
निजी दृष्टिकोण वाली संगठन-केंद्रित OSINT फुटप्रिंटिंग जो recon-ng और Maltego से प्रेरित है।
सूचना
यह प्रोजेक्ट केवल आंशिक रूप से पूरा है और मैंने अभी तक नीचे दिए गए ब्लॉग पोस्ट में वर्णित कई सुविधाओं को लागू नहीं किया है: https://penafieljlm.com/2017/07/14/inquisitor/।
Inquisitor कंपनियों और संगठनों के बारे में ओपन सोर्स इंटेलिजेंस (OSINT) स्रोतों के उपयोग से जानकारी एकत्र करने के लिए एक सरल उपकरण है। यह Maltego और recon-ng के संचालन से काफी प्रेरित है, और यह उपकरण उन उपकरणों की कुछ विशेषताओं को पुनः लागू करता है, लेकिन एक आसान-से-उपयोग कार्यप्रवाह बनाने के लिए संपत्ति प्रकारों के ऊपर राय-आधारित अर्थशास्त्र की एक अतिरिक्त परत जोड़ता है।
Inquisitor की प्रमुख विशेषताओं में शामिल हैं:
Inquisitor की पूरी अवधारणा इस विचार के इर्द-गिर्द घूमती है कि लक्ष्य संगठन के बारे में पहले से ज्ञात जानकारी के आधार पर ओपन स्रोतों से जानकारी निकाली जाए। Inquisitor के संदर्भ में इन्हें "ट्रांसफॉर्म" कहा जाता है। संबंधित जानकारी किसी ज्ञात संपत्ति से मेटाडेटा के आधार पर तुरंत प्राप्त की जा सकती है, जो whois और इंटरनेट रजिस्ट्री जैसे ओपन स्रोतों से भी प्राप्त किया जा सकता है।
इन अवधारणाओं पर इस ब्लॉग लेख में अधिक विस्तार से चर्चा की गई है: https://penafieljlm.com/2017/07/14/inquisitor/
Inquisitor को स्थापित करने के लिए, बस रिपॉजिटरी को क्लोन करें, उसमें प्रवेश करें, और स्थापना स्क्रिप्ट निष्पादित करें।``` pip install Cython click git clone [email protected]:penafieljlm/inquisitor.git cd inquisitor python setup.py install
## उपयोग
Inquisitor के पाँच मूलभूत कमांड हैं जिनमें `scan`, `status`, `classify`, `dump`, और `visualize` शामिल हैं।```
usage: inq [-h] {scan,status,classify,dump,visualize} ...
optional arguments:
-h, --help show this help message and exit
command:
{scan,status,classify,dump,visualize}
The action to perform.
scan Search OSINT sources for intelligence based on known
assets belonging to the target.
status Prints out the current status of the specified
intelligence database.
classify Classifies an existing asset as either belonging or
not belonging to the target. Adds a new asset with the
specified classification if none is present.
dump Dumps the contents of the database into a JSON file
visualize Create a D3.js visualization based on the contents of
the specified intelligence database.
स्कैन मोड में, उपकरण आपके खुफिया डेटाबेस में मौजूद सभी संपत्तियों के लिए सभी उपलब्ध ट्रांसफॉर्म चलाता है। सुनिश्चित करें कि आप नीचे बताए गए विभिन्न OSINT स्रोतों के लिए API कुंजियाँ बनाएँ और उन्हें स्क्रिप्ट को प्रदान करें, अन्यथा उन स्रोतों का उपयोग करने वाले ट्रांसफॉर्म को छोड़ दिया जाएगा। साथ ही, सुनिश्चित करें कि आप पहले classify कमांड का उपयोग करके अपने खुफिया डेटाबेस में कुछ ज्ञात स्वामित्व वाली लक्ष्य संपत्तियों को सीड करें, क्योंकि यदि डेटाबेस में कोई स्वामित्व वाली संपत्ति नहीं है, तो ट्रांसफॉर्म करने के लिए कुछ भी नहीं होगा।```
usage: inq scan [-h] [--google-dev-key GOOGLE_DEV_KEY]
[--google-cse-id GOOGLE_CSE_ID]
[--google-limit GOOGLE_LIMIT]
[--shodan-api-key SHODAN_API_KEY]
[--shodan-limit SHODAN_LIMIT]
DATABASE
positional arguments: DATABASE The path to the intelligence database to use. If specified file does not exist, a new one will be created.
optional arguments: -h, --help show this help message and exit --google-dev-key GOOGLE_DEV_KEY Specifies the developer key to use to query Google Custom Search. Visit the Google APIs Console (http://code.google.com/apis/console) to get an API key. If notspecified, the script will simply skip asset transforms that involve Google Search. --google-cse-id GOOGLE_CSE_ID Specifies the custom search engine to query. Visit the Google Custom Search Console (https://cse.google.com/cse/all) to create your own Google Custom Search Engine. If not specified, the script will simply skip asset transforms that involve Google Search. --google-limit GOOGLE_LIMIT The number of pages to limit Google Search to. This is to avoid exhausting your daily quota. --shodan-api-key SHODAN_API_KEY Specifies the API key to use to query Shodan. Log into your Shodan account (https://www.shodan.io/) and look at the top right corner of the page in order to view your API key. If not specified, the script will simply skip asset transforms that involve Shodan. --shodan-limit SHODAN_LIMIT The number of pages to limit Shodan Search to. This is to avoid exhausting your daily quota.
### स्थिति
स्थिति मोड में, उपकरण आपके स्कैन डेटाबेस की स्थिति का एक त्वरित सारांश प्रिंट करता है।```
usage: inq status [-h] [-s] DATABASE
positional arguments:
DATABASE The path to the intelligence database to use. If specified
file does not exist, a new one will be created.
optional arguments:
-h, --help show this help message and exit
-s, --strong Indicates if the status will be based on the strong ownership
classification.
वर्गीकृत मोड में, आप मैन्युअल रूप से संपत्तियां जोड़ सकते हैं और Intelligence Database में पहले से मौजूद संपत्तियों को पुनः वर्गीकृत कर सकते हैं। आपको इस कमांड का उपयोग अपने Intelligence Database को ज्ञात स्वामित्व वाले लक्ष्य संपत्तियों के साथ सीड करने के लिए करना चाहिए।``` usage: inq classify [-h] [-ar REGISTRANT [REGISTRANT ...]] [-ur REGISTRANT [REGISTRANT ...]] [-rr REGISTRANT [REGISTRANT ...]] [-ab BLOCK [BLOCK ...]] [-ub BLOCK [BLOCK ...]] [-rb BLOCK [BLOCK ...]] [-ah HOST [HOST ...]] [-uh HOST [HOST ...]] [-rh HOST [HOST ...]] [-ae EMAIL [EMAIL ...]] [-ue EMAIL [EMAIL ...]] [-re EMAIL [EMAIL ...]] [-al LINKEDIN [LINKEDIN ...]] [-ul LINKEDIN [LINKEDIN ...]] [-rl LINKEDIN [LINKEDIN ...]] DATABASE
positional arguments: DATABASE The path to the intelligence database to use. If specified file does not exist, a new one will be created.