Crafting Boolean Search Dorks
Markdown--- name: crafting-boolean-search-dorks description: Constructs precise boolean search queries and search engine "dorks" using advanced operators to find specific information, files, or content that general searches miss. Use when needing to locate exact documents, exposed data, specific site content, competitor information, or niche resources that keyword searches fail to surface. --- # Crafting Boolean Search Dorks
To find PDF reports on a specific topic from a specific domain:
site:example.com filetype:pdf "quarterly report" 2023..2024
To find pages that mention one term but exclude another:
"project management" -"software" -"certification" intitle:guide
Progress:
- Step 1: Define the exact goal — what format, source, or content is needed?
- Step 2: Identify core keywords (and exact phrases needing quotes)
- Step 3: Select operators to narrow scope (site, filetype, intitle, inurl)
- Step 4: Add exclusions to remove noise (
-keyword) - Step 5: Test query, review first page of results
- Step 6: Iterate — tighten or loosen based on result quality
Core Operators Reference
| Operator | Purpose | Example |
|---|---|---|
"exact phrase" | Match exact wording | "error 404 not found" |
site: | Limit to a domain | site:reddit.com |
-site: | Exclude a domain | -site:pinterest.com |
filetype: | Specific file format | filetype:xlsx |
intitle: | Word in page title | intitle:"index of" |
allintitle: | All words in title | allintitle:budget 2024 template |
inurl: | Word in URL | inurl:admin |
intext: | Word in body text | intext:"confidential" |
-keyword | Exclude a term | resume -template -example |
OR / | | Either term | "CEO" OR "Chief Executive" |
AND (implicit) | Both terms (default) | budget AND forecast |
* | Wildcard placeholder | "how to * a resume" |
.. | Number/date range | "camera" $200..$400 |
() | Group logic | (intitle:guide OR intitle:tutorial) |
related: | Similar sites | related:nytimes.com |
cache: | Cached version | cache:example.com |
Example 1 — Find exposed spreadsheets with sensitive data: Input: Need to audit if a company accidentally exposed internal spreadsheets. Output:
site:company.com filetype:xlsx OR filetype:csv intext:"confidential" OR intext:"internal use only"
Example 2 — Find competitor pricing pages without marketing fluff: Input: Locate direct pricing pages, not blog mentions. Output:
site:competitor.com inurl:pricing -inurl:blog -inurl:news
Example 3 — Find resumes of candidates with specific skills: Input: Sourcing candidates skilled in Python and AWS, excluding job boards. Output:
filetype:pdf intext:"resume" "Python" "AWS" -site:linkedin.com -site:indeed.com
Example 4 — Find unlisted/forgotten login portals: Input: Security research on a domain's exposed admin panels. Output:
site:target.com inurl:login OR inurl:admin OR inurl:portal -inurl:help
Example 5 — Find open directories of a file type: Input: Locate publicly indexed folders containing MP3s. Output:
intitle:"index of" "parent directory" filetype:mp3
- Quote exact phrases to avoid the engine splitting and loosely matching words.
- Combine
site:+filetype:as the fastest way to narrow to a specific document type on a specific source. - Use parentheses with OR to group alternatives clearly:
(intitle:resume OR intitle:cv). - Start broad, then add exclusions — run the query, scan noisy results, exclude the recurring junk terms.
- Use
intitle:"index of"as a classic dork for discovering open directory listings. - Prefer
intext:over bare keywords when the term must appear in body copy, not just metadata. - Date/number ranges (
..) are underused — great for filtering reports, prices, or years. - Keep queries under ~6 operators — past that, results often collapse to zero.
- Don't mix too many exclusions (
-word) at once — each one risks eliminating valid results. - Don't forget quotes on multi-word exact matches —
site:x.com annual report≠site:x.com "annual report". - Don't use
ANDexplicitly — it's implicit between terms in most engines and can sometimes break syntax. - Don't assume
filetype:is foolproof — some PDFs/docs are blocked from indexing or mislabeled. - Don't overlook that some dorks (especially
inurl:admin,intitle:"index of") can surface sensitive data — use only for legitimate security research or OSINT with proper authorization. - Don't forget search engines periodically change operator support — verify an operator still works if results seem empty.