Discord OSINT
Zach Malinich
Recon Village @ DEF CON 33 · Day 1 · Recon Village
Overview
Zach Malinich's Recon Village talk, "Discord OSINT: An Empathic Banana and a Data Scraper Walk into a Search Bar," delivers a comprehensive exploration of Open-Source Intelligence (OSINT) gathering on Discord. Malinich, an offensive security professional, highlights Discord's often-underestimated potential as a rich source of personal and professional data, detailing both manual techniques for individual researchers and the alarming rise of large-scale, automated data scraping operations. The presentation not only elucidates the methodologies for extracting valuable information from Discord profiles, server activity, and linked accounts but also critically examines the ethical, legal, and privacy implications of such activities.

Key moments
- 0:00 Introduction and talk overview
- 2:00 Talk agenda and Discord OSINT potential
- 4:00 Leveraging Discord's powerful search function
- 5:00 Examples: personal info, company badges
- 6:00 Extracting data from linked accounts and nicknames
- 7:40 OSINT opportunities in Discord Student Hubs
Discord OSINT
Speakers: Zach Malinich, Offensive Security Professional, PSU Alum
Conference: Recon Village
YouTube: https://www.youtube.com/watch?v=Xp4lWpD20Mo
Overview
Zach Malinich's Recon Village talk, "Discord OSINT: An Empathic Banana and a Data Scraper Walk into a Search Bar," delivers a comprehensive exploration of Open-Source Intelligence (OSINT) gathering on Discord. Malinich, an offensive security professional, highlights Discord's often-underestimated potential as a rich source of personal and professional data, detailing both manual techniques for individual researchers and the alarming rise of large-scale, automated data scraping operations. The presentation not only elucidates the methodologies for extracting valuable information from Discord profiles, server activity, and linked accounts but also critically examines the ethical, legal, and privacy implications of such activities.
The talk progresses from foundational OSINT techniques applicable to individuals to a deep dive into sophisticated platforms that have amassed billions of Discord messages and user data. Malinich uses real-world case studies and recent incidents, such as the SpyPet and SearchCord shutdowns, to illustrate the capabilities, vulnerabilities, and defensive countermeasures related to Discord OSINT. His insights underscore the critical need for users and server administrators to understand their digital footprint on the platform and adopt robust protection strategies.
This presentation is highly relevant for anyone interested in cybersecurity, digital privacy, and the evolving landscape of online intelligence gathering. It serves as a stark reminder that even seemingly private digital spaces can become targets for data aggregation, with significant consequences for personal security and privacy. Malinich's discussion of both legitimate OSINT applications and the darker side of data scraping, including potential targeting by cybercrime groups, positions the talk as a crucial resource for understanding modern digital threats.
Background
▶ Watch: Introduction and talk overview (0:00)
Open-Source Intelligence (OSINT) is the collection and analysis of information gathered from publicly available sources. Traditionally, OSINT has leveraged platforms like social media, public records, and news archives. However, as digital communication platforms evolve, so too do the targets and methodologies of OSINT practitioners. Discord, a popular voice, video, and text chat platform, has emerged as a significant, yet often overlooked, frontier for OSINT. Its user base, spanning gaming communities, professional groups, educational hubs, and niche interests, creates a vast repository of potentially exploitable information.
Prior to Malinich's research, initial explorations into Discord OSINT primarily focused on basic server discovery and identifying key personnel like administrators or moderators. Early articles, such as one from OSINT Curious, outlined methods for finding Discord servers via Google searches, Discord's internal explore feature, and third-party websites like Discord.me and Disboard. These approaches laid the groundwork for understanding Discord's public-facing architecture but often stopped short of delving into the deeper, more nuanced data points accessible through user interactions and platform features.
The problem that Malinich addresses is the underutilization of Discord's inherent features for OSINT, coupled with the escalating threat of automated data harvesting. While individual OSINT practitioners might manually sift through data, the sheer volume of Discord activity makes large-scale analysis challenging without significant investment or illicit tools. This gap has led to the emergence of highly sophisticated data scraping operations, which exploit Discord's functionalities to collect massive datasets, raising critical concerns about user privacy, data security, and the potential for malicious exploitation. Malinich's work aims to bridge this knowledge gap, providing both offensive and defensive perspectives on Discord as an OSINT target.
Key Findings
▶ Watch: Leveraging Discord's powerful search function (4:00)
Zach Malinich's talk reveals several key findings regarding effective OSINT on Discord, emphasizing both manual techniques and the alarming prevalence of automated data scraping. His research highlights that Discord, despite its apparent privacy settings, can be a goldmine for intelligence gathering if one knows where and how to look.
One of the primary findings revolves around leveraging Discord's native search function. Malinich demonstrates that this function, similar to Google dorking, employs operators (e.g., from:, has:, in:, mentions:, before:, during:, after:, pinned:) to narrow down searches. This allows researchers to pinpoint specific users, message content (like "password"), links, or files within particular channels or timeframes. The ability to find an "empathy banana" Easter egg while searching for "password" humorously illustrates the depth of information potentially retrievable.
Another crucial finding is the utility of linked accounts. Discord profiles allow users to connect external services like GitHub, Spotify, Instagram, PlayStation, and Epic Games. Malinich shows how these connections can reveal multiple online handles, and sometimes even real names, providing a rich cross-referencing opportunity to build a comprehensive profile of a target.
Server nicknames also present a valuable OSINT vector. While often used for convenience in gaming servers (e.g., matching an Xbox or PlayStation username), nicknames can sometimes expose real names or alternative online identities. Malinich notes that these can be observed directly in the mutual servers tab, offering another layer of data for correlation.
The concept of mutual servers is perhaps the most powerful finding for inferring interests, skills, and even location. By identifying common servers between a target and the investigator, one can deduce the target's affiliations. Malinich introduces student hubs as a prime example, where university students connect through institution-specific servers, often revealing full names and academic interests due to a lack of privacy awareness. He extends this concept to professional communities, demonstrating how mutual servers in cybersecurity (e.g., Cyberwox Academy, Security Blue Team, Hack The Box, TryHackMe for defensive beginners; Jay Haddock's Discord, Pentester Labs, Kaido for web app professionals) can accurately infer a target's skill level and specialized interests. Niche, invite-only servers like Breakdev Red or course-access servers like Evil Jinx Mastery provide even stronger inferences due to their exclusivity.
Beyond manual techniques, Malinich's most significant finding is the widespread and persistent nature of large-scale Discord data scrapers. He details several high-profile incidents:
- SpyPet (April 2023): Tracked 14,000 servers, 600,000 users, and 4 billion messages, notably capturing deleted messages. Its shutdown exposed critical OpSec failures of its owner and highlighted GDPR violations and malicious intent (harassment, extortion).
- Discord Unveiled (May 2023): Research by Brazilian academics that scraped 2 billion messages from 3,000 servers, tracking 4 million unique users. While anonymized, the dataset's existence underscores the feasibility of such operations.
- SearchCord (May 2023): A far larger operation, tracking 95,000 servers and 64 billion messages (285 TB of attachments) since 2015. Its purpose was to make public Discord messages accessible via a web interface, effectively replacing traditional forums. It operated by leveraging Discord's discovery feature and preview mode to scrape public channels without joining.
- Undiscovered Scrapers: Malinich reveals the ongoing existence of private data scrapers, including one he tracked that focuses on specific online game servers but has recently expanded to general Discord messages, operating from Europe, using DOS Guard (a host often associated with cybercrime), and having been linked to doxings and extortion attempts. This scraper grew from 800,000 messages and 5,000 servers in July to 1.5 million messages and 6,000 servers, 41 million files, and 42 TB stored by the time of the talk.
These findings collectively demonstrate that Discord is not as private as many users assume. Public channels, especially in discoverable servers, are highly susceptible to mass data collection, leading to potential privacy breaches, targeted harassment, and extortion by malicious actors.
Technical Deep Dive
▶ Watch: Examples: personal info, company badges (5:00)
The technical core of Malinich's presentation lies in dissecting both the manual and automated mechanisms for data extraction from Discord. On the manual front, the Discord search function is akin to a specialized search engine within the platform. Its operators are powerful tools:
from:username: Filters messages sent by a specific user.has:link/has:file: Identifies messages containing links or attached files.in:channel-name: Narrows the search to a particular channel.mentions:username: Finds messages where a user was mentioned.before:YYYY-MM-DD/during:YYYY-MM-DD/after:YYYY-MM-DD: Temporal filtering.pinned:true: Shows only pinned messages.
These operators, combined with keywords, allow for granular searching across potentially thousands of messages, turning vast chat histories into actionable intelligence.
However, scaling manual OSINT efforts encounters significant limitations. A standard Discord user is capped at 100 servers (200 for Nitro users). Building custom Discord bots, like MI6, to join servers and scrape data is not feasible for OSINT without administrative permissions, as bots must be manually added by server owners. This leads to the concept of self-bots, which are user accounts automated to perform actions normally done by a human. While highly effective for scaling, self-bots are explicitly against Discord's Terms of Service and carry a high risk of account termination. This "game of visibility" requires sophisticated OpSec to avoid detection.
The talk then transitions to the technical underpinnings of large-scale data scrapers, showcasing how these operations overcome the limitations of individual users and self-bots.
SpyPet leveraged a botnet architecture. While specific technical details on its botnet were not fully disclosed in the talk, the implication is that it operated numerous compromised or purpose-built Discord accounts to join servers and log data. Its ability to capture deleted messages suggests a rapid ingestion pipeline, where messages were recorded almost instantaneously upon being sent, before a user had a chance to delete them from Discord's database. This "capture before deletion" capability highlights a fundamental aspect of real-time data scraping. The platform was eventually shut down, partly due to its owner's poor OpSec, which allowed online communities to identify and dox him, and due to public outcry and GDPR violations, particularly concerning the storage of potentially minor chat history without consent.
The Discord Unveiled research, conducted by Brazilian academics, did not detail its technical specifics but implied a similar large-scale scraping methodology. Their ability to collect 2 billion messages from 3,000 servers and track 4 million unique users suggests a highly distributed and persistent scraping infrastructure, likely employing numerous automated accounts or exploiting API vulnerabilities.
SearchCord represented a more technically sophisticated and ideologically driven operation. Its owner developed a custom infrastructure to scrape a staggering 64 billion messages and 285 terabytes of attachments. The unique technical aspect of SearchCord was its exploitation of Discord's discovery feature and preview mode. When a server is listed in Discord Discovery, it allows non-members to view public channels without formally joining. SearchCord's system would enter this "preview mode" for discoverable servers and systematically scrape all visible public channel messages. This method bypassed the need for individual accounts to join thousands of servers, significantly reducing the risk of detection and circumventing server caps. The owner's publicly shared tech stack included tools like Kubernetes, PostgreSQL, Elasticsearch, and Redis, indicating a robust, scalable, and distributed system designed for massive data ingestion, indexing, and querying. The fact that the oldest collected message dated back to 2015 points to a long-term, possibly intermittent, scraping effort or an initial backfill of historical data. The owner's decision not to allow server owners to opt-out technically highlights a philosophical stance on data openness, but practically, it underscores the lack of control users and admins had over their data once a server was discoverable.
Finally, the undiscovered data scraper Malinich tracked operates in a similar vein to SpyPet, likely utilizing a botnet to join specific online game servers, and more recently, general Discord communities. Its rapid growth in messages (from 800k to 1.5M), files (15M to 41M), and stored data (20TB to 42TB) in just a few months indicates an active and expanding operation. The shift from Cloudflare to DOS Guard after numerous reports is a critical technical detail. DOS Guard is a hosting provider notorious for sheltering illicit activities, suggesting the scraper's operators prioritize evading legal and platform enforcement over maintaining a legitimate online presence. This move signifies a hardening of the infrastructure against takedown attempts and a clear intent to continue operations outside mainstream hosting.
In essence, these technical deep dives reveal a spectrum of scraping capabilities: from targeted manual searches to highly distributed botnets, and innovative exploitation of platform features like preview mode, all designed to overcome Discord's architectural safeguards and amass vast quantities of user data.
Demo / Proof of Concept
▶ Watch: Extracting data from linked accounts and nicknames (6:00)
Throughout the talk, Zach Malinich provides several compelling demonstrations and real-world examples to illustrate the effectiveness of Discord OSINT techniques and the capabilities of data scrapers.
For the Discord search function, Malinich shows a screenshot of a search for a specific username within a channel, highlighting how operators can narrow down over 10,000 messages from that user. He also mentions the discovery of an "empathy banana" Easter egg, showcasing the granular nature of keyword searches. Practical examples include finding a picture of someone's graduation, revealing their full face and university, and another instance where a user posted a desk setup with their company badge clearly visible, inadvertently exposing sensitive information.
The utility of linked accounts is demonstrated through a profile screenshot showing a user with three distinct online handles tied to their Discord, Instagram, GitHub, Spotify, PlayStation, and Epic accounts. This visually illustrates how an OSINT practitioner can quickly cross-reference identities across multiple platforms.
Server nicknames are exemplified by a common use case in gaming servers, where users adopt nicknames matching their in-game handles for easier identification. Malinich explains how these nicknames, especially when combined with mutual servers, can expose real names or specific gaming identities.
The power of mutual servers is showcased through two detailed case studies:
- Case Study 1: A person with mutual servers like Cyberwox Academy, Security Blue Team, Blue Team Labs Online, TryHackMe, and Hack The Box. Malinich infers a heavy emphasis on training, generally aimed at beginners to intermediates, with a bias towards defensive security and certifications.
- Case Study 2: A person linked to Jay Haddock's Discord, Pentester Labs, and Kaido (a niche Rust-based Burp Suite alternative). This leads to the inference that the individual is likely at a professional level, with a strong interest in web application security and bug bounty hunting.
Malinich emphasizes that these inferences, while strong, require confirmation through chat history or linked accounts. He also mentions the deanonymization attack researched by Hacker Hackmon Dev, which leverages Cloudflare CDN caching to provide a general idea of a user's geographical location, albeit with less accuracy.
Regarding the large-scale data scrapers, Malinich provides concrete examples of their capabilities:
- SpyPet: He demonstrates its ability to capture deleted messages by showing a CSV file of a chat channel where a message he sent and deleted within 5-10 seconds (sending it to the wrong channel) was still logged. This vividly illustrates the real-time data ingestion capabilities of such platforms. It also tracked double-joins to servers.
- SearchCord: Its search functionality is demonstrated with a simple query for "firmware." The results span approximately 400 pages, showcasing the immense volume of indexed data. Malinich also highlights its ability to replicate the Discord server interface on its own website, displaying detailed statistics like member counts, channel lists, total messages sent, active users, and even file extensions and names of attached files, all without requiring a Discord account or joining the server. The oldest message collected by SearchCord dating back to 2015 further underscores its historical data collection prowess.
These demonstrations collectively paint a clear picture of Discord's OSINT potential, from individual sleuthing to the terrifying scale of automated, persistent data harvesting operations.
Defensive Implications
▶ Watch: OSINT opportunities in Discord Student Hubs (7:40)
The detailed insights provided by Zach Malinich's talk offer critical defensive implications for both individual Discord users and server administrators. Understanding these threats is the first step towards mitigating the risks of OSINT and large-scale data scraping.
For Individual Discord Users:
- Remove Linked Accounts: The most direct action is to navigate to Discord's
Connectionssettings and unlink any external accounts (GitHub, Spotify, Instagram, etc.) from your profile. This significantly reduces the ability of OSINT practitioners to cross-reference your online identities and potentially discover your real name or other personal details. - Be Mindful of Posted Information: This is fundamental internet security advice, but it bears repeating: exercise extreme caution about what you share in any Discord channel, especially public ones. Avoid posting personal photos, location information, workplace details (e.g., company badges), or any data that could be used to identify or target you. Assume that any message sent in a public channel could be permanently recorded and made public.
- Disable Direct Messages (Optional but Recommended): For heightened paranoia, consider disabling direct messages (DMs) and message requests from non-friends. While not directly preventing data scraping, it can prevent a targeted individual who knows your Discord username from initiating contact, which could reveal mutual servers and further OSINT avenues.
For Discord Server Administrators and Moderators:
- Set Highest Verification Level: To deter automated accounts and casual snoopers, set your server's verification level to the highest possible requirement, typically requiring a verified phone number. This adds a hurdle for anyone attempting to join your server for scraping or malicious purposes.
- Do Not Have Your Server Discoverable: If your server contains sensitive discussions or a community that values privacy, ensure it is NOT listed in Discord's Discovery feature. As demonstrated by SearchCord, discoverable servers are prime targets for large-scale scraping operations that can access all public channels without ever formally joining the server. Removing your server from Discovery significantly reduces its attack surface for these automated scrapers.
- Review Public Channel Content: Regularly audit the content posted in public channels. Educate your community members about the risks of sharing personal information and the potential for data scraping. Encourage the use of private channels or threads for any sensitive discussions.
- Monitor for Suspicious Activity: Be vigilant for new accounts with unusual behavior, rapid message sending, or accounts that appear to be self-bots. While Discord's own detection mechanisms are in place, a proactive administrative team can identify and ban suspicious entities.
Ultimately, the core defensive strategy revolves around recognizing that Discord is not as private as many users think. Data sent in public channels, especially in discoverable servers, is vulnerable to collection and aggregation by both individual OSINT efforts and sophisticated, persistent data scrapers. Adopting these protective measures can significantly reduce an individual's or a community's digital footprint and mitigate the risks associated with pervasive online intelligence gathering.
Key Takeaways
- Discord is a Rich OSINT Source: Despite common perceptions, Discord offers significant opportunities for Open-Source Intelligence (OSINT) gathering, leveraging features like its search function, linked accounts, server nicknames, and mutual servers.
- Manual Techniques are Powerful: Individual OSINT practitioners can infer deep insights into a target's interests, skills, and even identity by combining information from these native Discord features, especially when analyzing membership in niche or exclusive servers.
- Large-Scale Data Scraping is Widespread and Persistent: Platforms like SpyPet, Discord Unveiled, and SearchCord have demonstrated the capability to scrape billions of Discord messages and user data, often by exploiting Discord's discovery feature and preview mode or using botnet architectures.
- Privacy is an Illusion in Public Channels: Any message sent in a public Discord channel, particularly within a server listed in Discord Discovery, should be considered potentially public and subject to permanent collection, even if deleted.
- Malicious Intent and Illicit Operations Exist: Beyond legitimate research, data scrapers have been linked to GDPR violations, poor OpSec, and targeting for harassment, doxings, and extortion by cybercrime groups, often migrating to bulletproof hosting like DOS Guard to evade takedowns.
- Defensive Measures are Crucial: Users should remove linked accounts and be mindful of what they post, while server administrators must set high verification levels and, crucially, avoid having their servers discoverable if privacy is a concern.
About the Speaker(s)
Zach Malinich is a Penn State University (PSU) alum with a professional background in offensive security. His work involves identifying vulnerabilities and weaknesses in systems, a perspective that deeply informs his research into Discord OSINT. Malinich holds various certifications, reflecting his expertise in the cybersecurity domain. In his talks, he aims to shed light on the capabilities of OSINT, the failures of past data scraping operations, and, most importantly, the protections available to users and server administrators. He is known for his online handle "Uber Zack Attack."
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent survey of Discord OSINT techniques with good real-world case studies on SpyPet and SearchCord, but it's fundamentally a well-organized tutorial rather than original research. Fits Recon Village's practitioner-education lane, delivers usable tradecraft, but won't move the needle for experienced OSINT operators.
Heather Calloway (CISO) — WEAK
Competent OSINT tradecraft presentation with genuine research value at the individual practitioner level, but it stops well short of where it needs to go for anyone with institutional responsibility. The data scraping findings — billions of messages, GDPR exposure, botnet infrastructure, cybercrime-linked operators — are serious, and Malinich clearly knows his material. The problem is that the talk treats a platform-scale privacy and governance failure as a tips-and-tricks session.