Google Advanced Search / Dorks
The essential search-operator workflow for surfacing indexed files, login portals, exposed data, and other public information.
Open Source Intelligence investigation tools presented as a live intelligence archive — searchable, filterable, and organized into mission-focused sectors without losing the original pwnHACKER content.
root@pwnhacker:~$56 TOOLSThe essential search-operator workflow for surfacing indexed files, login portals, exposed data, and other public information.
Visual link-analysis platform for mapping relationships between people, domains, IPs, organizations, and social accounts.
Modular web reconnaissance framework for gathering intelligence from public sources and online services.
Automated OSINT and threat-intelligence platform that queries many sources and builds investigation reports.
Collect emails, subdomains, hosts, employee names, and related public-source reconnaissance data.
Open-source tools for username, email, alias, and cross-platform identity correlation.
People-search and identity-resolution platform for public-record and online-profile research.
Aggregates public records, social profiles, and contact information for people-search workflows.
Reverse lookup by name, email, phone, address, or IP using public-facing data sources.
Find and verify professional email addresses and common email patterns associated with domains.
Public-records and people-search service for identity and background research.
Check whether an email address appears in known public breach datasets.
Python-based OSINT framework that aggregates public-source identity data into reports.
Graph-based identity and infrastructure correlation using visual transforms.
Consumer people-search service aggregating public records and online profile data.
Searches web presence across social networks, news, blogs, and public records.
Search engine for Internet-connected devices, open services, banners, and exposed systems.
Query public domain-registration records and registrar data.
Collection of DNS and infrastructure investigation utilities including reverse IP and DNS history.
Internet-wide search and certificate intelligence for hosts, services, and TLS infrastructure.
Analyze domains, IPs, URLs, and files against reputation and security engines.
ASN, BGP route, IP-range, and DNS research for mapping public infrastructure.
Domain research and visual DNS mapping for hosts, MX records, name servers, and subdomains.
Fingerprint public website technologies, frameworks, hosting, analytics, and infrastructure.
Safely inspect submitted URLs in a sandboxed browser and review requests, redirects, and indicators.
Hunt for a username across hundreds of social platforms from the command line.
Search and monitor public social-media content, mentions, hashtags, and keywords.
Legacy Twitter/X scraping project used for public-data research workflows.
Download and inspect public Instagram profile content and metadata where accessible.
Advanced Reddit archive/search tooling for historical public posts and user activity.
Interactive CLI toolkit for public Instagram OSINT and profile investigation.
Find visually similar images and possible source pages across the public web.
Reverse-image search for provenance, older copies, modifications, and reuse.
Inspect EXIF, IPTC, XMP, GPS, software, timestamp, and other file metadata.
Satellite and historical imagery for geolocation and visual verification.
Alternative reverse-image search useful when comparing results across engines.
Crowdsourced street-level imagery for location verification and geographic research.
Network discovery, service enumeration, OS fingerprinting, and authorized security assessment.
Packet capture and protocol analysis across hundreds of network protocols.
Passive wireless detector, sniffer, and IDS for Wi-Fi, Bluetooth, and RF research.
Global wireless-network geolocation database for SSID/BSSID and wardriving research.
Combines traceroute and ping to visualize routes, latency, and packet loss.
High-speed port scanner intended for large authorized network discovery tasks.
Extract publicly exposed metadata from Google documents for authorized OSINT research.
Metadata extraction and document-discovery tool for Office and PDF research.
Browse historical website snapshots and recover older public versions of pages.
Search public paste archives for exposed text and public breach indicators.
Harvest public documents from a target domain and extract metadata from them.
Reverse phone lookup and caller-identification service for unknown-number research.
Phone-number validation and carrier/line-type lookup service.
Reference for international dialing codes and country prefixes.
Phone-number OSINT scanner that gathers public carrier, country, and web-footprint data.
Privacy-focused browser for lawful access to Tor hidden services and research environments.
Search engine that indexes publicly reachable Tor hidden services.
Commercial breach-search platform for checking exposure in known leaked datasets.
Python utility that queries multiple Tor search engines for lawful research.
“Information is the oxygen of the modern age.”— Ronald Reagan · pwnHACKER OSINT Doctrine