By Charles Joseph | Cybersecurity Researcher
Published on
March 20th, 2023
This post was updated on November 25th, 2023
Table of Contents show
A sock puppet is an online identity that can be used for deception, privacy, or operational security (OPSEC) by investigators, journalists, or penetration testers.
OPSEC protects both the investigator and the target when evidence doesn’t lead anywhere.
Stay One Step Ahead of Cyber Threats
Want to Be the Smartest Guy in the Room? Get the Latest Cybersecurity News and Insights.
7 Steps to Set Up a Sock Puppet
- Use a dedicated computer for investigations.
- Use an encrypted email service like Proton Mail.
- Get a burner phone number or a Wi-Fi phone number.
- Create a social media profile on a platform where your target is most active.
- Set up a few virtual machines.
- Create a blog or website (using free platforms like WordPress, Blogger, or Medium).
- Use a VPN.
SOURCE: Creating an Effective Sock Puppet for OSINT Investigations
Articles to Assist in Creating Sock Puppets
- The Art of the Sock (article)
- Reddit user’s process for setting up anonymous sockpuppet accounts
- Fake Name Generator
- This Person Does Not Exist
- Use privacy.com to get a burner credit card
- Video on the process
QUOTE:
"Amateurs hack systems, professionals hack people."
-- Bruce Schneier, a renown computer security professional
"Amateurs hack systems, professionals hack people."
-- Bruce Schneier, a renown computer security professional