Soxoj insides
Open in Telegram
5 229
Subscribers
-424 hours
+277 days
+14630 days
Posts Archive
5 229
Repost from Cyber Detective
Digital Asset Inventory by @pandora_intelligence
Local-first scanner for discovering accounts and digital assets from data you already have:
- bookmarks
- password-manager exports
- browser history
- local email archives
- saved Google/Apple connected-app pages.
https://github.com/Panda-Lewandowski/digital_asset_inventory
5 229
Bookmarked a cool command-line OSINT tool from GitHub but never found time to try it?
I built OSINT Tool Deploy Skill for Claude Code which turns a GitHub link into a working tool 💪 with deployment and verification that it actually works. Windows is supported!
Installation time decreases from hours to minutes 📉 with templates and a knowledge base of common issues and fixes.
Investigate crimes, not Python dependency errors 🥸
👉 Try it: https://github.com/soxoj/claude-osint-deploy
5 229
A friend of mine built Exploratores, a collection of online OSINT tools inspired by CyberChef and Michael Bazzell's books.
It brings a wide range of investigation tools in one interface:
• Clear web and darknet search engines
• People search
• Social media research
• IP address and domain analysis
• GEOINT tools
• Media analysis
• Cryptocurrency lookups
• Company name and IBAN searches
The best part: you only need a browser. You can also download it and run everything locally!
🔎 Try it online
💻 Download and run locally
🤖 Use it with Claude
📖 Read more about the project
5 229
Maigret 0.6.3 is out! 🕵️
115 site checks fixed, 15 new sites added, better Chinese-site support, improved Cloudflare bypass, and upgraded PDF templates.
Over the past few months, I’ve been receiving more and more fixes from the community. Maigret now gets over 100K installs per month, with more than 1M installs in total! 🚀
👉 Try it yourself: https://github.com/soxoj/maigret#in-one-minute
5 229
At probably the hottest leHACK ever, I presented my new cybersecurity tool for penetration testers: 𝐂𝐨𝐦𝐦𝐢𝐏𝐢𝐬𝐭𝐞 🔥
CommiPiste can 𝐢𝐝𝐞𝐧𝐭𝐢𝐟𝐲 𝐭𝐡𝐞 𝐞𝐱𝐚𝐜𝐭 𝐯𝐞𝐫𝐬𝐢𝐨𝐧 𝐨𝐟 𝐨𝐩𝐞𝐧-𝐬𝐨𝐮𝐫𝐜𝐞 𝐰𝐞𝐛 𝐬𝐨𝐟𝐭𝐰𝐚𝐫𝐞 using only publicly accessible static files and then 𝐟𝐢𝐧𝐝 𝐭𝐡𝐞 𝐂𝐕𝐄𝐬 associated with that version.
It can be especially useful when version information is hidden, removed from headers, or unavailable through conventional fingerprinting methods 🔎
It already supports 300 𝐝𝐢𝐟𝐟𝐞𝐫𝐞𝐧𝐭 𝐩𝐥𝐚𝐭𝐟𝐨𝐫𝐦𝐬. For some of them, CommiPiste uses a complete index of commits, while others are identified through smart heuristics 🛠️
👉 𝐆𝐢𝐯𝐞 𝐢𝐭 𝐚 𝐭𝐫𝐲: https://github.com/soxoj/CommiPiste
A huge thank you to the person behind the idea and just an awesome guy, paranoid android 😉
5 229
My train from Amsterdam to Paris was cancelled due to the heat 🥵, but I'm still coming to leHACK!
See you at OSINT Village — feel free to reach out! ✌️
5 229
Repost from OSINT mindset [ENG]
OSINT mindset team came in 2nd place at Trace Labs Search Party! 🥈
This past weekend, the Trace Labs Global OSINT Search Party took place — an international CTF focused on finding missing persons. This time, 130+ teams from around the world competed for the top spots 🌍
Our team, consisting of @Soxoj, adk, @vali, and Pr1tchard, delivered an excellent result:
— 2nd place among 130+ teams 🥈
— 28 accepted submissions
— 1,050 points
We will continue participating in events like these and helping people 🧡
🌐Site | 💬 Forum | 🔍 Family |▶YT
5 229
Repost from Cyber Detective
Kronikier (web app version)
Get historical contacts (emails, phones) for a website from Internet Archive snapshots.
Web version of https://github.com/soxoj/kronikier
https://kronikier.soxoj.com/
Creator @soxoj_insides
#osint #python #webarchive
5 229
Repost from Cyber Detective
KRONIKIER
If you haven’t been able to find the contact details on a particular website today, that doesn’t mean they’ve never been there
The Internet Archive API and Kronikier may find contact details that have been removed very quickly
https://github.com/soxoj/kronikier
Creator @soxoj_insides
5 229
Do you remember my tool gitcolombo to extract emails from code repositories? I've updated it in my spare time:
🟢 hacker-style CLI
⚡ additional powerful checks
🌐 web version: gitcolombo.soxoj.com
P.S. If gitcolombo won't help you, try GitFive — the best tool to find Github user's email
5 229
Just a reminder: I maintain socid-extractor, an open-source Python tool that extracts account data from 130+ sites.
👉 Usernames, bios, avatars, follower counts, external links — plus the stable internal identifiers that survive renames and let you re-identify accounts across leaks and archives.
No API keys, no headless browser, normalized field names and ontology, MIT license. ✅
Powers Maigret 🥸 and a number of other OSINT tools.
Don't hesitate to give it a ⭐!
🔗 https://github.com/soxoj/socid-extractor
5 229
OSINT tools should give you actionable leads, not just random URLs and raw data 🫡
My open source tool Maigret has always been able to search by username, but results analysis was up to the user 🤔
I've now added AI analytics and identity resolution to it, so you can get fast conclusions about a target across 3K sites 🚀
Over the last few weeks, I also rewrote Maigret and cleaned up the checks database: it has near-zero false positives now 🔥
Want to know why such a powerful tool is open? Apply via the link and add the comment: “show me Crimewall QuickLink mode” — and see how insanely far the commercial tools I'm building go beyond this 😉
5 229
Three standout open-source OSINT username search tools right now: Blackbird, Aliens_eye, and Naminter 🚀
I finally updated my list of username search tools 👇, retested a bunch of them, and these 3 really stood out.
Huge thanks to their creators (p1ngul1n0, 3xp0rtblog, arxhr007) for building genuinely useful tools and pushing username-based OSINT forward! 🔥
Full list on GitHub: https://github.com/soxoj/osint-namecheckers-list
5 229
🎭 ShareTrace: reveal the identity behind any share link
Works for 12 platforms: TikTok, Instagram, Discord, Google Drive, Notion, Telegram, Pinterest, Substack, Suno, ChatGPT, Claude, Perplexity.
Original repo was deleted — I rebuilt it with new platforms and fixes.
👉 https://github.com/soxoj/sharetrace
5 229
MCP + OSINT is a powerful combo 🔥
Instead of figuring out how to run CLI tools, just ask your LLM — and it runs Shodan queries, Maigret lookups, DNS fuzzing, and threat intel checks for you.
So, I've made a curated list of OSINT MCP servers. Take a look, try plugging something into your AI tool, or submit a new one!
👉 https://github.com/soxoj/awesome-osint-mcp-servers
5 229
OSINT WORLD MAP
Together with @Adk, we created OSINT WORLD MAP — a curated collection of links to OSINT tools, websites, and projects, organized by geographic location. It includes:
• 193 UN member states
• Dependent territories
• Special administrative regions
• Partially recognized states and disputed territories
• Other regions
👉 https://map.wddadk.com
Just select or search for the country you need — and that’s it. All relevant OSINT tools and resources are listed right in front of you. If you have new links make PR here https://github.com/wddadk/OSINT-for-countries
5 229
I made an interactive website to "hack" Telegram spoilers
👉 https://spoiler.soxoj.com/
It has some examples, lets you upload your own screenshots; you can play with dictionaries, adjust region detection, or enter pseudo-Braille by hand.
Ping me if you want a source code! 👍
5 229
Telegram spoilers are vulnerable and can be decoded 😳
If you've ever shared your Telegram screen and used spoilers to hide certain info, I got bad news: your hidden text might be stolen.
The problem? Usually a spoiler is shown as an animated noise and only revealed on tap. But in some parts of the MacOS Telegram client it works differently, e.g. last message in the chat list and pinned message use a fallback that turns text into pseudo-Braille characters with a one-way mapping. The code.
This transform is mathematically non-invertible, but in practice we usually know the language and roughly what symbols someone uses. So you can guess and recover the original text with a limited brute-force over likely characters. 😨
Proof-of-concept encoder/decoder:
https://github.com/rawrdcore/tg-hidden-messages-decoder
Huge thanks to @dalmatrix for researching and documenting the privacy issue.
P.S. If you've ever put passwords or other secrets under a Telegram spoiler, now is a good time to change them! 😈
5 229
Repost from KazHackStan
KazHackStan 2025 спикері — Дмитрий Даниловты "Soxoj" қарсы алайық! 💥
OSINT құралдарын әзірлеуші
Баяндама тақырыбы: OSINT 0-days: hack to search
📍Track zone
Баяндамада тікелей қараңғы жағы қарастырылады — OSINT үшін нөлдік күндік осалдықтар және байқалмайтын осалдықтар қалай ақпараттық қару ретінде қолданылатыны. Барлығы толық қарастырылады: мұндай осалдықтарды қалай іздеу керек және оларды қалай пайдалану мүмкін екенін көрсетеді.
17–19 қыркүйек
📍 Алматы | SADU Arena
Тіркелу 👉🏼 kazhackstan.com
——
Welcome the speaker of KazHackStan 2025 - Dmitrii "Soxoj" Danilov! 💥
OSINT tools developer
Topic of the speech: OSINT 0-days: hack to search
📍Track zone
This talk is about the dark side — OSINT zerodays and how hidden vulnerabilities turn into information weapons. We'll cover everything from discovering and exploiting such 0-days to protection methods and little-known SaaS OSINT services.
September 17–19
📍 Almaty | SADU Arena
Registration 👉🏼 kazhackstan.com
——
Поприветствуем спикера KazHackStan 2025 - Дмитрий Данилов "Soxoj"! 💥
OSINT tools developer
Тема доклада: OSINT 0-days: hack to search`
📍Track zone
Это доклад про тёмную сторону — зиродеи для OSINT и то, как незаметные уязвимости становятся информационным оружием. Мы разберём всё: от поиска таких 0-days и их эксплуатации до методов защиты и малоизвестных SaaS OSINT сервисов.
17–19 сентября
📍 Алматы | SADU Arena
Обязательная регистрация 👉🏼 kazhackstan.com
