site frequently used for leak distribution
Telegram - Many data leaks and breach discussions now occur in Telegram channels. Search for relevant channels using keywords.
Discord - Discord servers frequently host breach discussions and data sharing. Use server discovery tools to find relevant communities.
Misc Tools and Resources
Cryptome - Archive of publicly leaked documents since 1996. Usually government and intelligence-related.
Breach Alarm Sources - Comprehensive, easy-to-read list tracking known data breaches.
Firefox Monitor - Mozilla's free breach monitoring service. Checks if your accounts appear in known data breaches and provides alerts for new breaches. Powered by Have I Been Pwned data.
Analysis Information Leak framework - AIL is a modular framework to analyze potential information leaks from unstructured data sources like pastes from Pastebin or similar services or unstructured data streams.
breach-parse - A tool for parsing breached passwords by The Cyber Mentor. Repo also contains large breach data collections.
https://www.reddit.com/r/DataHoarder/ - This is a sub that aims at bringing data hoarders together to share their passion with like minded people.
https://www.reddit.com/r/DHExchange/ - Exchange and Sharing sub for /r/DataHoarder
Code Repositories
Code repositories represent a goldmine for security reconnaissance. Despite growing awareness, many organizations still lack mature DevSecOps practices. Software engineers frequently commit sensitive information to public repositories—whether storing code snippets for later use or posting configuration files on forums when seeking help. Often, these seemingly innocent posts inadvertently expose credentials and other sensitive data. Repository searches are particularly valuable during penetration tests against organizations with active software development teams.
While numerous code repository platforms exist, the following are considered essential for security reconnaissance:
Github - https://github.com/
GitLab - https://about.gitlab.com/
Bitbucket - https://bitbucket.org/
Stack Overflow - https://stackoverflow.com/
Source Forge - https://sourceforge.net/
Gitea - https://gitea.io/ - Self-hosted Git service; many organizations run public instances
You can manually parse these by user or subject but there are some handy tools that can help search and keep track.
Important Search Techniques:
Certificate Transparency Logs - Use crt.sh to find subdomains that may host development servers or exposed repositories
Archive.org for Deleted Content - Check archived versions of repository pages or organization profiles for deleted repos or commits
GitHub Gist Search - Don't forget GitHub Gists, which often contain sensitive snippets:
site:gist.github.com "company-name"Docker Hub Search - hub.docker.com may reveal organization repositories with embedded secrets in container images
NPM/PyPI Package Search - Check package registries for organization-published packages that may contain sensitive configuration
Code Repo Search Tools
TruffleHog - Actively maintained and recommended. Searches git repositories for secrets across commit history and branches. Features 700+ credential detectors, high-entropy string detection, and verification of findings.
Gitleaks - Fast SAST tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repos. Supports custom rules and integrates with CI/CD pipelines.
GitDorker - Python tool to scrape secrets from GitHub using an extensive dork repository. Useful for automated GitHub reconnaissance.
Repo Supervisor - Find secrets and passwords in your code
Watchman - Git change monitor
https://grep.app/ - A search engine for contents of Git Repos
gitoops - GitOops is a tool to help attackers and defenders identify lateral movement and privilege escalation paths in GitHub organizations by abusing CI/CD pipelines and GitHub access controls.
https://searchcode.com/ - Search 75 billion lines of code from 40 million projects
Sourcegraph - Universal code search across multiple repositories with powerful search syntax
GitHub Advanced Search - GitHub's native advanced search with extensive filters and operators
Semgrep - Static analysis tool for finding code patterns, useful for identifying security issues across repositories
https://publicwww.com/ - Source code search engine that lets you find any alphanumeric snippet in web page HTML, JS, and CSS code
Dorking Word List
".mlab.com password" "access_key" "access_token" "amazonaws" "api.googlemaps AIza" "api_key" "api_secret" "apidocs" "apikey" "apiSecret" "app_key" "app_secret" "appkey" "appkeysecret" "application_key" "appsecret" "appspot" "auth" "auth_token" "authorizationToken" "aws_access" "aws_access_key_id" "aws_key" "aws_secret" "aws_token" "AWSSecretKey" "bashrc password" "bucket_password" "client_secret" "cloudfront" "codecov_token" "config" "conn.login" "connectionstring" "consumer_key" "credentials" "database_password" "db_password" "db_username" "dbpasswd" "dbpassword" "dbuser" "dot-files" "dotfiles" "encryption_key" "fabricApiSecret" "fb_secret" "firebase" "ftp" "gh_token" "github_key" "github_token" "gitlab" "gmail_password" "gmail_username" "herokuapp" "internal" "irc_pass" "JEKYLL_GITHUB_TOKEN" "key" "keyPassword" "ldap_password" "ldap_username" "login" "mailchimp" "mailgun" "master_key" "mydotfiles" "mysql" "node_env" "npmrc _auth" "oauth_token" "pass" "passwd" "password" "passwords" "pem private" "preprod" "private_key" "prod" "pwd" "pwds" "rds.amazonaws.com password" "redis_password" "root_password" "secret" "secret.password" "secret_access_key" "secret_key" "secret_token" "secrets" "secure" "security_credentials" "send.keys" "send_keys" "sendkeys" "SF_USERNAME salesforce" "sf_username" "site.com" FIREBASE_API_JSON= "site.com" vim_settings.xml "slack_api" "slack_token" "sql_password" "ssh" "ssh2_auth_password" "sshpass" "staging" "stg" "storePassword" "stripe" "swagger" "testuser" "token" "x-api-key" "xoxb " "xoxp" [WFClient] Password= extension:ica access_key bucket_password dbpassword dbuser extension:avastlic "support.avast.com" extension:bat extension:cfg extension:env extension:exs extension:ini extension:json api.forecast.io extension:json googleusercontent client_secret extension:json mongolab.com extension:pem extension:pem private extension:ppk extension:ppk private extension:properties extension:sh extension:sls extension:sql extension:sql mysql dump extension:sql mysql dump password extension:yaml mongolab.com extension:zsh filename:.bash_history filename:.bash_history DOMAIN-NAME filename:.bash_profile aws filename:.bashrc mailchimp filename:.bashrc password filename:.cshrc filename:.dockercfg auth filename:.env DB_USERNAME NOT homestead filename:.env MAIL_HOST=smtp.gmail.com filename:.esmtprc password filename:.ftpconfig filename:.git-credentials filename:.history filename:.htpasswd filename:.netrc password filename:.npmrc _auth filename:.pgpass filename:.remote-sync.json filename:.s3cfg filename:.sh_history filename:.tugboat NOT _tugboat filename:_netrc password filename:apikey filename:bash filename:bash_history filename:bash_profile filename:bashrc filename:beanstalkd.yml filename:CCCam.cfg filename:composer.json filename:config filename:config irc_pass filename:config.json auths filename:config.php dbpasswd filename:configuration.php JConfig password filename:connections filename:connections.xml filename:constants filename:credentials filename:credentials aws_access_key_id filename:cshrc filename:database filename:dbeaver-data-sources.xml filename:deployment-config.json filename:dhcpd.conf filename:dockercfg filename:environment filename:express.conf filename:express.conf path:.openshift filename:filezilla.xml filename:filezilla.xml Pass filename:git-credentials filename:gitconfig filename:global filename:history filename:htpasswd filename:hub oauth_token filename:id_dsa filename:id_rsa filename:id_rsa or filename:id_dsa filename:idea14.key filename:known_hosts filename:logins.json filename:makefile filename:master.key path:config filename:netrc filename:npmrc filename:pass filename:passwd path:etc filename:pgpass filename:prod.exs filename:prod.exs NOT prod.secret.exs filename:prod.secret.exs filename:proftpdpasswd filename:recentservers.xml filename:recentservers.xml Pass filename:robomongo.json filename:s3cfg filename:secrets.yml password filename:server.cfg filename:server.cfg rcon password filename:settings filename:settings.py SECRET_KEY filename:sftp-config.json filename:sftp-config.json password filename:sftp.json path:.vscode filename:shadow filename:shadow path:etc filename:spec filename:sshd_config filename:token filename:tugboat filename:ventrilo_srv.ini filename:WebServers.xml filename:wp-config filename:wp-config.php filename:zhrc HEROKU_API_KEY language:json HEROKU_API_KEY language:shell HOMEBREW_GITHUB_API_TOKEN language:shell jsforce extension:js conn.login language:yaml -filename:travis msg nickserv identify filename:config org:Target "AWS_ACCESS_KEY_ID" org:Target "list_aws_accounts" org:Target "aws_access_key" org:Target "aws_secret_key" org:Target "bucket_name" org:Target "S3_ACCESS_KEY_ID" org:Target "S3_BUCKET" org:Target "S3_ENDPOINT" org:Target "S3_SECRET_ACCESS_KEY" password path:sites databases password private -language:java PT_TOKEN language:bash redis_password root_password secret_access_key SECRET_KEY_BASE= shodan_api_key language:python WORDPRESS_DB_PASSWORD= xoxp OR xoxb OR xoxa s3.yml .exs beanstalkd.yml deploy.rake .sls
Training
Hands-on OSINT labs have been moved to the Training section.
Training and ResourcesDeprecated/Legacy Tools
The following tools are no longer maintained, have been shut down, or have better alternatives. They are listed here for historical reference and in case they become available again.
Deprecated Document Search Tools
UVRX.com - File storage search engine (Site defunct/unreliable)
Palined.com - Open directory search (Site defunct)
Deprecated Image/Video Tools
Portrait Matcher - Face to painting matcher (Service no longer available)
Pictriev - Face search engine (Service frequently unavailable/unreliable)
Deprecated Breach Search Tools
WeLeakInfo.to - Seized by law enforcement in 2020. Was a major breach database search site.
BreachForums at breached.to - Seized/disrupted and no longer a stable source. Breach forums frequently rebrand or move domains; verify current legal and safety implications before researching any successor.
GhostProject.fr - Free breach database search (Site frequently unavailable/unreliable)
MyPwd.io - Password leak monitoring (Service status unreliable)
pwd query - Password breach checking (Site frequently down)
Deprecated Paste Search Tools
Pastebin.ga - Multi-paste site search (Site defunct)
PasteLert - Paste monitoring service (Service no longer maintained)
Deprecated Code Repository Tools
Gitrob - No longer maintained. Use TruffleHog or GitLeaks instead.
Git-all-secrets - No longer actively maintained. Consider alternatives like TruffleHog.
TruffleHog Legacy - Original version, superseded by TruffleHog v3+
trufflehog3 - Enhanced fork, but official TruffleHog now incorporates similar features
Deprecated Presentation Tools
Slideshare-downloader - Heroku free tier deprecated, service may be unreliable
Last updated