Manish Patel

OSINT Security reports Open data

Manish Patel finds what’s left open

OSINT, security reports and a soft spot for open data.

I dig through what the internet shares in public, spot what should not be out there, and report it privately to the people who can fix it.

recon.log example.com
  1. look up example.com in public records
  2. 14 hostnames found in certificate logs
  3. check which ones answer
  4. staging.example.com lists its files
  5. confirm with one harmless request
  6. report sent to the owner, privately
security report
Open directory on a staging hostMedium

example.com · illustrative

  • Found in public data
  • Verified, nothing kept
  • Reported privately
  • Fixed by the owner
  • Write-up published

What I do

Three things, done carefully

OSINT

Open source intelligence: piecing together what is already public to answer a real question. Who runs what, what is exposed, and what someone forgot to switch off.

Security reports

When something is exposed, I verify it, keep only what proves the point, and send the owner a clear private report with the steps to reproduce and fix it.

Open data

I love open data. Public datasets make research honest and repeatable, so I use them, cite them, and share back whatever helps the next person.

How I report

Found something? Here’s the path.

  1. 1

    Find

    Spot it in public data. No logins bypassed, no passwords guessed, nothing broken to get there.

  2. 2

    Verify

    Confirm it is real with the smallest possible check, and keep only the evidence the owner needs.

  3. 3

    Report privately

    A clear note to the owner: what, where, why it matters, and exactly how to fix it.

  4. 4

    Share the lesson

    Once it is fixed, or after a fair wait, publish what others can learn from, with nothing that could hurt anyone.

Ground rules

  • Proof, not exploitation
  • No personal data kept after the report
  • Private first, public later
  • Credit where it is due

Why open data

I open data

Data that anyone can read, check and reuse is how research stays honest. A finding built on open data can be verified by the next person, not just taken on trust.

CheckableAnyone can follow the trail and reach the same answer.
RepeatableRun it again next month and see what changed.
ShareableWhat one person learns, everyone can build on.

Some of the public sources OSINT is built on

  • Certificate transparency logs
  • DNS records
  • WHOIS and RDAP
  • Government open data portals
  • Public code repositories
  • Internet-wide scan data
  • Web archives
  • Company registries

Free tool

Look up any domain

Domains, IP addresses and AS numbers, straight from the registries’ own open data. No sign-up, no ads, 30 free lookups an hour.