| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Primerjalna analiza prosto dostopnih osint orodij za potrebe kibernetske varnosti
Authors:ID Oman, Maj (Author)
ID Brezavšček, Alenka (Mentor) More about this mentor... New window
Files:.pdf UN_Oman_Maj_2026.pdf (1,58 MB)
MD5: BADD24429580CC9ECF736853F773562B
 
Language:Slovenian
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FOV - Faculty of Organizational Sciences in Kranj
Abstract:V diplomskem delu smo izvedli primerjalno analizo prosto dostopnih orodij za zbiranje in analiziranje podatkov iz javno dostopnih virov (angl. Open Source Intelligence, v nadaljevanju OSINT) za potrebe kibernetske varnosti. Delo se nanaša na področje začetnih zunanjih varnostnih pregledov, pri katerih organizacija s pasivnim pristopom ugotovi, kateri podatki o njej so javno vidni na internetu. Združili smo pregled literature s praktičnim preizkusom na anonimiziranem primeru izbranega podjetja. Za primerjavo osmih orodij smo določili šest kriterijev z utežmi in petstopenjsko ocenjevalno lestvico. Orodja smo ocenjevali po raznolikosti virov, globini analize, avtomatizaciji, enostavnosti uporabe, dokumentaciji in podpori ter uporabnosti za kibernetsko varnost. Pravno-etično skladnost smo obravnavali kot pogoj izvedbe. Korake smo sproti dokumentirali, ključne rezultate pa shranili v strojno berljivih zapisih (v formatu JSON ali CSV), kar omogoča njihovo nadaljnjo obdelavo. Rezultati so pokazali, da univerzalnega orodja ni. Najboljšo pokritost smo dosegli s kombinacijo orodij: agregator za širši zajem sledi, specializirana indeksnika za pregled izpostavljenih storitev in digitalnih potrdil, napredni iskalni operatorji za preverjanje indeksiranih vsebin ter orodje za vizualizacijo povezav. Na praktičnem primeru smo s to kombinacijo v enem tednu prišli do konkretnih ugotovitev in jih prevedli v izvedljiva priporočila. Na podlagi ugotovitev smo prednostno priporočili zaščito javno objavljenega e-poštnega naslova, utrditev e-poštne politike z mehanizmi za preverjanje izvora pošte ter obvezno večfaktorsko preverjanje pristnosti za ključne račune. Priporočili smo tudi osnovno utrjevanje spletišča in redno vzdrževanje programske opreme. Glavne omejitve naloge izhajajo iz pasivnega pristopa, omejenega časovnega okna in kvot brezplačnih različic orodij.
Keywords:odprti viri informacij, prosto dostopna orodja, primerjalna analiza, kibernetska varnost
Place of publishing:Maribor
Year of publishing:2026
PID:20.500.12556/DKUM-98365 New window
COBISS.SI-ID:286076163 New window
Publication date in DKUM:27.07.2026
Views:258
Downloads:17
Metadata:XML DC-XML DC-RDF
Categories:FOV
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:08.06.2026

Secondary language

Language:English
Title:A comparative analysis of free osint tools for cyber security purposes
Abstract:In this thesis, we carried out a comparative analysis of freely available tools for collecting and analysing data from publicly available sources (Open Source Intelligence, OSINT) for cyber security purposes. The work addresses the area of initial external security assessments, in which an organisation uses a passive approach to determine which data about it are publicly visible on the internet. We combined a literature review with a practical test on an anonymised case of a selected company. To compare eight tools, we defined six weighted criteria and a five-point rating scale. The tools were evaluated according to source diversity, depth of analysis, automation, ease of use, documentation and support, and usefulness for cyber security. Legal and ethical compliance was treated as a precondition for carrying out the work. We documented each step as we went and saved the key results in machine-readable formats (JSON or CSV), which allows their further processing. The results showed that no single, universal tool exists. We achieved the best coverage with a combination of tools: an aggregator for broader gathering of traces, two specialised search engines for reviewing exposed services and digital certificates, advanced search operators for checking indexed content, and a tool for visualising connections. On the practical case, this combination led us to concrete findings within one week, which we translated into actionable recommendations. As a priority, we recommended protecting the publicly published e-mail address, strengthening the e-mail policy with mechanisms for verifying the origin of messages, and mandatory multi-factor authentication for key accounts. We also recommended basic hardening of the website and regular software maintenance. The main limitations of the thesis stem from the passive approach, the limited time window, and the quotas of the free versions of the tools.
Keywords:open-source intelligence, free tools, comparative analysis, cyber security


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica