OSINT
Google Dorking (Search Operators)
Advanced search operators to find exposed files, logins, and indexed secrets.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Passive discovery of public exposures related to a target org.
How
Use site:, filetype:, inurl:, intitle: combinations carefully and ethically.
Why
Zero-packet recon that frequently finds real misconfigurations.
Commands & usage
site:example.com filetype:pdf
site:example.com inurl:admin
site:example.com ext:env OR ext:sql
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in OSINT
Maltego
Graph-based link analysis for people, domains, infrastructure, and relationships.
theHarvester
Gathers emails, subdomains, hosts, and employee names from public sources.
Recon-ng
Modular recon framework with workspace DB and API-backed modules.
SpiderFoot
Automated OSINT scanner with web UI covering 200+ data sources.
Sherlock
Hunt usernames across hundreds of social sites.
Maigret
Username OSINT tool with report generation across many sites.