July 25, 2026
OSINT 101 โ Hacking With Nothing but Public Info
Hey everyone! Nitin here ๐

By Nitin yadav
1 min read
OSINT sounds like spy stuff, but it's just this: finding useful information that's ALREADY public. No hacking required. And for a bug hunter, OSINT is how you map a target before you ever send a single "attack" request. Let me open this world up for you.
What OSINT Actually Is
OSINT = Open Source Intelligence. It means gathering info from publicly available sources: search engines, code repos, DNS records, certificate logs, social media, job postings, leaked data dumps, company filings. Stuff anyone can access. You're just the person who bothers to connect the dots.
For bug bounty, OSINT answers the questions that make everything else possible: What does this company OWN? What tech do they use? Where are their forgotten assets? What have they accidentally exposed?
Why It's So Powerful
Here's the thing โ companies leak information constantly without realizing it. A job posting says "experience with AWS, Jenkins, and MongoDB" โ congrats, you now know their tech stack. A developer's public GitHub reveals internal tools. A DNS record points to a forgotten server. None of it is "hacking." It's just paying attention.
And the payoff: OSINT surfaces the soft, forgotten, exposed stuff โ exactly where the bugs live.
The OSINT Sources That Matter For Bug Bounty
- Search engines & dorking โ exposed files, panels, docs (Google, and GHDB for ready-made dorks)
- Certificate Transparency logs โ reveal subdomains (whole post coming โ it's a superpower)
- DNS records โ map infrastructure, find dangling records
- GitHub/GitLab โ leaked secrets, internal code, endpoint references
- Shodan/Censys โ exposed servers, services, databases
- Wayback Machine โ old URLs, old JS, dead-but-alive endpoints
- Job postings & LinkedIn โ tech stack, internal tool names, team structure
- Breach/leak databases โ exposed credentials (for understanding exposure, not for misuse!)
The Mindset
Good OSINT is about curiosity and patience. You're building a picture of the target from a hundred small public clues. The hunter who spends an hour on OSINT first will out-hunt the one who dives straight into poking the main app โ because they know where to poke.