Google Dorking for Trace Labs: 50 OSINT Investigation Pivots
OSINT field guides
- Google Dorking for OSINT: The Practical Investigator's Guide
- Google Dorking for Trace Labs: 50 OSINT Investigation Pivots (this article)
- Social Media OSINT: From One Profile to a Digital Footprint
- OSINT Corroboration: How Do I Know I've Found the Right Person?
My Google Dorking for OSINT guide covers what the operators actually do: site:, filetype:, exclusions, date filters, all of it. This page assumes you already know that, and exists for the moment those operators are supposed to solve. You've found something, a name, a username, an email, a phone number typed out in a screenshot, and you need to know what to do with it right now, mid-investigation, before the lead goes cold.
Every confirmed piece of information is a potential pivot. An investigation isn't a straight line from person to Google to answer. It's a small network of people, usernames, emails, phone numbers, addresses, employers, schools, relatives, clubs and documents, and most of the work is finding and verifying the relationships between them. The question worth asking on every single result is: what else could this tell me?
Last verified against current Google search behaviour: September 2026.
$ ./pivot.sh --input "IDENTIFIER"
Found something? Do this.
- Search it exactly. Quote it, don't paraphrase it.
"IDENTIFIER" - Add context. A location, employer or year cuts out most of the noise.
"IDENTIFIER" LOCATION - Exclude where you found it. See where else it turns up.
"IDENTIFIER" -site:SOURCE.com - Combine it with another identifier. Two independent clues together are far stronger than either alone.
"IDENTIFIER A" "IDENTIFIER B" - Search historically. Check what existed before today.
"IDENTIFIER" before:2020-01-01 - Pivot to associated people or organisations. Nobody exists in isolation online, so look at who and what surrounds this identifier.
- Record it, corroborate it, then repeat. Add it to your identifier board with a confidence level before you move on.
visitor@thefish.nz:~$ cat pivots.txt
Sections
Start here
The pivot mindset
Don't think of an investigation as person → Google → answer. Think of it as a small network: people, usernames, emails, phone numbers, addresses, employers, schools, relatives, associates, clubs, hobbies, events, documents and old accounts, all connected to each other. Most of what you're actually doing, moment to moment, is finding an edge between two nodes you already have, then using that edge to reach the next node.
Practically, that means every result deserves the same question before you move on to the next search: what else could this tell me? A LinkedIn profile isn't just confirmation of an employer. It's a job title, a list of colleagues, a location, sometimes a university. A single Facebook comment isn't background noise. It's a name, a relationship, a shared event, occasionally a second account.
For the operator mechanics behind any query pattern below (what site:, filetype:, exclusions, OR or date filters actually do), see the Google Dorking for OSINT guide. This page assumes that part is covered and is built entirely around the next decision: what to do with what you've just found.
Identifier board
Keep a running record of everything you've found, what you believe it means, and how confident you are in it. A spreadsheet, a notes doc, a whiteboard: the format doesn't matter. What matters is writing it down before you pivot again, because four hours into a Trace Labs case you will not remember which of three candidate usernames was the one with the matching profile photo.
A worked example, using a fictional case:
| Field | Value | Confidence | Source / evidence |
|---|---|---|---|
| Full name | John Smith | CONFIRMED | Named in a public missing-persons appeal |
| Nickname | Johnny | PROBABLE | Used by family in Facebook comments |
| Current location | Auckland | CONFIRMED | Stated in the appeal |
| Previous location | Hamilton | POSSIBLE | Mentioned in an old forum post, unverified |
| Username | johnsmith82 | POSSIBLE | Same profile photo as confirmed Facebook account, not yet corroborated |
| j.smith82@example.com | POSSIBLE | Found in a forum export, unverified | |
| Employer | Example Ltd | PROBABLE | LinkedIn profile matching name and location |
| Relative | Jane Smith (mother) | CONFIRMED | Tagged in family photos, named in the public appeal |
| Vehicle | White Toyota Hilux | POSSIBLE | Mentioned once by an associate, unverified |
Fields worth tracking: full name, middle name, nicknames, DOB or approximate age, current location, previous locations, username(s), email(s), phone(s), current address, previous address, employer, previous employer, school or university, relative(s), associate(s), club or team, hobby, vehicle, website or domain, and any other distinctive clue.
Watch out
A username or photo match alone is never identity confirmation. People reuse profile photos, usernames get recycled by different people over the years, and stock photos exist. Treat a single-source match as POSSIBLE until something independent moves it up, such as a second platform, a named relative, or a detail only the real person would have.
The three-query rule
This isn't an OSINT law. It's a habit to stop you overlooking the obvious the moment you're under time pressure. Whenever you find a new identifier, of any kind, run it through three queries before moving on.
1: Exact
"johnsmith82"
2: Context
"johnsmith82" Auckland
3: Exclude the source
"johnsmith82" -site:instagram.com
That third step matters more than it looks. If you found the username on Instagram, excluding instagram.com clears away the platform you already know about and shows you everywhere else it appears, which is usually where the actual pivot is hiding.
The two-identifier rule
One identifier generates candidates. Two independent identifiers, searched together, help you tell which candidate is actually your target. That's a meaningfully different kind of search from anything in the three-query rule above.
"John Smith" Auckland
"John Smith" "Example Ltd"
"John Smith" "johnsmith82"
"John Smith" "0211234567"
"johnsmith82" "john@example.com"
Correlation isn't proof by itself. Two things appearing on the same page can be coincidence, especially with a common name. Treat a two-identifier match as a strong lead, then look for a second, independent source before moving it to CONFIRMED.
Confidence levels
| Level | What it means |
|---|---|
| CONFIRMED | Multiple independent pieces of evidence establish the relationship. |
| PROBABLE | Several clues strongly support it, but it isn't conclusive yet. |
| POSSIBLE | An interesting lead that needs more corroboration before you rely on it. |
| REJECTED | Evidence shows the candidate probably isn't the target. Worth recording so you don't re-investigate it later. |
This doesn't need to be formal. The point is to stop tunnel vision: it's very easy, four hours into a case, to start treating a POSSIBLE from hour one as though it was always CONFIRMED. Write the level down next to the evidence, and downgrade things the moment new evidence contradicts them.
Scope and ethics
This guide is about finding, connecting and corroborating information that's already public, not about getting access to information that isn't. A few boundaries worth keeping explicit, especially in a time-pressured Trace Labs environment where the instinct is to chase every lead as far as it'll go:
- This covers publicly available information. Don't attempt to access private accounts, bypass authentication, guess or use passwords, or otherwise get into something that isn't public.
- Don't contact targets, relatives or associates directly, deceptively or otherwise, as part of a pivot. That's outside the scope of open-source research and outside Trace Labs' rules.
- Finding a piece of information doesn't authorise using it beyond the investigation's actual purpose. Corroborate and record it; don't redistribute more than the case requires.
- Stay inside whatever rules and scope apply, whether that's a CTF's rules of engagement or your organisation's policy for a real case.
If you're taking part in Trace Labs specifically, check their current official rules and code of conduct before an event rather than relying on this or any other blog post. Competition structure and permitted techniques get updated between events.
Person
Starting point: a name. These are the fourteen directions I check before I consider a name search exhausted.
Pivot 1: Name variations
Run the full name, then the obvious variants: shortened first name, full legal first name, common nickname pairs (Jon/John/Jonathan, Liz/Elizabeth), and the name including a middle name or initial.
"Jon Smith" OR "John Smith" OR "Jonathan Smith"
Pivot 2: Name + location
The single highest-value piece of context for a common name.
"John Smith" Auckland
Pivot 3: Name + employer
"John Smith" "Example Ltd"
Confirms employment and often surfaces a staff page, press mention or LinkedIn profile you hadn't found yet.
Pivot 4: Name + school or university
"John Smith" "Auckland Grammar" OR "University of Auckland"
Alumni pages, old yearbooks and reunion event listings are frequently indexed and rarely locked down.
Pivot 5: Name + relative
"John Smith" "Jane Smith"
Pivot
A relative's public footprint is very often larger and less guarded than the target's. See sideways pivoting below. Sometimes the fastest route to your target is through someone else entirely.
Pivot 6: Name + associate
"John Smith" "Mike Jones"
Two names appearing together repeatedly across otherwise unrelated pages, such as a comment thread, a tagged photo or a team roster, is a real signal worth following up.
Pivot 7: Name + hobby or interest
"John Smith" "mountain biking" OR "rugby"
Hobbies lead to clubs, and clubs lead to member lists and event photos. See Associates & events.
Pivot 8: Name + club or team
"John Smith" "Ponsonby Rugby Club"
Pivot 9: Name + vehicle
"John Smith" "Toyota Hilux"
Vehicle mentions turn up in marketplace listings, car and motorbike club forums (prolifically documented communities), and local Facebook groups.
Pivot 10: Name + life event
"John Smith" "wedding" OR "obituary" OR "funeral"
Trace labs tip
Death, wedding and birth notices are some of the most reliably information-dense pages on the web for family relationships. They exist specifically to list names, relationships and locations. Local newspaper sites are usually well indexed.
Pivot 11: Name + document
"John Smith" filetype:pdf
See Documents below for what to actually extract once you've found one.
Pivot 12: Name + platform
site:linkedin.com/in "John Smith" Auckland
Run this once per platform that matters for the case. See the social platforms playbook in the operator guide for the full list.
Pivot 13: Name, searched historically
"John Smith" before:2015
Surfaces an earlier version of someone's online presence: a previous employer, an old username, a different city. See Search backwards.
Pivot 14: Exhausted the name? Pivot to an identifier
Once name variations, location and context stop producing anything new, stop searching the name and start searching whatever identifiers it's already produced: a username, an email, a phone number, an address. Those are usually far more specific than a name, and specificity is what breaks a stalled search.
An email address is one of the strongest identifiers available, because unlike a name it's usually unique to one person.
Pivot 15: Exact email
"john.smith@example.com"
Pivot 16: Local-part only
"john.smith82"
Drop the domain and search the part before the @ on its own. People frequently reuse the same local part as a username on other services, under a different domain entirely.
Pivot 17: Domain
"@example.com"
Pivot
Searching the bare domain can reveal who else uses it, which is often the fastest way to confirm an employer or organisation you only had a guess about.
Pivot 18: Exclude the source
"john.smith@example.com" -site:example.com
Removes the domain's own site from the results so you can see everywhere else the address has been used or mentioned: forum sign-ups, document indexes, old registrations.
Username
Usernames are the identifier most likely to be reused, unedited, across completely unrelated platforms, which makes them one of the best pivots available.
Pivot 19: Exact username
"johnsmith82"
Pivot 20: Username variations
"johnsmith82" OR "johnsmith_82" OR "john.smith.82"
Watch out
A shared username doesn't guarantee a shared person. Common patterns, such as a name plus a birth year, get reused independently by different people. Corroborate with a second identifier before treating two accounts as the same person.
Pivot 21: Platform sweep
site:reddit.com "johnsmith82"
Repeat with each platform that's plausible for the case. See the social platforms list in the operator guide.
Pivot 22: Exclude the platform you found it on
"johnsmith82" -site:instagram.com
Pivot 23: Username + real name or email
"johnsmith82" "John Smith"
"johnsmith82" "john@example.com"
Pivot 24: Username + location
"johnsmith82" Auckland
Pivot 25: Hand it to a dedicated tool
Google indexes a small and inconsistent slice of any platform's usernames. For genuine cross-platform username enumeration, a purpose-built tool will outperform Google every time.
Trace labs tip
WhatsMyName checks a username against several hundred sites in one pass. Use it to generate candidates fast, then bring the results back here and run the three-query rule on whichever ones look real.
Phone
Pivot 26: Every formatting variant
Phrase matching is exact, so a missing space is enough to miss a result. Search every plausible format.
"021 123 4567"
"0211234567"
"+64 21 123 4567"
"+64211234567"
Pivot 27: Phone + name
"021 123 4567" "John Smith"
Pivot 28: Phone + organisation
"021 123 4567" "Example Ltd"
Business directories, contact pages and old cached staff lists often pair a direct-dial number with both a name and an employer on the same page.
Pivot 29: Area code context
An area code narrows a landline number to a region even before you've found anything else, useful for corroborating or ruling out a candidate's claimed location.
Pivot 30: Marketplace and classifieds reuse
"021 123 4567" site:trademe.co.nz
Trace labs tip
People list a personal mobile number on marketplace and classifieds sites far more casually than anywhere else, and those listings often carry a full name alongside it. Worth checking even when the case has nothing to do with buying or selling anything.
Address
Pivot 31: Exact and abbreviated forms
"12 Queen Street, Auckland"
"12 Queen St" Auckland
Search both forms as separate exact phrases. Google won't normalise Street/St for you.
Pivot 32: Address + surname
"12 Queen Street" "Smith"
Surfaces other people associated with the same address, useful for finding relatives or flatmates.
Pivot 33: Address + organisation
"12 Queen Street" "Example Ltd"
Confirms a registered business address, or catches an organisation operating out of what looks like a residential one.
Pivot 34: Property and real-estate listings
Property-value and real-estate sites frequently carry historical sale and rental listings tied to an address, sometimes with agent contact details or a previous occupant's name in older cached pages.
Watch out
Property listing data is often stale. Ownership and occupancy change and the listing doesn't. Treat an address match as historical unless you can confirm it's current. Government property and company registries are also frequently sitting behind a search form rather than a crawlable page, so don't assume Google has indexed them at all. Check the register directly instead.
Employment & organisations
Pivot 35: Staff and directory pages
site:example.com "our team" OR "staff"
Pivot 36: Organisational documents
"Example Ltd" filetype:pdf "directors" OR "annual report"
Company filings, board minutes and annual reports frequently name directors, addresses and contact details that never appear on the company's own website. For confirmed NZ company registration and director information, the Companies Office register is the authoritative source. It sits behind a search form rather than being crawled by Google, so check it directly rather than dorking for it.
Pivot 37: Previous employers via reused biography text
"has spent the last decade helping" "Example Ltd"
See Text & historical footprints. A bio paragraph copied from an old CV into a new profile is one of the more reliable ways to trace someone's employment history.
Documents
Pivot 38: Broaden the format
Don't stop at PDF. Different organisations default to different formats.
"John Smith" filetype:pdf
"John Smith" filetype:doc OR filetype:docx OR filetype:xlsx
Pivot 39: Extract everything, not just the name
Pivot
A document isn't the end of a search. It's a source of several new identifiers. Once you've found one, go back through it and pull out: full and middle names, job titles, email addresses, phone numbers, organisation names, associates named alongside your target, dates, locations, usernames, event names, the document's own title, and any distinctive phrase worth searching on its own. Feed every one of those back into a new search. Search → extract → corroborate → pivot is the whole loop, and documents are usually where it produces the most in a single step.
Pivot 40: Check the document's own metadata
Right-click → Properties (or the file-info panel in a PDF viewer) sometimes shows an author name in the file's metadata that never appears in the visible text, occasionally the real name behind an otherwise anonymous upload.
Watch out
Document metadata is frequently wrong or generic: a shared department account, a template's default author, or whoever set up the laptop. Treat it as a lead to check, not a confirmed identity.
Text & historical footprints
Pivot 41: Distinctive sentence search
"passionate about restoring classic Japanese motorcycles"
People and organisations reuse text constantly: a bio pasted into three different profiles, a conference blurb, an old forum introduction. The more specific and oddly-phrased the sentence, the more it behaves like a fingerprint rather than a generic search term.
Pivot 42: Trace a bio backward through employers
"has over 10 years of experience in" "Example Ltd"
The same paragraph, reused on a newer profile with a different employer's name swapped in, is one of the more reliable ways to build an employment timeline.
Pivot 43: Date-bracketed historical search
"John Smith" after:2010 before:2015
The full technique, and an important caveat about what Google's date actually reflects, is covered in Timeline and historical searching in the operator guide. Short version: it's an index date, not a confirmed publish date. Treat it as a lead, not a fact.
Pivot 44: Old username to current identity
"johnsmith82" 2012
Corroborate
An old, abandoned account is often less guarded than a current one: old bios, old employer mentions, old real names in "about me" sections. Once you find one, use it as a bridge: search the old username against the identifiers you've already confirmed for the current identity, and look for the same relatives, location or employer showing up on both sides.
Associates & events
Pivot 45: Relatives
"Smith" "12 Queen Street"
Shared surname plus shared address is one of the fastest ways to surface a parent, sibling or partner.
Pivot 46: Associates
"John Smith" "Mike Jones"
Comments from friends and family tend to leak far more than a target's own posts: nicknames, relationships, inside jokes that turn out to be real details, tagged locations. Reading comments carefully is consistently one of the highest-value techniques in a time-boxed investigation.
Pivot 47: Events
"John Smith" "wedding" OR "reunion" OR "conference"
Weddings, reunions, sports fixtures and conferences are documented by people other than your target: organisers, photographers, other attendees. So the record of them often survives even when the target's own accounts are locked down or deleted.
Pivot 48: Clubs and communities
"John Smith" "Ponsonby Rugby Club" newsletter
Club newsletters, AGM minutes and membership lists are exactly the kind of low-attention-to-security document that ends up as a PDF on a club website with full names, sometimes addresses and phone numbers, never intended as a people-search tool.
Advanced pivoting
Pivot 49: Sideways pivoting
Repeatedly searching your target isn't always productive. Sometimes someone else's larger, less guarded public footprint is what actually gets you there.
TARGET ↓ RELATIVE ↓ ADDRESS ↓ EMPLOYER ↓ ASSOCIATE ↓ USERNAME ↓ TARGET
Watch out
Association is a lead, not a fact about the target. Finding your target's name next to someone else's doesn't establish anything about the target directly. It only tells you where to look next. Keep it on the identifier board as PROBABLE or POSSIBLE until you have independent evidence about the target specifically.
Pivot 50: Association searching
This is the strongest single technique in this guide, and it comes from a shift in the question you're asking. Instead of "what can I find about John?", ask: can I establish a relationship between these two independently discovered identifiers?
"John Smith" "johnsmith82"
"John Smith" "john@example.com"
"John Smith" "021 123 4567"
"John Smith" "12 Queen Street"
"John Smith" "Example Ltd"
"John Smith" "Jane Smith"
"johnsmith82" "john@example.com"
"johnsmith82" Auckland
"john@example.com" "021 123 4567"
"12 Queen Street" "Smith"
Corroborate
Two identifiers appearing together repeatedly, across otherwise unrelated pages, is a genuinely strong signal, but it's still correlation, not automatic proof. Look for a third, independent source before moving anything from PROBABLE to CONFIRMED. For the underlying concept, people, usernames, emails, phones, addresses and organisations as a network of nodes and edges, see Association searching in the operator guide.
When you're stuck
Pivot matrix
Find whatever you've got in the left column, and work down the right column until something produces a new identifier.
| I have | Pivot to |
|---|---|
| Name | location, employer, usernames, relatives, school, hobbies, documents |
| Username | platforms, real name, email, location, other usernames |
| username, domain, name, documents, other appearances | |
| Phone | name, address, organisation |
| Address | people, surname, phone, organisations |
| Employer | staff, documents, previous employees, contact information |
| School | alumni, newsletters, sports, events |
| Relative | target, addresses, locations, associates |
| Hobby | clubs, events, usernames, communities |
| Club | members, newsletters, events, photographs |
| Document | people, emails, usernames, organisations, dates |
| Social profile | username, biography text, associates, locations |
| Old identity | newer identity |
| Location | people, organisations, events, associates |
Search sideways
Covered above as Pivot 49. When repeated searches of the target produce nothing new, pivot through someone else's public footprint instead.
Search backwards (historically)
CURRENT IDENTITY ↓ OLD EMPLOYER ↓ OLD BIOGRAPHY ↓ OLD USERNAME ↓ OLD ACCOUNT ↓ ASSOCIATES / LOCATION ↓ CURRENT IDENTITY
Older footprints are frequently less guarded than current ones: privacy settings tightened later, an account abandoned rather than deleted, a bio nobody thought to update. See Pivot 43 and Pivot 44 above, and the full technique in Timeline and historical searching.
Search outside Google
A dead end in Google isn't necessarily a dead end on the internet. It's a dead end in one company's index. Bing, Brave Search, DuckDuckGo and, particularly for Russian-language or Eastern European content, Yandex all maintain independent indexes and can turn up material Google hasn't crawled or has since dropped. Take your confirmed identifiers with you and run the same exact-phrase searches again. This isn't a tutorial on those engines' own operators (see Search-engine hopping in the operator guide for that). The point here is simply: don't stop at one index.
The investigation loop
START ↓ What do I know? ↓ Choose the strongest identifier ↓ Search it exactly ↓ Add context ↓ Exclude the known source ↓ New identifier?
If yes:
Record it ↓ Corroborate it ↓ Add it to the identifier board ↓ Pivot again
If no:
Combine known identifiers ↓ Search historically ↓ Search associates ↓ Search documents ↓ Search other engines ↓ Reassess assumptions
60-second stuck checklist
Before you decide a lead is genuinely dead, run down this list. It takes less time than it looks.
A note on Trace Labs
This guide is written to be useful for Trace Labs OSINT Search Party CTFs, but it's deliberately not tied to any specific competition rule, scoring category or permitted-technique list, because those details are set and updated by Trace Labs itself between events. If you're relying on anything about what's in or out of scope, current scoring, or submission requirements, check Trace Labs' own current rules and code of conduct directly rather than this or any other third-party post. That's the only place guaranteed to be current.
What doesn't change between events is the underlying skill this guide is built around: recognising a pivot, corroborating it, and knowing when to stop and record rather than push further. I wrote a bit more about how that actually played out for me in practice in my first Trace Labs write-up.
Further reading
- Google Dorking for OSINT: The Practical Investigator's Guide: the operator reference this page assumes you know
- Trace Labs: official rules, code of conduct and event schedule
- WhatsMyName: cross-platform username enumeration
- My Trace Labs Search Party CTF 2026 write-up