Crafting Boolean Search Dorks
Markdown--- name: crafting-boolean-search-dorks description: Constructs advanced Boolean search queries and Google dorks using search operators (site:, intitle:, filetype:, inurl:, quotes, exclusions) to find precise information, documents, or exposed content. Use when needing to locate specific files, research competitors, find exposed data, conduct OSINT, or narrow broad searches to exact results. ---
Need a specific PDF report from a government site? Don't search naturally — dork it:
site:gov filetype:pdf "annual report" 2023 -site:irs.gov
Breakdown: site: restricts domain, filetype: restricts format, quotes force exact phrase, -site: excludes noise.
Progress:
- Clarify the exact target (file type, domain, phrase, date range)
- Pick core operators for that target
- Build query from most restrictive to least restrictive operator
- Test query, inspect top 10 results
- Refine: add exclusions, tighten phrases, adjust operators
- Save working query pattern for reuse
1. Clarify intent. Ask: Am I looking for a document type, a specific site's content, exposed data, or a competitor's pages?
2. Choose operators based on intent:
| Goal | Operator |
|---|---|
| Restrict to a domain/site | site:example.com |
| Restrict to file type | filetype:pdf, filetype:xlsx, filetype:docx |
| Phrase in title | intitle:"exact phrase" |
| Phrase in URL | inurl:admin |
| Exact phrase anywhere | "exact phrase" |
| Exclude term/site | -keyword, -site:pinterest.com |
| Either/or | term1 OR term2 |
| Wildcard/unknown word | "best * for beginners" |
| Number/date range | 2020..2023 |
| Related sites | related:example.com |
| Cached-style/content exposure | intitle:"index of" |
3. Stack operators — combine 2-4 max. More than that usually returns zero results.
4. Order matters for readability, not function — but put the most restrictive operator (site:, filetype:) first for quick mental parsing.
5. Iterate: if too few results, drop an operator or loosen phrase; if too many/noisy, add exclusions or intitle:/inurl: constraints.
Example 1 — Find exposed spreadsheets with emails on a domain: Input: "Find Excel files with contact lists on acmecorp.com" Output:
site:acmecorp.com filetype:xlsx ("email" OR "contact")
Example 2 — Find a competitor's pricing page without their homepage noise: Input: "Research competitor pricing pages across the web" Output:
intitle:"pricing" inurl:pricing -site:g2.com -site:capterra.com "per month" OR "per user"
Example 3 — Find PDFs of a specific report type published recently: Input: "Locate whitepapers on supply chain AI from 2023-2024" Output:
filetype:pdf intitle:"supply chain" "artificial intelligence" 2023..2024
Example 4 — Find exposed directory listings (classic OSINT dork): Input: "Check if a server exposes an open directory" Output:
intitle:"index of" "parent directory" site:example.com
Example 5 — Find forum/Reddit discussions excluding official marketing: Input: "Real user opinions on Product X, not ads" Output:
"Product X" (site:reddit.com OR site:news.ycombinator.com) -site:producthunt.com
- Use quotes for exact phrases — single words rarely need them.
- Combine
site:+filetype:first; it's the fastest way to kill noise. - Use parentheses with
ORto group alternatives:(term1 OR term2) term3. - Keep queries to 3-5 meaningful operators; readability aids debugging.
- For OSINT/security work, pair
intitle:"index of",inurl:, andfiletype:to find misconfigured exposures (e.g.,filetype:env "DB_PASSWORD"). - Re-run queries periodically — indexed content changes; a dork that returns nothing today may work next week.
- When searching for leaked/sensitive data, operate within legal and ethical bounds (authorized research/pentesting only).
- Overstacking operators — 6+ operators often returns zero results; search engines treat it as overly narrow AND logic.
- Forgetting quotes — unquoted multi-word phrases get treated as separate keywords, diluting precision.
- Wrong exclusion placement —
-site:must have no space after the dash (-site:, not- site:). - Assuming operators work identically across engines — Bing/DuckDuckGo support similar but not identical operator sets; verify before reusing a Google-specific dork elsewhere.
- Ignoring result staleness — cached snippets may show content no longer live on the page.
- Using dorks for unauthorized access — dorking is for finding publicly indexed info, not a substitute for proper authorization in security testing.