Visit the Open Source Cyber Intelligence - Introduction Training course recordings page
WEBVTT--> i'm fighting with it on this end give me a second all right uh i'm not sure if it's going to allow --> it to work the way i need it to but i'm still going to walk through it with you i'm not sure --> what's really going on depending on that uh so at this section we're going to talk about showdown --> right but before we dive in we're going to make sure that this is clear right it's not a it's not --> a tricks class this is more so like a strategic recon class i've had people in the past use this --> information in the wrong way so i try to be a little bit more critical about it these stages --> today so how do we begin right all right so we've already covered google dorking we've already --> covered culture we've already covered the osin tools don't just show systems right so --> now we're going to get into like the actual mechanics of a thing right showdown so it's --> often going to be described as the search engine for devices connected to the internet --> but you already know that you gotta go much deeper than that so we go through the architecture and --> the crawler models right we go through what metadata it collects right such as it'll collect --> banners it'll collect tls certs it collects ports your operations the operating system fingerprints --> your geolocation and a few more other things right and what it doesn't and sometimes what --> it doesn't collect and that's important too you know how that affects evidence so for example let's --> say this example doesn't specifically apply for this one but just in general example let's say --> you have 50 pictures and all of those pictures but one has been scrubbed of its metadata --> it's safe to say that the data that's left on the last final on the last time the image is --> probably going to be tampered with right so that would be something that you would want written in --> your report how the condition that you found the data what that information looks like for you --> and what your conclusion is about one second