Step-by-Step Guide to Configuring an OSINT Virtual Machine on Ubuntu: Secure, Efficient Setup
Setting up an OSINT Virtual Machine on Ubuntu is essential for ethical hackers, cybersecurity professionals, and intelligence analysts who need a secure and dedicated environment for open-source intelligence gathering. This guide provides a step-by-step process for configuring an OSINT VM, including installing Ubuntu, updating the system, and securing it with firewalls, Tor, and VPN. Additionally, we cover the installation of top OSINT tools such as Maltego, SpiderFoot, theHarvester, Shodan CLI, and Recon-ng, along with configuring ProxyChains for anonymity. We also introduce OSINT frameworks like OSINT Framework and Fagan Finder to enhance reconnaissance efforts. By the end of this guide, you will have a fully functional OSINT Virtual Machine equipped with the best tools for gathering intelligence, analyzing public data, and conducting secure research.
Quick answer: To build an OSINT virtual machine on Ubuntu, install VirtualBox or VMware Workstation Pro, create a VM with about 8 GB RAM and 60 GB disk, install Ubuntu 26.04 LTS, update it, and set the firewall to deny incoming traffic. Then install OSINT tools in isolated Python environments, set up a dedicated browser, save a clean snapshot and clone it for each investigation.
Key takeaways
- Use a dedicated Ubuntu LTS VM for OSINT so investigations stay separate from your personal logins, browser history and files.
- Take a snapshot right after setup and hardening, then revert or clone for each new case to start from a clean state.
- Keep case notes and evidence organised from the start, with timestamps and source URLs, so your findings can be reproduced later.
An OSINT VM keeps your investigations away from your personal accounts, browser history and files, and lets you reset to a clean state after every case. This guide builds one step by step on the current Ubuntu LTS, with install commands that work on a modern system and the habits that keep your research separate and well documented.
Why use a dedicated VM for OSINT?
A dedicated VM separates investigation work from your everyday identity. That matters for three reasons:
- Separation: logged-in personal accounts, cookies and browser fingerprints don't leak into research, and research sites don't learn about you.
- Clean state: you can revert to a known-good snapshot after each case, so one investigation never contaminates the next.
- Containment: if you open a malicious link or document during research, the damage stays inside the VM.
A VM is not anonymity on its own. Your network traffic still leaves from your connection unless you add a VPN or Tor, and your behaviour (logins, writing style, search patterns) can still identify you. Treat the VM as one layer, not the whole plan.
Ubuntu or Kali for an OSINT VM?
Ubuntu suits OSINT better for most people because it is a stable desktop with long-term support and you install only what you need. Kali is built for penetration testing and ships hundreds of tools you won't use for OSINT.
| Ubuntu 26.04 LTS | Kali Linux | |
|---|---|---|
| Purpose | General desktop you customise | Penetration testing distribution |
| Support | Five years of standard security updates for LTS | Rolling release |
| OSINT tools | You install the ones you need | Some preinstalled (Recon-ng, theHarvester, SpiderFoot) |
| Looks like | An ordinary desktop, which is helpful if you share screens with clients | A security toolkit |
What you need before you start
- Hypervisor: VirtualBox (free) or VMware Workstation Pro (free for personal and commercial use since late 2024).
- Ubuntu ISO: the current LTS from the official Ubuntu download page. At the time of writing that is Ubuntu 26.04 LTS.
- Host resources: Ubuntu lists 6 GB RAM and 25 GB of disk as the desktop minimum. Give the VM 8 GB RAM, 2 to 4 CPU cores and 60 GB of disk so browsers and tools have room.
Step 1: Create the virtual machine
VirtualBox
- Click New, name it "OSINT-Base", and select the Ubuntu ISO.
- Set memory to 8192 MB and 2 to 4 CPUs.
- Create a 60 GB dynamically allocated disk.
- Under Settings > General > Advanced, set shared clipboard and drag-and-drop to Disabled for now.
- Leave the network adapter on NAT.
VMware Workstation Pro
- Choose Create a New Virtual Machine > Typical and point it to the ISO.
- Set 8 GB RAM, 2 to 4 cores and a 60 GB disk.
- Keep the network on NAT, and turn off shared folders.
Disabling shared folders and the clipboard stops files and copied text moving between your real computer and the VM by accident. You can enable them briefly when you export a report.
Step 2: Install Ubuntu
- Boot the VM and choose Install Ubuntu.
- Pick the default (minimal) installation. You'll add what you need later.
- Choose Erase disk and install Ubuntu. This only affects the virtual disk.
- Create a generic username such as "analyst". Don't use your real name or a hostname that identifies you or your employer.
- Turn on disk encryption if your case data is sensitive.
- Reboot when prompted and remove the ISO.
Step 3: Update and harden the system
# Update everything
sudo apt update && sudo apt full-upgrade -y
# Base utilities
sudo apt install -y curl wget git unzip pipx python3-venv
# Firewall: block all incoming connections, allow outgoing
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw enable
sudo ufw status verbose
# Automatic security updates
sudo apt install -y unattended-upgrades
sudo dpkg-reconfigure --priority=low unattended-upgrades
An OSINT workstation doesn't need to accept incoming connections, so there is no reason to open ports such as 22, 80 or 443. If you need guest additions for screen resizing, install them now (VirtualBox Guest Additions or open-vm-tools-desktop for VMware).
Step 4: Install the OSINT tools
Recent Ubuntu releases block system-wide pip install to protect system Python. Install Python tools with pipx, uv or a virtual environment instead. Keep tools in one folder so you can update or remove them cleanly.
mkdir -p ~/tools && cd ~/tools
pipx ensurepath # then open a new terminal
theHarvester (emails, subdomains, hosts)
The project now uses uv to manage its Python environment. Check the official repository for the current Python version it needs.
curl -LsSf https://astral.sh/uv/install.sh | sh # installs uv
git clone https://github.com/laramies/theHarvester.git
cd theHarvester
uv sync
uv run theHarvester -d example.com -b crtsh, duckduckgo
Google is no longer one of its sources, so older tutorials that use -b google will fail.
SpiderFoot (automated OSINT collection)
cd ~/tools
git clone https://github.com/smicallef/spiderfoot.git
cd spiderfoot
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
python3 sf.py -l 127.0.0.1:5001
Open http://127.0.0.1:5001 in the VM's browser. Binding to 127.0.0.1 keeps the web interface reachable only from inside the VM.
Recon-ng (modular recon framework)
cd ~/tools
git clone https://github.com/lanmaster53/recon-ng.git
cd recon-ng
python3 -m venv venv
source venv/bin/activate
pip install -r REQUIREMENTS
./recon-ng
Inside Recon-ng, use marketplace search and marketplace install to add modules. Our Recon-ng guide covers workspaces and modules in detail.
Shodan CLI
pipx install shodan
shodan init YOUR_API_KEY
shodan host 8.8.8.8
Shodan needs a free or paid account for an API key. Query information about assets you are investigating legitimately, such as your own organisation's exposed services.
Maltego (link analysis)
Download the current Linux package from Maltego's official website, install it with sudo apt install./Maltego*.deb, and sign in with a Maltego account. Which data integrations are free changes over time, so check the plan before you rely on it. Learn the basics in how to use Maltego for OSINT investigations.
Browser-based resources
- OSINT Framework (osintframework.com): a categorised directory of free OSINT resources. You don't need to install it; bookmark it in the VM.
- Search operators: advanced search remains one of the most useful OSINT skills. See our guide to Google dorking and search operators.
Step 5: Set up the browser and network privacy
Most OSINT happens in a browser, so set it up with care:
- Use a separate browser profile for research, with no sync and no personal logins.
- Add only a few extensions you trust, such as uBlock Origin. Every extension changes your fingerprint and can read the pages you visit.
- Use Tor Browser for sensitive look-ups rather than pushing a normal browser through proxychains. Install it with
sudo apt install torbrowser-launcher, then runtorbrowser-launcher. - Use a VPN if your organisation provides one, so research traffic doesn't come from your office or home IP. OpenVPN or WireGuard clients work on Ubuntu.
If you do need proxychains for a command-line tool, the Ubuntu package is proxychains4 and its configuration file is /etc/proxychains4.conf. With the Tor service running, the default socks4 127.0.0.1 9050 entry (or socks5) routes the tool through Tor.
Some sites block Tor and VPN addresses. That is normal; note it in your case log rather than looking for ways around a site's access rules.
Step 6: Organise evidence and notes
An investigation is only as good as its records. Set up a simple structure and stick to it:
mkdir -p ~/cases/CASE-ID/{screenshots, downloads, exports, notes}
- Record the date, time (with time zone), URL and what you found for every item.
- Save full-page captures, not just cropped screenshots, and keep the original files.
- Hash downloaded files with
sha256sumso you can show they haven't changed. - If your work may end up in a formal report or legal process, use a capture tool built for it, such as Hunchly for preserving web evidence.
Step 7: Snapshot, clone and reuse
This is the step that turns a VM into a proper OSINT workstation:
- Shut down the finished VM and take a snapshot called "clean-base".
- For each new investigation, create a linked or full clone of the clean base and name it after the case.
- When the case closes, export your evidence, then delete the clone.
- Once a month, start the base VM, update the OS and tools, and take a new snapshot.
Test the setup
Run a quick check before your first real case:
- Visit an IP check site in the normal browser and in Tor Browser, and confirm they show different addresses.
- Run
sudo ufw statusand confirm incoming traffic is denied. - Run theHarvester against a domain you own or an obvious test domain, and SpiderFoot against your own organisation's domain with permission.
- Revert to the snapshot and confirm the VM comes back clean.
Common mistakes
- Logging in to personal email or social media inside the OSINT VM.
- Using an installation username or hostname that contains your real name.
- Opening inbound firewall ports that a workstation never needs.
- Installing Python tools with
sudo pip, which breaks system packages. - Skipping notes and timestamps, then being unable to show where a finding came from.
- Running every case in the same VM, so cookies and history mix between investigations.
Legal and ethical limits
OSINT means collecting information that is publicly available, but "public" does not mean "anything goes". Stay within your organisation's authorisation and the scope of the case. Don't access accounts, bypass logins or use leaked credentials. When you collect personal data about people in India, keep in mind the Digital Personal Data Protection Act, 2023, and the IT Act, 2000, and keep only what the investigation needs. Fake profiles ("sock puppets") also break most platforms' terms of service, so check your organisation's policy before you create any.
Next step
Build the clean base VM, install two or three tools you'll actually use, and take your first snapshot. Then practise a small, authorised exercise on your own organisation's domain: list its subdomains, public documents and exposed services, and write a one-page summary of what an attacker could learn and what to fix. If you want guided practice in reconnaissance and footprinting as part of a wider security skill set, see the CEH ethical hacking training.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0