Mishaal Khan ๐Ÿ”’

mishaal.us

Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2025-09-26

Upcoming in-person #OSINT Training

Train with the pros! Book it early!

Upcoming in-person OSINT Training schedule
Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2025-09-24

Back to basics. What is an ethical hacker?

Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2025-03-26

๐Ÿ—ฃ๏ธ Need a keynote speaker who doesnโ€™t beat around the bush?

I break down cybersecurity from a hackerโ€™s perspective โ€” the tricks they use, the gaps they exploit, and how to stay ahead. No jargon, no fluff โ€” just real-world stories from 20+ years of experience.

๐Ÿ”น CyberSecurity? AI? Social Engineering? Privacy? OSINT? I make it engaging.
๐Ÿ”น No vague theories โ€” just hard-hitting insights and actionable takeaways.
๐Ÿ”น Audiences leave informed, entertained, and a little paranoid (in a good way).

๐ŸŽฅ Watch my speaker reel below and see why event organizers book me again.

๐ŸŽค Looking for a speaker who cuts through the noise? Letโ€™s talk.

๐Ÿ™๐Ÿฝ Please share with or tag someone that may benefit from my speaking service.

#CyberSecurity #KeynoteSpeaker #Privacy #OSINT #EventSpeaker #Speaker #Training #SecurityAwareness #OSINT

Speaker Demo Reel: youtube.com/watch?v=VwNb9cgS5No

๐Ÿ‘‰๐Ÿฝ Let's schedule some time to talk: MishaalKhan.com/contact

Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2025-01-30

๐Ÿ’ก Private companies like Flock have their cameras everywhere. They read your plate number and store your location history to see where you've been. They sell this access to law enforcement, Home Owner's Association's, Private Detectives, and anyone who can pay their nominal ๐Ÿช™ subscription fee. (think of the abuse: stalkers, psychos, credential hacks,...)

๐Ÿ‘€ While you can't do much, as there's no expectation of privacy on the public roads, you CAN limit their data collection.

๐Ÿš— Change your license plate number every year at renewal with the DMV. It only costs about $20 extra.

Why? It limits your tracking history to just 1 year, making it harder for anyone to compile a detailed profile of your movements over time. You essentially reset your data every year.

โ›”๏ธ Limit Your Digital Footprint.

๐Ÿ˜• Sorry to those folks who have vanity plates, this does not apply to you.

โš ๏ธ This is a slightly extreme measure, but not disruptive to life. Most people will not care about it, unless they are a victim of vehicle tracking. I do it all the time, and it's eye opening ๐Ÿ‘๏ธ to say the least!

You can see a location of cameras by Flock (just 1 out of the many companies) here: deflock.me/ (DeFlock . me)

hashtag#PrivacyTipOfTheDay

Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2024-12-15

@thekileen that's not my website ๐Ÿ˜€ it's OperationPrivacy.com

Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2023-09-17

If you're new to the internet, I don't blame anyone using Google Auth, but PLZ transition to a better MFA app. (I use @bitwarden 's built-in TOTP code generator, you can also use KeePass), so much easier to search thru 1000s of entries.

Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2023-09-06

๐ŸŽคMy upcoming talks for the remainder of 2023. It's been a busy year ๐Ÿซก

Let's catch up if you're in any of these cities.

#CyberSecurityConference #speaker #KeynoteSpeaker #Talks

Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2023-08-29

@BjornToftMadsen good catch! I've been strictly using Privacy.com for all my online purchase for the last 4-5 years to avoid stuff like this. The cc gets tied to only 1 merchant, and I pause the card right after use, unless it's a utility bill, in that case I set an upper limit on purchases.

Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2023-08-27

Great books to donate and swap at @BlueTeamCon
The table was pretty much empty moments after taking this pic!

books at blue team con
Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2023-08-24

DuoLingo "scrape" of 2.6 Million users (email addresses, languages, usernames) sold in forums for $1,500 and advertised as a "breach" and "leak" by media outlets.

For people in the OSINT community, this was already known by inputting an email address and getting back some info from the API. Someone just automated and brute-forced it!

DuoLingo did not take that aspect of privacy into account. Maybe rate limiting the API or authentication could have prevented it?

Maybe a "FREE" ๐Ÿ†“ course from APISec University @apisecu may gave benefited them? (no affiliation to them, I just think it's a great free course, an emerging GAP in #cybersecyrity and here you have a "potential" use case)

Mishaal Khan ๐Ÿ”’ boosted:
nixCraft ๐ŸงnixCraft
2023-08-24

Bill Gates: Every Person on Earth Should โ€˜Prove Their Identityโ€™ with โ€˜Digital IDโ€™ slaynews.com/news/bill-gates-e Microsoft co-founder Bill Gates is calling on nations around the world to adopt his โ€œglobal solutionโ€ for โ€œdigital IDโ€ to ensure that every single person on Earth โ€œproves their identity.โ€ GTFO, Bill Gates.

Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2023-08-24

I got a check in the mail today from Apple for a $14-million class action lawsuit they settled for storing iCloud data in 3rd party storage without informing the users!!! Thank's #Apple for the 32 cents!!! I wonder what the postage cost must be per letter. I'm betting it was more than that ๐Ÿ˜…

"Please cash promptly"๐Ÿ˜…, hmmm I'm thinking about opportunity cost here, is it worth it! ๐Ÿ™„

This makes me think about breach notification costs for sending out snail mail to clients.

Mishaal Khan ๐Ÿ”’ boosted:
2023-08-09

๐Ÿ“ฃ Blue Team Con 2023 Speaker Highlight ๐Ÿ“ฃ

Blue Team Con 2023
25-27 August 2023
Chicago, IL

Mishaal Khan
Talk Title: Smoke and Mirrors: Wasting a hacker's time with misdirection & obscurity

See abstract: blueteamcon.com

Blue Team Con 2023 Speaker - Mishaal Khan
Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2023-08-04

Have you abused out-of-office information in your phishing pentests? I know I have. Hackers probably have as well.
phantomciso.com/The-OOO-Leak/

Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2023-08-02

๐Ÿ—ฃUpcoming In-Person Public Speaking :
- ๐Ÿงข@BlueTeamCon (Chicago, IL) [Aug-26] blueteamcon.com/2023/talk-trac
- ๐Ÿค Texas Cyber Summit [Sept-29] (Austin, TX) texascyber.org/
- ๐Ÿ„Wild West Hackin' Fest [Oct-17] (Deadwood, SD) wildwesthackinfest.com/event/n

Catch me at any one of these to say hi, have my book signed โœ๐Ÿผ ๐Ÿ““ or ask for a free copy, I'll keep a few with me to give away.

@texascyber @Antisy_Training

Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2023-07-28

#OSTIN #SockPuppet ProTip:

This-MP-Does-Not-Exist
is a better alternative to ThisPersonDoesNotExist.com

As it displays a blank background, shoulders included, and the image pose looks professional and ready for a profile pic.

โš ๏ธFor legit purposes only ๐Ÿ˜‰

vole.wtf/this-mp-does-not-exis

Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2023-07-27

#lighthumor ๐Ÿ˜€โ€‹

Only Fans, Old Memories
Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2023-07-25

Join us for our next Anti-Cast, โ€œOSINT Uncovered: Unlocking the Hidden Gems of Online Information,โ€ with Mishaal Khan this Wednesday at 12 p.m. EDT! Register here: zoom.us/webinar/register/WN_UU
Tune in at 11:30 a.m. EDT for some PreShow Banterโ„ข.

This Anti-Cast session explores advanced techniques and tools for extracting valuable information from diverse online platforms, social media, public databases, and breaches. By emphasizing responsible approaches to OSINT, attendees will learn how to navigate vast data sources, analyze digital footprints, and uncover the hidden gems of online information. Learn to harness the power of OSINT, as Mishaal walks you through some quick #OSINT demos. Stalkers not allowed!

Chat with your fellow attendees in the Antisyphon Discord server here: discord.com/invite/antisyphon -- in the #webcasts-livestreams channel

Check out Mishaal's class, "Next Level OSINT," that will be at Wild West Hackin' Fest - Deadwood 2023 for pre-con training! โ†’ wildwesthackinfest.com/event/n

OSINT Uncovered
Mishaal Khan ๐Ÿ”’mishaal@infosec.exchange
2023-07-25

Do you have a :google:โ€‹Google Voice number ๐Ÿ“ฑ and worried about losing it due to 30 days of inactivity? Maybe you have many like me. Here's a simple Google App Script to auto send a reply, triggered by pre-approved numbers. Avoids logging in to the interface and sending an sms to retain the GV number.

Send an sms to your google voice number, you'll get an auto reply. Read why it has to be this way and not email auto responders, and warnings about violating ToS.
#OSINT #Privacy
github.com/0perationPrivacy/Go

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst