Skip to content

People OSINT

People are almost always the weakest link. Before a targeted phishing, a password spraying, or social engineering, the attacker profiles the organization’s employees: who they are, their role, their email, their social networks, their interests, and what they post unintentionally. People OSINT builds that profile from public sources only, and feeds targeted attacks directly.

  • Names and roles → priority targets (IT, HR, finance, leadership).
  • Emails → lists for spraying (Email Enumeration) and phishing.
  • Usernames (handles) → reuse across platforms, personal accounts.
  • Phone numbers → smishing, vishing, SMS 2FA.
  • Interests/personal life → credible pretexts for social engineering.
  • Photo/appearance → impersonation, deepfakes, recognition.
LinkedIn the gold: org chart, roles, technologies they use, new hires
Twitter/X, Instagram, Facebook, TikTok personal life, pretexts, locations
GitHub developer accounts (and their secrets, see recon-code)
Company portals "team", "about us", press releases
Google name + company, dorks about the person
# enumerate employees and roles
# tools: linkedin2username, CrossLinked -> generate name lists
crosslinked -f '{first}.{last}@target.com' "Target Inc"
# email pattern: deduce it (see recon-email) and validate

LinkedIn reveals the company’s email pattern, the technologies (job ads, profiles), and recent hires (new employees = more vulnerable to “welcome” phishing).

Sherlock / Maigret search a username across hundreds of platforms
Sherlock user123
WhatsMyName account enumeration by username
Pipl, Spokeo, That'sThem personal-data aggregators (by country)
# photo correlation
reverse image search (Google, Yandex, PimEyes)
HaveIBeenPwned does the email appear in breaches?
Dehashed / LeakCheck (per access) leaked credentials associated
# a password leaked in a personal breach is often reused at work

Password reuse connects an old personal breach to current corporate access.

1. Identify the company and its employees (LinkedIn, web)
2. Deduce the email pattern and generate the list (recon-email)
3. Profile high-value targets (IT, finance, support)
4. Search their usernames/accounts (Sherlock/Maigret)
5. Check leaks (HIBP, leaks) for reuse
6. Gather pretexts (interests, events) for social engineering

Profiling people touches the personal: stay within the authorized scope, don’t harass or contact outside the test’s framework, and remember much of this info is sensitive. In bug bounty/pentest, people OSINT is usually limited to what’s needed to demonstrate the vector (e.g. phishing), with explicit permission.

Reduce the profile: train employees on what they post (detailed technical roles, internal technologies), social-network privacy policies, anti-phishing/vishing awareness, MFA not relying on SMS, and monitor corporate-domain leaks (HIBP for business). The human factor is defended with training, not just technology.

  • Employees and roles mapped (LinkedIn)
  • High-value targets identified (IT/finance/support)
  • Email pattern deduced and list generated
  • Usernames searched across platforms (Sherlock/Maigret)
  • Phone numbers and personal accounts collected
  • Leaks checked (HIBP/leaks) for reuse
  • Social-engineering pretexts gathered
  • All within scope and ethical