Don’t F*** with ThreatPipes

A handful of ThreatPipes modules you can use for OSINT investigations

David G
3 min readDec 31, 2019

Star Wars, Frozen 2, (Don’t F**k With) Cats…

How many of the biggest film releases did you see last month?

My opinion. All were good. Particularly Don’t F**k With Cats.

Most of my family are now OSINT investigators, plugging images into Tineye and extracting the EXIF data to map them on Google Earth.

Inspired, here are a handful of ThreatPipes modules that you might find useful during your next OSINT investigation.

Search

Search engines proved vital in identifying items in Luka’s videos.

Google, Bing, DuckDuckGo, etc. Each search engine has its own strengths. That’s why we search all of them.

If you’re looking to improve your OSINT search skills, check out my post on Google Dorks.

Example ThreatPipes modules you could use to automate web search

Location

Location was a large part of the teams investigation, chasing Luka from North America to Europe, and back.

Mapping an asset, perhaps by IP address, to a location can be useful.

WiFi networks when tracking a person are a good example.

Example ThreatPipes modules you could use to automate location search

Accounts

Luka used a number of online persona to spin a variety of stories.

It’s easy to find online accounts created using the same email addresses.

Or accounts with the same user id using the following modules.

Example ThreatPipes modules you could use to automate account identification

Assets

SPOILER ALERT

Luka was caught after a stroke of luck when recognised at an internet cafe.

The arrest was captured by a web cam streaming from the cafe.

Webcams, doorbells, baby monitors… many can be discovered and accessed by tools like Shodan or Censys.

Example ThreatPipes modules you could use to automate asset discovery

100’s more ThreatPipes Modules available for OSINT investigations…

View them all here…

David Greenwood, ThreatPipes Team

Originally published at https://www.threatpipes.com on December 31, 2019.

--

--

David G

I help early stage cyber-security companies to build products that make users go; “Wow! That’s what I need!”. https://www.himynamesdave.com/