Counter-OSINT Self-Audit
2026 Expansion41.1 Verified Tools
| Tool | URL | Function |
|---|---|---|
| Have I Been Pwned | https://haveibeenpwned.com | Free personal breach check (1018+ sites) |
| DeHashed | https://dehashed.com | Deep-web scans (freemium) |
| Intelligence X | https://intelx.io | Dark web + breaches |
| JustDeleteMe | https://justdeleteme.xyz | Direct deletion links for 500+ services |
| JustGetMyData | https://justgetmydata.com | GDPR data request links |
| Hudson Rock | https://www.hudsonrock.com/threat-intelligence-cybercrime-tools | Infostealer free lookup |
41.2 Self-Doxxing Audit Workflow — 6 Steps
- Initial self-audit: search your email, username, real name in HIBP + DeHashed + IntelX + Google (
"your name" filetype:pdf). - Identify forgotten accounts via JustDeleteMe — list of services where you ever registered.
- Request personal data download via JustGetMyData (GDPR gives right to data export in 30 days).
- Delete unnecessary accounts with priority: old social networks, abandoned forums, duplicate services.
- Rotate compromised passwords with a password manager (Bitwarden, 1Password, KeePassXC).
- Document your own footprint BEFORE starting a sensitive investigation — knowing your exposure prevents surprises.
41.3 Per-Service Privacy
- Google Account: Activity Controls (disable Web & App Activity, Location History, YouTube History).
- Facebook: review privacy settings, download data, disable facial recognition.
- LinkedIn: review profile visibility, hide connections if you investigate sectors where your network may be a signal.
- Telegram: use a virtual number, not your main one. Enable 2FA.
- WhatsApp: review profile photo visibility, last connection, status. For investigations: secondary account with virtual number.