People OSINT
People are almost always the weakest link. Before a targeted phishing, a password spraying, or social engineering, the attacker profiles the organization’s employees: who they are, their role, their email, their social networks, their interests, and what they post unintentionally. People OSINT builds that profile from public sources only, and feeds targeted attacks directly.
What’s sought and why
Section titled “What’s sought and why”- Names and roles → priority targets (IT, HR, finance, leadership).
- Emails → lists for spraying (Email Enumeration) and phishing.
- Usernames (handles) → reuse across platforms, personal accounts.
- Phone numbers → smishing, vishing, SMS 2FA.
- Interests/personal life → credible pretexts for social engineering.
- Photo/appearance → impersonation, deepfakes, recognition.
Main sources
Section titled “Main sources”LinkedIn the gold: org chart, roles, technologies they use, new hiresTwitter/X, Instagram, Facebook, TikTok personal life, pretexts, locationsGitHub developer accounts (and their secrets, see recon-code)Company portals "team", "about us", press releasesGoogle name + company, dorks about the personLinkedIn: building the org chart
Section titled “LinkedIn: building the org chart”# enumerate employees and roles# tools: linkedin2username, CrossLinked -> generate name listscrosslinked -f '{first}.{last}@target.com' "Target Inc"# email pattern: deduce it (see recon-email) and validateLinkedIn reveals the company’s email pattern, the technologies (job ads, profiles), and recent hires (new employees = more vulnerable to “welcome” phishing).
Aggregators and people search
Section titled “Aggregators and people search”Sherlock / Maigret search a username across hundreds of platformsSherlock user123WhatsMyName account enumeration by usernamePipl, Spokeo, That'sThem personal-data aggregators (by country)# photo correlationreverse image search (Google, Yandex, PimEyes)Leaks (the person’s credentials)
Section titled “Leaks (the person’s credentials)”HaveIBeenPwned does the email appear in breaches?Dehashed / LeakCheck (per access) leaked credentials associated# a password leaked in a personal breach is often reused at workPassword reuse connects an old personal breach to current corporate access.
Methodology
Section titled “Methodology”1. Identify the company and its employees (LinkedIn, web)2. Deduce the email pattern and generate the list (recon-email)3. Profile high-value targets (IT, finance, support)4. Search their usernames/accounts (Sherlock/Maigret)5. Check leaks (HIBP, leaks) for reuse6. Gather pretexts (interests, events) for social engineeringOPSEC and ethics
Section titled “OPSEC and ethics”Profiling people touches the personal: stay within the authorized scope, don’t harass or contact outside the test’s framework, and remember much of this info is sensitive. In bug bounty/pentest, people OSINT is usually limited to what’s needed to demonstrate the vector (e.g. phishing), with explicit permission.
For the defense
Section titled “For the defense”Reduce the profile: train employees on what they post (detailed technical roles, internal technologies), social-network privacy policies, anti-phishing/vishing awareness, MFA not relying on SMS, and monitor corporate-domain leaks (HIBP for business). The human factor is defended with training, not just technology.
Testing checklist
Section titled “Testing checklist”- Employees and roles mapped (LinkedIn)
- High-value targets identified (IT/finance/support)
- Email pattern deduced and list generated
- Usernames searched across platforms (Sherlock/Maigret)
- Phone numbers and personal accounts collected
- Leaks checked (HIBP/leaks) for reuse
- Social-engineering pretexts gathered
- All within scope and ethical