Buscador Investigative Operating System

Buscador is a Linux Virtual Machine that is pre-configured for online investigators. It was developed by David Westcott and Michael Bazzell, and distributions are maintained on this page. The current build is 3.5GB and includes the following resources (Further Info):

Custom Firefox Install and Add-Ons
Custom Chrome Install and Extensions
Tor Browser
Custom Video Manipulation Utilities
Custom Video Download Utility
Recon-NG
Maltego
Creepy
Metagoofil
MediaInfo
ExifTool
Spiderfoot
Google Earth Pro
EmailHarvester
theHarvester
Wayback Exporter
HTTrack Cloner
Web Snapper
Knock Pages
SubBrute
Twitter Exporter
Tinfoleak
InstaLooter
BleachBit
VeraCrypt
KeePass

Installation Notes

You will need a Virtual Machine application in order to use this system. VirtualBox is free and will suffice for most investigations. Some users prefer a more robust option with VMWare Workstation for Windows or VMWare Fusion for Mac. Any of these options will get you started.

VirtualBox Installation and Configuration:

* Make sure you have latest version of VirtualBox and VirtualBox Extension Pack installed
1) In the VirtualBox menu, click on File > Import Appliance
2) Navigate to the OVA file that was downloaded (Buscador)
3) Choose this file and select "Import"
4) Before starting the new machine, highlight it and choose "Settings"
5) Under General > Basic, rename this machine as desired (Buscador?)
6) Under General > Advanced, change Shared Clipboard to Bi-Directional
7) Under System > Motherboard, increase the RAM if you have ample resoucres (half of total system)
8) Under Display > Screen, increase the Video Memory to 128MB is available
9) Under Storage, click the small "plus" in the lower left corner, "Add Optical Drive", and "Leave Empty"
10) Under Shared Folders, click the "plus" on the right, choose folder to store evidence, select "Auto-Mount"
11) Click "OK" and launch the new machine
12) Upon boot, log into the user "osint" with the password of osint
13) In the VirtualBox Menu, select Devices > "Insert Guest Additions CD Image"
14) Allow the image to be installed, and reboot upon completion.
15) Start the Terminal in the new VM and type sudo adduser osint vboxsf
16) Provide the password as needed (osint)
17) Reboot

You should now have access to the shared directory in order to save data to the host operating system (evidence). It can be found in the File Manager (Home), on the left column, titled "sf_" followed by the name of the folder to which it is connected. This shared folder will also be on your desktop for easy access. You can make the machine full-screen, copy and paste text to and from the image, and you are ready to begin using the applications.

VMWare Installation and Configuration:

1) In the VMWare menu, select File > Import > Select OVA
2) Select the location where the VM will be imported. Click "OK" Click "Retry" if the initial import fails
3) Power on the VM and Login to the OS
4) Install VMware tools as appropriate for your version:

VMWare Fusion: In the menu, select Virtual Machine > Install VMware Tools
VMWare Workstation: In the menu, select VM > Install VMware Tools
VMWare Player: In the menu, select Player > Manage > Install VMware Tools. Note:

5) Open (Double Click) the VMware Tools CD mounted on the desktop
6) Right-click the file that is similar to VMware.xx.tar.gz and click Extract to, and select Desktop
7) Open Terminal (Select 'No' to avoid an update) and type cd Desktop/vmware-tools-distrib
8) Type sudo ./vmware-install.pl and enter password (osint).
9) Type Y when prompted about downloading from the Linux repository
10) Accept all default values by striking the enter/return key at every prompt.
11) Reboot the VM
12) Enable Shared Folders from the file menu: Settings > Options > Shared Folders (Always Enabled)
13) Add a Shared Folder by selecting the desired folder on the host OS
14) Create a shortcut to the shared folder on the desktop with the following command in the terminal:
ln -s /mnt/hgfs/foldername /home/osint/Desktop/Shared_Folder

Usage Notes

A great feature of virtual machines is the use of Snapshots. These "frozen" moments in time allow you to revert to an original configuration or preserve an optimal setup. Most users install the virtual machine as detailed above, and then immediately create a snapshot of the unused environment. When your virtual machine eventually becomes contaminated with remnants of other investigations, or you accidentally remove or break a feature, you can simply revert to the previously created snapshot and eliminate the need to ever re-install.

VirtualBox use of Snapshots

1) Completely shut down the Virtual Machine
2) In the VirtualBox Menu, click on the Snapshots button in the upper right
3) Click on the blue camera icon to "take a snapshot"
4) Create a name and any notes to remind you of the state of the machine, such as "New Install"
5) Click OK

You can now use your virtual machine as normal. If you ever want to revert to the exact state of the machine that existed at the time of the snapshot, follow these instructions:

1) Completely shut down the Virtual Machine
2) In the VirtualBox Menu, click on the Snapshots button in the upper right
3) Select the desired snapshot to apply
4) Click on the blue camera icon with arrow to "restore snapshot"
5) Click Restore

Optionally, if you ever want to remove a snapshot, simply use the icon with a red X. This will remove data files to eliminate wasted space, but you cannot restore to that image once removed. It will not impact the current machine state. Many users remove old, redundant snapshots after creating newer clean machines.

VMWare Use of Snapshots (VMWare Workstation or Fusion, NOT Player)

1) Completely shut down the Virtual Machine
2) In the VMWare Menu, click on the Snapshots button in the upper right
3) Click on the camera icon to "take" a snapshot
4) Create a name and any notes to remind you of the state of the machine, such as "New Install"
5) Click Take

You can now use your virtual machine as normal. If you ever want to revert to the exact state of the machine that existed at the time of the snapshot, follow these instructions:

1) Completely shut down the Virtual Machine
2) In the VMWare Menu, click on the Snapshots button in the upper right
3) Select the desired snapshot to apply
4) Click on the camera icon with arrow to "restore" a snapshot
5) Click Restore

Optionally, if you ever want to remove a snapshot, simply use the "delete" icon. This will remove data files to eliminate wasted space, but you cannot restore to that image once removed. It will not impact the current machine state. Many users remove old, redundant snapshots after creating newer clean machines.

It is suggested to enable VMware autoprotect snapshots, set to daily, and limit the snapshot count to 3. Autoprotect snapshots are an easy way to always have a snapshot to revert to. The following steps will enable this feature.

1) Select the virtual machine and select VM > Settings
2) On the Options tab, select AutoProtect and select Enable AutoProtect
3) Select the "Daily" interval between snapshots
4) Select the maximum number of AutoProtect snapshots to retain (Recommended "3")
5 Select OK to save your changes

After the maximum number of AutoProtect snapshots is reached, Workstation deletes the oldest AutoProtect snapshot each time a new AutoProtect snapshot is taken. This setting does not affect the number of manual snapshots that you can take and keep.

Yubikey Notes

You can use a Yubikey as a second factor for login from your VirtualBox image.

In the Terminal, copy/paste each line and click Enter:

    wget "https://raw.githubusercontent.com/Yubico/yubikey-personalization/master/69-yubikey.rules" -O /tmp/69-yubikey.rules
    wget "https://raw.githubusercontent.com/Yubico/yubikey-personalization/master/70-yubikey.rules" -O /tmp/70-yubikey.rules
    sudo mv /tmp/69-yubikey.rules /etc/udev/rules.d/69-yubikey.rules
    sudo mv /tmp/70-yubikey.rules /etc/udev/rules.d/70-yubikey.rules           

Shut Buscador down completely
Insert Yubikey into computer
VirtualBox > Settings > Ports > USB > Click Icon with green "+”, select Yubikey, click OK
Remove Yubikey
Start Virtual Machine, boot completely into Buscador
Insert Yubikey
Attach Yubikey in VirtualBox > Device > USB . Yubikey
In the Terminal, type:
wget "https://raw.githubusercontent.com/beast-fighter/saves_the_day/master/activate_yubikey.sh"
chmod +x activate_yubikey.sh
./activate_yubikey.sh
When prompted, press Enter
When prompted to “Commit”, type y and hit Enter
Shut down Buscador completely
Remove Yubikey
Restart system, try to login with Yubikey (Fail)
Insert Yubikey, Login (Success) You may need to try password twice

USB Live Boot (Unstable, testing only)

Every online investigation computer should have a selection of removable operating systems ready to boot at any time. While optical media such as compact discs could be used to boot a computer, creating bootable USB devices is the easiest and most robust solution. The general premise of this method is to create a USB drive that can be used to boot an entire operating system from itself. After completing these instructions, you will have a USB drive the size of a quarter that possesses its own operating system, custom browser, investigation extensions, and Android emulator. Insert it into practically any computer and receive a fast and secure solution to online investigations.

Requirements:

A computer capable of booting to USB. This can be Windows or Mac OS X hardware (Macs are preferred), and most computers made in the past 10 years will work. You may need to hold down a specific key on your keyboard while booting to force the machne to boot to the USB drive. On Apple computers, it is the Alt/Option key. On many Windows machines it is a function key such as F2, ESC, or DEL.

A small USB 3.0 drive. I prefer the Sandisk Utra Fit 16GB drive (LINK). You will also need a USB 3.0 port on your computer. Windows ports are often blue in color while Apple ports are not. This WILL work on older ports, but may be too slow to be useful.

A micro USB Wi-Fi adapter (Link). While you may already have native network access, the new operating system may not recognize your drivers. This $10 piece of hardware ensures a working system without configuration.

The Buscador Linux operating system (ISO LINK). User name and password is osint.

Windows Users: A program called Rufus (LINK).

Mac Users: A program called UNetBootin (LINK).

Instructions:

1) Insert your desired USB drive that will be overwritten.
2) Execute the Rufus program and choose your USB drive.
3) Choose a partition scheme of “MBR … for BIOS or UEFI Computers”.
4) Click the button similar to a CD and choose the appropriate ISO file that you downloaded.
5) Click “Start” and allow the process to complete.
6) Reboot the computer and select the USB drive upon boot sequence.



Download v.1.1

VMWare:

Download: V 1.1 07/05/17
Checksum (MD5):
0e4a4d1a2c731fa2d3f7a24dde99460b

This is an OVA file that should work in any version of VMWare, including Workstation, Fusion, and Player.

VirtualBox:

Download: V 1.1 07/05/17
Checksum (MD5):
52bd85e7037c7523f85728761039d1ae

This is an OVA file that should work in any version of VirtualBox, including Windows, Mac, and Linux.

ISO:

Download: V 1.1 07/05/17
Checksum (MD5):
255fdf5e562d25a9ccccad97d5a83473

This ISO can be used to create USB boot devices or as a host operating system. This option is not supported, but several have had success with it.

Change Log:

Version 1.1

Updated Operating System
Updated Firefox and Extensions
Updated Chrome and Extensions
Updated Tor Browser
Updated Video Download
Updated Recon-NG
Added InstaLooter
Added EmailHarvester
Added SpiderFoot
Added Google Earth Pro
Added RipGrep
Added Tor/Privoxy
Repaired Video Utilities Script
Repaired Metagoofil Script
Updated all script dialogues

Support & Updates

While we do not offer technical support for Buscador, the IntelTechniques forums has a dedicated discussion group about usage of the system. Please post any questions there. All updates since the latest release will be posted there.

If you would like further instruction, the IntelTechniques Video Training Course has a dedicated section that will focus exclusively on the setup and usage of Buscador.

Video Training

You can order our online OSINT video training package with any credit card right now and receive immediate access to the entire training! Click below to order today.

 

Contact Us to order by check or money order.

OSINT Search Guide

The Fifth Edition of my book on internet search techniques is now available. Click the book below for details.

OSINT Challenges

David Westcott is putting together new OSINT challenges to test your skills. Check them out HERE.

Updated Scripts

Coming Soon

Optional Installs

Datasploit

VKMetaDate