📋 Paste Site Intelligence (PASTINT)
Paste Sites and Leaked Text Dumps
Cyber & Threat
Sources
0
0 no-auth
Mission domains
0
reach
Data points
0
covered
Related INT
0
disciplines
🔍 Lookup
📊 Pre-built Queries · Paste Site Intelligence
📜 Playbook — Paste Site Intelligence collection
- Direction — frame the requirement for Paste Site Intelligence: what decision does this support, by when?
- Collection — collect from the 0 mapped sources (0 free) — filter the catalog by PASTINT; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
✨ Enrichment pathways
🎯 Mission
Paste Site Intelligence monitors public text-dump platforms for leaked credentials, source code, configuration files, secret keys, and threat actor chatter as they are posted. It answers what data has leaked, who is dumping it, and which organizations are exposed before the data is weaponized.
📡 Collection methods
- Continuous polling of Pastebin public/recent archives and trending feeds for bulk dumps
- Keyword and regex watchers for owned domains, email patterns, and hostnames across Ghostbin, Rentry, JustPaste.it, dpaste, 0bin and Gist
- Secret extraction from paste bodies (AWS keys, JWTs, private keys, connection strings) via trufflehog/gitleaks regex
- Cross-referencing paste-borne credentials against known breach corpora and HIBP
- Fingerprinting and hashing paste content to detect reposts and track dump lineage
- Tracking poster aliases, contact links, and crypto wallets to cluster pastes to actors
- Monitoring Telegram/Discord channels that announce or mirror paste drops
📚 Key sources & datasets
🎫 Data points produced
🔧 Tools & frameworks
- SpiderFoot
- PSBDMP
- trufflehog
- gitleaks
- Maltego
- IntelX SDK
- theHarvester
- custom regex/YARA
📜 Paste Site Intelligence Tradecraft
- Collect: deploy keyword and secret-format regex watchers across Pastebin, Rentry, Ghostbin, and Gist recent feeds
- Process: normalize and dedupe paste bodies, hash to fingerprint reposts, and extract IOCs and secrets with trufflehog/gitleaks
- Analyze: validate leaked credentials against HIBP and breach corpora, classify each paste as dump, config, or chatter, and scope affected orgs by email domain
- Attribute: pivot on poster alias, contact links, formatting, and reused wallet addresses to cluster pastes to a single actor or crew
- Disseminate: push confirmed exposures as tickets to asset owners and enrich the actor profile with observed paste TTPs
- Act: trigger credential resets, revoke leaked API keys, and file takedown/abuse reports with hosting paste sites
📊 Dashboard KPIs
Pastes ingested/daySecrets extractedCredential-exposure hitsTime-to-detect (leak→alert)Takedowns filed
🔍 Pre-built queries
🔗 Cross-discipline pivots
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron