> OSINT Techniques Updates: inurl & Amass path
[AUTHOR: michaelbazzell]
[DATE: 05/07/2025 14:47]
[LANGUAGE: EN]
In my book OSINT Techniques, 11th Edition, I discuss the ability to use Google search operators to both isolate and eliminate specific data. This is more important than ever with the substantial increase of AI-generated content infiltrating our queries. We are testing some new techniques which practically eliminate sites created by AI, but more research is necessary. For now, I want to focus on a change at Google which requires us to pivot our query structure for specific types of pages.
In the book, I give the following Google search example which would identify any FTP servers which possess PDF files that contain the term OSINT within the file.
inurl:ftp filetype:pdf "osint"
This still works, but results become lost in the slew of junk. The book then gives the following query to eliminate any HTTP or HTTPS results.
inurl:ftp -inurl(http|https) filetype:pdf "osint"
This worked for a while, but Google has now enforced some specific behaviors, which I really should have included anyway. The following query is now required to present only FTP sites without general web sites. The change is the colon after "inurl".
inurl:ftp -inurl:(http|https) filetype:pdf "osint"
This query provided only the four results I wanted. Replacing "ftp" with your desired content should be more productive now.
I also modified the updates.sh script (line 58) within our Linux VM build to properly remove the Amass zip file downloaded during the update. This only impacted a minority of users, but the change is cleaner.
Thank you to all of the readers who report the issues which need corrected. More details are in the book.