In brief
A how-to guide on OSINT: how to get to a site's owner, administrator and developer through the domain, the hosting, DNS, the content and the traffic. WHOIS is unreliable after GDPR, but there are plenty of side traces. A condensed version of an hour-and-a-half lecture for security services and investigators: ≈17 minutes, there were no questions from the audience.
Key points
- USB Type-C will be dropped from smartphones — forensics will have "simply nothing left" to plug into, and what will grow is data analysis. The roles: the owner (domain, hosting), the administrator (content), the developer (the engine). A portable Opera from T.Hunter: runs from a USB stick, "more than 2,000 sources", mostly free.
- WHOIS has degraded: domains are "registered extremely sloppily", and after GDPR it says "a private person". The way out: WHOIS archives, the services on the slide.
- "A bit off-topic": in August the Supreme Court of the Russian Federation, according to the speaker, obliged business to detect typosquatting and fraud on its own. Free of charge: DNSTwister, DNSTwist, a third one (not made out); IntelX, Have I Been Pwned — leaks involving the domain.
- Cloudflare was created against DDoS, but it is "actively used by offenders"; "you can't always" strip it away: URLScan and VirusTotal (they indexed it earlier), "leaks of Cloudflare itself", DNS, verification in Yandex and Google, acquiring services, reuse of SSL and favicon.
- DNS records hold the linked servers: some of them outside Cloudflare, some of them inside Russia — drug-trafficking and disinformation ones, "we came across quite a lot of that". October 2021: during the outage of a social network "banned and designated terrorist in Russia" he was getting in "to the IP address".
- Contacts — in the body of the site and in leaks: archived WHOIS, "millions-strong leaks" on the domain (the email pattern, names, passwords); guessing by the pattern office, contact, admin, support, HR, PR with an SMTP check.
- Files — VirusTotal and dorks, the metadata is what is valuable. A 2025 case: a site against a competitor, pictures taken on an iPhone — the geolocation turned out to be the suspect's home address. Also robots.txt, sitemap.xml and "the utterly trivial InfoApp application" by way of a VKontakte group — the admins.
- The marketing add-ons (acquiring services, chatbots, analytics counters, advertising codes) are "a huge minus" for the owner. Metrica: "about 10%" of counters are public, and Yandex support discloses the email address by the identifier. Acquiring — "you can contact the bank" for the recipient. Web archives — the old code, contacts, "even files".
- Petitions are "almost always" inflated by bots, but the author does the first seeding himself — they look for who was the first to post the link. The figure "in about 70–80%" was spoken, but what it refers to is unclear.
Tools, artifacts, technologies
- A portable Opera (T.Hunter) — free, the link is on the slide; WHOIS is criticized, WHOIS archives are recommended (the services are on the slide), ICANN — in passing.
- DNSTwister, DNSTwist (+ a third one, not made out), IntelX, Have I Been Pwned — free; URLScan, VirusTotal, "leaks of Cloudflare itself" — bypassing Cloudflare.
- Artifacts: DNS records, the SSL certificate, favicon, file metadata, robots.txt, sitemap.xml; ping, an SMTP check, dorks (examples on the slide).
- Yandex.Metrica, acquiring — deanonymization; InfoApp (VKontakte) — by ear; chatbots, forms, advertising codes, web archives (the names were not spoken).
Legal and organizational context
- The Supreme Court of the Russian Federation, August: according to the speaker, "obliging commercial entities to detect typosquatting on their own, and online fraud"; the details of the act were not named. GDPR is the reason personal data disappeared from WHOIS; ICANN — in passing.
- Yandex support approached on behalf of an administrator who "forgot which email is linked", and a request to the bank about the acquiring service — working techniques (in the conference-wide summary — pretexting). The case was "an invasion of privacy"; there are no references to the Code of Criminal Procedure or the Criminal Code.
Questions from the audience
There were no questions. The moderator: "Igor, you've apparently fired up the audience so much that it's all perfectly clear now" — applause, and on to the "roast". "No doubt about that" — by the context the moderator, the attribution is not obvious.
The speaker's position
OSINT is an equal neighbor of forensics. He names the limitations himself; the path is "not quite a linear story". The tone is a checklist with self-irony and two slides about his own browser.
Quotes
- "…domain names being registered extremely sloppily, the owners' details are not verified…"
- "…Cloudflare is actively used by offenders to hide the actual location of their site."
- "…for reconnaissance on domain names and sites it's, of course, a huge minus."
- "Just ask them for a hint: I'm the site administrator, I forgot which email is linked to this Yandex.Metrica counter…"
Closing of the online part of day 1
The moderator Dmitry Yankovoy says goodbye to the online viewers until day 2 and invites those present in the room "to the bar area". The "roast", the prize draw and the informal part were not streamed; what follows is day 2, after a pause in the recording.