Hunting Threat Actors using OSINT Forensics

Abi Waddell (Vice President of Security Testing · Inquirics)

BSides NYC 2023 (0x04) · Day 1 · Talk - Blue

Overview

In this compelling presentation from BSides NYC, Abi Waddell, Vice President of Security Testing at Inquirics, delved into the often-overlooked yet critical domain of Open Source Intelligence (OSINT) forensics for identifying the source of cyber breaches and the individuals behind them. The talk highlighted a significant gap in traditional cybersecurity investigations: while existing tools and methodologies excel at determining what an attacker did and how they did it, they frequently fall short in answering the crucial question of who is responsible. This deficiency arises because much of the preparatory and post-breach reconnaissance activities occur off-network, beyond the visibility of conventional security controls.

Watch on YouTube

Visual summary for Hunting Threat Actors using OSINT Forensics by Abi Waddell
Visual summary for Hunting Threat Actors using OSINT Forensics by Abi Waddell

Key moments

  1. 0:00 Introduction to OSINT for cyber breach forensics
  2. 1:00 Revealing hidden parts of profile images (Instagram/Twitter)
  3. 2:00 Viewing original PDF content despite edits in Google Docs
  4. 4:00 Tool to reveal cropped parts of Microsoft file screenshots
  5. 4:40 Using account recovery functions to gain user intel
  6. 6:20 Obtaining password length clues from banking websites
  7. 7:00 Tracing suspects by matching unique writing patterns

Hunting Threat Actors using OSINT Forensics

Speakers: Abi Waddell, Vice President of Security Testing, Inquirics

Conference: BSides NYC

YouTube: https://www.youtube.com/watch?v=gCN42va4cgw

Overview

In this compelling presentation from BSides NYC, Abi Waddell, Vice President of Security Testing at Inquirics, delved into the often-overlooked yet critical domain of Open Source Intelligence (OSINT) forensics for identifying the source of cyber breaches and the individuals behind them. The talk highlighted a significant gap in traditional cybersecurity investigations: while existing tools and methodologies excel at determining what an attacker did and how they did it, they frequently fall short in answering the crucial question of who is responsible. This deficiency arises because much of the preparatory and post-breach reconnaissance activities occur off-network, beyond the visibility of conventional security controls.

Waddell presented a robust framework of OSINT techniques, meticulously developed from years of research and original discovery, designed to bridge this investigative gap. The methodologies explore publicly available data – ranging from social media profiles and document metadata to leaked password repositories and exposed network devices – to construct comprehensive profiles of threat actors. The talk underscored the profound importance of OSINT in modern cybersecurity, particularly for organizations and law enforcement seeking to attribute attacks and understand adversary motivations and methods beyond purely technical indicators.

The relevance of this work extends across various sectors, from assisting non-profits in understanding their digital footprint to empowering law enforcement in criminal investigations. By demonstrating practical, actionable methods for extracting intelligence from seemingly innocuous public data, Waddell's presentation armed attendees with novel approaches to threat actor identification, shifting the paradigm from reactive incident response to proactive intelligence-driven attribution.

Background

▶ Watch: Introduction to OSINT for cyber breach forensics (0:00)

The landscape of cybercrime is continually evolving, with threat actors employing sophisticated tactics that often extend beyond the immediate digital boundaries of a target organization. Traditional security tools, such as Security Information and Event Management (SIEM) systems, Intrusion Detection Systems (IDS), and Endpoint Detection and Response (EDR) solutions, are primarily designed to monitor and analyze activities within a company's network or endpoints. While invaluable for detecting and responding to active threats, these tools inherently struggle to capture reconnaissance, planning, and post-exploitation activities that occur on external platforms, public websites, or the deep web. This creates a significant blind spot for investigators attempting to understand the full lifecycle of an attack and, crucially, to identify the individuals or groups orchestrating them.

OSINT, in this context, refers to the collection and analysis of information that is available from public or openly accessible sources. This encompasses a vast array of data, including social media posts, forum discussions, public records, news articles, academic papers, and even unintentional data leaks. Unintentional leakage, as highlighted by Waddell, can be as simple as a misdirected email or a misconfigured web server exposing hidden directories. The problem this talk addresses is the inherent difficulty in correlating these disparate pieces of public information to form a coherent picture of a threat actor, especially when they actively attempt to obscure their identity.

Waddell's research and the services offered by Inquirics aim to systematize these OSINT techniques, transforming what might seem like random data points into actionable intelligence. The underlying premise is that even the most cautious threat actors often leave a digital breadcrumb trail, whether through consistent linguistic patterns, reused online personas, or inadvertent data disclosures across various public platforms. By methodically searching, correlating, and analyzing this publicly available information, investigators can develop profiles, establish links, and ultimately identify individuals who would otherwise remain anonymous. This approach complements traditional forensic methods by extending the investigative reach beyond the compromised network into the broader digital ecosystem where adversaries operate.

Key Findings

▶ Watch: Viewing original PDF content despite edits in Google Docs (2:00)

Abi Waddell's talk unveiled a treasure trove of OSINT techniques, demonstrating how seemingly minor details from publicly available sources can be leveraged to unmask threat actors. The key findings and contributions can be categorized as follows:

  • Revealing Hidden Material: Simple tricks can uncover information deliberately obscured in common digital formats. This includes revealing cropped portions of images in Microsoft files, stripping edits from PDF documents by opening them in specific viewers like Google Docs, and expanding truncated profile pictures on social media platforms like Instagram and Twitter to expose full images.
  • Account Recovery Information Leakage: Many online services, through their "forgot password" or account recovery functions, inadvertently leak partial user details such as redacted email addresses, phone numbers, and even password length clues. These snippets, while incomplete, can be crucial for corroborating other information or narrowing down guesses.
  • Writing Style Analysis for Profiling: Analyzing linguistic patterns in public posts can help link disparate online personas. Tools like Gender Guesser can even infer the gender of a user based on their writing style, adding another dimension to profiling.
  • Exploiting Suspect Accounts (Legal Access): For those with legal access to a suspect's accounts, platforms like Grammarly (showing draft documents), fitness apps (historic location data), and booking sites (travel and personal details) can provide rich intelligence.
  • Forum Pseudonym Deanonymization: Specific search techniques within forums (e.g., username + phone prefixes, "for sale/wanted" keywords, analyzing attached media metadata, cross-referencing nicknames, or sign-off abbreviations) can lead to the real identity, location, or associated usernames of forum members.
  • Advanced Facebook Forensics: Waddell demonstrated sophisticated methods for querying Facebook, including constructing base64 encoded queries with specific parameters (user ID, location ID, date) to uncover targeted information. Techniques for analyzing friends lists (even when hidden), identifying family members via surnames, and discerning fake profiles based on a comprehensive set of characteristics were also presented. The Inquirics Facebook/LinkedIn profile join date estimator tool was highlighted for its 98% accuracy in determining profile creation dates.
  • Leaked Password Analysis: A significant and novel finding involved statistical analysis of thousands of leaked passwords, revealing distinct gender-based patterns in the use of special characters, first names, surnames, and email domain names. For instance, women were three times more likely to use their first name in a password, while men were twice as likely to use their surname.
  • Company and Domain Registration Records: Publicly accessible domain registration records and company filings can reveal linked entities, administrative/technical contact data, and even full dates of birth for company directors, especially from scanned paper records.
  • Exposed Network Devices: Many IoT and network devices expose sensitive information (IMEI, MAC addresses, firmware, service details, accessible files via anonymous FTP) through open ports or misconfigurations, which can be accessed with minimal technical skill and within OSINT legal boundaries.
  • IP Address and RF Forensics: Techniques like analyzing torrent peer connections for IP addresses and country locations, mapping Software-Defined Radio (SDR) servers via SpyServer, and using OpenCellID for cell tower locations or Helium Explorer for crypto mining devices, provide geographical and device-specific intelligence.
  • iPhone "Find My" Exploitation: Knowing iCloud credentials (with authority) allows bypassing 2FA via a browser to use "Find My iPhone," revealing device model and enabling assumptions about technologies like Ultra-Wideband (UWB).
  • VPN Detection: An Inquirics tool identifies suspicious source IP addresses from log files by cross-referencing them against ranges of free VPN services that do not require credit card sign-up, often favored by nefarious actors.
  • WebEx Profile Viewing: Even without joining a meeting, it's sometimes possible to view a user's profile picture on WebEx, which might not be publicly visible otherwise.
  • Credential Stealer Log Analysis: Logs from credential stealers can reveal not just usernames and passwords, but also a suspect's visited sites, providing insights into their tools, methods, and hidden services.
  • Website Font Comparison: A simple browser trick (Ctrl+Shift+C) allows comparing fonts between websites to identify potential common authorship.

Technical Deep Dive

▶ Watch: Tool to reveal cropped parts of Microsoft file screenshots (4:00)

Waddell’s presentation offered a granular look at the technical underpinnings and execution of advanced OSINT techniques, moving beyond surface-level searches to reveal deeply embedded or subtly exposed information.

One of the foundational technical insights revolved around revealing hidden material in common digital formats. For images, particularly those cropped within Microsoft PowerPoint, Excel, or Word documents, the talk highlighted that the "cropped" areas are often merely hidden, not deleted. This means that if a user takes a screenshot of their desktop, crops out sensitive information (like internal URLs or personal details), but forgets to actively delete the cropped parts, the full original screenshot can be recovered. Waddell introduced a Nifty free tool from Inquirics, built on Microsoft Excel, that automates this extraction. Users simply upload the target files, and the tool extracts all images, saving them to a results file where the full, uncropped screenshots, including previously hidden sensitive data, are revealed. This method bypasses editing restrictions and has no known patch. Similarly, for PDF files, opening an edited document in Google Docs (not just Google Drive preview) effectively strips away the edits, allowing the viewing of the original, unaltered content – a crucial technique for detecting forgery. Social media profile images on platforms like Instagram and Twitter, when viewed in a separate browser window or saved locally, can sometimes reveal portions of the image that are typically hidden by the platform's display formatting, such as tattoos or surrounding individuals.

Another significant area detailed was the information leakage through account recovery functions. Many mainstream services, including Facebook, Gmail, Microsoft Office, Twitter, and even banking sites like NatWest, expose partial user data when initiating a password reset. This might include partial email addresses (e.g., a*****@gmail.com), the last two digits of a phone number, or device information. For NatWest, it was noted that by entering the customer account number (derived from date of birth), one could observe the length of the user's password based on the application's character input requirements, providing a valuable clue for brute-forcing against leaked password databases.

The talk extensively covered advanced Facebook forensics, including the technical construction of targeted queries. Facebook's search function can be manipulated using base64 encoded parameters in the URL. A query string might begin with top (for all categories), followed by q= and a keyword (e.g., knitting). Crucially, the filters parameter can then be appended to refine the search by user ID, location ID, or exact date. User IDs can be found by inspecting the HTML source code of a profile, while location IDs are derived by decoding the base64 string from a standard location search. This allows for highly precise searches that would otherwise be impossible through the standard interface. Waddell also presented the Inquirics Facebook/LinkedIn profile join date estimator tool, which boasts 98% accuracy (within 60 days) in determining when a profile was created, a key indicator for identifying fake profiles.

The analysis of leaked passwords provided a fascinating technical deep dive into user psychology and gender-based patterns. A study of thousands of leaked passwords revealed distinct choices:

  • Special Characters: While overall use was equal, special characters placed in the middle of a password were more common for men (74%) than women (26%). Women preferred @, #, and %, while men chose _, $, and ?.
  • Personal Names: Women were over three times more likely to use their first name, while men were over twice as likely to use their surname. Men were also four times more likely to use both first and surname in the same password.
  • Email Domains: Men were nearly twice as likely to include their email account domain name.
  • Name Gender Preference: Intriguingly, males were 1.39 times more likely to choose a female name in their password, while females were over twice as likely to choose a male name.

Regarding exposed network devices, Waddell provided concrete examples of information accessible without authentication. A 4G IoT NETCOM device login screen exposed IMEI, MZ firmware, and other status details directly in a browser. A Nebra hotspot crypto Miner device, accessible over a specific port, revealed its version, MAC address, Helium Miner address, and frequency. A Samsung DVR device offered anonymous FTP access on Port 21, exposing its file system. The talk emphasized that such anonymous system access is legally considered within the bounds of OSINT. Furthermore, investigating open ports not just on a suspect's IP but on other addresses within the same ISP range could reveal linked threat actor infrastructure, such as Metasploit running on Port 3790 or various hacking software on Port 80.

Finally, the talk introduced an Inquirics app designed to identify suspicious IP addresses from log files. This tool extracts all IP addresses and cross-references them against known ranges of free VPN services that do not require credit card registration. The underlying assumption is that threat actors seeking greater anonymity are more likely to use such services, thus flagging potentially suspicious source IPs.

These technical deep dives illustrate that OSINT is far from a simple Google search; it involves a nuanced understanding of how data is stored, presented, and inadvertently exposed across a multitude of digital platforms and devices.

Demo / Proof of Concept

▶ Watch: Obtaining password length clues from banking websites (6:20)

While the presentation did not feature a live software demonstration in the traditional sense, Abi Waddell provided three compelling real-world case studies that served as powerful proofs of concept, illustrating how the discussed OSINT techniques are successfully applied to hunt threat actors. These scenarios showcased the iterative nature of OSINT, where initial clues lead to further investigations, triangulating information from diverse sources to build a complete picture.

Case 1: Hunting a .NET Malware Tools Supplier

The first example involved a vendor of .NET malware hack tools found on AlphaBay, a darknet market. The initial clue was a username.

  1. Username Cross-Matching: The username was cross-referenced with password leak repositories.
  2. Password Analysis: This search revealed a password containing the number "1731" and an associated email address. Further searches for the username being used as a password also led to references of "1731" and other email addresses. The password itself appeared to contain a first name.
  3. IP and Phone Number Discovery: Multiple real estate-related email addresses were found associated with the "1731" password, along with two IP addresses and a phone number, all pointing to Algeria.
  4. Physical Address Triangulation: A Google search combining the discovered phone number and first name led directly to the person's identity and their associated physical address. This case exemplified how a single username, when cross-referenced across leaked data, can rapidly lead to real-world identification.

Case 2: Identifying a Telco Breacher

This scenario began with only a username associated with a breach of a large telecommunications company.

  1. Google Search & Variant Username: A Google search for the username revealed a slight variant, which in turn led to a public forum.
  2. Forum Data Extraction: The forum provided a photo of the user, their country location (Brazil), and a link to a Facebook profile.
  3. Facebook Profile Analysis: The Facebook profile name used letters swapped for numbers, a common obfuscation technique. By reversing this, a probable surname was deduced.
  4. Password Leaks & Account Recovery: Searching password leak lists with the new information yielded several passwords and a Hotmail address. Using Google's "forgot password" function with the Hotmail address revealed two associated phone devices and an iCloud account. One of these devices had a phone number ending in "77."
  5. Further Correlation: Searches for the Brazilian equivalent of "John" (a common first name guess) combined with other gathered information led to a reference of a user with these details selling cracked gaming software (Arsenal 4 and 4) and an account on the hacking forum Nulled.
  6. Social Media Persistence: Although the original Facebook profile had been deleted, the team successfully located the suspect's Skype and Instagram profiles. The Instagram profile was particularly rich, revealing his birthday, probable employer, and hometown in Brazil, which was corroborated by the IP addresses found in the password leak lists. This case demonstrated the power of persistent investigation across multiple social media and data leak sources, even when profiles are deleted or obfuscated.

Case 3: Tracing Prohibitive Wildlife Trade

The final case involved identifying an individual selling Red List prohibitive wildlife (e.g., cheetah and lion cubs) across various countries.

  1. Initial Contact & Email Dialogue: The investigation started with a contact form on the illicit vendor's website. After initial contact, an email dialogue was established, yielding an email address and a phone number.
  2. WhatsApp, Skype, Gmail Checks: The phone number was checked on WhatsApp (no info), but Skype and Gmail provided a username and partial Gmail addresses.
  3. Guesswork & Identity Discovery: Through educated guesswork with the redacted Gmail addresses, a person's name, business email, company names, and country location were discovered.
  4. Password Leaks & Corporate Links: Further cross-matching of passwords, email addresses, and names on password leak lists generated more leads, ultimately pointing to an export company based in South Africa.
  5. Illicit Trade Facilitation: The conclusion was that this export company was likely being used to facilitate the export of illicit products, including pharmaceuticals and wildlife. This case highlighted the effectiveness of engaging with targets (even indirectly) and then leveraging OSINT to trace the digital breadcrumbs to real-world entities and illegal operations.

These detailed examples underscore the practical utility and investigative success of Waddell's OSINT methodologies in attributing cyber breaches and uncovering criminal activities.

Defensive Implications

▶ Watch: Tracing suspects by matching unique writing patterns (7:00)

The insights shared by Abi Waddell offer critical lessons for defenders, emphasizing that security extends beyond network perimeters. Understanding how threat actors leverage OSINT is crucial for bolstering an organization's overall security posture.

  1. Employee Training on Data Hygiene: Organizations must educate employees about the risks associated with public information. This includes careful consideration before posting personal details online, understanding what metadata might be embedded in shared documents or images, and being aware of how screenshots (especially those not actively deleted after cropping) can inadvertently leak sensitive internal information. Training should cover best practices for using social media and handling digital documents.
  2. Reviewing Public-Facing Applications for Information Leakage: Security teams should proactively audit their own organization's public-facing applications, particularly "forgot password" or account recovery functions. The talk showed how partial email addresses, phone numbers, or password length clues can be inadvertently exposed. Minimizing the information returned by these functions can reduce the OSINT footprint available to adversaries.
  3. Securing Networked Devices and Services: The examples of exposed IoT devices, anonymous FTP access, and open ports reiterate the importance of securing all internet-facing assets. Default credentials must be changed, unnecessary services disabled, and configurations regularly reviewed to prevent unintentional exposure of sensitive device information (IMEI, MAC addresses, firmware, files).
  4. Monitoring for Organizational Mentions: Proactive OSINT monitoring for mentions of the company, its employees, or sensitive projects on public forums, social media, darknet markets, and paste sites can provide early warnings of potential threats or data leaks. This includes searching for company-specific keywords, employee names, and even common internal codes or project names.
  5. Strong Password Policies and Awareness: The detailed analysis of leaked passwords underscores the importance of strong, unique passwords. Employees should be discouraged from using personal identifiers (first names, surnames, birthdays) or email domain names in their passwords. Implementing Multi-Factor Authentication (MFA) across all critical accounts is a fundamental defense against credential stuffing attacks facilitated by OSINT-derived password leaks.
  6. Vigilance Against Social Engineering and Fake Profiles: The detailed hallmarks of fake social media profiles provide a guide for employees to identify and report suspicious accounts. Threat actors frequently use fake profiles for reconnaissance, phishing, and social engineering. Training staff to recognize these indicators can prevent them from falling victim to targeted attacks.
  7. Understanding Adversary Profiling: Defenders should internalize that threat actors are actively profiling them and their colleagues using OSINT. This awareness should inform what information is shared publicly, how professional and personal online personas are managed, and the potential implications of seemingly innocuous details.
  8. Leveraging OSINT for Threat Intelligence: Security teams can adopt many of the discussed OSINT techniques to gather intelligence on emerging threats, track adversary groups, and understand their Tactics, Techniques, and Procedures (TTPs). This proactive intelligence can inform defensive strategies and incident response planning.
  9. Data Minimization: Both individuals and organizations should practice data minimization, limiting the amount of sensitive information that is publicly accessible or stored in insecure locations. This includes reviewing privacy settings on social media and professional networking sites.

By integrating these defensive strategies, organizations can significantly reduce their vulnerability to OSINT-driven reconnaissance and enhance their ability to defend against sophisticated threat actors who rely on publicly available information for their attacks.

Key Takeaways

  • OSINT is a Critical Component of Threat Attribution: Traditional security tools often fail to identify who is behind cyber breaches because reconnaissance and off-network activities are not captured. OSINT fills this crucial gap by leveraging publicly available data to profile and attribute threat actors.
  • Common Applications Inadvertently Leak Data: Many everyday platforms, including social media, document editors, and even account recovery functions on major services (Facebook, Gmail, Microsoft, Twitter), can be exploited to reveal partial user details, metadata, or hidden content if not properly configured or understood.
  • Small Clues Can Lead to Full Identities: The talk demonstrated how seemingly insignificant pieces of information – a partial email, a password fragment, a cropped image, a forum post – can be triangulated across multiple OSINT sources to build a comprehensive profile, including real names, locations, and affiliations.
  • User Behavior and Data Patterns are Exploitable: Analysis of leaked passwords reveals predictable gender-based patterns in password choices, while consistent writing styles or specific online habits can link disparate personas, providing valuable profiling insights for investigators.
  • Proactive OSINT is Essential for Defense: Organizations and individuals must understand how adversaries use OSINT. This awareness should drive better data hygiene, stricter security configurations on public-facing assets, careful management of online personas, and proactive monitoring for mentions and data leaks to mitigate risks.
  • Specialized Tools and Techniques Enhance OSINT: Beyond basic searches, advanced techniques like constructing base64 encoded Facebook queries, using specialized tools for extracting hidden image data from Microsoft files, or analyzing exposed network device configurations are vital for deep-dive OSINT investigations.

About the Speaker(s)

Abi Waddell is a distinguished expert in the field of security testing and Open Source Intelligence (OSINT). She currently serves as the Vice President of Security Testing, a role that underscores her deep technical expertise and leadership in cybersecurity. In addition to her corporate responsibilities, Waddell is the founder of Inquirics, an organization dedicated to providing specialized research and services, particularly focusing on OSINT vulnerability assessments for non-profit organizations. Her extensive background is rooted in years of dedicated research and original discovery in the domain of OSINT, equipping her with unique methodologies for locating the source of cyber breaches and identifying suspects. Her work emphasizes bridging the gap in traditional cyber forensics by focusing on off-network activities and publicly available information to unmask threat actors.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent BSides-tier OSINT talk with genuine breadth — the leaked password gender analysis and base64 Facebook query construction show real original research baked in. The case studies are well-structured and honest about methodology. Not groundbreaking for anyone who's done serious attribution work, but it's practitioner-built content with actual receipts, not a vendor deck.

Heather Calloway (CISO) — WEAK

Waddell clearly knows her craft, and the case studies are genuinely instructive for investigators. But this talk is built for analysts doing attribution work — not for the security leaders, governance teams, or operators who need to understand what to do with OSINT as an institutional capability or exposure vector.

→ Top-rated talks at BSides NYC 2023 (0x04)

All talks from BSides NYC 2023 (0x04)