Data is key and it is everywhere

OSINT is using any tool to collect and analyze publicly accessible data. Sources can be divided into six categories:

  • Media
    newspapers, magazines, television, radio
  • Internet
    blogs, user created content, social media websites, and message boards
  • Public Government Data
    court documents, land deeds, census, press conferences, websites, and speeches
  • Professional and Academic Publications
    journals, academic papers, symposia, and dissertations
  • Commercial Data
    satellite imagery, financial and industrial assessments
  • Grey Literature
    business documents, newsletters, technical reports, and patents

Record as much information about your target.

Use Google Earth and Maps to for physical recon.

Start a TECHNICAL map of systems/technologies/methodologies of target
ex Facebook, Twitter, LinkedIn, Google+, Instagram

LinkedIn gives real names to twitter accounts!
Search social networks, public sites, and visit the company websites. See if they leak information on what systems they are using. Search job boards for tech stacks.

Look for current projects, trips to conferences, phone numbers, and email addresses.  Craft phishing and impersonation attacks.

Search for Company contracts with the US Government or other public entities.

Run whois and get

  • Owner name
  • Street addresses
  • Email addresses
  • Technical contacts

Double check target's sites

  • Products
  • Services
  • Technologies
  • Company culture
  • Board members, profiles
  • Current/future projects/products
  • Suppliers
  • Job Vacancies, etc

Look at target's email pattern and record points of contact

Send fake advertisement email for testing email formats

Google dork for leaked documents

References:

System for Award Management
SAM.gov The System for Award Management (SAM) is the Official U.S. Government system that consolidated the capabilities of CCR/FedReg, ORCA, and EPLS

http://www.gsaelibrary.gsa.gov/

https://haveibeenpwned.com/

Crunchbase: Discover innovative companies and the people behind them
Crunchbase is the leading destination for company insights from early-stage startups to the Fortune 1000. Get insights into your competition. Uncover startup trends, get company funding data. Find new prospects, beat competitors and quotas.
Shodan
Homepage
Since 2008, Maltego has empowered over a million investigations worldwide, and we are far from being done. How can Maltego support you?
ElevenPaths/FOCA
Tool to find metadata and hidden information in the documents. - ElevenPaths/FOCA
Home
Through a series of short films, video interviews, guides and resources, Exposing the Invisible looks at different techniques, tools and methods along with the individual practices of those working at the new frontiers of investigation.