WEBVTT

00:00.800 --> 00:03.520
In this video we're going to take a look at the tool Magritte.

00:03.920 --> 00:07.800
Now this is based off of a fictional French detective.

00:08.600 --> 00:16.840
And this is designed for using the tool for finding usernames where that username was used in other

00:16.840 --> 00:17.640
places.

00:17.640 --> 00:25.400
And this is really useful when, say, we have a Twitter handle or Facebook handle, a handle in some

00:25.400 --> 00:30.160
sort of form, we want to see where else that name was potentially used.

00:30.160 --> 00:36.320
This includes email addresses, because a lot of times people will use the same email name as they will

00:36.320 --> 00:40.000
in other places, and this is where this will come in handy.

00:40.480 --> 00:45.840
So the first part we're going to look at is the GitHub tool.

00:46.600 --> 00:48.760
And you can find at github.com.

00:51.840 --> 00:59.200
Forward slash Magritte and I have the link for this in another one in the description for this video.

01:00.760 --> 01:05.200
So if we scroll down in here this gives us some nice information about the tool.

01:05.920 --> 01:09.240
And you could either install it through a pipe.

01:09.240 --> 01:14.500
Pi pi pi um or clone the repository or docker instance.

01:14.500 --> 01:16.980
If you have Docker, I'm going to do the repository here.

01:16.980 --> 01:20.980
So I'm just going to click the little copy thing right there.

01:21.020 --> 01:24.140
I'm going to open a terminal and I'm going to paste this in here.

01:24.140 --> 01:25.460
Now I already have this installed.

01:25.460 --> 01:30.220
But you can simply do this and it'll go through and install the program for you.

01:30.220 --> 01:38.540
And then you can run it now down in here it gives you some nice usage examples here output as HTML,

01:38.580 --> 01:42.300
PDF, how to use it, so on and so forth.

01:42.820 --> 01:51.140
So another way I've been using for a while now is Osint rocks and you can find this at Osint rocks.

01:51.140 --> 01:57.700
This has several different tools built into this, and I like it a lot because it is simpler.

01:57.980 --> 01:59.460
I don't have to install anything.

01:59.700 --> 02:03.700
It is good to have the backup, uh, installed on your computer.

02:04.140 --> 02:12.620
But as far as, uh, being able to do quick searches like domain IP lookups, telephone lookup, email

02:12.620 --> 02:17.220
addresses, lookup, and username, I like using this.

02:17.220 --> 02:18.600
So I can go in here.

02:18.600 --> 02:21.160
I can go to Magritte, I can type in something like, um.

02:24.920 --> 02:28.520
Elon Musk, click on the search here.

02:28.520 --> 02:30.680
And you can also click on this to get some information.

02:30.680 --> 02:35.560
But if you're not sure what the tool does and we click on the magnifying glass here.

02:39.480 --> 02:41.880
And this will start performing a search for us.

02:47.840 --> 02:51.960
So we'll give this a moment to go ahead and perform the search.

02:54.840 --> 02:55.280
Okay.

02:55.320 --> 02:56.280
And we're back.

02:56.280 --> 03:00.160
So that actually took a really long time to pull up the information.

03:00.160 --> 03:03.960
So I changed the actual search criteria to a human hacker.

03:03.960 --> 03:07.720
But we could see what it looks like on the output.

03:08.120 --> 03:14.760
Now this kind of goes to show that sometimes tools will break.

03:14.760 --> 03:19.120
That's why I always recommend being flexible and how you use the tools.

03:19.480 --> 03:25.200
And also sometimes the web version works better than the GitHub version and vice versa.

03:25.200 --> 03:27.190
So again, be flexible.

03:27.190 --> 03:33.550
Things don't work out, which a lot of times they will not because things never seem to go right during

03:33.550 --> 03:34.630
an investigation.

03:36.430 --> 03:43.230
Be prepared to pivot in another direction to get your findings.

03:43.310 --> 03:51.270
So this is a example output of what you're going to find for Magritte.

03:51.270 --> 03:54.790
So we can see all these different, uh.

03:57.270 --> 04:01.990
Sites that are associated with this username.

04:02.310 --> 04:07.230
Now this may or may not be the particular person that we're that we have in mind, especially depending

04:07.230 --> 04:09.430
on how unique that username is.

04:10.550 --> 04:12.590
And the nice thing is we can see images here.

04:12.590 --> 04:18.670
We can see the ID, we can see the username reputation count zero, reputation neutral.

04:19.150 --> 04:26.910
And we can see an image created on and the time and we can see uh imager, GitHub, Figma, uh, some

04:26.910 --> 04:31.350
Russian telegrams, um accounts, so on and so forth.

04:31.550 --> 04:37.810
And it's always good to go in here and verify the results, because sometimes you will get false positives.

04:38.730 --> 04:39.730
So we click on here.

04:39.730 --> 04:44.410
And yes, it actually does have a human hacker account here on imager.

04:45.410 --> 04:48.890
And that makes sense because it does have a creation date here.

04:50.610 --> 04:53.530
So there's another one here ru.

04:53.570 --> 04:54.450
Yandex ru.

04:54.490 --> 04:59.330
So our Russian site um it community false.

04:59.570 --> 05:00.330
Video channel.

05:00.330 --> 05:00.690
False.

05:00.690 --> 05:01.650
So and so forth.

05:01.650 --> 05:03.810
So you can see there's a lot of great information here.

05:03.810 --> 05:11.810
But again always verify one that the info that the account is actually there because sometimes it,

05:12.290 --> 05:13.450
it might not be.

05:14.090 --> 05:20.370
The second thing is try to verify this is the particular individual or group that you're looking for,

05:20.370 --> 05:26.770
because it may be someone using the same username as the person you're looking for.

05:26.810 --> 05:30.610
But again, uh, great tool to check out.

05:31.330 --> 05:32.130
It's Magritte.

05:32.130 --> 05:34.330
You can find the links on the.

05:36.570 --> 05:37.970
On the description of the video.

05:38.250 --> 05:42.130
So again we have the GitHub version and we have the web version.

05:42.130 --> 05:43.290
Thank you so much for watching.

05:43.290 --> 05:44.410
I'll see you next video.
