Step-by-Step Guide to Configuring an OSINT Virtual Machine on Ubuntu: Secure, Efficient Setup

Setting up an OSINT Virtual Machine on Ubuntu is essential for ethical hackers, cybersecurity professionals, and intelligence analysts who need a secure and dedicated environment for open-source intelligence gathering. This guide provides a step-by-step process for configuring an OSINT VM, including installing Ubuntu, updating the system, and securing it with firewalls, Tor, and VPN. Additionally, we cover the installation of top OSINT tools such as Maltego, SpiderFoot, theHarvester, Shodan CLI, and Recon-ng, along with configuring ProxyChains for anonymity. We also introduce OSINT frameworks like OSINT Framework and Fagan Finder to enhance reconnaissance efforts. By the end of this guide, you will have a fully functional OSINT Virtual Machine equipped with the best tools for gathering intelligence, analyzing public data, and conducting secure research.

Mar 29, 2025 - 11:50
Updated: 7 days ago
110k
Step-by-Step Guide to Configuring an OSINT Virtual Machine on Ubuntu: Secure, Efficient Setup

Quick answer: To build an OSINT virtual machine on Ubuntu, install VirtualBox or VMware Workstation Pro, create a VM with about 8 GB RAM and 60 GB disk, install Ubuntu 26.04 LTS, update it, and set the firewall to deny incoming traffic. Then install OSINT tools in isolated Python environments, set up a dedicated browser, save a clean snapshot and clone it for each investigation.

Key takeaways

  • Use a dedicated Ubuntu LTS VM for OSINT so investigations stay separate from your personal logins, browser history and files.
  • Take a snapshot right after setup and hardening, then revert or clone for each new case to start from a clean state.
  • Keep case notes and evidence organised from the start, with timestamps and source URLs, so your findings can be reproduced later.

An OSINT VM keeps your investigations away from your personal accounts, browser history and files, and lets you reset to a clean state after every case. This guide builds one step by step on the current Ubuntu LTS, with install commands that work on a modern system and the habits that keep your research separate and well documented.

Why use a dedicated VM for OSINT?

A dedicated VM separates investigation work from your everyday identity. That matters for three reasons:

  • Separation: logged-in personal accounts, cookies and browser fingerprints don't leak into research, and research sites don't learn about you.
  • Clean state: you can revert to a known-good snapshot after each case, so one investigation never contaminates the next.
  • Containment: if you open a malicious link or document during research, the damage stays inside the VM.

A VM is not anonymity on its own. Your network traffic still leaves from your connection unless you add a VPN or Tor, and your behaviour (logins, writing style, search patterns) can still identify you. Treat the VM as one layer, not the whole plan.

Ubuntu or Kali for an OSINT VM?

Ubuntu suits OSINT better for most people because it is a stable desktop with long-term support and you install only what you need. Kali is built for penetration testing and ships hundreds of tools you won't use for OSINT.

Ubuntu 26.04 LTSKali Linux
PurposeGeneral desktop you customisePenetration testing distribution
SupportFive years of standard security updates for LTSRolling release
OSINT toolsYou install the ones you needSome preinstalled (Recon-ng, theHarvester, SpiderFoot)
Looks likeAn ordinary desktop, which is helpful if you share screens with clientsA security toolkit

What you need before you start

  • Hypervisor: VirtualBox (free) or VMware Workstation Pro (free for personal and commercial use since late 2024).
  • Ubuntu ISO: the current LTS from the official Ubuntu download page. At the time of writing that is Ubuntu 26.04 LTS.
  • Host resources: Ubuntu lists 6 GB RAM and 25 GB of disk as the desktop minimum. Give the VM 8 GB RAM, 2 to 4 CPU cores and 60 GB of disk so browsers and tools have room.

Step 1: Create the virtual machine

VirtualBox

  1. Click New, name it "OSINT-Base", and select the Ubuntu ISO.
  2. Set memory to 8192 MB and 2 to 4 CPUs.
  3. Create a 60 GB dynamically allocated disk.
  4. Under Settings > General > Advanced, set shared clipboard and drag-and-drop to Disabled for now.
  5. Leave the network adapter on NAT.

VMware Workstation Pro

  1. Choose Create a New Virtual Machine > Typical and point it to the ISO.
  2. Set 8 GB RAM, 2 to 4 cores and a 60 GB disk.
  3. Keep the network on NAT, and turn off shared folders.

Disabling shared folders and the clipboard stops files and copied text moving between your real computer and the VM by accident. You can enable them briefly when you export a report.

Step 2: Install Ubuntu

  1. Boot the VM and choose Install Ubuntu.
  2. Pick the default (minimal) installation. You'll add what you need later.
  3. Choose Erase disk and install Ubuntu. This only affects the virtual disk.
  4. Create a generic username such as "analyst". Don't use your real name or a hostname that identifies you or your employer.
  5. Turn on disk encryption if your case data is sensitive.
  6. Reboot when prompted and remove the ISO.

Step 3: Update and harden the system

# Update everything
sudo apt update && sudo apt full-upgrade -y

# Base utilities
sudo apt install -y curl wget git unzip pipx python3-venv

# Firewall: block all incoming connections, allow outgoing
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw enable
sudo ufw status verbose

# Automatic security updates
sudo apt install -y unattended-upgrades
sudo dpkg-reconfigure --priority=low unattended-upgrades

An OSINT workstation doesn't need to accept incoming connections, so there is no reason to open ports such as 22, 80 or 443. If you need guest additions for screen resizing, install them now (VirtualBox Guest Additions or open-vm-tools-desktop for VMware).

Step 4: Install the OSINT tools

Recent Ubuntu releases block system-wide pip install to protect system Python. Install Python tools with pipx, uv or a virtual environment instead. Keep tools in one folder so you can update or remove them cleanly.

mkdir -p ~/tools && cd ~/tools
pipx ensurepath # then open a new terminal

theHarvester (emails, subdomains, hosts)

The project now uses uv to manage its Python environment. Check the official repository for the current Python version it needs.

curl -LsSf https://astral.sh/uv/install.sh | sh # installs uv
git clone https://github.com/laramies/theHarvester.git
cd theHarvester
uv sync
uv run theHarvester -d example.com -b crtsh, duckduckgo

Google is no longer one of its sources, so older tutorials that use -b google will fail.

SpiderFoot (automated OSINT collection)

cd ~/tools
git clone https://github.com/smicallef/spiderfoot.git
cd spiderfoot
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
python3 sf.py -l 127.0.0.1:5001

Open http://127.0.0.1:5001 in the VM's browser. Binding to 127.0.0.1 keeps the web interface reachable only from inside the VM.

Recon-ng (modular recon framework)

cd ~/tools
git clone https://github.com/lanmaster53/recon-ng.git
cd recon-ng
python3 -m venv venv
source venv/bin/activate
pip install -r REQUIREMENTS
./recon-ng

Inside Recon-ng, use marketplace search and marketplace install to add modules. Our Recon-ng guide covers workspaces and modules in detail.

Shodan CLI

pipx install shodan
shodan init YOUR_API_KEY
shodan host 8.8.8.8

Shodan needs a free or paid account for an API key. Query information about assets you are investigating legitimately, such as your own organisation's exposed services.

Maltego (link analysis)

Download the current Linux package from Maltego's official website, install it with sudo apt install./Maltego*.deb, and sign in with a Maltego account. Which data integrations are free changes over time, so check the plan before you rely on it. Learn the basics in how to use Maltego for OSINT investigations.

Browser-based resources

  • OSINT Framework (osintframework.com): a categorised directory of free OSINT resources. You don't need to install it; bookmark it in the VM.
  • Search operators: advanced search remains one of the most useful OSINT skills. See our guide to Google dorking and search operators.

Step 5: Set up the browser and network privacy

Most OSINT happens in a browser, so set it up with care:

  1. Use a separate browser profile for research, with no sync and no personal logins.
  2. Add only a few extensions you trust, such as uBlock Origin. Every extension changes your fingerprint and can read the pages you visit.
  3. Use Tor Browser for sensitive look-ups rather than pushing a normal browser through proxychains. Install it with sudo apt install torbrowser-launcher, then run torbrowser-launcher.
  4. Use a VPN if your organisation provides one, so research traffic doesn't come from your office or home IP. OpenVPN or WireGuard clients work on Ubuntu.

If you do need proxychains for a command-line tool, the Ubuntu package is proxychains4 and its configuration file is /etc/proxychains4.conf. With the Tor service running, the default socks4 127.0.0.1 9050 entry (or socks5) routes the tool through Tor.

Some sites block Tor and VPN addresses. That is normal; note it in your case log rather than looking for ways around a site's access rules.

Step 6: Organise evidence and notes

An investigation is only as good as its records. Set up a simple structure and stick to it:

mkdir -p ~/cases/CASE-ID/{screenshots, downloads, exports, notes}
  • Record the date, time (with time zone), URL and what you found for every item.
  • Save full-page captures, not just cropped screenshots, and keep the original files.
  • Hash downloaded files with sha256sum so you can show they haven't changed.
  • If your work may end up in a formal report or legal process, use a capture tool built for it, such as Hunchly for preserving web evidence.

Step 7: Snapshot, clone and reuse

This is the step that turns a VM into a proper OSINT workstation:

  1. Shut down the finished VM and take a snapshot called "clean-base".
  2. For each new investigation, create a linked or full clone of the clean base and name it after the case.
  3. When the case closes, export your evidence, then delete the clone.
  4. Once a month, start the base VM, update the OS and tools, and take a new snapshot.

Test the setup

Run a quick check before your first real case:

  • Visit an IP check site in the normal browser and in Tor Browser, and confirm they show different addresses.
  • Run sudo ufw status and confirm incoming traffic is denied.
  • Run theHarvester against a domain you own or an obvious test domain, and SpiderFoot against your own organisation's domain with permission.
  • Revert to the snapshot and confirm the VM comes back clean.

Common mistakes

  • Logging in to personal email or social media inside the OSINT VM.
  • Using an installation username or hostname that contains your real name.
  • Opening inbound firewall ports that a workstation never needs.
  • Installing Python tools with sudo pip, which breaks system packages.
  • Skipping notes and timestamps, then being unable to show where a finding came from.
  • Running every case in the same VM, so cookies and history mix between investigations.

Legal and ethical limits

OSINT means collecting information that is publicly available, but "public" does not mean "anything goes". Stay within your organisation's authorisation and the scope of the case. Don't access accounts, bypass logins or use leaked credentials. When you collect personal data about people in India, keep in mind the Digital Personal Data Protection Act, 2023, and the IT Act, 2000, and keep only what the investigation needs. Fake profiles ("sock puppets") also break most platforms' terms of service, so check your organisation's policy before you create any.

Next step

Build the clean base VM, install two or three tools you'll actually use, and take your first snapshot. Then practise a small, authorised exercise on your own organisation's domain: list its subdomains, public documents and exposed services, and write a one-page summary of what an attacker could learn and what to fix. If you want guided practice in reconnaissance and footprinting as part of a wider security skill set, see the CEH ethical hacking training.

Related reading

Frequently Asked Questions

An OSINT virtual machine is a dedicated, isolated computer running inside a hypervisor and set up only for open-source intelligence work. It keeps research separate from your personal accounts and files, and you can revert it to a clean snapshot after each investigation.

Ubuntu suits most OSINT work better. It is a stable long-term support desktop where you install only the tools you need, while Kali is designed for penetration testing and ships many tools you won't use for OSINT. Either can work if you configure it carefully.

Ubuntu's own minimum for the desktop is 6 GB RAM and 25 GB of disk. For an OSINT VM, 8 GB RAM, 2 to 4 CPU cores and about 60 GB of disk leaves room for several browser tabs, Maltego and SpiderFoot running together.

Recent Ubuntu releases mark system Python as externally managed, so a system-wide pip install is blocked to avoid breaking OS packages. Install command-line tools with pipx or uv, or create a virtual environment with python3 -m venv for each tool.

No. A VM separates your research from your personal system, but your traffic still comes from your own internet connection unless you use a VPN or Tor. Logins, browser fingerprints and behaviour can also identify you, so treat the VM as one layer.

Collecting genuinely public information is generally lawful, but how you collect and use it matters. Don't access accounts, bypass logins or use leaked data, stay within your authorisation, and handle personal data in line with the Digital Personal Data Protection Act, 2023, and the IT Act, 2000.

Start with a well-configured browser and good search operator skills, then add theHarvester for domains and emails, SpiderFoot for automated collection, Recon-ng for structured recon, and Maltego for link analysis. Add more tools only when a case needs them.

Use a folder per case, record the date, time, time zone and URL for every finding, save full-page captures and original files, and hash downloads with sha256sum. For work that may go to court, use a dedicated capture tool such as Hunchly.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.