OSINT tools FAQOSINT 工具 FAQ
Frequently asked questions常见问题
What problem does OSINTStack solve?OSINTStack 解决什么问题?
It helps defensive users choose a tool, run a small authorized first task, avoid unsafe use, and jump to official sources instead of opening ten unrelated tabs.它帮助防御型用户选择工具、完成一个小范围授权任务、避开不安全用法,并快速跳转官方来源,而不是打开十几个无关页面。
Is this an official SpiderFoot site?这是 SpiderFoot 官方网站吗?
No. OSINTStack is an independent field guide that links to official sources and avoids republishing protected docs or datasets.不是。OSINTStack 是独立资料站,会链接官方来源,不转载受保护文档或数据集。
Which tool should a beginner start with?新手应该先用哪个工具?
Start with the job. For a small owned-domain inventory, use passive lookup first, then a narrow SpiderFoot run. For quick domain/email discovery, theHarvester is lighter.先看任务。小范围自有域名盘点先做被动查询,再做窄范围 SpiderFoot;快速域名/邮箱发现可以先用 theHarvester。
Can I scan third-party systems?可以扫描第三方系统吗?
Do not scan systems you do not own or have explicit permission to test. When in doubt, use passive lookups or ask for written authorization first.不要扫描你不拥有或未明确授权测试的系统。不确定时,只做被动查询,或先取得书面授权。
Why does the site avoid exploit steps?为什么本站不写利用步骤?
The site is for authorized OSINT and defensive inventory. Exploitation, credential collection and bypass guidance are outside the site boundary.本站面向授权 OSINT 和防御性盘点。漏洞利用、凭据收集和绕过指导不在本站边界内。