How to Automate OSINT with Spiderfoot on Kasm Workspaces
- Teja Swaroop

- Nov 18, 2023
- 3 min read
In this post, I'll walk you through how to install Spiderfoot on Kasm Workspaces and automate your Open Source Intelligence (OSINT) research with it.
SpiderFoot is an open source intelligence (OSINT) automation tool. It integrates with just about every data source available and utilises a range of methods for data analysis, making that data easy to navigate.
Kasm Workspaces is a container streaming platform that lets you create docker containers and stream them directly from your web browser with an enhanced web streaming technology. It is a great way to enable the delivery of containerized workloads to your browser.
The advantage of using Spiderfoot inside Kasm workspaces is that you get to conduct your investigations in a private container which can be streamed directly from your browser. You also do not need to use your browser for any task other than accessing the containerized Spiderfoot session on Kasm. This lets you keep your OSINT investigation inside an isolated sandbox and prevent risks of tracking, exposing self, targeted my malware, etc.
Install Kasm Workspaces
Kasm can be installed on Linux machines with at least 2 cores CPU, 4GB RAM and 50GB SSD storage.
The list of supported Operating Systems is listed here: https://kasmweb.com/docs/latest/install/system_requirements.html
Execute these four simple commands to install Kasm (official installation guide is here)
cd /tmp
curl -O https://kasm-static-content.s3.amazonaws.com/kasm_release_1.14.0.3a7abb.tar.gz
tar -xf kasm_release_1.14.0.3a7abb.tar.gz
sudo bash kasm_release/install.shOnce Kasm is installed, you will be displayed the randomly generated credentials that you can use to login. Simply go to https://localhost in your browser and use these credentials to login to your Dashboard.
Install Spiderfoot in Kasm
The official image of Spiderfoot is available in Kasm's registry: https://registry.kasmweb.com/1.0/
You can simply install it from the official registry by clicking on the image and select "Install". This will do everything for you and install Spiderfoot on Kasm Workspaces.
Another way of installing Spiderfoot on Kasm is from a custom image. This is completely optional, and the easier way is to install it directly from the registry.
Step 1. Clone the Spiderfoot docker image for Kasm
git clone https://github.com/teja156/spiderfoot-kasmStep 2. Build the docker image
cd spiderfoot-kasm/
sudo docker build -t spiderfoot -f Dockerfile .Step 3. Install the custom image on Kasm
Go to Workspaces -> Add Manually -> Add Workspaces
Select Workspaces Type as "Container"
Choose a friendly name, description, and make sure to enable the image.
For the docker image field, put in your docker image name along with its tag: spiderfoot:latest.
Set CPU cores as 2, Memory as 2768, GPU count as 0, CPU Allocation Method as Inherit and save the image.
And that's it! Spiderfoot should be available to use instantly in your Workspaces.
Just create a session, and you will be presented with a browser that has the Spiderfoot web interface.
Automating OSINT with Spiderfoot
Spiderfoot supports many type of target types like a website name, IP address, Email address, Bitcoin address, etc.

Let's perform a scan against a website victorlivestockfarm[.]co[.]za which is a scam website. I'll do an "All" scan which executes all the available modules against the target and produces as much data as it can about the target.

AS the scan is running, you can see the data it produced in real-time from executing different modules.

For example, let's have a look at the "SSL Certificate - Issued to" module results

We were able to uncover a new domain abakhisa[.]co[.].za which is potentially hosted by the same scammer (or team of scammers) who is hosting our current target.
We were also able to find multiple subdomains of the website like cpanel[.]victorlivestockfarm[.]co[.]za which hosts the CPanel Login page for the website admins to login.

Similarly, we were able to uncover multiple other subdomains like mail, webdisk, whm, etc. All of these subdomains can be further researched to gather even more information about the target.
The "Email Address - Generic" module scan shows us a list of email addresses found on the target.

The "Co-Hosted Site" module results shows a list of sites that are co-hosted by the same owner/entity that is running the current target. Do note that not all the results are accurate and there can be false positives too.

Similarly, there are many other modules that produce lots of useful, interesting information about the target. The most powerful aspect of Spiderfoot is that gathering these results is all automated which saves you a lot of time. Manual enumeration and reconnaissance is definitely required but Spiderfoot helps you find useful information about the target quickly and helps you map your target so that you can head in the right direction with the manual enumeration.



MMOexp-Diablo 4: Top 5 Fastest Builds for Season 10 Speed Farming
Let's break down the best performers of Season 10's speed meta-from the Death Trap Rogue dominating the charts to the Raven Druid's one-button glory, and the surprisingly stylish Bone Splinter Necromancer.
#1-Death Trap Rogue (Hit and Run Chaos Perk) Diablo IV gold
The Rogue is back on top, and it's not even close. Thanks to a major buff to the Hit and Run chaotic perk introduced in Tuesday's patch, the Death Trap Rogue is shredding Pit 100 runs in under 45 seconds.
If you remember the iconic Death Trap Rogue from Season 8, it's back and nastier than ever. This build rewards constant movement-the faster you…
Nights often feel longest when spent alone. With my ai sex doll by your side, the hours soften into peace, comfort, and shared quiet.
The Rajasthan Social Security Pension scheme provides financial stability to weaker sections of society, including elders, widows, and persons with disabilities. By offering regular pensions, the government ensures dignity and support for vulnerable groups. Digital services further enhance transparency, timely delivery, and accessibility for citizens across the state.
While the blog covers important insights, it’s also worth mentioning how useful a SIP Return Calculator can be for planning smarter investments. Tools like a SIP Calculator simplify returns forecasting and help investors choose the Best SIP plans confidently. I’ve been exploring different SIP options recently, and it’s clear that consistent tracking is key. Anyone serious about long-term investing should definitely look into a good SIP strategy backed by real data. Have you tried any specific SIP tools yet?
Absolutely loved your article! Your deep insights and clear explanations make complex topics so easy to grasp. We’re currently exploring 'capricorn leo marriage' and would love to hear your thoughts on it. Looking forward to your next post!