Utilities
Google dork builder
Pick a template (exposed files, login pages, directory listings…), fill in a domain or keyword, and get a ready-to-run Google query using operators like site:, filetype:, intitle:, and inurl:.
Template
Used by site:-based templates.
Optional, used where the template needs a term.
Generated query81 chars
site:example.com (filetype:pdf OR filetype:xlsx OR filetype:docx OR filetype:csv)Educational use only: searching is lawful, but accessing clearly non-public systems or downloading sensitive material you find is not. If a dork reveals someone's exposed data, report it to them, don't keep it.
Advanced search operators turn Google from a question-answer box into a recon scope. site: restricts results to one domain, filetype: surfaces documents by extension, intitle: and inurl: look into structural fields that normal keywords ignore, and minus or quoted phrases subtract noise or demand exact wording. Security teams routinely find their own stray spreadsheets, config backups and staging panels with nothing more than a composed query and a scroll through the second page of results.
The builder on this page composes those queries point-and-click. Pick a template like exposed files or login pages, fill in a domain or keyword, and copy a syntactically correct query or open it directly in Google. No syntax is memorized, no operator precedence guessed.
What dorking is and is not
A dork is not an exploit. It is a legal Google search whose operators happen to select for sensitive patterns that creators forgot they indexed: open directory listings, public S3 XML, forgotten phpinfo pages, and backups named with tilde suffixes. The typical workflow is defensive, an organization scopes queries to its own domains to find what scanners will find anyway, and investigative, where researchers scope a topic to a filetype to locate datasets.
Search engines occasionally show snippets of content that the origin later deleted; assume anything ever indexed remains retrievable through caches and archives even after the source removes it.
How the templates map to risk
Templates are grouped by intent: exposure of files by extension, discovery of login or admin interfaces by title, discovery of directory listings by inurl:, and locating documents that contain a keyword pair. Each operator is shown with its effect so a composed query is inspectable before it is run: you can see why site:example.com filetype:pdf produces PDFs from that site, or why intitle:"index of ..\" inurl:/backup narrows to backup listings whose title signals directory exposure.
A common error is quoting too aggressively so the search returns nothing. The builder manages quoting around multi-word keywords automatically and leaves single distinctive tokens bare.
- Start narrow: one domain plus one operator, then widen after you see the pattern of false positives.
- Work page two and beyond; operators rank imperfectly and interesting misses hide behind mediocre snippets.
- Never open or download material from a system where you know you lack authorization to view it.
Legal and ethical framing
Searching Google is lawful. Using results to access accounts, lift private data, or pester an owner is not. The responsible norm when you find exposed sensitive material on someone else's domain is disclosure to the owner, not collection or amplification. When the domain is yours, privileged and stray files should be removed or locked, and their presence should trigger a review of deployment hygiene that allowed them to be public in the first place.
Our terms prohibit harassment, stalking and unauthorized access, regardless of how trivial operators made discovery. The tool exists to help owners preempt what scanners automate continuously.
Choose a category, type the domain you control or the keyword you are researching, and review the generated query before running it. Ten minutes of dorking your own properties each quarter finds the slips that scanners will otherwise find for you.
How it works
Choose a template category.
Fill in the domain and/or keyword fields; the query updates as you type.
Copy it, or open it directly in Google.
Questions about this tool
Are Google dorks illegal?
Searching Google is legal. What you do with results isn't always, accessing systems you shouldn't, or downloading data you know is private, is not protected by anything. Found something sensitive? Report it to its owner.
Who uses these?
Security teams dork their own domains to find stray spreadsheets and staging panels before someone malicious does. Researchers use the same queries to scope investigations.