Advanced OSINT Search Dork Builder
Zero-Trust Utilities
OSINT Dorking cheat sheet
- site: limits searches to a single domain name or suffix (e.g.
site:gov). - filetype: finds specific file formats (e.g.
filetype:pdforfiletype:xls). - inurl: filters results based on keywords located in the URL path.
- intitle: searches for exact text in the page headers (e.g.
intitle:"Index of").
What is Advanced OSINT Search Dork Builder?
How it works
Features & Benefits
- 100% Private: Search targets and keywords never leave your browser; no queries are logged
- Visual Query Builder: Create complex dorks for document leaks, credentials, backups, and directory lists
- Multi-Engine Support: Generates queries for Google, Twitter/X, and historical archives (Wayback Machine)
- Direct Execution: Copy search parameters with one click or execute them immediately in a new tab
Frequently Asked Questions
What is Google Dorking?
Google Dorking (or Google Hacking) involves using advanced search operators to find security vulnerabilities, exposed files, or hidden configuration data indexed by Google.
Does this tool search Google for me?
No. The tool constructs the query string. You can copy it or click 'Open Search' to execute it yourself in a new tab.
Are my search keywords private?
Yes. They are processed entirely locally in your browser. No queries or search parameters are sent to Utilora's servers.
Related Tools
Analyze DNS records (MX, SPF, DMARC, TXT) to identify email spoofing risks and domain security configurations privately in your browser.
Scan for active subdomains entirely in your browser using secure DNS-over-HTTPS. Protect your investigation targets from logging.
Popular Utilities
Format, validate, and minify JSON instantly in your browser. Your data never leaves your device.
Decode JWT tokens and inspect header and payload instantly in your browser. Your tokens never leave your device.
Count words, characters, sentences, and estimate reading time instantly in your browser. No sign-up required.
Learn More & Guides
Real DNS From a Browser Tab: DoH, CORS, and What You Genuinely Cannot Scan
A browser can resolve real DNS records, brute-force subdomains, and audit mail security without a server. It cannot scan a port. Here is exactly where the line sits, and why.
5 min readUsername Sweeps and the Rate-Limit Trap
Checking one handle across eight platforms is easy. The bug worth avoiding is treating every failed request as proof the account does not exist, which is how OSINT tools quietly lie to you.
5 min readSPF, DMARC, and the Grades Nobody Checks
A domain with an SPF record can be completely unprotected against spoofing. Two records is worse than one. And p=none, the most common DMARC policy in the wild, blocks nothing at all.
5 min readWhat Changed Since Tuesday: Recon as a Longitudinal Job
A one-shot scan answers the wrong question. The finding that matters is not which subdomains exist, it is which one appeared last week. That requires storing scans, and getting one field exactly right.
5 min read