๐ต๏ธโโ๏ธ OSINT Bible 2026
August 9, 2026 ยท View on GitHub
Compilation, procedures, tools and ethics for open source research
โ ๏ธ Ethical Disclaimer
This repository is dedicated to the responsible and ethical practice of Open-Source Intelligence (OSINT). All information, tools, and methodologies provided herein are intended solely for educational, research, and lawful investigative purposes. Users are strongly encouraged to adhere to ethical guidelines, respect privacy rights, comply with applicable laws and regulations, and obtain necessary permissions before conducting any investigations. Misuse of this information for illegal activities, harassment, or violation of privacy is strictly prohibited and may result in legal consequences. By accessing this repository, you agree to use the content responsibly and ethically.
๐งญ Quick Index with Buttons
Foundations
1. Fundamentals | 2. 4-Step Methodology | 3. Tools Mind Map | 11. Legal Considerations | 28. Professional Methodologies
Investigation Techniques
4. Internet Search | 5. Social Networks | 6. GEOINT & Images | 7. Domain / IP / DNS | 15. Email/Phone Investigation | 17. Blockchain/Crypto | 18. Transport OSINT | 19. WiFi/Wardriving | 20. Content Verification | 21. Username Enumeration | 22. Web Scraping | 23. Metadata Extraction | 24. Network Scanning | 29. Advanced Google Dorks | 31. People Investigations | 32. Company Research
Sources & Data
8. Deep & Dark Web | 16. Data Breaches | 25. Dark Web | 30. Learning Resources | 12. Extra Resources
Frameworks & Automation
9. Automation (Python) | 10. Report Templates | 13. AI Intelligence | 14. Facial Recognition | 26. All-in-One Frameworks | 27. Advanced Maltego
Specialized
33. Threat Intelligence Feeds | 34. ICS/OT & Critical-Infrastructure OSINT | 35. AI Agent Skills & MCP
2026 Expansion
36. Financial OSINT | 37. Investigator OPSEC & Sock Puppets | 38. Cloud Storage OSINT | 39. Mobile App OSINT | 40. Decentralized Social OSINT | 41. Counter-OSINT Self-Audit | 42. Discord & Telegram OSINT 2026 | 43. Satellite OSINT 2026 | 44. C2PA + SynthID + Deepfake Detection 2026 | 45. Professional Templates & Deliverables | 46. Regional OSINT | 47. Corporate OSINT Tradecraft | Appendix B. Structured Analytic Techniques
Tip
Extend OSINT-BIBLE with the companion tools that fit your workflow:
- Operationalize its methodologies with osint-agent-skills.
- Investigate privately with Abster-Intelligence.
- Automate auditable workflows with agentic-harness.
1. Fundamentals
| Concept | Quick Definition |
|---|---|
| OSINT | Intelligence obtained from public sources without violating logical or physical access |
| OPSEC | Minimize footprint: VPN โ VM โ alias โ metadata strip |
| Intelligence Cycle | Direction โ Collection โ Processing โ Analysis โ Dissemination |
| PII | Information that identifies: email, phone, RFC, CURP, IP, IMEI, MAC |
| Primary Source | Original publication (tweet, official PDF, photo EXIF) |
| Secondary Source | Article citing the primary (validate) |
2. 4-Step Methodology
- Define question โ What do I want to know?
- Identify sources โ Table below |
- Collect โ Manual + automations |
- Validate and document โ Screenshots, hash, date, URL, archive.org |
| Data Type | Usual Location | Star Tool |
|---|---|---|
| Name | LinkedIn, Facebook | Maigret |
| Data breaches, newsletters | HIBP | |
| Phone | WhatsApp Business, TrueCaller | Infobel |
| Username | Forums, gaming, GitHub | Snoop |
| Photo | Geolocation, EXIF | Exiftool |
| Domain | WHOIS, certificates | Amass |
| IP | Scanning, Shodan | Shodan |
| Crypto wallet | Blockchain explorers | BlockCypher |
3. Tools Mind Map
graph TD
A[OSINT] --> B(Search)
A --> C(Social Networks)
A --> D(Geo)
A --> E(Domain/IP)
A --> F(DeepDark)
A --> G(Automate)
B --> B1(Google Dorks)
B --> B2(Useful Dorks)
C --> C1(Twint-fork)
C --> C2(Maigret)
C --> C3(Instaloader)
D --> D1(Overpass-turbo)
D --> D2(Satellites.pro)
D --> D3(ExifTool)
E --> E1(Amass)
E --> E2(CRT.sh)
E --> E3(DNSDumpster)
F --> F1(Onionscan)
F --> F2(Ahmia)
G --> G1(Recon-ng)
G --> G2(SpiderFoot)
4. Internet Search
4.1 Google Dorks โ 20 essentials
| Objective | Dork | Example |
|---|---|---|
| Government PDFs | site:gov filetype:pdf "contract" | Mexico |
| Exposure | intitle:"index of" passwords.txt | โ |
| IP Cameras | inurl:viewer/live/index.html | โ |
| Emails | site:linkedin.com "@company.com" | โ |
| Subdomains | site:*.target.com -www | โ |
4.2 Alternative Search Engines
- DuckDuckGo "bangs" โ
!archive - Yandex โ best results CIS
- Baidu โ Asia
- Startpage โ no logs
- Shodan โ IoT, ICS, SCADA
- Censys โ cert + banner
- FOFA โ China, free API
- BinaryEdge โ global scanning
- Hunter.io โ corporate emails
- PublicWWW โ search in source code
- SearchCode โ search in 75B lines of code
- SimilarSites โ similar sites
- Netlas โ internet intelligence
- CriminalIP โ search in connected internet
- NerdyData โ website technologies
- GreyNoise โ internet noise
- Intezer Analyze โ malware analysis
- Kaspersky OpenTIP โ threat scanning
- VirusTotal โ file/URL analysis
- AlienVault OTX โ threat exchange
- ExploitDB โ exploit database
- MalwareBazaar โ malware samples
- Malware Domain List โ malicious domains
- PhishTank โ phishing URLs
- URLhaus โ malware URLs
- ThreatMiner โ threat intelligence
- YARAify โ YARA rules
- PulseDive โ IOC search
- ThreatFox โ malware IOCs
- Breach Directory โ breach searches
- Have I Been Pwned โ breach verification
- DNSViz โ DNSSEC visualization
- DNSdumpster โ DNS enumeration
- SpyOnWeb โ related sites
- Yark โ archive YouTube
- CovertAction โ investigative journalism
- Trellix Research โ threat research
- CP Research โ Checkpoint research
- Wikistrat โ collaborative analysis
- PolySwarm โ threat scanning
- HackerOne Hacktivity โ public vulnerabilities
- WikiLeaks โ leaked documents
- Talos Reports โ vulnerability reports
- MalAPI โ malware APIs
- UserSearch โ user search
- SecureList โ Kaspersky blog
- SPLC Hate Map โ hate map
- ICSR โ radicalization studies
- Militant Wire โ militancy analysis
- START Publications โ terrorism publications
- SPLC Resources โ SPLC resources
- Tracking Terrorism โ terrorism tracking
- Mapping Militants โ mapping militants
- Naval Institute โ naval news
- Institute of International Relations โ international relations
- Janes โ defense intelligence
- TASS News โ Russian news
- Sputnik News โ Sputnik news
- PIPS โ Pakistan peace studies
- PICSS โ Pakistan conflict studies
- Reuters โ news agency
- RT โ Russia Today
- InternetActivism โ humanitarian tools
- IISS โ international studies institute
- CFR โ council on foreign relations
- SciHub โ access to scientific papers
- ResearchHub โ research discussion
- IDCrawl โ people search
- Osint Industries โ email/phone search
- ESPY โ phone search
- SUNDERS โ surveillance cameras
- Deepinfo โ internet intelligence
- Session โ private messaging
- Consortium News โ independent journalism
- Tutanota โ encrypted email
- Committee to Protect Journalists โ journalist protection
- SecurityWeek โ security news
- NCRI โ network contagion research
- Geopolitical Economy Report โ geopolitical reports
- The Grayzone โ independent journalism
- FlightAware โ flight tracking
- FlightRadar24 โ flight radar
- MarineTraffic โ maritime traffic
- VesselFinder โ ship search
- NewspaperArchive โ newspaper archives
- The Indian Express โ Indian news
- Daily Excelsior โ Jammu Kashmir news
- DNA India โ Indian news
- Greater Kashmir โ Kashmir news
- Nagaland Post โ Nagaland news
- RFE/RL โ Radio Free Europe
- Akto โ API security
- Generated Photos โ AI photos
- HDRobots โ AI tools directory
- Channel 4 News โ British news
- ThreatMon Reports โ threat reports
- Israel Datasets โ Israeli datasets
- AI Dubbing โ AI dubbing
- Budget Key โ Israel budget
- Ship Spotting โ ship photos
- Broadcastify โ police audio
- OpenCelliD โ cell tower database
- AviationStack โ aviation API
- DocumentCloud โ document management
- IDRW โ Indian defense
- XFE โ X-Force exchange
- Scumware โ malware research
- Ukraine Live Cams โ Ukraine cameras
- TWN โ webcam network
- Opentopia โ public webcams
- Transparency โ anti-corruption
- Maigret โ user search
- OCCRP โ organized crime
- Qdorks โ dork generator
- Radio Garden โ world radios
- LolArchiver OSINT โ OSINT search
- BreachBase โ breach base
- WorldCam โ world webcams
- Webcam Galore โ webcams
- WiFi Map โ WiFi hotspots
- OpenTrafficCamMap โ traffic cameras
- Skyline Webcams โ skyline webcams
- Pictimo โ world webcams
- Instances.social โ Mastodon recommender
- CamHacker โ public webcams
- Labs TIB Geoestimation โ geographic estimation
- Picarta โ photo location prediction
- Tiny Scan โ URL scanning
- ZeroDay โ zero-day vulnerabilities
- Predicta Search โ digital search
- Ventusky โ weather maps
- OSV โ open source vulnerabilities
- Coalition ESS โ exploit scoring
- Validin โ attack surface mapping
- CIRCL PDNS โ passive DNS
- InTheWild โ exploits in wild
- 360 Quake โ cyberspace mapping
- Cloudflare Radar โ internet trends
- Crisis24 โ security risk management
- arXiv โ scientific papers
4.3 Archives and snapshots
- Wayback Machine
- CachedView (Google + Archive.is)
- URLScan โ capture + DOM + requests
- Ubikron โ AI-powered evidence collection & entity extraction
- Screenshot Guru โ screen test
- Stored Website โ cached pages
- ThreatMiner โ IOC context
- YARAify โ YARA rules
- PulseDive โ IOC search
- ThreatFox โ malware IOCs
- Breach Directory โ breaches
- Have I Been Pwned โ breach verification
- DNSViz โ DNSSEC
- DNSdumpster โ DNS enumeration
- SpyOnWeb โ related sites
- Yark โ archive YouTube
5. Social Networks
5.1 Facebook
- Facebook Recover Lookup - Link: Facebook Recover Lookup - Description: Used to check if a given email or phone number is associated with any Facebook account or not.
- Social Searcher - Link: Social Searcher - Description: Allows you to monitor all public social mentions in social networks and the web.
- Lookup-id.com - Link: Lookup-id.com - Description: Helps you find the Facebook ID of anyone's profile or a Group.
- Who posted this - Link: Who posted this - Description: Facebook keyword search for people who work in the public interest. It allows you to search keywords on specific dates.
- Facebook Search - Link: Facebook Search - Description: Allows you to search on Facebook for posts, people, photos, etc., using some filters.
- Facebook Graph Searcher - Link: Facebook Graph Searcher - Description: To search someone on Facebook.
- Facebook People Search - Link: Facebook People Search - Description: Search on Facebook by victim's name.
- DumpItBlue - Link: DumpItBlue+ - Description: helps to dump Facebook stuff for analysis or reporting purposes.
- Export Comments - Link: Export Comments - Description: Easily exports all comments from your social media posts to Excel file.
- Facebook Applications - Link: Facebook Applications - Description: A collection of online tools that automate and facilitate Facebook.
- Social Analyzer - Link: SocialAnalyzer - Social Sentiment & Analysis - Description: a free tool of social media monitoring and analysis.
- AnalyzeID - Link: AnalyzeID - Description: Just looking for sites that supposedly may have the same owner. Including a FaceBook App ID match.
- SOWsearch - Link: sowsearch - Description: a simple interface to show how the current Facebook search function works.
- Facebook Matrix - Link: FacebookMatrix - Description: Formulas for Searching Facebook.
- Who posted what - Link: Who Posted What - Description: A non public Facebook keyword search for people who work in the public interest. It allows you to search keywords on specific dates.
- StalkFace - Link: StalkFace - Description: Toolkit to stalk someone on Facebook.
- Search is Back - Link: Search is Back - Description: ind people and events on Facebook Search by location, relationships, and more!.
- FB-Search - Link: FB-Search - Description: busca por telรฉfono o correo.
- FB-Posts-scraper - Link: FB-Posts-scraper - Description: (Python).
- FB-Video-downloader - Link: FB-Video-downloader - Description: .
5.2 Instagram
- IFTTT Integrations - Link: IFTTT Instagram integrations - Description: Popular Instagram workflows & automations.
- IMGinn.io - Link: IMGinn.io - Description: view and download all the content on the social network Instagram all at one place.
- Instaloader - Link: Instaloader - Description: Download pictures (or videos) along with their captions and other metadata from Instagram.
- SolG - Link: SolG - Description: The Instagram OSINT Tool gets a range of information from an Instagram account that you normally wouldn't be able to get from just looking at their profile.
- Osintgram - Link: Osintgram - Description: Osintgram is an OSINT tool on Instagram to collect, analyze, and run reconnaissance.
- Toutatis - Link: toutatis - Description: It is a tool written to retrieve private information such as Phone Number, Mail Address, ID on Instagram accounts via API.
- instalooter - Link: instalooter - Description: InstaLooter is a program that can download any picture or video associated from an Instagram profile, without any API access.
- Exportgram - Link: Exportgram - Description: A web application made for people who want to export instagram comments into excel, csv and json formats.
- Profile Analyzer - Link: Profile Analyzer - Description: Analyze any public profile on Instagram โ the tool is free, unlimited, and secure. Enter a username to take advantage of precise statistics.
- Find Instagram User Id - Link: Find Instagram User Id - Description: This tool called "Find Instagram User ID" provides an easy way for developers and designers to get Instagram account numeric ID by username.
- Instahunt - Link: Instahunt - Description: Easily find social media posts surrounding a location.
- Musicaldown - Link: Musicaldown - Description: web.
5.3 LinkedIn
- RecruitEm - Link: RecruitEm - Description: Allows you to search social media profiles. It helps recruiters to create a Google boolean string that searches all public profiles.
- RocketReach - Link: RocketReach - Description: Allows you to programmatically search and lookup contact info over 700 million professionals and 35 million companies.
- Phantom Buster - Link: Phantom Buster - Description: Automation tool suite that includes data extraction capabilities.
- linkedprospect - Link: LinkedIn Boolean Search - Description: Build a targeted list of LinkedIn people using boolean search.
- ReverseContact - Link: Reverse Email Lookup - Description: Find Linked Profiles associated with any email.
- LinkedIn Search Engine - Link: Programmable Search Engine - Description: Programmable Search Engine for LinkedIn profiles.
- Free People Search Tool - Link: Free People Search Tool - Description: Find people easily online.
- IntelligenceX Linkedin - Link: IntelligenceX Linkedin - Description: A webbased tool for searching someone on Linkedin.
- Linkedin Search Tool - Link: Linkedin Search Tool - Description: Provides you a interface with various tools for Linkedin Osint.
- LinkedInt - Link: LinkedInt - Description: Providing you with Linkedin Intelligence.
- InSpy - Link: InSpy - Description: InSpy is a python based LinkedIn enumeration tool.
- CrossLinked - Link: CrossLinked - Description: CrossLinked is a LinkedIn enumeration tool that uses search engine scraping to collect valid employee names from an organization.
- Hunter.io - Link: Hunter.io - Description: Find and verify corporate email patterns. 25 free searches per month.
5.4 Twitter/X
- TweetDeck - Link: TweetDeck - Description: Offers a more convenient Twitter experience by allowing you to view multiple timelines in one easy interface.
- FollowerWonk - Link: FollowerWonk - Description: Helps you find Twitter accounts using bio and provides many other useful features.
- Twitter Advanced Search - Link: Twitter Advanced Search - Description: Allows you to search on Twitter using filters for better search results.
- memory.lol - Link: memory.lol - Description: a tiny web service that provides historical information about twitter users.
- SocialData API - Link: SocialData API - Description: an unofficial Twitter API alternative that allows scraping historical tweets, user profiles, lists and Twitter spaces without using Twitter's API.
- Social Bearing - Link: Social Bearing - Description: Insights & analytics for tweets & timelines.
- Tinfoleak - Link: Tinfoleak - Description: Search for Twitter users leaks.
- Network Tool - Link: Network Tool - Description: Explore how information spreads across Twitter with an interactive network using OSoMe data.
- Foller - Link: Foller - Description: Looking for someone in the United States? Our free people search engine finds social media profiles, public records, and more!
- SimpleScraper OSINT - Link: SimpleScraper OSINT - Description: This Airtable automatically scrapes OSINT-related twitter accounts ever 3 minutes and saves tweets that contain coordinates.
- Deleted Tweet Finder - Link: Deleted Tweet Finder - Description: Search for deleted tweets across multiple archival services.
- Twitter Search Tool - Link: Twitter search tool - Description: On this page you can create advanced search queries within Twitter.
- Twitter Video Downloader - Link: Twitter Video Downloader - Description: Download Twitter videos & GIFs from tweets.
- Download Twitter Data - Link: Download Twitter Data - Description: Download Twitter data in csv format by entering any Twitter handle, keyword, hashtag, List ID or Space ID.
- Twitonomy - Link: Twitonomy - Description: Twitter #analytics and much more.
- tweeterid - Link: tweeterid - Description: Type in any Twitter ID or @handle below, and it will be converted into the respective ID or username.
- BirdHunt - Link: BirdHunt - Description: Easily find social media posts surrounding a location.
- Twint-docker - Link: Twint-docker - Description: Download all tweets from a user without API access.
- Sentiment140 - Link: Sentiment140 - Description: Bulk sentiment analysis for tweets via CSV.
- Xquik - Link: Xquik - Description: 122 API endpoints for search, user, post and monitor. API key, USD 0.00015/read.
5.5 Pinterest
- DownAlbum - Link: DownAlbum - Description: Google Chrome extension for downloading albums of photos from various websites, including Pinterest.
- Experts PHP: Pinterest Photo Downloader - Link: Pinterest Photo Downloader - Description: Website providing a tool to download photos from Pinterest.
- Pingroupie - Link: Pingroupie - Description: A Meta Search Engine for Pinterest that lets you discover Collaborative Boards, Influencers, Pins, and new Keywords.
- Tailwind - Link: Tailwind - Description: Social media scheduling and management tool that supports Pinterest.
- Pinterest Guest - Link: Pinterest Guest - Description: Mozilla Firefox add-on for browsing Pinterest without logging in or creating an account.
5.6 Reddit
- F5BOT - Link: F5BOT - Description: Receive notifications for new Reddit posts matching specific keywords.
- Mostly Harmless - Link: Mostly Harmless - Description: A suite of tools for Reddit, including user analysis, subreddit comparison, and more.
- OSINT Combine: Reddit Post Analyzer - Link: OSINT Combine: Reddit Post Analyzer - Description: Analyze and gather information from Reddit posts for OSINT purposes.
- Phantom Buster - Link: Phantom Buster - Description: Automation tool suite that includes Reddit data extraction capabilities.
- rdddeck - Link: rdddeck - Description: Real-time dashboard for monitoring multiple Reddit communities.
- Readr for Reddit - Link: Readr for Reddit - Description: Google Chrome extension for an improved reading experience on Reddit.
- Reddit Archive - Link: Reddit Archive - Description: Archive of Reddit posts and comments for historical reference.
- Reddit Comment Search - Link: Reddit Comment Search - Description: Search for specific comments and conversations on Reddit.
- Redditery - Link: Redditery - Description: Explore Reddit posts and comments based on various criteria.
- Reddit Hacks - Link: Reddit Hacks - Description: Collection of Reddit hacks and tricks for advanced users.
- Reddit List - Link: Reddit List - Description: Directory of popular subreddits organized by various categories.
- reddtip - Link: reddtip - Description: Show appreciation to Reddit users by sending them tips in cryptocurrencies.
- Reddit Search - Link: Reddit Search (realsrikar) - Description: Various tools and websites for searching and discovering content on Reddit.
- Reddit Shell - Link: Reddit Shell - Description: Command-line interface for browsing and interacting with Reddit.
- Reddit Stream - Link: Reddit Stream - Description: Live-streaming of Reddit comments for real-time discussions.
- Reddit Suite - Link: Reddit Enhancement Suite (Chrome Extension) - Description: Browser extension that enhances the Reddit browsing experience with additional features.
- Reddit User Analyser - Link: Reddit User Analyser - Description: Analyze and visualize the activity and behavior of Reddit users.
- redditvids - Link: redditvids - Description: Watch Reddit videos and browse popular video subreddits.
- Reditr - Link: Reditr - Description: Desktop Reddit client with a clean and intuitive interface.
- Reeddit - Link: Reeddit - Description: Simplified and clean Reddit web interface for a distraction-free browsing experience.
- smat - Link: smat - Description: Social media analytics tool that includes Reddit for tracking trends and engagement.
- socid_extractor - Link: socid_extractor - Description: Extract user information from Reddit and other social media platforms.
- Suggest me a subreddit - Link: Suggest me a subreddit - Description: Get recommendations for new subreddits to explore based on your preferences.
- Subreddits - Link: Subreddits - Description: Directory of active subreddits organized by various categories.
- uforio - Link: uforio - Description: Generate word clouds from Reddit comment threads.
- Universal Reddit Scraper (URS) - Link: Universal Reddit Scraper (URS) - Description: Python-based tool for scraping Reddit data for analysis.
- Vizit - Link: Vizit - Description: Visualize and analyze relationships between Reddit users and subreddits.
- Wisdom of Reddit - Link: Wisdom of Reddit - Description: Curated collection of insightful quotes and comments from Reddit.
5.7 Github Leak Detection
- Awesome Lists - Link: Awesome Lists - Description: A curated list of awesome lists for various programming languages, frameworks, and tools.
- CoderStats - Link: CoderStats - Description: A platform for developers to track and showcase their coding activity and statistics from GitHub.
- Digital Privacy - Link: Digital Privacy - Description: A collection of resources and tools for enhancing digital privacy and security.
- Find Github User ID - Link: Find Github User ID - Description: A web tool for finding the unique identifier (ID) of a GitHub user.
- GH Archive - Link: GH Archive - Description: A project that provides a public dataset of GitHub activity, including events and metadata.
- GitGot - Link: GitGot - Description: A semi-automated, feedback-driven tool for auditing Git repositories.
- gitGraber - Link: gitGraber - Description: A tool for searching and cloning sensitive information in GitHub repositories.
- git-hound - Link: git-hound - Description: A tool for finding sensitive information exposed in GitHub repositories.
- Github Dorks - Link: Github Dorks - Description: A collection of GitHub dorks, which are search queries to find sensitive information in repositories.
- Github Stars - Link: Github Stars - Description: A website that showcases GitHub repositories with the most stars and popularity.
- Github Trending RSS - Link: Github Trending RSS - Description: An RSS feed generator for trending repositories on GitHub.
- Github Username Search Engine - Link: Github Username Search Engine - Description: A search engine to find GitHub usernames based on various filters and criteria.
- Github Username Search Engine - Link: Github Username Search Engine - Description: Another search engine to find GitHub usernames with advanced filtering options.
- GitHut - Link: GitHut - Description: A website that provides statistics and visualizations of programming languages on GitHub.
5.7.x.1 Verified Tools
| Tool | URL | Function |
|---|---|---|
| GitGot | https://github.com/BishopFox/GitGot | GitHub repo audit |
| gitGraber | https://github.com/hisxo/gitGraber | GitHub secrets search |
| GitHound | https://github.com/tillson/git-hound | Sensitive info search |
| TruffleHog | https://github.com/trufflesecurity/trufflehog | Credential detection with verification |
| Gitleaks | https://github.com/gitleaks/gitleaks | Fast secrets detection |
5.7.x.2 GitHub Dorks โ 15 Practical Examples
1. ORGNAME filename:.env AWS_SECRET_ACCESS_KEY
2. ORGNAME filename:.env MAIL_PASSWORD
3. ORGNAME filename:.npmrc _auth
4. ORGNAME filename:.dockercfg
5. ORGNAME filename:config.rb password
6. ORGNAME filename:id_rsa BEGIN OPENSSH PRIVATE KEY
7. ORGNAME filename:id_dsa BEGIN DSA PRIVATE KEY
8. ORGNAME extension:pem PRIVATE KEY
9. ORGNAME filename:.git-credentials
10. ORGNAME filename:settings.py SECRET_KEY
11. ORGNAME filename:wp-config.php DB_PASSWORD
12. ORGNAME filename:database.yml password
13. ORGNAME "api.openai.com" Authorization:Bearer
14. ORGNAME extension:sh AWS_ACCESS_KEY_ID
15. ORGNAME filename:terraform.tfvars
Variations: fork:true to include forks ยท archived:true for archived repos ยท pushed:>2026-01-01 for recent.
5.7.x.3 Tool Workflows
TruffleHog (active credential verification):
# Install
go install github.com/trufflesecurity/trufflehog/v3@latest
# Scan repo with full history:
trufflehog git https://github.com/ORGNAME/repo.git --only-verified
# Scan organisation:
trufflehog github --org=ORGNAME --only-verified
# JSON output:
trufflehog git https://github.com/ORGNAME/repo.git --json --only-verified > findings.json
The --only-verified flag filters only secrets confirmed active. Reduces false positives.
gitGraber (continuous monitoring in cron):
git clone https://github.com/hisxo/gitGraber.git
cd gitGraber
# Configure config.py with GITHUB_TOKENS, WORDLIST, SLACK_WEBHOOK
# First run:
python3 gitGraber.py --wordlist wordlists/your_wordlist.txt --output
# Cron every 6h:
# 0 */6 * * * cd /opt/gitGraber && python3 gitGraber.py --wordlist ...
GitGot (interactive audit):
pip install gitgot
python3 gitgot.py -q "ORGNAME"
# Interactive session: [i]gnore, [s]ave, [r]eview, [q]uit
5.7.x.4 Ethical Considerations
- Accessing a public repo is legitimate. GitHub public is public.
- NOT legitimate: using a found secret to escalate access. The difference between defensive OSINT and attack is use, not access.
- Responsible disclosure: discovering a leak obliges you to notify the repo owner. 90 days before public disclosure (Project Zero standard).
- Do not include the full secret in the client report. Format
ghp_โขโขโขโขโขโข[last4]. - GitHub Security Advisory for leaks in third-party repos.
5.8 Snapchat
- addmeContacts - Link: addmeContacts - Description: A platform to find and connect with new contacts on various social media platforms.
- AddMeSnaps - Link: AddMeSnaps - Description: A website for discovering and adding new Snapchat friends.
- ChatToday - Link: ChatToday - Description: An online chat platform for connecting and chatting with people from around the world.
- Gebruikersnamen: Snapchat - Link: Gebruikersnamen: Snapchat - Description: A website for finding Snapchat usernames.
- OSINT Combine: Snapchat MultiViewer - Link: OSINT Combine: Snapchat MultiViewer - Description: A tool for viewing multiple Snapchat accounts simultaneously.
- Snapchat-mapscraper - Link: Snapchat-mapscraper - Description: A tool for scraping public Snapchat Stories from the Snap Map.
- Snap Political Ads Library - Link: Snap Political Ads Library - Description: Snapchat's library of political ads displayed on the platform.
- Social Finder - Link: Social Finder - Description: A platform to search and discover social media profiles on various platforms.
- SnapIntel - Link: SnapIntel - Description: a python tool providing you information about Snapchat users.
- AddMeS - Link: AddMeS - Description: The 'Add Me' directory of Snapchat users on web.
5.9 WhatsApp
- checkwa - Link: checkwa - Description: An online tool to check the status and availability of WhatsApp numbers.
- WhatsApp Fake Chat - Link: WhatsApp Fake Chat - Description: An online tool to generate fake WhatsApp conversations for fun or pranks.
- whatsfoto - Link: whatsfoto - Description: A Python script to download profile pictures from WhatsApp contacts.
- CheckLeaked WhatsApp - Link: CheckLeaked WhatsApp - Description: An online tool to look up WhatsApp numbers โ download the current and historical profile pictures, read the About/bio text, and detect Business/Enterprise accounts. Free web interface with an optional API.
5.10 Skype
- addmeContacts - Link: addmeContacts - Description: A platform to find and connect with new contacts on various social media platforms.
- ChatToday - Link: ChatToday - Description: An online chat platform for connecting and chatting with people from around the world.
- Skypli - Link: Skypli - Description: A website for discovering and connecting with new Skype contacts.
5.11 Telegram
- ChatBottle: Telegram - Link: ChatBottle: Telegram - Description: A directory of Telegram bots for various purposes.
- ChatToday - Link: ChatToday - Description: An online chat platform for connecting and chatting with people from around the world.
- informer - Link: informer - Description: A Python library for retrieving information about Telegram channels, groups, and users.
- _IntelligenceX: Telegram - Link: _IntelligenceX: Telegram - Description: IntelligenceX's Telegram tool for searching and analyzing Telegram data.
- Lyzem.com - Link: Lyzem.com - Description: A website to search and find Telegram groups and channels.
- Telegram Channels - Link: Telegram Channels - Description: A directory of Telegram channels covering various topics.
- Telegram Channels - Link: Telegram Channels - Description: A platform to discover and browse Telegram channels.
- Telegram Channels Search - Link: Telegram Channels Search - Description: A search engine to find Telegram channels by keywords.
- Telegram Directory - Link: Telegram Directory - Description: A comprehensive directory of Telegram channels, groups, and bots.
- Telegram Group - Link: Telegram Group - Description: A website to search and join Telegram groups.
- telegram-history-dump - Link: telegram-history-dump - Description: A Python script to dump the history of a Telegram chat into a SQLite database.
- Telegram-osint-lib - Link: Telegram-osint-lib - Description: A Python library for performing open-source intelligence (OSINT) on Telegram.
- Telegram Scraper - Link: Telegram Scraper - Description: A powerful Telegram scraping tool for extracting user information and media.
- Tgram.io - Link: Tgram.io - Description: A platform to explore and search for Telegram channels, groups, and bots.
- Tgstat.com - Link: Tgstat.com - Description: A comprehensive platform for analyzing and tracking Telegram channels and groups.
- Tgstat RU - Link: Tgstat RU - Description: A Russian platform for analyzing and monitoring Telegram channels and groups.
5.12 Discord
- DiscordOSINT - Link: DiscordOSINT - Description: This Repository Will contain useful resources to conduct research on Discord.
- Discord.name - Link: Discord.name - Description: Discord profile lookup using user ID.
- Discord History Tracker - Link: Discord History Tracker - Description: Discord History Tracker lets you save chat history in your servers, groups, and private conversations, and view it offline.
- Top.gg - Link: Top.gg - Description: Explore millions of Discord Bots.
- Unofficial Discord Lookup - Link: Unofficial Discord Lookup - Description: Search for discord profile using id.
- Disboard - Link: Disboard - Description: DISBOARD is the place where you can list/find Discord servers.
5.13 ONLYFANS
- OnlyFans Finder - Link: The Favourite OnlyFans search - Description: The tools allow easy searching via advanced filtering capabilities and sorting functionality, making it easy to access desired material.
- OnlyFam - Link: OnlyFam - Description: OnlyFans Search & Model Finder - Find Creators in the World's Largest OnlyFans Database
- OnlyFinder - Link: OnlyFinder - Description: OnlyFans Search Engine - OnlyFans Account Finder.
- OnlySearch - Link: OnlySearch - Description: Find OnlyFans profiles by searching for key words.
- Sotugas - Link: SรณTugas - Description: Encontra Contas do OnlyFans Portugal ๐ต๐น.
- Fansmetrics - Link: Fansmetrics - Description: Use this OnlyFans Finder to search in 3,000,000 OnlyFans Accounts.
- Findr.fans - Link: Findr.fans - Description: Only Fans Search Tool.
- Hubite - Link: Hubite - Description: Advanced OnlyFans Search Engine.
- Similarfans - Link: Similarfans - Description: Blog for OnlyFans content creators.
- Fansearch - Link: Fansearch - Description: Fansearch is the best OnlyFans Finder to search in 3,000,000 OnlyFans Accounts.
5.14 TikTok
- Mavekite - Link: Mavekite - Description: Search the profile using username.
- TikTok hashtag analysis toolset - Link: TikTok hashtag analysis toolset - Description: The tool helps to download posts and videos from TikTok for a given set of hashtags over a period of time.
- TikTok Video Downloader - Link: TikTok Video Downloader - Description: ssstiktok is a free TikTok video downloader without watermark tool that helps you download TikTok videos without watermark (Musically) online.
- Exolyt - Link: exolyt - Description: The best tool for TikTok analytics & insights.
6. Geoint & Images
6.1 Metadata
exiftool -a -u foto.jpg | grep -i "gps\|date\|camera"
# strip before publishing
exiftool -all= foto_sanitizada.jpg
6.2 Geolocate
- Google Earth Pro โ temporal displacement
- Suncalc โ shadow = time
- Overpass-turbo โ POI within radius
- FlightAware โ flight tracking
- FlightRadar24 โ flight radar
- MarineTraffic โ maritime traffic
- VesselFinder โ ships
- WiGLE โ geolocated WiFi database
- OpenCelliD โ cell towers
- Broadcastify โ police audio
- AviationStack โ aviation API
- Labs TIB Geoestimation โ geographic estimation
- Picarta โ photo location prediction
- Ventusky โ weather maps
- Ukraine Live Cams โ Ukraine cameras
- TWN โ webcam network
- Opentopia โ public webcams
- WorldCam โ world webcams
- Webcam Galore โ webcams
- OpenTrafficCamMap โ traffic cameras
- Skyline Webcams โ skyline webcams
- Pictimo โ world webcams
- CamHacker โ public webcams
6.3 Satellite / Drone
- Sentinel-Hub โ 10m resolution, free
- NASA-FIRMS โ real-time fires
- Zoom Earth โ METAR overlay
- FlightRadar24 โ flight radar
- ADS-B Exchange โ no military filters
- FlightAware โ flight history
- PiAware (Raspberry Pi) โ own ADS-B receiver
- MarineTraffic โ global AIS tracking
- VesselFinder โ free alternative
- ShipSpotting โ ship photo database
6.4 Video OSINT & Chronolocation
Video as a specific OSINT source plus chronolocation (determining when material was recorded). Does not duplicate 6.1-6.3 (metadata, geolocation, satellite).
6.4.1 Video Geolocation Workflow โ 12 Steps
| # | Step | Tool |
|---|---|---|
| 1 | Identify the geolocation objective (humanitarian/journalistic/military) | โ |
| 2 | Extract keyframes with FFmpeg: ffmpeg -i video.mp4 -vf "fps=1/10" frame_%04d.png | FFmpeg |
| 3 | Extract EXIF metadata: exiftool video.mp4 | ExifTool |
| 4 | Analyse audio: language, accent, calls to prayer (adhan = time + orientation to Mecca) | โ |
| 5 | Identify visual anchors: signs, licence plates, architecture, vegetation | โ |
| 6 | Geolocate anchors individually with Google Lens / Yandex Images + Overpass Turbo | โ |
| 7 | Trace sight lines from each anchor | Google Earth Pro |
| 8 | Validate with Street View | Google Street View |
| 9 | Validate with historical satellite imagery | Google Earth Pro + Copernicus Browser |
| 10 | Determine camera cardinal orientation with SunCalc | SunCalc |
| 11 | Triangulate date (chronolocation) | See 6.4.2 |
| 12 | Document with BLUF + evidence package (each anchor with frame + screenshot + URL + hash) | โ |
6.4.2 Shadow-Based Chronolocation โ 8 Steps
- Geolocate first (6.4.1). Without lat/long, solar position cannot be calculated.
- Identify vertical object with a sharp projected shadow. Pole, column, standing person.
- Measure cardinal direction of the shadow (azimuth in degrees from Google Earth Pro).
- Measure relative length: ratio
shadow/object_height. Solar elevation =arctan(h/l). - Compute solar position with SunCalc.org (move slider until azimuth+elevation match).
- Resolve symmetric date ambiguity with contextual clues (vegetation, snow, datable events).
- Validate with historical weather. Visual Crossing Weather History (free tier).
- Document margin of error. Typically ยฑ30-90 min of time, ยฑ2-7 days of date. Report with confidence level.
6.4.3 Verified Video OSINT Tools
| Tool | URL | Function |
|---|---|---|
| FFmpeg | https://ffmpeg.org | Video analysis and processing |
| FotoForensics | https://fotoforensics.com | ELA image analysis |
| Forensically | https://29a.ch/photo-forensics | Visual analysis suite |
| ExifTool | https://exiftool.org | Metadata |
| SunCalc | https://www.suncalc.org | Solar position |
| Google Earth Pro | https://www.google.com/earth | Historical satellite |
| Sentinel Hub | https://www.sentinel-hub.com | Sentinel-2 imagery |
| yt-dlp | https://github.com/yt-dlp/yt-dlp | Video download |
| GeoConfirmed | https://geoconfirmed.org | Collaborative geolocation |
6.4.4 Real Case โ Bellingcat Bucha 2022
Following the withdrawal of Russian troops from Bucha (Ukraine) in March 2022, images of civilian bodies in Yablunska Street appeared. Russia denied responsibility. Bellingcat and The New York Times published on 4 April 2022 an analysis demonstrating that the bodies were already present during the Russian occupation, using Maxar satellite imagery from 19 March.
Methodology:
- Geolocation of each frame with a visible body in Yablunska Street.
- Acquisition of Maxar imagery from 19 March (during Russian occupation).
- Frame-by-frame comparison: dark objects on the street in the same locations where the 2 April video showed bodies. One-to-one correspondence.
- Validation with second satellite (Planet Labs, 21 March).
- Conclusion: bodies were already on the street on 19 March (Russian control). High confidence (cross-corroboration of satellite + video + testimonies).
Sources:
7. Domain / IP / DNS
| Objective | Tool | Quick Command |
|---|---|---|
| Subdomains | Amass | amass enum -d target.com -o subs.txt |
| Certificates | CRT.sh | curl https://crt.sh/?q=%25.target.com&output=json |
| Historical DNS | SecurityTrails | Free API 50/month |
| Neighbor IPs | BGP.he | CIDR |
| Reputation | VirusTotal | vt ip_info <ip> |
| Quick scan | Nmap-online | no VPN |
| Subdomains | Subdomain Center | https://www.subdomain.center |
| Subdomains | SubdomainRadar | https://www.subdomainradar.io |
| Historical DNS | DNS History | http://dnshistory.org |
| Reputation | Talos | https://www.talosintelligence.com/ |
| Scan | Binary Defense | https://www.binarydefense.com/banlist.txt |
| BGP Ranking | CIRCL BGP | https://bgpranking.circl.lu |
| Botnet Tracker | MalwareTech | https://intel.malwaretech.com/ |
| BOTVRIJ.EU | BOTVRIJ | http://www.botvrij.eu/ |
| C&C Tracker | Bambenek | http://osint.bambenekconsulting.com/feeds/c2-ipmasterlist.txt |
| CertStream | CertStream | https://certstream.calidog.io/ |
| CCSS Forum | CCSS Forum | http://www.ccssforum.org/malware-certificates.php |
| CI Army List | CINS Score | http://cinsscore.com/#list |
| Cisco Umbrella | Cisco Umbrella | http://s3-us-west-1.amazonaws.com/umbrella-static/index.html |
| Cloudmersive | Cloudmersive | https://cloudmersive.com/virus-api |
| Critical Stack | Critical Stack | https://intelstack.com/ |
| CrowdSec | CrowdSec | https://app.crowdsec.net/ |
| Cyber Cure | Cyber Cure | https://www.cybercure.ai/ |
| DataPlane | DataPlane | https://dataplane.org/ |
| Focsec | Focsec | https://focsec.com |
| Disposable Domains | Disposable Domains | https://github.com/martenson/disposable-email-domains |
| Emerging Threats | Emerging Threats | http://rules.emergingthreats.net/fwrules/ |
| ExoneraTor | ExoneraTor | https://exonerator.torproject.org/ |
| Exploitalert | Exploitalert | http://www.exploitalert.com/ |
| FastIntercept | FastIntercept | https://intercept.sh/threatlists/ |
| Feodo Tracker | Feodo Tracker | https://feodotracker.abuse.ch/ |
| FireHOL | FireHOL | http://iplists.firehol.org/ |
| FraudGuard | FraudGuard | https://fraudguard.io/ |
| Grey Noise | Grey Noise | http://greynoise.io/ |
| HoneyDB | HoneyDB | https://riskdiscovery.com/honeydb/ |
| Icewater | Icewater | https://github.com/SupportIntelligence/Icewater |
| InQuest Labs | InQuest Labs | https://labs.inquest.net |
| I-Blocklist | I-Blocklist | https://www.iblocklist.com/lists |
| IPsum | IPsum | https://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt |
| James Brine | James Brine | https://jamesbrine.com.au |
| Kaspersky Feeds | Kaspersky | https://support.kaspersky.com/datafeeds |
| Malpedia | Malpedia | https://malpedia.caad.fkie.fraunhofer.de/ |
| MalShare | MalShare | http://www.malshare.com/ |
| Maltiverse | Maltiverse | https://www.maltiverse.com/ |
| MalwareBazaar | MalwareBazaar | https://bazaar.abuse.ch/ |
| Malware Domain List | Malware Domain List | https://www.malwarepatrol.net/ |
| MetaDefender | MetaDefender | https://www.opswat.com/developers/threat-intelligence-feed |
| Netlab OpenData | Netlab | https://data.netlab.360.com/ |
| NoThink! | NoThink! | http://www.nothink.org |
| Obstracts | Obstracts | https://www.obstracts.com/ |
| OpenPhish | OpenPhish | https://openphish.com/phishing_feeds.html |
| 0xSI_f33d | 0xSI_f33d | https://feed.seguranca-informatica.pt/index.php |
| PhishTank | PhishTank | https://www.phishtank.com/developer_info.php |
| PickupSTIX | PickupSTIX | https://www.celerium.com/pickupstix |
| RST Cloud | RST Cloud | https://rstcloud.net/ |
| SecurityScorecard | SecurityScorecard | https://github.com/securityscorecard/SSC-Threat-Intel-IoCs |
| Stixify | Stixify | https://www.stixify.com/ |
| signature-base | signature-base | https://github.com/Neo23x0/signature-base |
| Spamhaus | Spamhaus | https://www.spamhaus.org/ |
| Sophos Intelix | Sophos | https://www.sophos.com/intelix |
| Spur | Spur | https://spur.us |
| SSL Blacklist | SSL Blacklist | https://sslbl.abuse.ch/ |
| Statvoo | Statvoo | https://statvoo.com/dl/top-1million-sites.csv.zip |
| Strongarm | Strongarm | https://strongarm.io |
| SIEM Rules | SIEM Rules | https://www.siemrules.com |
| Talos | Talos | https://www.talosintelligence.com/ |
| threatfeeds.io | threatfeeds.io | https://threatfeeds.io |
| threatfox | threatfox | https://threatfox.abuse.ch/ |
| Technical Blogs (Dataminr) | Technical Blogs | https://www.dataminr.com/blog/ |
| ThreatMiner | ThreatMiner | https://www.threatminer.org/ |
| ThreatExchange | ThreatExchange | https://developers.facebook.com/docs/threat-exchange/ |
| TypeDB CTI | TypeDB CTI | https://github.com/typedb-osi/typedb-cti |
| XFE | XFE | https://exchange.xforce.ibmcloud.com/ |
| Yeti | Yeti | https://yeti-platform.github.io/ |
| 1st Dual Stack | 1st Dual Stack | https://IOCFeed.mrlooquer.com/ |
| Yara-Rules | Yara-Rules | https://github.com/Yara-Rules/rules |
| VirusShare | VirusShare | https://virusshare.com/ |
| CIRCL PDNS | CIRCL PDNS | https://www.circl.lu/services/passive-dns |
| InTheWild | InTheWild | https://inthewild.io |
| 360 Quake | 360 Quake | https://quake.360.net |
| Cloudflare Radar | Cloudflare Radar | https://radar.cloudflare.com/traffic |
| Validin | Validin | https://app.validin.com |
| OSV | OSV | https://osv.dev |
| Coalition ESS | Coalition ESS | https://ess.coalitioninc.com |
| WHOIS & Domain History | WhoisFreaks | https://whoisfreaks.com |
| IP Geolocation & Threat Intel | ipgeolocation.io | https://ipgeolocation.io |
7.1 Google Dorks โ Domains
site:*.target.com filetype:pdf
site:*.target.com intitle:"dashboard"
site:*.target.com intext:"confidential"
8. Deep & Dark Web
| Need | Solution | URL |
|---|---|---|
| Search .onion | Ahmia | clean index |
| IOC aggregation | DeepTrawl (author's) | https://github.com/frangelbarrera/deepweb-leak-search |
| Check if data leaked | HaveIBeenPwned | API |
| Markets | DarkOwl (paid) | โ |
| Credentials | DeHashed (freemium) | โ |
| Search .onion | TOR Link | https://tor.link |
| Scanner services | OnionScan | https://github.com/s-rah/onionscan |
| Verified directory | Dark.fail | https://dark.fail |
| Old searcher | Torch | (only .onion) |
| Scraper onion | DarkDump | https://github.com/josh0xA/darkdump |
| Tor Project | Tor Project | https://torproject.org |
| Public webcams | TWN | http://www.the-webcam-network.com |
| Public webcams | Opentopia | http://www.opentopia.com |
| World webcams | WorldCam | https://worldcam.eu |
| Webcams | Webcam Galore | https://www.webcamgalore.com |
| Traffic cameras | OpenTrafficCamMap | https://otc.armchairresearch.org/map |
| Skyline webcams | Skyline Webcams | https://www.skylinewebcams.com/en/webcam |
| World webcams | Pictimo | https://www.pictimo.com |
| Public webcams | CamHacker | https://www.camhacker.com |
| Surveillance cameras | SUNDERS | https://sunders.uber.space |
| Ukraine cameras | Ukraine Live Cams | https://nagix.github.io/ukraine-livecams |
OPSEC for .onion
- TailsOS โ USB โ bridge-Tor โ NO extra proxies
- Disable scripts Noscript โ max
- Never maximize window (fingerprint)
- Never use VPN + Tor (traffic correlation)
- Use bridges if Tor is blocked
- NoScript to max
- No window resizing
- No downloading to persistent disk
9. Automation (Python)
9.1 Minimum Stack
python -m venv osint-env
source osint-env/bin/activate
pip install twint-fork recon-ng selenium requests beautifulsoup4 shodan
9.2 Mini-OSINT Script โ unifies 5 sources
#!/usr/bin/env python3
# mini_osint.py
import shodan, requests, json, sys
from bs4 import BeautifulSoup
API_KEY = 'YOUR_SHODAN_API'
s = shodan.Shodan(API_KEY)
domain = sys.argv[1]
# 1. Subdomains via CRT.sh
crt = requests.get(f'https://crt.sh/?q=%25.{domain}&output=json').json()
subs = sorted(set([r['name_value'] for r in crt]))
print('[+] Found subdomains:', len(subs))
# 2. IPs from resolution
ips = set()
for sub in subs[:20]: # demo limit
try:
ips.add(socket.gethostbyname(sub))
except:
pass
# 3. Shodan quick look
for ip in ips:
try:
info = s.host(ip)
print(ip, info['org'], info.get('vulns', 'N/A'))
except:
pass
9.3 Recon-ng โ fast workflow
recon-ng
> marketplace install all
> workspaces add target
> use domains-domains/brute_force
> set SOURCE target.com
> run
> use hosts-hosts/resolve
> run
> use reporting/csv
> run
10. Report Templates
Folder /templates/ in your repo. Mandatory YAML front-matter:
---
investigator: your-alias
date: 2025-12-16
objective: "Target Name"
scope: domain + RRSS
status: draft # draft | reviewed | delivered
---
# Executive Summary
(5 lines)
# Primary Sources
- URL | date | capture hash
# Chronology
- 2024-10-01: Domain registration
- 2025-01-15: First leak
# Annexes
- Screenshots folder `/annexes/`
- CSV extracts
11. Legal Considerations
| Country | Framework | Key |
|---|---|---|
| Mexico | PDP Law 2018 | Explicit consent for PII |
| Spain | LOPD-GDPR | Art. 6.1-f: legitimate interest (research) |
| USA | CFAA | No bypass to authentication |
| Europe | GDPR | DPIA if >1000 people |
| โ | OSINT-Code-Ethics | No doxxing, no stalking, no data selling |
Ethical checklist โ Is the source 100% public? โ Is the data sensitive PII? โ minimize โ Is there verifiable public interest? โ Can it be de-identified?
12. Extra Resources
Free Books
- Open Source Intelligence Techniques โ Michael Bazzell โ Official site with book updates, podcast & tools (current edition available on Amazon)
- Bellingcat Resources โ Free guides, case studies & methodology articles
- Bellingcat Online Investigation Toolkit โ Live, searchable toolkit maintained by Bellingcat
- SANS Reading Room โ OSINT โ Peer-reviewed whitepapers (free with registration)
- SANS Reading Room โ Forensics โ DFIR whitepapers, free
- SANS SEC497 OSINT Course โ Course outline, free sample content
- NIST SP 800-150 โ Guide to Cyber Threat Information Sharing โ Official US gov PDF, free
- ENISA Threat Landscape 2024 โ Full EU report, free PDF
- UK NCSC Threat Reports โ UK government cyber threat reports
- INTERPOL Cybercrime Reports โ Official INTERPOL publications hub
- Citizen Lab Publications โ Academic research on digital threats, free PDFs
- RAND Open Source Intelligence Research โ Peer-reviewed RAND papers
- CSIS Strategic Technologies Program โ Think-tank reports on tech & security
- arXiv Cryptography & Security โ Academic preprints, fully free
- FIRST.org Best Practices Guides โ CSIRT best-practice guides
- MITRE ATT&CK Resources โ Framework docs, FAQs, training
- Trace Labs Resources โ Missing persons OSINT CTF methodology
- OSINT Dojo โ Free daily challenges & training paths
- OSINT Framework โ Live searchable tree of OSINT tools
- Awesome OSINT (jivoi) โ Curated mega-list, GitHub
- OSINT Collection (Ph055a) โ Curated free & actionable resources
- INCIBE-CERT Blog โ Spanish cybersecurity articles (free)
- The DFIR Report โ Real-world intrusion case studies, free
- Krebs on Security โ Investigative cybersecurity journalism
- Cisco Talos Blog โ Daily threat intel blog
- EFF Surveillance Self-Defense โ Free multilingual guides on privacy & OPSEC
- Pwn.college โ Free ASU-hosted security course platform
Courses / Certifications
- SEINT (SANS 487)
- OSINT-Do-jo โ daily challenges
Communities
13. AI Intelligence
AI-powered tools for OSINT 2025:
| Tool | Function | URL | Note |
|---|---|---|---|
| anonchatgpt | Anonymous ChatGPT client | https://anonchatgpt.com | No account needed |
| ai-toolkit | Essential AI toolkit for journalists | https://huggingface.co/spaces/JournalistsonHF/ai-toolkit | Free and open-source |
| ChatPDF | Ask questions to PDFs | https://www.chatpdf.com/ | Simple and free |
| Monica | ChatGPT copilot in Chrome | https://monica.im/ | Summarize, translate |
| BabelX | Multilingual OSINT platform | https://www.babelstreet.com | 200+ languages |
| Fivecast | Predictive analysis with ML | https://www.fivecast.com | Real-time threat detection |
| HyperVerge | Deepfake detection | https://hyperverge.co | AI biometric verification |
| ShadowDragon | Social Darkint with AI | https://shadowdragon.io | Behavior analysis |
| Talkwalker | Media monitoring with AI | https://www.talkwalker.com | Sentiment analysis |
| DorkGPT | AI dork generator | https://www.dorkgpt.com | Auto-creates Google dorks |
| SearchDorks | Dorks for multiple engines | https://kriztalz.sh/search-dorks | FOFA, Shodan, Censys |
| Sensity AI | Deepfake detection | https://sensity.ai | Professional |
| Full Fact | AI fact-checking (UK) | https://fullfact.org | Free |
| Logically | AI disinfo detection | https://logically.com | Free tier |
13.1 Curated AI directories (cross-references)
| Directory | Coverage | URL |
|---|---|---|
| Artificial-Intelligence-Universe | 800+ AI tools | https://github.com/frangelbarrera/Artificial-Intelligence-Universe |
| awesome-ai-agents | 132 AI agents, 22 categories | https://github.com/frangelbarrera/awesome-ai-agents |
| Awesome-Hacking-with-AI | AI-powered offensive security | https://github.com/frangelbarrera/Awesome-Hacking-with-AI |
| osint-agent-skills | MCP server for OSINT agents | https://github.com/frangelbarrera/osint-agent-skills |
14. Facial Recognition
Beyond basic searches:
| Tool | Capability | URL | Cost |
|---|---|---|---|
| PimEyes | Facial search on internet | https://pimeyes.com/en | Freemium |
| OSINT by PimEyes | Pro version for professionals | https://osint.pimeyes.com | Paid |
| FaceCheck.ID | Search in social networks | https://facecheck.id | Freemium |
| Clearview AI | Police facial recognition | (Requires authorization) | Professional |
Usage methodology:
- Capture high-quality image
- Use FaceCheck.ID for social networks
- PimEyes for broad web search
- Validate results by crossing platforms
15. Email/Phone Investigation
๐ง Email OSINT Tools
| Tool | Function | URL |
|---|---|---|
| Holehe | Find associated accounts to email | https://github.com/megadose/holehe |
| GHunt | Investigate Google accounts | https://github.com/mxrch/GHunt |
| Epieos | Email + phone reverse lookup | https://epieos.com |
| h8mail | Search in data breaches | https://github.com/khast3x/h8mail |
| EmailHippo | Email verification | https://tools.emailhippo.com |
| Hunter.io | Find corporate emails | https://hunter.io |
๐ฑ Phone OSINT Tools
| Tool | Function | URL |
|---|---|---|
| Phoneinfoga | Investigation framework | https://github.com/sundowndev/phoneinfoga |
| Truecaller | Call identifier | https://www.truecaller.com |
| Infobel | International search | https://www.infobel.com |
| Numverify | Validation API | https://numverify.com |
Automation script (Python):
# email_osint_checker.py
import holehe
import requests
def check_email_accounts(email):
"""Checks in 120+ platforms"""
modules = holehe.import_submodules('holehe.modules')
for module in modules:
# Execute verification
pass
16. Data Breaches
Alternatives and complements to HIBP:
| Platform | Database | URL | Access |
|---|---|---|---|
| DeHashed | 17+ billion records | https://dehashed.com | Freemium |
| Snusbase | Recent breaches | https://snusbase.com | Paid |
| LeakCheck | Real-time search | https://leakcheck.io | Freemium |
| Intelligence X | Dark web + breaches | https://intelx.io | Freemium |
| h8mail | Local breach search | GitHub | Free |
| Hudson Rock | Infostealer intelligence | https://www.hudsonrock.com/threat-intelligence-cybercrime-tools | Free |
| LeakRadar | 290B+ stealer logs & breaches | https://leakradar.io | Freemium |
| CheckLeaked | Real-time email/username/phone/password search | https://checkleaked.cc | Freemium |
Quick command:
# h8mail - mass search
h8mail -t targets.txt -bc local_breach_folder/ --power-all
17. Blockchain/Crypto
Specialized tools:
| Tool | Blockchain | URL | Function |
|---|---|---|---|
| Chainalysis Reactor | Multi-chain | https://www.chainalysis.com | Forensic analysis professional |
| Elliptic | Bitcoin, Ethereum | https://www.elliptic.co | Money laundering detection |
| Arkham Intelligence | Multi-chain | https://www.arkhamintelligence.com | Entity mapping with AI |
| Glassnode | On-chain analytics | https://glassnode.com | Advanced metrics |
| Etherscan | Ethereum | https://etherscan.io | Main explorer |
| Blockchain.info | Bitcoin | https://www.blockchain.com/explorer | Classic explorer |
| BlockCypher | Multi-chain API | https://www.blockcypher.com | Free API |
| Wallet Explorer | Bitcoin | https://www.walletexplorer.com | Wallet analysis |
Investigation methodology:
1. Identify wallet address
2. Search in Arkham Intelligence (known labels)
3. Analyze transactions in Etherscan/Blockchain.info
4. Trace fund flow with BlockCypher
5. Check in Chainalysis if available
18. Transport OSINT
๐ Vehicle Investigation
| Tool | Function | URL |
|---|---|---|
| OpenALPR | License plate recognition | https://github.com/openalpr/openalpr |
| Carfax | Vehicle history (US) | https://www.carfax.com |
โ๏ธ Aviation - FlightRadar and ADS-B
| Tool | Function | URL |
|---|---|---|
| FlightRadar24 | Live tracking | https://www.flightradar24.com |
| ADS-B Exchange | No military filters | https://globe.adsbexchange.com |
| FlightAware | Flight history | https://flightaware.com |
| Phantom Tide | Restricted airspace, maritime, and incident map | https://phantom.labs.jamessawyer.co.uk |
| PiAware (Raspberry Pi) | Own ADS-B receiver | https://flightaware.com/adsb/piaware |
Setup of homemade ADS-B receiver:
# Configure PiAware on Raspberry Pi
sudo apt-get install piaware
sudo piaware-config <options>
sudo systemctl restart piaware
๐ข Maritime - AIS Tracking
| Tool | Function | URL |
|---|---|---|
| MarineTraffic | Global AIS tracking | https://www.marinetraffic.com |
| VesselFinder | Free alternative | https://www.vesselfinder.com |
| ShipSpotting | Photo database | http://www.shipspotting.com |
19. WiFi/Wardriving
| Tool | Function | URL/Installation |
|---|---|---|
| WiGLE | Global WiFi database | https://wigle.net |
| WiGLE WiFi Wardriving (Android) | Mapping app | Google Play |
| Kismet | WiFi/Bluetooth detector | https://www.kismetwireless.net |
| Aircrack-ng | WiFi audit suite | https://www.aircrack-ng.org |
OSINT use case:
1. Search unique SSID in WiGLE
2. Find approximate router location
3. Correlate with other geolocation data
4. Identify movements/locations of target
20. Content Verification
Fact-checking tools:
| Tool | Function | URL | Type |
|---|---|---|---|
| InVID & WeVerify | Video verification plugin | https://weverify.eu/verification-plugin | Extension |
| FotoForensics | ELA image analysis | https://fotoforensics.com | Web |
| Forensically | Visual analysis suite | https://29a.ch/photo-forensics | Web |
| HyperVerge Deepfake Detector | AI detection | https://hyperverge.co | API |
| Sensity AI | Deepfakes detection | https://sensity.ai | Professional |
| Content Authenticity Initiative | Origin verification | https://contentauthenticity.org | Standard |
Verification process:
1. Extract metadata with ExifTool
2. Analyze with FotoForensics (ELA)
3. Check consistencies with Forensically
4. For video: use InVID for keyframes
5. Reverse image search in TinEye/Google
21. Username Enumeration
Beyond Maigret and Sherlock:
| Tool | Platforms | URL | Highlight |
|---|---|---|---|
| Sherlock | 400+ platforms | https://github.com/sherlock-project/sherlock | Faster |
| Maigret | 500+ platforms | https://github.com/soxoj/maigret | More precise |
| WhatsMyName | 600+ platforms | https://github.com/WebBreacher/WhatsMyName | Most complete |
| Snoop | 320+ (RU/CIS emphasis) | https://github.com/snooppr/snoop | Russian/CIS |
| Blackbird | 200+ with PDF report | https://github.com/p1ngul1n0/blackbird | Export |
| UserSearch | 600+ platforms | https://usersearch.org | Largest Reverse User Search Online |
Speed comparison:
# Benchmark (10 usernames)
sherlock: ~45 seconds
maigret: ~90 seconds (more precise)
blackbird: ~60 seconds (with report)
22. Web Scraping
| Tool | Function | URL | Level |
|---|---|---|---|
| Photon | Ultra-fast crawler | https://github.com/s0md3v/Photon | Intermediate |
| Scrapy | Complete framework | https://scrapy.org | Advanced |
| Playwright | Browser automation | https://playwright.dev | Advanced |
| Selenium | Classic automation | https://www.selenium.dev | Intermediate |
| Beautiful Soup | HTML/XML parser | https://www.crummy.com/software/BeautifulSoup | Basic |
Basic Photon script:
python photon.py -u https://target.com \
--export=json \
--dns \
--keys \
--threads 10
23. Metadata Extraction
Complete suite:
| Tool | File Type | URL | Platform |
|---|---|---|---|
| ExifTool | Images, PDF, Office | https://exiftool.org | CLI |
| FOCA | Office, PDF (GUI) | https://github.com/ElevenPaths/FOCA | Windows |
| Metagoofil | Public documents | https://github.com/laramies/metagoofil | CLI |
| MAT2 | Metadata cleaner | https://0xacab.org/jvoisin/mat2 | CLI |
Metadata workflow:
# 1. Extract metadata
exiftool -a -u -g1 document.pdf > metadata.txt
# 2. Search sensitive info
grep -i "author\|creator\|email\|gps" metadata.txt
# 3. Clean before publishing
mat2 --inplace clean_document.pdf
24. Network Scanning
Advanced tools:
| Tool | Speed | URL | Ideal Use |
|---|---|---|---|
| Nmap | Medium | https://nmap.org | Complete scan |
| Masscan | Very fast | https://github.com/robertdavidgraham/masscan | Internet-scale |
| RustScan | Very fast | https://github.com/RustScan/RustScan | Modern port |
| Nuclei | Templates | https://github.com/projectdiscovery/nuclei | Vulnerabilities |
Speed comparison:
# Scan 65k ports on 1 IP
nmap: ~5 minutes
rustscan: ~10 seconds โ then nmap
masscan: ~5 seconds (less detail)
25. Dark Web
Specialized tools:
| Tool | Function | URL | Requirement |
|---|---|---|---|
| Ahmia | .onion searcher | https://ahmia.fi | Web browser |
| OnionScan | Service scanner | https://github.com/s-rah/onionscan | Tor installed |
| Dark.fail | Verified directory | https://dark.fail | Tor Browser |
| Torch | Old searcher | (only .onion) | Tor Browser |
| DarkDump | Onion scraper | https://github.com/josh0xA/darkdump | Python + Tor |
| DeepTrawl | Tor-routed IOC aggregator + BTC/XMR wallet extraction | https://github.com/frangelbarrera/deepweb-leak-search | Python + Tor + PostgreSQL |
Dark Web OPSEC:
1. Operating system: Tails OS (amnesic)
2. Never use VPN + Tor (traffic correlation)
3. Use bridges if Tor is blocked
4. NoScript to max
5. No window resizing
6. No downloading to persistent disk
26. All-in-One Frameworks
All-in-one platforms:
| Framework | Language | URL | Strength |
|---|---|---|---|
| Abster Intelligence | TypeScript / Next.js | https://github.com/frangelbarrera/Abster-Intelligence | Local-first, graph engine, BYOK-LLM, privacy-first |
| Ubikron | Browser Ext | https://ubikron.com | AI-powered case management & entity extraction |
| SpiderFoot | Python | https://github.com/smicallef/spiderfoot | Total automation |
| Recon-ng | Python | https://github.com/lanmaster53/recon-ng | Modular |
| theHarvester | Python | https://github.com/laramies/theHarvester | Email/subdomain |
| Maltego | Java | https://www.maltego.com | Visualization |
| SentinelScope | Python | https://github.com/frangelbarrera/sentinelscope | Lightweight Recon-ng alternative, modular |
SpiderFoot setup:
git clone https://github.com/smicallef/spiderfoot.git
cd spiderfoot
pip3 install -r requirements.txt
python3 sf.py -l 127.0.0.1:5001
27. Advanced Maltego
Essential plugins:
| Transform Hub | Function | Note |
|---|---|---|
| Standard Transforms | 150+ official transforms | Free |
| Shodan Transform | Shodan integration | Requires API |
| VirusTotal | Malware/URL analysis | Requires API |
| Netlas Transform | Similar to Shodan | https://netlas.io |
| Hunter.io | Email search | Requires account |
| Builtwith | Site technologies | Requires API |
Create custom transform:
# my_transform.py
from maltego_trx.entities import Person, EmailAddress
from maltego_trx.transform import DiscoverableTransform
class PersonToEmail(DiscoverableTransform):
@classmethod
def create_entities(cls, request, response):
person_name = request.Value
# Your logic here
response.addEntity(EmailAddress, f"{person_name}@example.com")
return response
28. Professional Methodologies
Bellingcat Methodology
1. Identification: What are we investigating?
2. Preservation: Archive EVERYTHING (archive.is, wayback)
3. Verification: Triangulate with 3+ sources
4. Contextualization: Complete chronology
5. Documentation: Screenshots + hash + timestamp
6. Validation: Peer review before publishing
Professional OSINT Cycle (5 Phases)
PHASE 1: DIRECTION
โโโ Define questions (RFI)
โโโ Establish legal limits
โโโ Approve scope
PHASE 2: COLLECTION
โโโ Passive sources
โโโ Semi-passive sources
โโโ Save evidence
PHASE 3: PROCESSING
โโโ Normalize data
โโโ Translate languages
โโโ Structure information
PHASE 4: ANALYSIS
โโโ Link analysis (Maltego)
โโโ Timeline creation
โโโ Pattern recognition
โโโ Cross validation
PHASE 5: DISSEMINATION
โโโ Executive report
โโโ Technical report
โโโ Visual presentation
โโโ Evidence archive
29. Advanced Google Dorks
2025 Dorks (specific):
# Sensitive information leaks
site:pastebin.com "password" "@company.com"
site:github.com "api_key" OR "api_secret" "company"
site:trello.com intext:"password" OR intext:"passwd"
# Exposed corporate documents
site:*.s3.amazonaws.com ext:xls | ext:xlsx "confidential"
filetype:pdf intext:"internal use only" site:gov
# IP cameras and IoT devices
inurl:/view/view.shtml
intitle:"webcamXP 5"
# Exposed admin panels
intitle:"index of" "admin"
intitle:"Dashboard" inurl:login
inurl:wp-admin intitle:"Dashboard"
# Exposed databases
intitle:"phpMyAdmin" "Welcome to phpMyAdmin"
inurl:"/phpmyadmin/index.php"
"#mysql dump" filetype:sql
# Employee information
site:linkedin.com "company name" "CEO" | "CTO" | "CISO"
site:*.linkedin.com "@companymail.com"
# Subdomains (combine with crt.sh)
site:*.target.com -www
site:*.*.target.com
30. Learning Resources
๐บ YouTube Channels (Spanish):
- Ethical Hacking - Pablo Gonzรกlez
- CyberSecurityJobs
- DragonJAR
- Josรฉ Luis Garcรญa
- Security Hacklabs
๐ Recommended Books:
- "Open Source Intelligence Techniques" - Michael Bazzell (8th ed., 2024)
- "OSINT for Threat Intelligence" - Scott J Roberts
- "The OSINT Handbook" - i-intelligence
๐ Certifications:
- GOSI (GIAC Open Source Intelligence) - SANS
- CSCTP (Certified Social Media Intelligence Expert) - McAfee Institute
- OSINT Professional Certification - OSINT Combine
๐ Communities:
- Reddit: r/OSINT, r/OpenSourceIntelligence
- Discord: IntelTechniques Server, OSINT-FR
- Telegram: OSINT Latam, OSINT Dojo
- Twitter/X: #OSINT, #OSINTfor Good
31. People Investigations
Tools for investigating individuals:
| Tool | Function | URL |
|---|---|---|
| Pipl | People search engine | https://pipl.com |
| Spokeo | Background checks | https://www.spokeo.com |
| BeenVerified | Public records search | https://www.beenverified.com |
| Intelius | People finder | https://www.intelius.com |
| Whitepages | Phone and address lookup | https://www.whitepages.com |
| ZabaSearch | Free people search | https://www.zabasearch.com |
| PeopleFinder | Comprehensive search | https://www.peoplefinder.com |
| Instant Checkmate | Background reports | https://www.instantcheckmate.com |
| TruthFinder | Public records | https://www.truthfinder.com |
| US Search | People search | https://www.ussearch.com |
32. Company Research
Tools for investigating companies:
| Tool | Function | URL |
|---|---|---|
| Crunchbase | Company database | https://crunchbase.com |
| WellFound (formerly AngelList) | Startup database | https://wellfound.com |
| PitchBook | Private company data | https://pitchbook.com |
| ZoomInfo | Business contacts | https://www.zoominfo.com |
| D&B Hoovers | Company profiles | https://app.dnbhoovers.com |
| Dun & Bradstreet | Business credit reports | https://www.dnb.com |
| EDGAR | SEC filings | https://www.sec.gov/edgar |
| OpenCorporates | Global company registry | https://opencorporates.com |
| Company House | UK company registry | https://find-and-update.company-information.service.gov.uk |
| Bloomberg | Financial data | https://www.bloomberg.com |
33. Threat Intelligence Feeds
Consolidated IoC feeds for threat intelligence :
33.1 Malware & C2 Feeds
| Feed | Type | URL |
|---|---|---|
| MalwareBazaar | Malware samples | https://bazaar.abuse.ch |
| ThreatFox | IoC aggregator | https://threatfox.abuse.ch |
| Feodo Tracker | C2 IPs | https://feodotracker.abuse.ch |
| SSL Blacklist | Malicious SSL certs | https://sslbl.abuse.ch |
| URLhaus | Malware URLs | https://urlhaus.abuse.ch |
| MalShare | Malware repository | http://www.malshare.com |
| VirusShare | Sample sharing | https://virusshare.com |
| Malware Domain List | Malicious domains | https://www.malwarepatrol.net |
| AlienVault OTX | Community threat intel | https://otx.alienvault.com |
| IBM X-Force | Threat exchange | https://exchange.xforce.ibmcloud.com |
| Recorded Future | Commercial feed (free blog) | https://www.recordedfuture.com |
| Microsoft Threat Intelligence | MS-curated | https://www.microsoft.com/en-us/wdsi |
| CISA Known Exploited Vulnerabilities | KEV catalog | https://www.cisa.gov/known-exploited-vulnerabilities-catalog |
| Vulnrichment | CISA enriched CVEs | https://github.com/cisagov/vulnrichment |
33.2 Phishing & Fraud Feeds
| Feed | Type | URL |
|---|---|---|
| PhishTank | Phishing URLs | https://www.phishtank.com |
| OpenPhish | Phishing URLs | https://openphish.com |
| FraudGuard | Fraud intelligence | https://fraudguard.io |
| HaveIBeenPwned | Breach notification | https://haveibeenpwned.com |
| DeHashed | Breach search | https://dehashed.com |
| IntelligenceX | Dark web + leaks | https://intelx.io |
| LeakCheck | Real-time breach | https://leakcheck.io |
| Snusbase | Recent breaches | https://snusbase.com |
| Hudson Rock | Infostealer intel | https://www.hudsonrock.com |
33.3 IP & Domain Reputation
| Feed | Type | URL |
|---|---|---|
| Spamhaus | IP/domain reputation | https://www.spamhaus.org |
| FireHOL | IP blocklists | http://iplists.firehol.org |
| AbuseIPDB | IP abuse reports | https://www.abuseipdb.com |
| GreyNoise | Internet scanner noise | https://www.greynoise.io |
| CINS Score | Botnet IPs | http://cinsscore.com/#list |
| Binary Defense | Banlist | https://www.binarydefense.com/banlist.txt |
| IPsum | Curated IPs | https://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt |
33.4 CTI Platforms (ingest & correlate)
| Platform | Type | URL |
|---|---|---|
| MISP | Open-source CTI platform | https://www.misp-project.org |
| OpenCTI | CTI platform | https://www.opencti.io |
| Yeti | IoC platform | https://yeti-platform.github.io |
| aegistrace-threat-intelligence | Python CTI pipeline (author's) | https://github.com/frangelbarrera/aegistrace-threat-intelligence |
| ThreatMiner | Threat intel search | https://www.threatminer.org |
| PulseDive | IoC enrichment | https://pulsedive.com |
| AlienVault OTX | Threat exchange | https://otx.alienvault.com |
34. ICS/OT & Critical-Infrastructure OSINT
OSINT for industrial control systems, SCADA, and critical infrastructure:
34.1 Methodology & Frameworks
| Resource | Type | URL |
|---|---|---|
| ICS-Cybersecurity-Audit (author's) | 5-phase audit methodology, IEC 62443 / NIST 800-82 | https://github.com/frangelbarrera/ICS-Cybersecurity-Audit |
| MITRE ATT&CK for ICS | Tactics & techniques matrix | https://attack.mitre.org/matrices/ics |
| CISA ICS Advisories | Vulnerability advisories | https://www.cisa.gov/news-events/cybersecurity-advisories |
| ICS-CERT | US-CERT industrial alerts | https://us-cert.cisa.gov/ics |
34.2 Scanners & Tools
| Tool | Function | URL |
|---|---|---|
| IndustrialScanner-Lite (author's) | Modbus/S7Comm/DNP3 PCAP analyzer | https://github.com/frangelbarrera/IndustrialScanner-Lite |
| Shodan ICS filters | ICS device search | https://www.shodan.io/search?query=port%3A502 |
| Censys ICS | ICS device search | https://search.censys.io/search?resource=hosts&q=tags%3A%22ics%22 |
| Claroty | OT security (vendor) | https://claroty.com |
| Nozomi Networks | OT security (vendor) | https://www.nozominetworks.com |
34.3 Notable ICS Incidents (Case Studies)
| Year | Incident | Target | Lesson |
|---|---|---|---|
| 2010 | Stuxnet | Natanz uranium enrichment (IR) | First digital weapon, S7 PLC reprogramming |
| 2015 | BlackEnergy | Ukraine power grid | First confirmed cyber-physical blackout |
| 2016 | Industroyer/CrashOverride | Ukraine power grid | Automated ICS protocol abuse |
| 2017 | TRITON/TRISIS | Saudi Petrochemical (SIS) | First attack on Safety Instrumented Systems |
| 2021 | Colonial Pipeline | US fuel pipeline (IT-side) | Ransomware OT impact without direct compromise |
| 2022 | Industroyer2 | Ukraine energy sector | Modular ICS malware evolution |
Full case studies: https://github.com/frangelbarrera/ICS-Cybersecurity-Audit/tree/main/docs/case-studies
34.4 Protocol-specific Dorks (Shodan)
port:502 country:DE # Modbus
port:102 country:ES # S7Comm
port:20000 # DNP3
port:47808 # BACnet
port:4840 # OPC UA
"Schneider Electric" # Quantum PLCs
"Siemens" port:102 # S7 devices
35. AI Agent Skills & MCP
Run OSINT workflows inside Claude Code, Cursor, Ollama, or any MCP-compatible client:
35.1 MCP Servers & Skill Packs
| Resource | Type | URL |
|---|---|---|
| osint-agent-skills (author's) | 22 MCP tools + 295-line system prompt + 9 pivot playbooks | https://github.com/frangelbarrera/osint-agent-skills |
| PulseMCP | MCP server directory | https://www.pulsemcp.com |
| MCP Server Finder (Glama) | Directory | https://glama.ai/mcp/servers |
| awesome-mcp-servers | Curated list | https://github.com/punkpeye/awesome-mcp-servers |
35.2 MCP Servers for Specific OSINT Tools
| MCP Server | Wraps | URL |
|---|---|---|
| Brave Search MCP | Brave Search | https://github.com/brave/brave-search-mcp-server |
| Fetch MCP | Web fetcher | https://github.com/modelcontextprotocol/servers/blob/main/src/fetch |
| SQLite MCP | Local DB | https://github.com/modelcontextprotocol/servers-archived/tree/main/src/sqlite |
35.3 Agent Frameworks for OSINT Orchestration
| Framework | Language | URL | Highlight |
|---|---|---|---|
| AutoGPT | Python | https://github.com/Significant-Gravitas/AutoGPT | Autonomous goal-driven agents |
| CrewAI | Python | https://github.com/crewAIInc/crewAI | Role-based multi-agent |
| LangGraph | Python | https://github.com/langchain-ai/langgraph | Stateful agent graphs |
| n8n | TypeScript | https://n8n.io | Visual workflow + AI nodes |
| Dify | Python | https://dify.ai | Open-source LLM app platform |
| secure-agent-orchestrator (author's) | Python | https://github.com/frangelbarrera/secure-agent-orchestrator | Lightweight SOAR for distributed security agents |
35.4 Local & Sovereign LLMs (OPSEC for sensitive investigations)
| Tool | Type | URL |
|---|---|---|
| Ollama | Local LLM runner | https://ollama.com |
| LM Studio | Desktop GUI | https://lmstudio.ai |
| vLLM | Production server | https://github.com/vllm-project/vllm |
| Jan | Offline assistant | https://jan.ai |
35.5 Quick Start (Claude Code)
# 1. Clone the skills repo
git clone https://github.com/frangelbarrera/osint-agent-skills.git
cd osint-agent-skills
# 2. Add to .claude/settings.json
{
"mcpServers": {
"osint": {
"command": "node",
"args": ["./tools/mcp-server.js"],
"env": {
"SHODAN_KEY": "your-key",
"VT_API_KEY": "your-key",
"GITHUB_TOKEN": "your-token"
}
}
}
}
# 3. Launch Claude Code โ tools will be auto-discovered
36. Financial OSINT
36.1 UBO Tracing Workflow (Ultimate Beneficial Owner) โ 12 Steps
| Step | Action | Tool / Source |
|---|---|---|
| 1 | Identify initial entity: legal name, jurisdiction, registration number | OpenCorporates ยท Companies House UK |
| 2 | Obtain incorporation document | National public registry ยท OCCRP Aleph |
| 3 | Identify active AND historical directors | OpenCorporates ยท SEC EDGAR |
| 4 | Identify declared shareholders | OpenOwnership Register ยท GLEIF |
| 5 | Detect nominees and trusts | ICIJ Offshore Leaks |
| 6 | Verify physical-person identities | LittleSis ยท national civil registries |
| 7 | Walk the chain to next level (iterate to person or 5 levels max) | Maltego ยท Obsidian |
| 8 | Cross-check against sanctions (incl. OFAC 50 Percent Rule) | OpenSanctions ยท OFAC SDN |
| 9 | Verify UBO tax-residency transparency | FATF High-Risk Jurisdictions |
| 10 | Search adverse media and litigation | OpenSanctions PEPs ยท CourtListener |
| 11 | Validate with blockchain/crypto if applicable | Arkham Intelligence ยท Etherscan |
| 12 | Document final ownership chain (nodes, edges, %, dates, hashes) | Maltego + Obsidian + SHA-256 per document |
36.2 Verified Financial OSINT Tools
| Tool | URL | Function |
|---|---|---|
| OpenCorporates | https://opencorporates.com | Global corporate registry (140M+ entities) |
| OpenOwnership Register | https://register.openownership.org | Public UBO registers |
| OpenSanctions | https://www.opensanctions.org | Aggregated sanctions + PEPs |
| OCCRP Aleph | https://aleph.occrp.org | Cross-border asset investigation |
| ICIJ Offshore Leaks | https://offshoreleaks.icij.org | Pandora / Panama / Paradise Papers |
| LittleSis | https://littlesis.org | US peopleโpower connections |
| FollowTheMoney | https://followthemoney.tech | OpenSanctions data model |
| FinCEN | https://www.fincen.gov | US financial records portal |
| SEC EDGAR | https://www.sec.gov/edgar | US corporate filings |
| GLEIF | https://www.gleif.org | Legal Entity Identifier registry |
| OFAC SDN List | https://ofac.treasury.gov | US Treasury sanctions |
| EU Sanctions Map | https://www.sanctionsmap.eu | Interactive EU sanctions map |
| CourtListener | https://www.courtlistener.com | US federal court records |
| OpenSecrets | https://www.opensecrets.org | US money-in-politics |
| Sayari | https://sayari.com | Commercial corporate-network intel |
| Equasis | https://www.equasis.org | Global merchant vessel registry |
| Arkham Intelligence | https://www.arkhamintelligence.com | On-chain wallet attribution |
| Dune Analytics | https://dune.com | SQL across 100+ blockchains (free tier) |
| Nansen | https://nansen.ai | Smart-money signals ($49/mo) |
| Arbiscan | https://arbiscan.io | Arbitrum L2 explorer |
| Basescan | https://basescan.org | Base L2 explorer |
| Optimistic Etherscan | https://optimistic.etherscan.io | Optimism L2 explorer |
36.3 Common Errors in Financial OSINT
- Confusing director with UBO. A director signs minutes; a UBO economically controls. In offshore shells the director is usually a professional nominee with 200+ companies.
- Not handling transliterations. Mohammed / Muhammad / Mohamad / Mehmet โ exact match fails. Use ISO 9 (Russian) or Hanyu Pinyin (Chinese).
- Trusting PSC Register as ground truth. The UK PSC Register is self-reported; real UBOs hide behind nominees. Always cross-check with ICIJ.
- Treating sanctions lists as binary. "Not listed" โ "clean". Designation takes monthsโyears. Use adverse media + peer designations.
- Mixing accusation with conviction. A DOJ forfeiture complaint is a civil allegation, not a conviction. Cite as "the DOJ alleges in its 2016 complaint...".
- Forgetting OFAC 50 Percent Rule. An unlisted entity owned 50%+ in aggregate by sanctioned persons is legally blocked.
- Treating blockchain analytics as absolute truth. Wallet attributions (Arkham, Chainalysis) are heuristics. Always document source and confidence level.
- No chain-of-custody. A screenshot without URL, date, and hash is not admissible. For formal DD: archive.org snapshot + timestamped screenshot + SHA-256.
36.4 Case Study โ 1MDB ($4.5B Misappropriated)
1Malaysia Development Berhad (1MDB) was a Malaysian sovereign wealth fund established in 2009. Between 2009 and 2015, approximately USD 4.5 billion was misappropriated according to the US Department of Justice. The DOJ filed civil forfeiture complaints in 2016, 2017 and 2019 seeking to recover more than USD 1.7 billion in assets.
Public money flow reconstructed from open sources:
- Origin: Bonds issued by 1MDB (2009-2013) under joint management with Goldman Sachs.
- First shell layer: Transfers to Good Star Limited (Seychelles), controlled by Jho Low (Low Taek Jho).
- Intermediate layer: Good Star โ Wynton Trading (BVI) โ Black Rock Asia (HK) โ accounts linked to Malaysian PM Najib Razak. Part reached Najib's personal AmBank account (USD 681M in 2013, the "Saudi donation").
- Final destination: Real estate in NY / Beverly Hills (USD 100M+), the yacht Equanimus (USD 250M), rights to The Wolf of Wall Street, art works.
Verified public sources:
- DOJ Money Laundering and Asset Recovery Section (kleptocracy cases)
- DOJ press release July 2016
- DOJ: Over $1 Billion in Misappropriated 1MDB Funds Now Repatriated to Malaysia
- Sarawak Report โ Clare Rewcastle Brown's blog that broke the scandal in 2015
- ICIJ Offshore Leaks โ search "Good Star", "Wynton", "Jho Low"
- PACER US Courts โ civil filings, Central District of California
37. Investigator OPSEC & Sock Puppets
37.1 Browser Fingerprinting โ Audit & Mitigation
| Tool | URL | Function |
|---|---|---|
| Cover Your Tracks (EFF) | https://coveryourtracks.eff.org | Browser fingerprinting test |
| CreepJS | https://github.com/AbrahamJuliot/creepjs | Advanced Trust Score analysis |
| Mullvad Browser | https://mullvad.net/en/browser | Anti-fingerprinting browser (Tor Project + Mullvad VPN) |
| LibreWolf | https://librewolf.net | Hardened Firefox for privacy |
| Whonix | https://www.whonix.org | Two-VM Tor workstation |
37.2 Pre-Investigation OPSEC Workflow โ 10 Steps
- Audit your current fingerprint with Cover Your Tracks + CreepJS. Document the baseline.
- Decide OPSEC level: Low (normal browser + VPN), Medium (Mullvad Browser + VPN), High (Whonix gateway + Workstation VM).
- Create an isolated research identity: dedicated email, no reuse of personal identity elements.
- For sensitive investigations: use Tails OS on a bootable USB, no persistence.
- Rotate identity periodically (every 30โ90 days for long-running investigations).
- Never mix identities: each sock puppet lives in its own browser profile / VM.
- Network hygiene: trusted VPN + DNS over HTTPS. Do not use ISP DNS.
- Metadata strip: MAT2 or ExifTool before uploading any file.
- Communications: Signal or Session for source contact. Not personal WhatsApp.
- Document OPSEC decisions in the final report: what level was used, why, what was done if something failed.
37.3 Sock Puppet Methodology (Updated 2026)
Rule 1: Never use real personal identity. Create a consistent fictitious identity (age, interests, plausible location).
Rule 2: The sock puppet needs a "digital history" โ it cannot be born the day of the investigation. Buy accounts with 1โ2 years of age or cultivate identities in standby.
Rule 3: Human behaviour. Do not do 200 searches in an hour. Respect plausible hours. Interact with irrelevant content to mix signal.
Rule 4: Consistent device fingerprint. If the sock puppet "lives" in Madrid, the browser must have timezone Europe/Madrid, locale es-ES, no obvious extensions.
Rule 5: Do not cross the line. Sock puppets for verifying public accounts = legitimate. Sock puppets to deceive, manipulate or extract information from people = ethically problematic and legally risky in many jurisdictions.
37.4 VPN & Anti-Correlation
| Resource | URL | Function |
|---|---|---|
| Mullvad VPN | https://mullvad.net | No-log VPN, anonymous cash payment |
| IVPN | https://www.ivpn.net | Audited no-log VPN |
| ProtonVPN | https://protonvpn.com | Swiss VPN, freemium |
| Tor Project | https://www.torproject.org | Network anonymity |
| Snowflake | https://snowflake.torproject.org | WebRTC pluggable transport |
| obfs4 bridges | https://bridges.torproject.org | Anti-censorship Tor bridges |
38. Cloud Storage OSINT
38.1 Verified Tools
| Tool | URL | Function |
|---|---|---|
| GrayhatWarfare | https://buckets.grayhatwarfare.com | 712K+ indexed buckets (2K free, premium paid) |
| osint.sh/buckets | https://osint.sh/buckets | Keyword search across AWS+Azure buckets |
| cloud_enum | https://github.com/initstring/cloud_enum | Multi-cloud enumeration (AWS / Azure / GCP) |
| GrayhatWarfare Shorteners | https://grayhatwarfare.com | URL shortener enumeration |
38.2 Cloud Storage OSINT Workflow โ 8 Steps
- Identify candidate bucket names based on target domain (e.g.
acmecorp-backups,acme-assets,acme-public). - Search GrayhatWarfare by target keyword.
- Validate with cloud_enum (permutation brute-force of plausible names).
- If an open bucket is found, enumerate objects with
aws s3 ls --no-sign-request s3://bucket-name/ --recursive. - Document timestamp + hash before downloading evidence.
- For Azure: use Azure Storage Explorer or
az storage blob list --account-name X --container-name Y --auth-mode login. - For GCP:
gsutil ls gs://bucket-name/(without auth shows public objects). - Responsible disclosure if sensitive data is found exposed.
38.3 Cloud Storage Google Dorks
site:s3.amazonaws.com "target"
site:blob.core.windows.net "target"
site:storage.googleapis.com "target"
site:amazonaws.com filetype:pdf "confidential"
38.4 Legal Considerations
- Accessing a public bucket is legitimate. If the bucket is open, it is the owner's responsibility.
- Downloading sensitive data (PII, credentials) and publishing it = illegal in most jurisdictions.
- Report to the owner via responsible disclosure (security.txt of the domain).
- Do not use found credentials to escalate access. That crosses from OSINT into attack.
39. Mobile App OSINT
39.1 Verified Tools
| Tool | URL | Function |
|---|---|---|
| MobSF | https://github.com/MobSF/Mobile-Security-Framework-MobSF | Automated static/dynamic analysis framework |
| jadx | https://github.com/skylot/jadx | Java decompiler for APKs |
| apktool | https://ibotpeaches.github.io/Apktool/ | APK resource decoder |
| dex2jar | https://github.com/pxb1988/dex2jar | .dex โ .jar converter |
| APKPure | https://apkpure.com | Alternative APK source to Google Play |
| APKMirror | https://www.apkmirror.com | Historical APK archive |
39.2 Mobile App OSINT Workflow โ 6 Steps
- Download APK from APKPure, APKMirror or Google Play (with
apkeeporgplaycli). - Load into MobSF for an automatic report: permissions, components, hardcoded secrets, URLs in code.
- Decompile with jadx for manual inspection: search for
api_key|secret|token|password|AWS_|STRIPE_with grep. - Audit AndroidManifest.xml for excessive permissions (location + contacts + SMS in an app that doesn't need them).
- Identify third-party SDKs (analytics, ads, trackers): Facebook SDK, Google Analytics, Firebase, AppsFlyer, Adjust.
- Document findings with code captures + file names + line numbers.
39.3 Use Cases
- Government / banking apps: audit permissions and SDKs to see what data they collect.
- Competitor apps: identify internal APIs (hardcoded URLs) for competitive intelligence.
- Dating / social apps: find undocumented endpoints (useful for safety investigations).
- Tracking apps: verify what data from minors educational apps collect.
39.4 Ethical Considerations
- Static analysis is legitimate. The APK is distributable and public.
- Dynamic analysis on your own device is legitimate.
- Publicly sharing decompiled code may violate copyright and Terms of Service.
- Do not use discovered internal APIs for mass scraping or abuse.
40. Decentralized Social OSINT
40.1 Verified Tools
| Tool | URL | Function |
|---|---|---|
| Bluesky Firehose (official) | https://docs.bsky.app/docs/advanced-guides/firehose | Authenticated stream of ALL events |
| AT Protocol SDK | https://atproto.blue/en/latest/atproto_firehose/index.html | Python SDK for the firehose |
| Reaper Social | https://reaper.social | Mastodon / Fediverse search & investigation |
| DigitalStakeout Bluesky monitoring | https://www.digitalstakeout.com/blog/bluesky-firehose-integration | Commercial monitoring |
| Nostr | https://nostr.org | Protocol + NIP-05 identity verification |
40.2 Minimum Methodology
- Bluesky real-time: subscribe to the firehose with a keyword/user filter. For historical data, Bluesky has no native search API โ use third-party (Reaper Social).
- Mastodon: each instance has its own API. Federated search is limited. List instances relevant to the target (e.g.
infosec.exchange,mas.to). - Nostr: NIP-05 verification exposes domain-linked identity. Allows pivoting from handle to verified domain.
- Farcaster: Warpcast is the main client. Public API for feeds.
40.3 Use Cases
- Extremism monitoring: migration of accounts banned from X to Mastodon / Nostr.
- Geopolitical investigations: Russian / Chinese actors moving to decentralized platforms after blocks on Western ones.
- Crypto communities: many Web3 projects use Farcaster and Nostr natively.
41. Counter-OSINT Self-Audit
41.1 Verified Tools
| Tool | URL | Function |
|---|---|---|
| Have I Been Pwned | https://haveibeenpwned.com | Free personal breach check (1018+ sites) |
| DeHashed | https://dehashed.com | Deep-web scans (freemium) |
| Intelligence X | https://intelx.io | Dark web + breaches |
| JustDeleteMe | https://justdeleteme.xyz | Direct deletion links for 500+ services |
| JustGetMyData | https://justgetmydata.com | GDPR data request links |
| Hudson Rock | https://www.hudsonrock.com/threat-intelligence-cybercrime-tools | Infostealer free lookup |
41.2 Self-Doxxing Audit Workflow โ 6 Steps
- Initial self-audit: search your email, username, real name in HIBP + DeHashed + IntelX + Google (
"your name" filetype:pdf). - Identify forgotten accounts via JustDeleteMe โ list of services where you ever registered.
- Request personal data download via JustGetMyData (GDPR gives right to data export in 30 days).
- Delete unnecessary accounts with priority: old social networks, abandoned forums, duplicate services.
- Rotate compromised passwords with a password manager (Bitwarden, 1Password, KeePassXC).
- Document your own footprint BEFORE starting a sensitive investigation โ knowing your exposure prevents surprises.
41.3 Per-Service Privacy
- Google Account: Activity Controls (disable Web & App Activity, Location History, YouTube History).
- Facebook: review privacy settings, download data, disable facial recognition.
- LinkedIn: review profile visibility, hide connections if you investigate sectors where your network may be a signal.
- Telegram: use a virtual number, not your main one. Enable 2FA.
- WhatsApp: review profile photo visibility, last connection, status. For investigations: secondary account with virtual number.
42. Discord & Telegram OSINT 2026
42.1 Verified Tools
| Tool | URL | Function |
|---|---|---|
| Telepathy v2.3.4 | https://github.com/prose-intelligence-ltd/Telepathy-Community | Telegram OSINT toolkit (Jordan Wildon) |
| Telegago (Google CSE) | https://cse.google.com/cse?cx=006368593537057042503:efxu7xprihg | Google CSE for Telegram (do NOT use telegago.com โ hijacked) |
| TelegramDB | https://telegramdb.org | Telegram channel search engine |
| TGStat | https://tgstat.com | Telegram statistics |
| DiscordLeaks (Unicorn Riot) | https://discordleaks.unicornriot.ninja/ | Discord server leaks |
42.2 Telegram OSINT Workflow
- Get API credentials at https://my.telegram.org (real, valid phone number required).
- Install Telepathy:
pip install telepathy. - Basic commands:
telepathy -c channel_name(channel info),telepathy -u username(user info),telepathy -g group_id --members(memberlist). - Mass archiving:
telepathy -c channel --export json. - Location lookup: Telegram users may expose approximate location via the "People Nearby" feature.
42.3 Discord OSINT Workflow
- Server discovery via https://disboard.org and https://discordservers.com (third-party search engines).
- Discord API v10 with correct intents:
GUILD_MESSAGESto read messages,GUILD_MEMBERSfor memberlist (requires verification if bot is in >100 servers). - Audit log analysis if you have admin in the server:
discord.com/api/v10/guilds/{guild.id}/audit-logs. - User ID lookup: https://discord.id (decodes snowflake to creation timestamp).
- OPSEC: NEVER join a target server with your personal account. Create a sock puppet with a dedicated email.
42.4 Verified Learning Resources
- OSINT Combine โ Inside Discord: An OSINT Guide
- Bellingcat Toolkit โ Telepathy entry
- OSINT Handbook โ Telegram
43. Satellite OSINT 2026
Critical context (2026): The Economist (15 March 2026) documented "Open-source intelligence shuts down" โ Planet Labs enacted an indefinite blackout over the Middle East following the Gaza war; Maxar, Planet and BlackSky restricted commercial imagery. In parallel, democratization via SkyFi ($15 per image) and Copernicus Browser (ESA, free) continues. This is the defining tension of GEOINT in 2026.
43.1 Verified Tools
| Tool | URL | Function |
|---|---|---|
| Copernicus Browser | https://browser.dataspace.copernicus.eu | Sentinel-1/2/3/5P free, full resolution |
| SkyFi | https://skyfi.com | Multi-provider marketplace ($15/image) |
| Sentinel Hub | https://www.sentinel-hub.com | Commercial over Sentinel data |
| NASA Worldview | https://worldview.earthdata.nasa.gov | Near-real-time satellite |
| USGS Earth Explorer | https://earthexplorer.usgs.gov | USGS catalogue (Landsat, MODIS) |
| Planet Labs | https://www.planet.com | Daily commercial satellite (may be restricted) |
| Maxar | https://www.maxar.com | High resolution (may be restricted post-Gaza) |
| Umbra Space | https://www.umbra.space | High-resolution SAR |
43.2 Satellite OSINT Workflow โ 7 Steps
- Start with Copernicus Browser (free, historical archive from 2015+, Sentinel-2 at 10 m resolution).
- If you need near-real-time: NASA Worldview (latency <3 hours for MODIS).
- For new tasking or sub-meter resolution: SkyFi ($15+ per selective image, multi-provider).
- Before publishing: verify the provider's EULA (Planet/Maxar may revoke publication rights).
- Document source + timestamp + cloud cover % for every image used.
- For chronolocation: combine with historical imagery from Google Earth Pro (free).
- For SAR (cloud-penetrating): Copernicus Sentinel-1 or Umbra (commercial).
43.3 Verified Learning Resources
- Bellingcat โ How to Use Free Satellite Imagery (May 2024)
- GIJN Reporter's Tipsheet โ Free Satellite Images
44. C2PA + SynthID + Deepfake Detection 2026
Industrial milestone (MayโAugust 2026): OpenAI joined the C2PA steering committee and adopted Google DeepMind's SynthID. Google announced native C2PA + SynthID verification in Search and Chrome (Google I/O 2026). Reality Defender was named "Market Shaper" by Gartner. This is the industry's scalable response to the deepfake arms race.
44.1 Verified Standards & Tools
| Tool | URL | Function |
|---|---|---|
| C2PA viewer | https://c2paviewer.com | Visual verifier of C2PA manifests |
| Content Credentials | https://contentcredentials.org | Official C2PA standard |
| SynthID (Google DeepMind) | https://deepmind.google/technologies/synthid/ | AI content watermarking |
| Reality Defender | https://www.realitydefender.com | Deepfake detection (free API 50/mo) |
| Truepic | https://truepic.com | Content credentials platform |
| Sensity AI | https://sensity.ai | Deepfake detection |
44.2 Layered Verification Methodology
- Verify C2PA Content Credentials with c2paviewer.com before any analysis.
- Detect SynthID watermark if present (Google SynthID detector).
- If no credentials, run Reality Defender / Sensity for forensic analysis.
- Document absence of credentials as an indicator (not proof) of manipulation.
- Cross-check with reverse image search (Google Lens, Yandex, TinEye).
- For video: extract keyframes with FFmpeg and analyse each one.
45. Professional Templates & Deliverables
45.1 Intelligence Information Report (IIR) โ NATO/OSINT Adapted Format
The IIR is the atomic deliverable: one question, one source, one time, one evaluation. It is not a dossier (that is the Target Package). The IIR feeds a dossier.
====================================================================
INTELLIGENCE INFORMATION REPORT (IIR)
====================================================================
--- HEADER ---
REPORT NUMBER: [ORG]-IIR-[YYYY]-[NNNN]
CLASSIFICATION: UNCLASSIFIED // FOR OFFICIAL USE ONLY
SUBJECT COUNTRY: [Country ISO 3166-1 alpha-3]
PREPARED BY: [Analyst name or team]
REPORT DATE: [ISO 8601: YYYY-MM-DDThh:mmZ]
PERIOD OF REPORT: [Start date โ End date]
REQUESTING OFFICE: [Team/Department that requested the analysis]
--- SOURCE EVALUATION (NATO A-F / 1-6 system) ---
SOURCE RELIABILITY: [A/B/C/D/E/F]
A=Confirmed ยท B=Usually reliable ยท C=Fairly reliable
D=Not usually reliable ยท E=Unreliable ยท F=Cannot be judged
INFO CREDIBILITY: [1/2/3/4/5/6]
1=Confirmed by others ยท 2=Probably true
3=Possibly true ยท 4=Doubtfully true ยท 5=Improbable
6=Cannot be judged
SOURCE DESCRIPTION: [One line, do not expose sensitive source]
SOURCE ACCESS: [Public / Aggregated / Paid / Provided by third party]
--- CONFIDENCE LEVEL (ICD 203) ---
CONFIDENCE: [HIGH / MODERATE / LOW]
JUSTIFICATION: [2-3 lines. High = corroborated by โฅ2 independent sources
with solid causal logic. Moderate = 1 reliable or 2 moderate.
Low = single or weak source]
KEY ASSUMPTIONS: [List of assumptions that, if broken, lower confidence]
--- BODY ---
BLUF (Bottom Line Up Front):
[1-3 sentences. The reader must understand the critical finding from this alone.]
KEY FINDINGS (numbered, max 5):
1. [Critical finding #1]
2. [Critical finding #2]
3. [Critical finding #3]
EVIDENCE (each finding with support):
- Finding #1:
* Sources: [URL + capture date]
* Capture: [SHA-256 of original document / screenshot]
* Archive: [archive.org snapshot URL if applicable]
ANALYSIS (interpretation, not evidence):
[What it means, what it implies, what it does not imply. Apply SATs from Appendix B]
KNOWLEDGE GAPS (what you DO NOT know):
- [Gap 1]
- [Gap 2]
RECOMMENDATIONS (prioritized next steps):
1. [Action โ who, what, when]
2. [Action]
3. [Action]
--- ANNEXES ---
A. Sources list (URLs, dates, hashes)
B. Charts/maps/graphs (ownership diagram, timeline, geo)
C. Raw data (PDFs, screenshots, exports)
D. Methodology note (which SATs were applied)
E. Chain of Custody log (see 45.5)
--- DISTRIBUTION ---
TO: [Nominal list]
CC: [Nominal list]
NOFORN: [Y/N]
--- REVISION HISTORY ---
| Rev | Date | Author | Changes |
|-----|------------|---------------------|-------------------------------|
| 0.1 | 2026-07-19 | A. Senior | Initial draft |
| 1.0 | 2026-07-20 | A. Senior+Reviewer | Peer review, approval |
====================================================================
45.2 Target Package (Person) Template โ 20 Fields
| # | Field | Typical Source |
|---|---|---|
| 1 | Full canonical name + aliases | LinkedIn, civil registry |
| 2 | Date and place of birth | Adverse media, public records |
| 3 | Nationality(ies) | Public visas, public records |
| 4 | Official identifiers (RFC/CURP/CPF/CUIT/DNI) | Public registry |
| 5 | Reference photo(s) (min. 1 frontal) | LinkedIn, press |
| 6 | Chronological professional bio | LinkedIn, OCCRP Aleph |
| 7 | Current positions | LinkedIn, corporate registry |
| 8 | Relevant historical positions (10 years) | OpenCorporates, EDGAR |
| 9 | Key personal relationships | LittleSis, adverse media |
| 10 | Corporate relationships (UBO/director) | OpenOwnership, OpenCorporates |
| 11 | PEP status + since when + level | OpenSanctions PEP |
| 12 | Sanctions status + designation date | OpenSanctions aggregator |
| 13 | Adverse media (3-5 incidents) | Google News, OCCRP, ICIJ |
| 14 | Litigation (civil/criminal/admin) | PACER, local judicial registry |
| 15 | Digital footprint (email/phone/domains) | Maigret, HIBP, WhoisXML |
| 16 | Real estate footprint | Property registry |
| 17 | Declared net worth (if PEP) | Asset declaration |
| 18 | Travel and residences (5 years) | Press, Instagram geotags |
| 19 | Identified associated risks | Output of analysis |
| 20 | Analytic confidence + gap list | โ |
45.3 Executive Briefing Template (1 Page)
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ EXECUTIVE BRIEFING โ [Topic] โ
โ Classification: CONFIDENTIAL // C-Suite only Date: YYYY-MM-DD โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ โ
โ BLUF (Bottom Line Up Front): โ
โ [2-3 sentences, no jargon] โ
โ โ
โ Confidence: HIGH โโโ / MODERATE โโโ / LOW โโโ โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 1. CONTEXT (what was investigated and why) [3-4 lines] โ
โ โ
โ 2. KEY FINDING [4-6 lines] โ
โ - Central fact โ
โ - Source(s) โ
โ - Implication for the organization โ
โ โ
โ 3. RISK AND IMPACT (financial/reputational/operational/legal) โ
โ [2x2 table or list; A/B/C marks by severity/probability] โ
โ โ
โ 4. RECOMMENDATIONS (3, prioritized) โ
โ 1. [Immediate action โ 24-72h] โ
โ 2. [30-day action] โ
โ 3. [90-day action] โ
โ โ
โ 5. NEXT STEPS / KNOWLEDGE GAPS โ
โ - What is missing and how to close it (cost/effort estimate) โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Full annex: [link to full IIR / Target Package] โ
โ Analyst contact: [name, email, phone] โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
45.4 Fact-Check Report Template (Journalism)
FACT-CHECK REPORT
=================
1. CLAIM (the verified statement)
Literal text: "..."
Claim source: [URL + date + capture]
Who said it: [person/entity + position]
2. VERIFICATION DATE: YYYY-MM-DD
3. VERIFIER(S): [name(s)]
4. VERIFICATION STATUS:
[ ] True [ ] Mostly true
[ ] Misleading [ ] Mostly false
[ ] False [ ] Unverifiable
5. EVIDENCE COLLECTED
5.1 Source 1: [type, URL, date, hash]
5.2 Source 2: ...
5.3 Source 3: ...
6. ANALYSIS (what weighs more and why)
7. OMITTED CONTEXT (what the claim does not say)
8. CONTACT WITH ORIGINAL SOURCE
Was the claimant contacted? Yes/No ยท Response: [...]
9. REFERENCES [verifiable URLs]
10. POST-PUBLICATION CORRECTIONS [log]
11. LICENSE AND REUSE
45.5 Digital Chain of Custody Checklist โ 12 Steps
Before capturing:
- 1. Synchronise the device clock with NTP (difference <1s).
- 2. Verify the browser is clean (no logged-in session that biases served content).
- 3. Log pre-capture: exact URL, date/time with explicit timezone, public IP, access method (direct/VPN/Tor).
During capture:
- 4. Capture with visible timestamp on screen.
- 5. Save original format: complete HTML ("Save Page As โ Webpage, Complete") + uncropped PNG screenshot.
- 6. Generate a snapshot on archive.org / archive.today and save the returned URL.
- 7. For video: download with
yt-dlppreserving original metadata; do not re-encode.
Immediately after:
- 8. Compute SHA-256 of the original file and log: filename, hash, size, UTC capture date.
- 9. For JS-heavy captures: also save HAR file (Network โ Save All as HAR) and WARC if using wpull or archiveweb.
- 10. Rename files with convention
{YYYYMMDDTHHMMZ}_{slug}.{ext}(no spaces or accents).
Storage:
- 11. Store in an append-only repository (git with tags or WORM system). Never overwrite, only version. Second offline repository recommended.
- 12. Maintain a master CSV/JSON log with columns: case_id ยท filename ยท sha256 ยท capture_url ยท capture_timestamp_utc ยท capture_method ยท analyst ยท notes. One master file per case.
45.6 Verified Templates & Deliverables Tools
| Tool | URL | Function |
|---|---|---|
| Obsidian | https://obsidian.md | Linked notes with graphs |
| TimelineJS | https://timeline.knightlab.com | Interactive timelines |
| Aeon Timeline | https://www.aeontimeline.com | Complex timelines |
| Draw.io / diagrams.net | https://www.diagrams.net | Diagrams and flows |
| Zotero | https://www.zotero.org | Reference management |
| CryptPad | https://cryptpad.fr | Encrypted collaboration |
| Standard Notes | https://standardnotes.com | E2E encrypted notes |
| VeraCrypt | https://www.veracrypt.fr | Container encryption |
| MAT2 | https://0xacab.org/jvoisin/mat2 | Metadata stripping |
| ExifTool | https://exiftool.org | Metadata extraction |
| OpenTimestamps | https://opentimestamps.org | Blockchain timestamping |
| Hunchly | https://www.hunchly.com | Web capture with OPSEC ($129/yr) |
| archive.org Wayback | https://web.archive.org | Historical web archive |
| Archive.today | https://archive.today | Wayback alternative |
| Maltego | https://www.maltego.com | Link analysis and visualization |
| Datasette | https://datasette.io | Explore CSV/SQLite |
| Gephi | https://gephi.org | Graph analysis |
| RAWGraphs | https://rawgraphs.io | Charts from CSV |
| Datawrapper | https://www.datawrapper.de | Visualization for reports |
| QGIS | https://qgis.org | Desktop GIS |
| Mapillary | https://www.mapillary.com | Crowdsourced street-view |
| Atlos | https://www.atlos.org | Collaborative investigation |
| Auto-Archiver (Bellingcat) | https://github.com/bellingcat/auto-archiver | Automatic archiving |
| 4CAT | https://github.com/digitalmethodsinitiative/4cat | Social data analysis |
| Pinpoint (Google Journalist Studio) | https://journaliststudio.google.com/pinpoint/ | Document analysis |
45.7 Common Errors in OSINT Deliverables
- BLUF absent or buried. The executive reader has no time. If the critical finding is on page 7, it does not exist.
- Confusing fact with inference. "Company X is owned by Y" (fact) vs. "probably controlled by Y" (inference). Use markers
[FACT]vs[ANALYSIS]. - No chain of custody. A screenshot without URL, date and hash is anecdotal.
- Overloading with tools. The C-Suite does not care which tools you used, only the findings.
- Not declaring knowledge gaps. A senior declares what they do not know; a junior hides it.
- Unjustified confidence. "High Confidence" without justification = suspicious.
- Wrong format scaling. A 30-page IIR to a CFO = won't be read. A 1-page executive briefing to an auditor = useless.
- No versioning. Without revision history, no one knows if they are reading version 0.1 or 1.4.
46. Regional OSINT
Each country below is in a collapsible block โ click to expand. Country selection criteria: digital footprint, OSINT practitioner community, geopolitical relevance, and verifiable public sources. All URLs were verified on 2026-07-19. Status legend: โ 200 OK ยท โ ๏ธ 403/401 (bot-blocked at edge, live in browser) ยท โ ๏ธ Timeout (slow gov site, works with patience).
46.1 Americas
๐บ๐ธ United States โ Click to expand
Digital Landscape
Internet penetration ~93% of ~335M (Pew/ITU). Google (~88% market share), Bing, DuckDuckGo and Brave dominate search. Facebook, Instagram, X/Twitter, TikTok, Reddit, LinkedIn, Snapchat and Discord are the dominant social platforms; messaging skews to iMessage, WhatsApp, SMS (still heavily used for 2FA), Signal (journalistic) and Telegram (extremist/cyber-criminal). The US is also headquarters to most of the global OSINT-vendor stack (Palantir, Recorded Future, Sayari, Maltego ownership, Blackbird.AI, OSINT Industries).
Intelligence Agency & OSINT Tradecraft
- Lead civilian foreign-intelligence agency: Central Intelligence Agency (CIA) โ https://www.cia.gov โ
- Lead signals-intelligence agency: National Security Agency (NSA) โ https://www.nsa.gov
- Federal law-enforcement & domestic intel: Federal Bureau of Investigation (FBI) โ https://www.fbi.gov
- OSINT dedicated unit: Open Source Enterprise (OSE), organisational descendant of the Open Source Center (OSC, est. 2005), itself descended from the Foreign Broadcast Information Service (FBIS, est. 1941). OSE sits under the CIA's Directorate of Digital Innovation (DDI) but coordinates across the IC through the Open Source Inter-Agency Center (OSIAC) reporting to the Director of National Intelligence.
- Publicly verifiable tradecraft points:
- ODNI Intelligence Community Open Source Strategy 2024-2026 โ https://www.dni.gov/files/ODNI/documents/IC_OSINT_Strategy.pdf โ ๏ธ 403 to bots, downloadable in any browser. This is the first public IC document that formally elevates OSINT to a first-tier INT alongside HUMINT/SIGINT/GEOINT/MASINT.
- State Department OSINT Strategy 2024-2026 โ corroborates the IC-wide elevation.
- FBIS historical lineage (declassified): CIA Historical Review Program released the FBIS collection guide and millions of translated foreign-broadcast transcripts (1941-1995).
- WMD Commission (Silberman-Robb, 2005): publicly recommended elevating OSINT โ documented origin of the Open Source Center.
- What is NOT verified (myth-busting):
- There is no public confirmation that the CIA runs sockpuppet armies at scale. The single documented case is the 2014 AP story on "ZunZuneo", a fake Cuban Twitter.
- "The NSA reads every email" โ actual Snowden-disclosed programs (PRISM, UPSTREAM, XKEYSCORE) targeted traffic under FISA ยง702; bulk domestic collection was narrowed by the USA FREEDOM Act 2015.
- The CIA did not create the internet (DARPA did, 1969). CIA venture arm In-Q-Tel did fund Keyhole (โ Google Earth) and Palantir.
Government Sources (Verified URLs)
| Source | URL | Function | Status |
|---|---|---|---|
| SEC EDGAR | https://www.sec.gov/edgar | Corporate filings (10-K, 10-Q, 13D, S-1) | โ ๏ธ 403 bot-block, live in browser |
| PACER | https://pacer.uscourts.gov | Federal court records | โ 200 |
| OFAC SDN search | https://sanctionssearch.ofac.treas.gov | Sanctions / PEP screening | โ 200 |
| Data.gov | https://www.data.gov | Federal open data portal | โ 200 |
| FOIA.gov | https://www.foia.gov | FOIA portal & requester info | โ 200 |
| Federal Register | https://www.federalregister.gov | Presidential docs, rules, notices | โ 200 |
| USCourts.gov | https://www.uscourts.gov | Federal case statistics & finder | โ 200 |
| SAM.gov | https://sam.gov | Federal contractor registry + exclusions | โ 200 |
| FEC | https://www.fec.gov/data/ | Campaign finance data | โ 200 |
State-level company registers: The US has no federal companies register. Each state runs its own Secretary of State business search (e.g. California https://businesssearch.sos.ca.gov, Delaware https://icis.corp.delaware.gov/ecorp/entitysearch/namesearch.aspx, New York https://apps.dos.ny.gov/publicInquiry/).
Local Sources & Press
- Quality press: New York Times, Washington Post, Wall Street Journal, ProPublica, Reuters, AP, Bloomberg, Los Angeles Times, Miami Herald, Texas Tribune, CALmatters.
- Investigative NGOs: ProPublica (Pulitzer-winning nonprofit), International Consortium of Investigative Journalists (ICIJ) โ https://www.icij.org โ , Center for Public Integrity, OpenSecrets (https://www.opensecrets.org โ ๏ธ 403, live in browser), LittleSis (https://littlesis.org โ ).
- OSINT community: Bellingcat (US-originated, Amsterdam-based since 2018), IntelTechniques (Michael Bazzell), OSINT Framework (Lockfale), SANS SEC497/SEC487 training, Trace Labs, OSINT Curious, The OSINT Newsletter.
- Academic OSINT: National Security Institute (George Mason U.), Harvard Belfer Center, Stanford Internet Observatory, Texas A&M Scowcroft Institute.
Country-Specific OSINT Tools
- CourtListener (Free Law Project) โ https://www.courtlistener.com โ โ PACER alternative for federal appellate/district opinions and the RECAP archive.
- OpenCorporates US state data โ https://opencorporates.com โ pulls from 50+ state SOS feeds.
- OpenSanctions US datasets โ https://www.opensanctions.org/datasets/ โ โ FBI Most Wanted, OFAC SDN, BIS Denied Persons, SAM exclusions.
- Sayari โ https://sayari.com โ ๏ธ โ commercial, strong on corporate-network construction.
- Palantir Gotham / Foundry โ used by US defense & law-enforcement.
- Maltego โ https://www.maltego.com โ โ graph-based link analysis.
- Recorded Future โ https://www.recordedfuture.com โ ๏ธ โ commercial threat intel.
- OSINT Industries โ https://osint.industries โ email/username โ linked accounts.
Legal Considerations
- First Amendment protects newsgathering broadly but is not absolute.
- Computer Fraud and Abuse Act (CFAA), 18 U.S.C. ยง 1030 โ https://www.law.cornell.edu/uscode/text/18/1030 โ . Post-Van Buren v. United States (2021) the Supreme Court narrowed "exceeds authorised access" but ToS-violation scraping with a login remains risky.
- Electronic Communications Privacy Act (ECPA) and Stored Communications Act (SCA) govern interception and access to stored comms.
- FOIA (1966) โ https://www.foia.gov โ โ the strongest federal transparency lever. State public-records laws vary (California PRA, Texas PIA, Florida Sunshine Law).
- State privacy laws: California CCPA/CPRA (2020/2023), Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA (2024).
- No federal GDPR-equivalent. Investigators publishing personal data of US persons are largely constrained by defamation, false-light and tortious-interference law.
- SLAPP risk: 32 states have anti-SLAPP statutes (California, Texas, New York, Florida among the strongest).
- State secret / classification: 18 U.S.C. ยง 798 (Espionage Act) relevant if an investigator receives leaked classified docs.
- OPSEC: US-based investigators can be subpoenaed by grand jury. Border searches under 8 CFR 287 โ devices can be searched at the US border without reasonable suspicion.
Notable Cases
- MH17 (2014, Netherlands-led but Bellingcat-driven). Bellingcat used open VK posts, satellite imagery, geolocation of a Buk TELAR transport and matched social-media timestamps to attribute the downing of MH17 to Russian forces. Methodology PDF: https://www.bellingcat.com/app/uploads/2015/10/MH17-The-Open-Source-Evidence-EN.pdf โ . The case is the textbook example of OSINT-as-evidence (used by the JIT and cited in the Dutch court verdict in absentia against Russians Girkin/Dubinsky/Pulatkij in 2022).
- 1MDB kleptocracy asset recovery (2016-2024). DOJ Civil forfeiture complaints โ https://www.justice.gov/criminal/criminal-mlnsa/kleptocracy-asset-recovery-initiative โ ๏ธ โ used leaked bank records, SEC filings, real-estate records from NYC registry and shell-company filings from BVI/Seychelles.
- Boston Marathon bombing misidentification (2013). The cautionary counter-example: Reddit/Twitter crowd-sleuths wrongly identified missing student Sunil Tripathi as a suspect; he was later found dead by suicide. Teaching case on confirmation bias in OSINT.
- January 6 Capitol riot (2021). Sedition Hunters (https://seditionhunters.org) and the FBI used Parler video metadata and facial matches to identify >1,400 suspects.
๐ง๐ท Brazil โ Click to expand
Digital Landscape
Brazil had 187.9 million internet users at the start of 2024 (86.6% penetration) per DataReportal's Digital 2024: Brazil. WhatsApp is the dominant communication layer โ roughly 147โ148 million users, ~93% of internet users send messages online โ making it the primary OSINT surface. Google dominates search; YouTube is the second social platform after WhatsApp.
Intelligence Agency & OSINT Tradecraft
- Main agency: Agรชncia Brasileira de Inteligรชncia (ABIN), subordinated to the Institutional Security Cabinet (GSI/PR). Public site: https://www.gov.br/abin/en
- OSINT unit / tradecraft: ABIN does not publicly advertise a dedicated OSINT directorate. Its Desafios de Inteligรชncia โ Ediรงรฃo 2026 public report describes OSINT as a collection discipline integrated into its Obtaining (Obtenรงรฃo) area, but no named OSINT unit is publicly attributed. The Brazilian intelligence community (SISBIN) coordinates civilian + military intelligence; ABIN is the central body.
- Publicly attributable tradecraft: None specifically attributable beyond ABIN's public acknowledgement that it collects open-source information as part of its mandate. The most mature Brazilian OSINT tradecraft is practised by investigative journalists (Agรชncia Pรบblica, Piauรญ) and civil-society investigators, not by ABIN.
Government Sources (Verified URLs)
| Source | URL | Function |
|---|---|---|
| Receita Federal โ CNPJ | https://www.gov.br/receitafederal/pt-br/servicos/cadastro/cnpj | Business registry lookup |
| CNPJ Comprovante | https://solucoes.receita.fazenda.gov.br/servicos/cnpjreva/cnpjreva_solicitacao.asp | Registration/situation certificate |
| Diรกrio Oficial da Uniรฃo (DOU) | https://in.gov.br/servicos/diario-oficial-da-uniao | Federal official gazette |
| Imprensa Nacional | https://www.gov.br/imprensanacional/pt-br | Print house & gazette archive |
| Portal de Compras (Comprasnet) | https://www.gov.br/compras/pt-br | Federal procurement contracts |
| Portal da Transparรชncia | https://www.portaltransparencia.gov.br | CEIS (sanctioned companies), public spending |
Court records: Jusbrasil (https://www.jusbrasil.com.br/consulta-processual) and Escavador (https://www.escavador.com) are the two principal case-law aggregators; both index CNJ-connected tribunals. The official CNJ platform is https://www.cnj.jus.br.
Property registry: Brazil has no unified federal property registry; each Cartรณrio de Registro de Imรณveis (notary office) keeps its own records.
Local Sources & Press
- Quality press: Folha de S.Paulo (https://www1.folha.uol.com.br), O Globo (https://oglobo.globo.com), Estadรฃo (https://www.estadao.com.br), Valor Econรดmico (https://valor.globo.com).
- Investigative / non-profit: Agรชncia Pรบblica (https://apublica.org), Agรชncia Lupa (https://piaui.folha.uol.com.br/lupa/ fact-checking), The Intercept Brasil (https://theintercept.com/brasil/), Instituto Socioambiental (https://www.socioambiental.org).
- Open-data portals: dados.gov.br (federal open data), TSE Eleiรงรตes (https://divulgacandcontas.tse.jus.br) for electoral/campaign finance.
Country-Specific OSINT Tools
- Jusbrasil & Escavador โ case-law search (the closest Brazilian equivalent to US PACER).
- Consulta CNPJ Receita โ corporate registry lookup (free; CAPTCHA-protected).
- CNPJ.biz / ReceitaAWS โ community wrappers over the Receita Federal CNPJ API.
- TSE DivulgaCandContas โ campaign finance & candidate asset declarations.
- OSINT-Tools-Brazil (GitHub:
bgmello/OSINT-Tools-Brazil) โ community-curated list. - OSINT Brasil blog (https://osintbrasil.blogspot.com) โ practitioner write-ups.
Legal Considerations
- Data protection: LGPD โ Lei Geral de Proteรงรฃo de Dados, Law 13.709/2018, in force since 18 Sep 2020. Enforced by ANPD (https://www.gov.br/anpd).
- Access to information: Lei de Acesso ร Informaรงรฃo (LAI), Law 12.527/2011 โ every citizen can request government records; FalaBR (https://falabr.cgu.gov.br) is the central portal.
- SLAPP risk: No dedicated anti-SLAPP statute; journalists face criminal defamation suits under the Cรณdigo Penal (arts. 138โ145).
- Internet regulation: Marco Civil da Internet (Law 12.965/2014) governs intermediary liability and data retention.
Notable Cases
- Operaรงรฃo Lava Jato (Operation Car Wash) โ 2014โ2021 anti-corruption task force led by the Curitiba federal court (Judge Sรฉrgio Moro) and the Ministรฉrio Pรบblico Federal. Convictions included former president Lula (later annulled by STF in 2021), Odebrecht/Novonor executives, and Petrobras directors. OSINT tradecraft was light; the case was built on plea bargains (delaรงรฃo premiada) and leaks. Verified URLs: https://en.wikipedia.org/wiki/Operation_Car_Wash ยท https://apublica.org/especial/vaza-jato (the "Vaza Jato" leak archive).
๐ฒ๐ฝ Mexico โ Click to expand
Digital Landscape
Mexico has ~96 million internet users (~75% penetration per DataReportal Digital 2024 Mexico). WhatsApp is the dominant communication channel; Facebook, Instagram, X (Twitter) and TikTok follow. Google holds >90% search share. Internet penetration is highly uneven โ urban vs rural gap is significant.
Intelligence Agency & OSINT Tradecraft
- Main agency: Centro de Investigaciรณn y Seguridad Nacional (CISEN) was replaced in December 2018 by the Centro Nacional de Inteligencia (CNI) under the Secretariat of Security and Citizen Protection (SSPC). Public reference: https://www.gob.mx/sspc/cni
- OSINT unit / tradecraft: No publicly attributed OSINT directorate. Mexican intelligence is widely regarded as under-resourced on technical collection; the public-record consensus is that Mexico "lacks a robust external intelligence capability" comparable to its partners in the region.
- Verified URLs:
Government Sources (Verified URLs)
| Source | URL | Function |
|---|---|---|
| SAT (Servicio de Administraciรณn Tributaria) | https://www.sat.gob.mx | Tax authority, RFC lookup, e.factura |
| DOF (Diario Oficial de la Federaciรณn) | https://www.dof.gob.mx | Federal official gazette |
| INEGI | https://www.inegi.org.mx | DENUE business directory, census, statistics |
| Compranet | https://www.gob.mx/compranet | Federal public procurement |
| INAI | https://www.inai.org.mx | Transparency / FOIA portal |
| Plataforma Digital Nacional | https://plataformadigitalnacional.org | Asset declarations, sanctions |
| RNIE | https://www.rnie.sems.gob.mx | National educational institutions registry |
Local Sources & Press
- Quality press: Proceso, Animal Polรญtico, Latinus, Emeequis, Reforma, El Universal, Milenio.
- Investigative / non-profit: MexicanLeaks (https://mexicanleaks.mx), Quinto Elemento Lab, Article 19 Mรฉxico (https://article19.org/offices/mexico-office).
- OSINT community: OSINT Espaรฑol, OSINT Mรฉxico communities on Telegram/Discord.
Country-Specific OSINT Tools
- INEGI DENUE โ Directorio Estadรญstico Nacional de Unidades Econรณmicas (business directory).
- SAT RFC lookup โ tax ID verification.
- MexicanLeaks โ anonymous leak submission platform.
- Plataforma Digital Nacional โ asset declarations of public officials, sanctioned entities.
- Article 19 Mรฉxico โ attacks on journalists tracker.
Legal Considerations
- Data protection: LFPDPPP โ Ley Federal de Protecciรณn de Datos Personales en Posesiรณn de los Particulares (2010), reformed in 2025 for the private sector. ARCO rights (Acceso, Rectificaciรณn, Cancelaciรณn, Oposiciรณn). INAI is the authority (when in operation โ INAI was paralysed for months in 2024-2025 due to lack of commissioners).
- Access to information: Ley General de Transparencia y Acceso a la Informaciรณn Pรบblica (2015).
- SLAPP risk: High. Mexico is one of the most dangerous countries for journalists (Article 19, CPJ). Criminal defamation suits are used to silence investigators.
- OPSEC: Critical. Investigating cartels or political corruption carries physical risk.
Notable Cases
- Ayotzinapa case (2014). 43 student teachers from the Ayotzinapa Rural Teachers' College disappeared in Iguala, Guerrero. The official "Historical Truth" (Verdad Histรณrica) was challenged by the GIEI (Grupo Interdisciplinario de Expertos Personas) report, which used OSINT (satellite imagery, phone records, geolocation of security forces) to contradict the government narrative. Verified URLs: https://en.wikipedia.org/wiki/2014_Iguala_mass_kidnapping ยท https://gieicom.org/informes/.
- MexicanLeaks investigations โ multiple investigations into political corruption published through the platform.
๐ฆ๐ท Argentina โ Click to expand
Digital Landscape
Argentina has ~37 million internet users (~83% penetration per DataReportal Digital 2024 Argentina). WhatsApp is the dominant messaging channel; Facebook, Instagram and X (Twitter) follow. Google holds >90% search share.
Intelligence Agency & OSINT Tradecraft
- Main agency: Historically SIDE / Secretarรญa de Inteligencia del Estado; renamed AFI (Agencia Federal de Inteligencia) by Law 27.126 in 2015. In July 2024, President Javier Milei dissolved AFI by decree and re-created it as the Secretarรญa de Estado de Inteligencia (SIDE) under direct presidential authority.
- OSINT unit / tradecraft: No publicly attributed OSINT directorate. Argentine intelligence is widely regarded as under-resourced on technical collection.
- Verified URLs:
Government Sources (Verified URLs)
| Source | URL | Function |
|---|---|---|
| Boletรญn Oficial de la Repรบblica Argentina | https://www.boletinoficial.gob.ar | National official gazette |
| AFIP / ARCA | https://www.afip.gob.ar | Tax authority, CUIT lookup |
| IGJ (Inspecciรณn General de Justicia) | https://www.jus.gob.ar/igj | National corporate registry |
| INDEC | https://www.indec.gob.ar | National statistics |
| Datos Jus.Gob.Ar | https://www.datos.jus.gob.ar | Justice open data |
| Padrรณn Electoral | https://www.padron.gob.ar | Electoral roll lookup |
Local Sources & Press
- Quality press: La Naciรณn, Clarรญn, Pรกgina/12, Infobae, Perfil.
- Investigative / non-profit: Chequeado (https://chequeado.com, fact-checking), Revista Anfibia (https://revistaanfibia.com), Centro de Implementaciรณn de Polรญticas Pรบblicas para la Equidad y el Crecimiento (CIPPEC).
- OSINT community: Hacks/Hackers Buenos Aires.
Country-Specific OSINT Tools
- Chequeado โ Argentina's leading fact-checking organisation.
- AFIP / ARCA CUIT lookup โ tax ID verification.
- IGJ Sociedades โ corporate registry lookup.
- Atlas ID โ forensic identification system (national registry).
Legal Considerations
- Data protection: Ley 25.326 (2000), regulated by AAIP (https://www.argentina.gob.ar/aaip). Argentina has EU adequacy status.
- Access to information: Ley 27.275 (2016) โ comprehensive FOIA law.
- SLAPP risk: Moderate. Journalists face criminal defamation suits.
Notable Cases
- Cuadernos de las coimas (Notebooks of the bribes, 2018). Chauffeur Oscar Centeno's notebooks documented bribes from public-works contractors to Kirchner-era officials. Investigation led by journalist Diego Cabot (La Naciรณn) and Cynthia Garcรญa (C5N). Verified URL: https://en.wikipedia.org/wiki/Cuadernos_de_las_coimas.
๐จ๐ฆ Canada โ Click to expand
Digital Landscape
Canada has ~36 million internet users (~94% penetration). Google dominates search; Facebook, X, Instagram, Reddit and LinkedIn are the main social platforms. WhatsApp and iMessage dominate messaging. Local tech-OSINT ecosystem is concentrated in Toronto, Montreal and Vancouver.
Intelligence Agency & OSINT Tradecraft
- Main civilian agency: Canadian Security Intelligence Service (CSIS) โ https://www.csis-scrs.gc.ca
- Signals intelligence agency: Communications Security Establishment (CSE) โ https://www.cse-cst.gc.ca
- Foreign intelligence assessment: Office of the Intelligence Commissioner and Global Affairs Canada's Intelligence Assessment Division.
- OSINT unit / tradecraft: CSIS and CSE both maintain OSINT collection capabilities but do not publicly advertise dedicated OSINT directorates. CSIS publicly acknowledges OSINT as a collection discipline in its annual reports.
- Verified URLs:
Government Sources (Verified URLs)
| Source | URL | Function |
|---|---|---|
| Corporations Canada | https://www.ic.gc.ca/app/scr/cc/CorporationsCanada/feder.html | Federal corporate registry |
| Industry Canada Open Data | https://open.canada.ca | Federal open data portal |
| Canada Gazette | https://gazette.gc.ca/rp-pr/p1/whats-new/index-eng.html | Official gazette |
| CASL Registry | https://crtc.gc.ca/eng/internet/anti.htm | Anti-spam compliance |
| NSICOP reports | https://www.canada.ca/en/parliament/information/publications/national-security-intelligence-committee-parliamentarians.html | National security oversight reports |
Local Sources & Press
- Quality press: CBC, Toronto Star, The Globe and Mail, La Presse (French), National Post.
- Investigative / non-profit: CBC Investigates, Toronto Star Investigative, Discourse Media, The Pointer.
- OSINT community: Canadian OSINT community on LinkedIn, SecTor conference.
Country-Specific OSINT Tools
- Open Canada โ open data aggregator.
- Lobby Canada โ federal lobbying registry.
- CASL Registry โ anti-spam compliance lookup.
- Provincial corporate registries โ each province maintains its own (e.g. Ontario https://www.ontario.ca/page/search-and-buy-business-name-and-incorporation-information).
Legal Considerations
- Data protection: PIPEDA โ Personal Information Protection and Electronic Documents Act (2000). Provincial equivalents (Quebec Law 25, BC PIPA, Alberta PIPA).
- Access to information: Access to Information Act (1985) โ federal FOIA.
- SLAPP risk: Ontario has anti-SLAPP protections (Anti-SLAPP Act 2015). Other provinces vary.
- OPSEC: Strong press protections. Source shield recognised by courts.
Notable Cases
- NSICOP reports (2019-2024). The National Security and Intelligence Committee of Parliamentarians has published multiple reports on intelligence community activities, including the 2024 report on foreign interference in Canadian elections.
- Hogue Commission (2024). Public inquiry into foreign interference in Canadian electoral processes, led by Justice Marie-Josรฉe Hogue.
46.2 Western Europe
๐ฌ๐ง United Kingdom โ Click to expand
Digital Landscape
Internet penetration ~98% (Ofcom 2024); 5G nationwide; gigabit-fibre rollout ~80% by 2025. Google (~90%), Bing and DuckDuckGo dominate search. WhatsApp is dominant (~80% of UK smartphone users), with iMessage, Signal (journalists) and Telegram. London is Europe's largest LinkedIn market. The UK has a concentrated tech-OSINT ecosystem including Darktrace, BAE Systems Applied Intelligence, Cellebrite UK, DeepMind (now Google DeepMind) and Recorded Future UK.
Intelligence Agency & OSINT Tradecraft
- Lead foreign-intelligence agency: Secret Intelligence Service (SIS / "MI6") โ https://www.sis.gov.uk โ ๏ธ 403 to bots, live in browser.
- Lead signals-intelligence & cyber agency: Government Communications Headquarters (GCHQ) โ https://www.gchq.gov.uk โ . Includes the National Cyber Security Centre (NCSC) โ https://www.ncsc.gov.uk โ .
- Domestic security service: Security Service (MI5) โ https://mi5.gov.uk.
- Military intelligence: Defence Intelligence (DI) sits under the Ministry of Defence.
- OSINT dedicated unit: GCHQ Open Source Intelligence Hub (OSI Hub) โ publicly referenced in the 2023 GCHQ annual report and in the 2024 Intelligence and Security Committee report. Less publicly visible than CIA OSE. NCSC uses OSINT for threat-intel (weekly threat reports).
- Publicly verifiable tradecraft points:
- GCHQ's legal basis is the Investigatory Powers Act 2016 ("Snooper's Charter"); bulk personal datasets and bulk interception warrants are reviewed by the Investigatory Powers Commissioner's Office (IPCO) โ public reports at https://ipco.org.uk.
- NCSC publishes the Early Warning service (free to UK organisations) which is OSINT + sinkhole data โ https://www.ncsc.gov.uk/section/services/early-warning.
- GCHQ published "Pioneers, a UK strategy for AI" (2024) openly โ first IC in Five Eyes to do so.
- What is NOT verified (myth-busting):
- "GCHQ reads every email in the UK" โ actual programs target external traffic under RIPA/IPA warrants; bulk domestic collection requires specific authorization.
- JTRIG (Joint Threat Research Intelligence Group) โ existence disclosed by Snowden; specific operations remain classified. Do not attribute specific operations without source.
Government Sources (Verified URLs)
| Source | URL | Function | Status |
|---|---|---|---|
| Companies House | https://find-and-update.company-information.service.gov.uk | UK companies registry (free, full, historical) | โ 200 |
| The Gazette | https://www.thegazette.co.uk | UK official public record | โ 200 |
| HM Land Registry | https://www.gov.uk/government/organisations/hm-land-registry | Property ownership | โ 200 |
| data.gov.uk | https://www.data.gov.uk | UK open data portal | โ 200 |
| UK Parliament | https://parliament.uk | Hansard, committee reports | โ 200 |
| National Archives | https://www.nationalarchives.gov.uk | Historical records | โ 200 |
| Find a Company | https://find-and-update.company-information.service.gov.uk | Search by name/number | โ 200 |
| OpenOwnership Register | https://register.openownership.org | UK PSC register | โ ๏ธ 403, live in browser |
Local Sources & Press
- Quality press: The Guardian, BBC News, Reuters, Financial Times, The Times, The Telegraph, The Independent.
- Investigative NGOs: Bureau of Investigative Journalism (https://www.thebureauinvestigates.com), OpenDemocracy, Finance Uncovered.
- OSINT community: Bellingcat (Amsterdam-HQ since 2018, originally UK-founded), CIISec (Chartered Institute of Information Security), OSINT Curious UK chapter.
Country-Specific OSINT Tools
- Companies House API โ free, comprehensive UK corporate registry with full historical filings.
- OpenOwnership Register โ UK PSC (Person with Significant Control) register.
- OpenSanctions UK datasets โ UK OFSI sanctions, Consolidated List.
- Hansard API โ parliamentary debates (https://hansard.parliament.uk).
- DueDil โ UK corporate intelligence aggregator (commercial).
- Wayback Machine UK Government snapshot archive โ via UK Web Archive (https://www.webarchive.org.uk).
Legal Considerations
- Data protection: UK GDPR (post-Brexit, retained EU GDPR) + Data Protection Act 2018. Regulated by ICO (https://ico.org.uk).
- Access to information: Freedom of Information Act 2000 (https://www.legislation.gov.uk/ukpga/2000/36/contents).
- Investigatory Powers Act 2016 โ regulates bulk interception and equipment interference.
- Official Secrets Act 1989 โ protects state secrets; relevant for investigators handling leaked UK gov material.
- SLAPP risk: UK has a libel tourism problem; Defamation Act 2013 added a "serious harm" threshold. UK recently published an anti-SLAPP bill proposal in 2024.
Notable Cases
- Skripal poisoning (2018). Bellingcat identified Salisbury suspects "Petrov" and "Boshirov" as GRU officers Anatoliy Chepiga and Alexander Mishkin using Russian leaked databases (probiv). URLs: https://www.bellingcat.com/news/europe/2018/10/09/full-report-skripal-poisoning-suspect-dr-alexander-mishkin-hero-russia/ ยท https://www.bellingcat.com/news/europe/2018/09/20/skripal-suspects-confirmed-gru-operatives-prior-european-operations-disclosed/
- Cambridge Analytica / Facebook data breach (2018). Investigation led by The Guardian / Observer (Carole Cadwalladr) and The New York Times.
- Panama Papers / Pandora Papers โ UK persons featured prominently; ICIJ investigations.
๐ฉ๐ช Germany โ Click to expand
Digital Landscape
Internet penetration ~93% (Bitkom 2024). Google dominates search; alternative privacy-focused search engines (Ecosia, Metager) have notable market share. WhatsApp is the dominant messaging app; Telegram is notably stronger in Germany than in other Western European countries (used by political fringe, anti-vax, Reichsbรผrger). X and LinkedIn are the main professional networks.
Intelligence Agency & OSINT Tradecraft
- Foreign intelligence agency: Bundesnachrichtendienst (BND) โ https://www.bnd.bund.de
- Domestic intelligence agency (Verfassungsschutz): Bundesamt fรผr Verfassungsschutz (BfV) โ https://www.verfassungsschutz.de
- Military intelligence: Militรคrischer Abschirmdienst (MAD) โ https://www.bmvg.de/de/organisation/mad
- OSINT unit / tradecraft: BND has an OSINT branch (Open Source Intelligence), but its work is classified. The BfV publishes the annual Verfassungsschutzbericht (Constitutional Protection Report) which uses OSINT analysis of extremism and disinformation.
- Publicly verifiable tradecraft points:
- BND's legal basis is the BND-Gesetz (BND Act, 2020) โ https://www.gesetze-im-internet.de/bndg/, which explicitly regulates OSINT collection.
- BfV publishes Verfassungsschutzbericht annually (https://www.verfassungsschutz.de/de/oeffentlichkeitsarbeit/publikationen/publikationsarchiv) โ uses OSINT to map extremism.
- Federal Office for Information Security (BSI) โ https://www.bsi.bund.de โ publishes threat reports based on OSINT.
- What is NOT verified: Specific BND OSINT operations are not publicly attributed. Avoid claims about "BND sockpuppets" without source.
Government Sources (Verified URLs)
| Source | URL | Function | Status |
|---|---|---|---|
| Unternehmensregister | https://www.unternehmensregister.de/en | Federal business registry | โ 200 |
| Bundesanzeiger | https://www.bundesanzeiger.de/pub/en/start | Federal gazette (annual financial statements) | โ 200 |
| Transparenzregister | https://www.transparenzregister.de | UBO register (implementing EU AMLD) | โ 200 |
| Datenportal der Bundesregierung | https://www.govdata.de | Federal open data portal | โ 200 |
| Destatis | https://www.destatis.de | Federal statistics office | โ 200 |
| Bundestag | https://www.bundestag.de | Parliamentary records (DIP) | โ 200 |
Local Sources & Press
- Quality press: Sรผddeutsche Zeitung, Frankfurter Allgemeine Zeitung (FAZ), Die Zeit, Der Spiegel, Die Welt, Handelsblatt, Tagesschau (public broadcaster ARD), ZDF heute.
- Investigative NGOs: Correctiv (https://correctiv.org/en โ ), Netzpolitik.org, Frag Den Staat (https://fragdenstaat.de, FOIA platform), OCCRP Germany partner.
- OSINT community: OSINT Deutsch (Telegram), IntelTechniques Germany, BSI Cyber-Sicherheitskonferenz.
Country-Specific OSINT Tools
- Unternehmensregister โ official federal business registry (paid for full filings, free for basic info).
- Bundesanzeiger โ federal gazette with annual financial statements of all German companies.
- Transparenzregister โ UBO register (implementing EU 4th AMLD).
- Frag Den Staat โ FOIA platform (https://fragdenstaat.de) โ sends and tracks freedom-of-information requests.
- Correctiv Research Hub โ investigative OSINT tools and methodology.
- Netzpolitik.org โ digital rights and surveillance investigative site.
Legal Considerations
- Data protection: GDPR (DSGVO in German) + Bundesdatenschutzgesetz (BDSG). Regulated by BfDI (https://www.bfdi.bund.de).
- Access to information: Informationsfreiheitsgesetz (IFG, 2005) โ federal FOIA. Each state (Land) has its own IFG.
- Stasi files: The BStU (Federal Commissioner for the Stasi Records, now BStU archives at Bundesarchiv) holds millions of records of the former East German secret police โ accessible to researchers and individuals.
- Network Enforcement Act (NetzDG, 2017) โ requires social platforms to remove "manifestly illegal" content within 24h.
- SLAPP risk: No specific anti-SLAPP law, but criminal defamation is rarely used against journalists.
Notable Cases
- Wirecard scandal (2020). Financial fraud at Wirecard AG, exposed by Financial Times (Dan McCrum) using OSINT on Asian phantom operations. Correctiv contributed with follow-up investigations. URLs: https://en.wikipedia.org/wiki/Wirecard_scandal ยท https://correctiv.org/en/latest-stories/wirecard/
- Cum-Ex Files (2018). Cross-border tax fraud scheme exposed by Correctiv and partners. URL: https://correctiv.org/en/thema/latest-stories/cumex-files-en/
- NSU (National Socialist Underground, 2011). Neo-Nazi terror cell; investigation heavily criticised for intelligence failures.
๐ซ๐ท France โ Click to expand
Digital Landscape
Internet penetration ~85% (ARCEP 2024). Google dominates search; Qwant is the French-made privacy-focused alternative. WhatsApp, iMessage, and Signal (used by journalists) dominate messaging. X, LinkedIn, Facebook, Instagram are the main social platforms. France has a strong domestic tech ecosystem (Dassault Systรจmes, Thales, Mistral AI).
Intelligence Agency & OSINT Tradecraft
- External intelligence agency: Direction Gรฉnรฉrale de la Sรฉcuritรฉ Extรฉrieure (DGSE) โ https://www.dgse.gouv.fr โ
- Internal intelligence agency: Direction Gรฉnรฉrale de la Sรฉcuritรฉ Intรฉrieure (DGSI) โ https://www.dgsi.gouv.fr
- Military intelligence: Direction du Renseignement et de la Sรฉcuritรฉ de la Dรฉfense (DRSD) and Direction du Renseignement Militaire (DRM).
- OSINT unit / tradecraft: No publicly named OSINT directorate. DGSE and DGSI acknowledge OSINT as part of their collection disciplines in annual public reports to Parliament (https://www.assemblee-nationale.fr/dyn/15/rapplets).
- Publicly verifiable tradecraft points:
- Loi 2015-1556 (anti-terrorist intelligence law) โ https://www.legifrance.gouv.fr/eli/loi/2015/11/30/DEFX1414385L/jo/texte โ explicitly regulates OSINT collection by French intelligence.
- CNCTR (Commission Nationale de Contrรดle des Techniques de Renseignement) โ https://www.cncctr.fr โ public oversight reports on intelligence techniques including OSINT.
- What is NOT verified: "DGSE runs suitcase nuclear devices" โ this is fiction (referenced in films like La French) and not attributable.
Government Sources (Verified URLs)
| Source | URL | Function | Status |
|---|---|---|---|
| Infogreffe | https://www.infogreffe.fr | Commercial court registry | โ 200 |
| Pappers | https://www.pappers.fr | Free corporate data aggregator | โ ๏ธ 403, live in browser |
| data.gouv.fr | https://www.data.gouv.fr | French open data portal | โ 200 |
| Lรฉgifrance | https://www.legifrance.gouv.fr | Official legal gazette | โ 200 |
| INSEE | https://www.insee.fr | National statistics | โ 200 |
| BODACC | https://www.bodacc.fr | Bulletin officiel des annonces civiles et commerciales | โ 200 |
Local Sources & Press
- Quality press: Le Monde, Le Figaro, Libรฉration, Les Echos, Le Parisien, L'Equipe, Mediapart (investigative).
- Investigative NGOs: Mediapart (https://www.mediapart.fr/en/english โ ), StreetPress, Disclose (https://disclose.ngo).
- OSINT community: OSINT-FR community (Discord), CFM News (https://cfmnews.fr).
Country-Specific OSINT Tools
- Pappers โ free corporate data aggregator (uses Infogreffe data).
- Infogreffe โ official commercial court registry.
- BODACC โ official bulletin of civil and commercial announcements.
- Lรฉgifrance โ official legal database (laws, decrees, jurisprudence).
- data.gouv.fr โ French open data portal.
- INSEE Sirene database โ official business directory (https://www.sirene.fr).
Legal Considerations
- Data protection: GDPR + Loi Informatique et Libertรฉs (1978, modified 2018). Regulated by CNIL (https://www.cnil.fr/en โ ).
- Access to information: Loi CADA (1978) โ French FOIA.
- Secret dรฉfense: Classified defense information protected by law; relevant for investigators handling leaked French intel material.
- SLAPP risk: France has strong defamation laws; recent reform is moving toward anti-SLAPP protections.
- Loi Sรฉcuritรฉ Globale (2021) โ restricts publication of police officer images (controversial).
Notable Cases
- Cahuzac case (2013). Budget Minister Jรฉrรดme Cahuzac was exposed for hiding money in Swiss bank accounts. Investigation led by Mediapart (Fabrice Arfi). URL: https://en.wikipedia.org/wiki/Jรฉrรดme_Cahuzac
- CatalanGate (2022). Citizen Lab investigation into Pegasus spyware infections of Catalan politicians and civil society. URL: https://citizenlab.ca/2022/04/catalangate/
- Panama Papers / Pandora Papers โ French persons featured prominently; ICIJ investigations.
๐ช๐ธ Spain โ Click to expand
Digital Landscape
Internet penetration ~93% (ONTSI 2024). Google dominates search. WhatsApp is the dominant messaging app; Telegram has high penetration (used by political groups). X, LinkedIn, Instagram are the main social platforms. Spain has active OSINT and hacking communities (DragonJAR, OSINT Espaรฑol).
Intelligence Agency & OSINT Tradecraft
- National intelligence agency: Centro Nacional de Inteligencia (CNI) โ https://www.cni.es/en โ
- Defence intelligence centre: Centro de Inteligencia de las Fuerzas Armadas (CIFAS).
- OSINT unit / tradecraft: CNI acknowledges OSINT as part of its collection disciplines. The public Ley 11/1995 (https://www.boe.es/buscar/act.php?id=BOE-A-1995-22306) regulates intelligence activity including OSINT.
- Publicly verifiable tradecraft points:
- CCN-CERT (Centro Criptolรณgico Nacional) โ https://www.ccn-cert.cni.es/en/ โ public cybersecurity incidents and threat reports based on OSINT.
- INCIBE (Instituto Nacional de Ciberseguridad) โ https://www.incibe.es โ public threat intel.
- What is NOT verified: "CNI runs mass surveillance" โ the Catalangate Citizen Lab report documented Pegasus infections but did not attribute them directly to CNI; CNI's director Pablo Melgar was asked about this in parliamentary committee and neither confirmed nor denied.
Government Sources (Verified URLs)
| Source | URL | Function | Status |
|---|---|---|---|
| BORME (Boletรญn Oficial del Registro Mercantil) | https://www.boe.es/datosabiertos/borme | Commercial registry bulletin | โ 200 |
| BOE (Boletรญn Oficial del Estado) | https://www.boe.es | State official gazette | โ 200 |
| datos.gob.es | https://datos.gob.es/en | Spanish open data portal | โ 200 |
| Registro Mercantil Central | https://www.rmcerranet.es | Central commercial registry | โ ๏ธ requires login |
| AEPD | https://www.aepd.es | Data protection authority | โ 200 |
| Congress of Deputies | https://www.congreso.es | Parliamentary records | โ 200 |
Local Sources & Press
- Quality press: El Paรญs, El Mundo, La Vanguardia, ABC, La Razรณn, El Confidencial, El Diario.
- Investigative NGOs: Civio (https://civio.es/en/ โ ), eldiario.es, Newtral (fact-checking), Maldita (fact-checking).
- OSINT community: OSINT Espaรฑol (Telegram/Discord), DragonJAR community.
Country-Specific OSINT Tools
- BORME โ official commercial registry bulletin.
- Civio โ civic tech and OSINT tools.
- Maldita โ leading Spanish fact-checker.
- AEPD โ Spanish data protection authority.
- INCIBE Cybersecurity โ public threat intel.
Legal Considerations
- Data protection: GDPR + LOPDGDD (Ley Orgรกnica de Protecciรณn de Datos Personales y garantรญa de los derechos digitales, 2018). Regulated by AEPD.
- Access to information: Ley 19/2013 de transparencia.
- Ley Mordaza (Gag Law, 2015) โ restricts photography of police officers (controversial).
- SLAPP risk: Criminal defamation suits are used against journalists.
Notable Cases
- CatalanGate (2022). Citizen Lab investigation documented Pegasus infections of 65+ Catalan politicians, civil society members, and European MPs. URL: https://citizenlab.ca/2022/04/catalangate/
- Pandora Papers (2021) โ Spanish political figures exposed.
๐ฎ๐น Italy โ Click to expand
Digital Landscape
Internet penetration ~87% (AGCOM 2024). Google dominates search. WhatsApp is the dominant messaging app. X, LinkedIn, Instagram are the main social platforms. Italy has a strong cybersecurity and OSINT community (SANS Milan, Italian Cybersecurity Summit).
Intelligence Agency & OSINT Tradecraft
- External intelligence agency: Agenzia Informazioni e Sicurezza Esterna (AISE) โ https://www.sicurezzanazionale.gov.it โ
- Internal intelligence agency: Agenzia Informazioni e Sicurezza Interna (AISI) โ https://www.sicurezzanazionale.gov.it
- Coordinating body: Dipartimento delle Informazioni per la Sicurezza (DIS) โ https://www.sicurezzanazionale.gov.it
- OSINT unit / tradecraft: AISE and AISI acknowledge OSINT collection. The annual Relazione al Parlamento (https://www.sicurezzanazionale.gov.it/pubblicazioni/relazione-annuale-al-parlamento) is public and references OSINT analysis.
- Publicly verifiable tradecraft points:
- Legge 124/2007 (Intelligence reform) โ https://www.normattiva.it/uri-res/N2Ls?urn:nir:stato:legge:2007-08-03;124 โ regulates intelligence activity.
- ACN (Agenzia per la Cybersicurezza Nazionale) โ https://www.acn.gov.it โ public cybersecurity agency with OSINT-based threat reports.
Government Sources (Verified URLs)
| Source | URL | Function | Status |
|---|---|---|---|
| Registro Imprese | https://www.registroimprese.it | National business registry | โ 200 |
| Gazzetta Ufficiale | https://www.gazzettaufficiale.it | Official gazette | โ 200 |
| INPS | https://www.inps.it | Social security | โ 200 |
| ISTAT | https://www.istat.it | National statistics | โ 200 |
| Garante Privacy | https://www.garanteprivacy.it | Data protection authority | โ 200 |
| dati.gov.it | https://www.dati.gov.it | Italian open data portal | โ 200 |
Local Sources & Press
- Quality press: Corriere della Sera, La Repubblica, La Stampa, Il Sole 24 Ore, Il Fatto Quotidiano, Internazionale.
- Investigative NGOs: IRPI (Investigative Reporting Project Italy, https://irpimedia.irpi.eu/en/ โ ), La Notizia (Fact-checking), FrontiereCriminali.
- OSINT community: OSINT Italia community, Cybersecurity Italia Summit.
Country-Specific OSINT Tools
- Registro Imprese โ national business registry (free for basic lookups, paid for full filings).
- IRPI โ investigative reporting with OSINT methodology.
- Garante Privacy โ data protection authority with public decisions.
- ACN Cybersecurity Alerts โ public threat reports.
Legal Considerations
- Data protection: GDPR + Codice Privacy (Decreto Legislativo 196/2003, modified 2018). Regulated by Garante per la Protezione dei Dati Personali.
- Access to information: Decreto Legislativo 33/2013 (FOIA).
- SLAPP risk: Italy has criminal defamation with prison sentences; multiple SLAPP cases against journalists documented by EFJ.
- OPSEC: Anti-mafia investigations carry significant physical risk.
Notable Cases
- Mafia Capitale (2015). Investigation into Rome's criminal-political network, led by prosecutor Michele Prestipino. URLs: https://en.wikipedia.org/wiki/Mafia_Capitale
- IRPI investigations โ cross-border crime and corruption investigations using OSINT. URL: https://irpimedia.irpi.eu/en/
๐ต๐ฑ Poland โ Click to expand
Digital Landscape
Internet penetration ~88% (GUS 2024). Google dominates search; presearch.com has small share. WhatsApp and Messenger dominate messaging; Signal is growing among journalists and activists. X, LinkedIn, Facebook are the main social platforms. Poland has a strong cybersecurity and OSINT community (CyberSec community, NASK, Sekurak).
Intelligence Agency & OSINT Tradecraft
- External intelligence agency: Agencja Wywiadu (AW) โ https://www.aw.gov.pl
- Internal intelligence agency: Agencja Bezpieczeลstwa Wewnฤtrznego (ABW) โ https://www.abw.gov.pl
- Military intelligence: Sลuลผba Wywiadu Wojskowego (SWW) and Sลuลผba Kontrwywiadu Wojskowego (SKW).
- OSINT unit / tradecraft: AW and ABW acknowledge OSINT collection. The annual Raport o stanie bezpieczeลstwa (https://www.bbn.gov.pl) references OSINT analysis.
- Publicly verifiable tradecraft points:
- Ustawa o Agencji Wywiadu (2002) โ https://isap.sejm.gov.pl/isap.nsf/DocDetails.xsp?id=WDU2002065118 โ regulates intelligence activity including OSINT.
- NASK ARIA (Cybersecurity Response) โ https://www.nask.pl/en โ public threat reports based on OSINT.
- Sekurak โ public OSINT and pentesting blog.
Government Sources (Verified URLs)
| Source | URL | Function | Status |
|---|---|---|---|
| eKRS (Krajowy Rejestr Sฤ dowy) | https://ekrs.ms.gov.pl | National court registry | โ 200 |
| Biznes.gov.pl | https://biznes.gov.pl/en/wyszukiwarka-firm | Business search | โ 200 |
| dane.gov.pl | https://dane.gov.pl/en/dataset | Open data portal | โ 200 |
| Dziennik Ustaw | https://www.dziennikustaw.gov.pl | Official journal of laws | โ 200 |
| UODO | https://uodo.gov.pl/en | Data protection authority | โ 200 |
| Sejm | https://www.sejm.gov.pl | Parliamentary records | โ 200 |
Local Sources & Press
- Quality press: Gazeta Wyborcza (https://wyborcza.pl โ ), Rzeczpospolita, Dziennik Gazeta Prawna, Polityka, OKO.press (https://oko.press โ , investigative), Onet.
- Investigative NGOs: OKO.press, Fundacja Batorego (https://www.batory.org.pl), ICPC Poland.
- OSINT community: Sekurak (https://sekurak.pl), OSINT Polska (Telegram), 9wind's OSINT Poland GitHub (https://github.com/9wind/OSINT-Poland โ ).
Country-Specific OSINT Tools
- eKRS โ National Court Registry (free, comprehensive for Polish companies).
- Biznes.gov.pl โ business search portal.
- OKO.press โ investigative journalism with OSINT.
- Sekurak โ OSINT and pentesting resources.
- OSINT Poland GitHub (https://github.com/9wind/OSINT-Poland) โ curated list of Polish OSINT resources.
Legal Considerations
- Data protection: GDPR + Polish Data Protection Act (2018). Regulated by UODO (https://uodo.gov.pl/en).
- Access to information: Ustawa o dostฤpie do informacji publicznej (2001).
- SLAPP risk: Multiple SLAPP cases against journalists documented by OKO.press and EFJ.
- Hate speech laws: Strong regulations against defamation of religious and ethnic groups.
Notable Cases
- Visegrad Insight / Notes from Poland โ investigations into rule-of-law backsliding using OSINT.
- Aleksandra Gajewska corruption case โ OSINT used by OKO.press to expose political corruption.
46.3 Eastern Europe & Russia
๐ท๐บ Russia โ Click to expand
Digital Landscape
Internet penetration ~88% (RUNet 2024). Yandex dominates search (~65% market share). VKontakte (VK) is the dominant social network; Odnoklassniki (OK) for older demographic. Telegram is the dominant messaging app (post-2022 blocking of Western platforms). X, Facebook and Instagram are blocked (since March 2022). LinkedIn has been blocked since 2016.
Intelligence Agency & OSINT Tradecraft
- External intelligence agency: Sluzhba Vneshney Razvedki (SVR) โ https://www.svr.gov.ru
- Military intelligence: Glavnoye Upravleniye General'nogo Shtaba (GRU) โ https://structure.mil.ru/structure/forces/hq/general.htm
- Domestic security service: Federal'naya Sluzhba Bezopasnosti (FSB) โ https://www.fsb.ru
- OSINT unit / tradecraft: Russian intelligence services use OSINT as part of their active measures and disinformation campaigns. The GRU's Unit 26165 (Fancy Bear / APT28) has been documented using OSINT to identify targets for spear-phishing and influence operations (Mueller Report, 2019; Bellingcat investigations).
- Publicly verifiable tradecraft points:
- CSIS Russia Shadow War analysis โ https://www.csis.org/analysis/russias-shadow-war-against-west โ โ documents Russian intelligence tradecraft including OSINT use.
- CheckFirst investigation on GRU Information Operations Troops โ https://checkfirst.network/unveiling-grus-information-operations-troops-with-osint-and-medals โ uses OSINT to map GRU units through medal analysis.
- Bellingcat Russia investigations โ https://www.bellingcat.com/category/regions/europe/russia/ โ multiple investigations using Russian probiv databases.
- What is NOT verified (myth-busting):
- "Every Russian troll is GRU" โ many influence operations are conducted by private actors (IRA, Prigozhin's networks) with loose state coordination.
- "Russian intelligence has perfect access to all Russian data" โ Russian investigators also use grey-market probiv bots, suggesting they don't have direct access to all databases.
Government Sources (Verified URLs)
| Source | URL | Function | Status |
|---|---|---|---|
| ะคะะก (Federal Tax Service) | https://www.nalog.gov.ru | Federal Tax Service | โ 200 |
| ะะะ ะฎะ (Unified State Register of Legal Entities) | https://egrul.nalog.ru | Russian business registry | โ ๏ธ 307 redirect |
| Pravo.gov.ru | https://publication.pravo.gov.ru | Official legal portal | โ ๏ธ Timeout |
| Rosstat | https://www.rosstat.gov.ru | Federal statistics | โ 200 |
| Kremlin | https://en.kremlin.ru | Presidential administration | โ 200 |
Local Sources & Press
- Independent press (in exile): Meduza (https://meduza.io โ , Riga-based), Novaya Gazeta Europe (https://novayagazeta.eu), The Moscow Times (https://www.themoscowtimes.com).
- Investigative NGOs: OCCRP Russian partners, Bellingcat Russia desk, Agentstvo (https://agentstvo.net).
- OSINT community: Russian-speaking OSINT community on Telegram (pro-Ukrainian investigative channels: InformNapalm, Cyber Resistance,.peacekeeper).
Country-Specific OSINT Tools
- RuPEP (Russian Political Exposed Persons) โ https://rupep.ru โ ๏ธ Timeout โ database of Russian elites and PEPs.
- Meduza โ independent Russian-language news.
- Agentstvo โ investigative journalism.
- InformNapalm โ OSINT community documenting Russian military actions.
- Peacekeeper (Mirotvorets) โ Ukrainian-run database of pro-Russian actors (controversial).
- Russian Telegram channels โ main source for real-time OSINT on Russian military, political events.
Legal Considerations & OPSEC
- "Fake news" law (March 2022): Criminalises publication of "false information" about the Russian military, punishable by up to 15 years imprisonment. This affects any OSINT investigator publishing about Russian military actions.
- Foreign agent law: Individuals and organizations receiving foreign support must register as "foreign agents".
- VPN legality: VPNs are technically legal but providers must block sites on the Russian government's blacklist. Many VPN providers have left the Russian market.
- OPSEC: Investigators publishing about Russia from outside should use sock puppets, never real identities. Russian intelligence has a documented history of targeting diaspora investigators.
Notable Cases
- MH17 (2014). Bellingcat used open VK posts, satellite imagery, and geolocation to attribute the downing of MH17 to Russian forces. URL: https://www.bellingcat.com/app/uploads/2015/10/MH17-The-Open-Source-Evidence-EN.pdf โ
- Skripal poisoning (2018). Bellingcat identified the GRU officers behind the Salisbury poisoning using Russian leaked databases. URL: https://www.bellingcat.com/news/europe/2018/10/09/full-report-skripal-poisoning-suspect-dr-alexander-mishkin-hero-russia/
- Navalny poisoning (2020). Bellingcat and The Insider identified an FSB team of chemical-weapons experts that had trailed Navalny. URL: https://www.bellingcat.com/news/2020/12/14/fsb-team-of-chemical-weapon-experts-implicated-in-alexey-navalny-novichok-poisoning/
๐บ๐ฆ Ukraine (added for completeness) โ Click to expand
Digital Landscape
Internet penetration ~80% (early 2024). Google dominates search. Telegram is the dominant messaging app (used by both military and civilians during the war). X, Facebook, Instagram, TikTok, YouTube are the main social platforms. Ukraine has developed a sophisticated OSINT ecosystem since 2014.
Intelligence Agency & OSINT Tradecraft
- External intelligence agency: Sluzhba Zovnishn'oyi Rozvidky (SZRU) โ https://szru.gov.ua
- Military intelligence: HUR (Holovne Upravlinnya Rozvidky) โ https://www.gur.gov.ua
- OSINT unit / tradecraft: Ukraine has the most sophisticated open-source OSINT ecosystem of any country at war, centred on:
- InformNapalm โ volunteer OSINT community documenting Russian military equipment and personnel.
- Cyber Resistance โ Ukrainian hacktivist collective.
- Molfar โ Ukrainian OSINT agency (https://molfar.com).
- State Emergency Service uses OSINT for damage assessment.
- Publicly verifiable tradecraft points:
- Ukraine's National Agency for Corruption Prevention (NACP) maintains a public "International Sponsors of War" list (https://war-sanctions.gur.gov.ua) using OSINT to identify companies supporting Russia.
- Bellingcat Ukraine โ https://www.bellingcat.com/tag/ukraine/ โ extensive OSINT investigations.
Government Sources (Verified URLs)
| Source | URL | Function |
|---|---|---|
| YouControl | https://youcontrol.com.ua | Comprehensive business registry aggregator |
| EDR (Unified State Register) | https://usr.minjust.gov.ua | Ministry of Justice registry |
| Prozorro | https://prozorro.gov.ua | Public procurement (gold standard transparency) |
| data.gov.ua | https://data.gov.ua | Open data portal |
| Verkhovna Rada | https://www.rada.gov.ua | Parliamentary records |
Local Sources & Press
- Quality press: Ukrainska Pravda, Kyiv Independent, Suspilne, Babel, Levyi Bereg.
- Investigative NGOs: Bihus.Info (https://bihus.info), Nashi Groshi, Slidstvo.Info.
Country-Specific OSINT Tools
- YouControl โ business registry aggregator (free for basic lookups).
- Prozorro โ public procurement transparency (gold standard).
- EDR โ Ministry of Justice registry.
- War Sanctions (war-sanctions.gur.gov.ua) โ OSINT-based list of companies supporting Russian war.
Legal Considerations
- Martial law (ongoing since February 2022) โ restricts access to certain geographic and military information.
- Data protection: Ukrainian Law on Personal Data Protection (2010, modified 2020).
- OPSEC: Investigators operating in or on Ukraine during wartime should follow Ukrainian government OSINT guidelines to avoid compromising military operations.
Notable Cases
- Bucha investigation (2022). Bellingcat and NYT used satellite imagery (Maxar) to confirm that civilian bodies were on Yablunska Street during Russian occupation. URLs: https://www.bellingcat.com/news/uk-and-europe/2022/05/23/bucha-cleaning-up-the-streets-and-the-evidence/ ยท https://www.nytimes.com/2022/04/04/world/europe/bucha-ukraine-bodies.html
- MH17 (2014). Joint investigation with Bellingcat using OSINT on Russian military equipment crossing the border.
46.4 Asia
๐จ๐ณ China โ Click to expand
Digital Landscape
Internet penetration ~73% (1.05 billion users, CNNIC 2024). The Great Firewall blocks Google, Facebook, X, WhatsApp, YouTube, Telegram and most Western platforms. Baidu is the dominant search engine (~70% market share). WeChat (Weixin) is the universal super-app; Weibo is the main microblog; Douyin (Chinese TikTok) dominates short video; Xiaohongshu (RED) is the lifestyle social platform; Bilibili is the youth video platform.
Intelligence Agency & OSINT Tradecraft
- Civilian intelligence agency: Ministry of State Security (MSS) โ https://www.gov.cn
- Military intelligence: The PLA Strategic Support Force (SSF) was disbanded in April 2024 and replaced by the Information Support Force (ISF) โ verified by IISS: https://www.iiss.org/online-analysis/online-analysis/2024/05/chinas-new-information-support-force โ ๏ธ 403, and CNA: https://www.cna.org/our-media/indepth/2024/08/chinese-information-support-force. The ISF consolidates cyber, electronic warfare, and information operations.
- OSINT unit / tradecraft: The MSS has a Cyber Bureau responsible for offensive cyber operations. The PLA ISF conducts intelligence collection through cyber means. Both use OSINT as part of targeting for espionage.
- Publicly verifiable tradecraft points:
- Recorded Future research on Chinese AI military intelligence โ https://www.recordedfuture.com/research/artificial-eyes-generative-ai-chinas-military-intelligence โ documents PLA use of generative AI for intelligence.
- US DoD Annual Report on Military and Security Developments Involving the PRC (2024) โ https://media.defense.gov/2024/dec/18/2003615520/-1/-1/0/military-and-security-developments-involving-the-peoples-republic-of-china-2024.pdf โ public report on Chinese military capabilities including cyber.
- What is NOT verified (myth-busting):
- "China uses social credit score as mass surveillance tool" โ the social credit system is real but fragmented across provinces; the dystopian version portrayed in Western media is exaggerated.
- "Every Chinese student abroad is a spy" โ this is a harmful stereotype; documented cases of student informants are rare.
Government Sources (Verified URLs)
| Source | URL | Function | Status |
|---|---|---|---|
| National Enterprise Credit Info (gsxt) | http://www.gsxt.gov.cn | National business registry | โ ๏ธ 521 โ slow, may require China-based access |
| creditchina.gov.cn | http://www.creditchina.gov.cn | Credit information portal | โ ๏ธ 412 |
| gov.cn | https://www.gov.cn | Central government portal | โ 200 |
| Shanghai Stock Exchange | https://www.sse.com.cn | Stock exchange filings | โ ๏ธ Timeout |
| Shenzhen Stock Exchange | https://www.szse.cn | Stock exchange filings | โ ๏ธ Timeout |
| China Court | https://www.chinacourt.org | Court judgments (limited) | โ ๏ธ Timeout |
Note: Most Chinese government portals are slow or block foreign IPs. Use China-based VPN (legality varies) or third-party commercial aggregators like Sayari, Sayari Graph, or ChinะฐFAQs.
Local Sources & Press
- Domestic (state-controlled): Xinhua, People's Daily, China Daily, Global Times, Caixin (most independent of major outlets).
- Independent / diaspora: China Digital Times (https://chinadigitaltimes.net), The China Project (formerly SupChina, https://thechinaproject.com, ceased operations 2024), ChinaFile (https://www.chinafile.com).
- Investigative NGOs: ASPI Australian Strategic Policy Institute (https://www.aspi.org.au) โ Xinjiang Data Project documenting detention camps (https://xjdp.aspi.org.au).
- OSINT community: Chinese-speaking OSINT community is small due to censorship. GlobeTowns (Twitter/X), ChinaAnalysts.
Country-Specific OSINT Tools
- National Enterprise Credit Information Publicity System (gsxt.gov.cn) โ official business registry (requires China-based access).
- ASPI Xinjiang Data Project โ https://xjdp.aspi.org.au โ database of detention camps.
- ChinaFile Documentary Center โ https://www.chinafile.com/documentary-center โ leaked documents and reports.
- China Digital Times โ https://chinadigitaltimes.net โ censored content archive.
- Sayari Graph (commercial) โ corporate network analysis with strong China coverage.
- Shahit.biz (Xinjiang Victims Database) โ https://shahit.biz/eng/ โ โ database of detained Uyghurs and other minorities.
Legal Considerations & OPSEC
- Cybersecurity Law (2017) and Data Security Law (2021) โ strict regulations on data handling, cross-border data transfer.
- Personal Information Protection Law (PIPL, 2021) โ China's GDPR-equivalent.
- National Intelligence Law (2017) โ requires Chinese organisations and citizens to "support, assist and cooperate with national intelligence efforts" โ applies extraterritorially to Chinese nationals abroad.
- VPN legality: Personal VPN use is technically illegal but widely tolerated. Commercial VPN providers must register with the government; many Western VPNs are blocked.
- OPSEC for investigators: Do not investigate Chinese targets from within China. Use a non-Chinese VPN. Do not contact sources via WeChat (monitored). Use Signal or ProtonMail.
Notable Cases
- ASPI Xinjiang Data Project (2020). Mapped 380+ detention camps in Xinjiang using satellite imagery, government procurement documents, and leaked construction bids. URL: https://xjdp.aspi.org.au
- Pegasus Project (2021). Forbidden Stories and Amnesty International investigation documented use of Pegasus spyware against Uyghur activists.
๐ฐ๐ฟ๐ฐ๐ท Korea (North & South) โ Click to expand
North Korea (DPRK)
Digital Landscape
Internet penetration <1% of the population. The country uses Kwangmyong, a closed intranet, instead of the global internet. Mobile phones (~6 million subscribers on Koryolink) are restricted to domestic calls and Kwangmyong. Foreign diplomats and elites have limited internet access.
Intelligence Agency & OSINT Tradecraft
- Main intelligence agency: Reconnaissance General Bureau (RGB), under the Korean People's Army. URL: https://en.wikipedia.org/wiki/Reconnaissance_General_Bureau (Wikipedia, official RGB page is not publicly accessible).
- Cyber operations: Bureau 121, the cyber warfare unit, operates from North Korea and overseas (notably from China, Malaysia, and other countries with DPRK diplomatic presence).
- OSINT unit / tradecraft: DPRK uses OSINT for foreign intelligence collection, primarily through Bureau 35 (foreign intelligence gathering).
- Publicly verifiable tradecraft points:
- HRNK report on RGB โ https://www.hrnk.org/documentations/the-reconnaissance-general-bureau-the-kim-regimes-precious-treasured-sword โ documents RGB structure and operations.
- 38 North OSINT interview โ https://www.38north.org/2024/12/open-source-intelligence-and-north-korea-an-interview-with-uk-air-vice-marshal-ret-sean-corbetten โ interview on OSINT use for DPRK monitoring.
- Korea Herald on RGB expansion โ https://www.koreaherald.com/article/10805054.
Government Sources (Verified URLs)
North Korea has no publicly accessible government databases. All OSINT on DPRK uses external sources:
| Source | URL | Function | Status |
|---|---|---|---|
| 38 North | https://www.38north.org | US-Korea Institute analysis | โ ๏ธ 403, live in browser |
| NK News | https://www.nknews.org | DPRK-focused news and analysis | โ 200 |
| NK Pro | https://www.nknews.org/pro | Premium DPRK analysis (paid) | โ 200 |
| NKEconWatch | https://www.nkeconwatch.com | DPRK economy watch | โ ๏ธ 403, live in browser |
| OpenSanctions DPRK | https://www.opensanctions.org/datasets/ | UN sanctions | โ 200 |
Local Sources & Press
- External: NK News, 38 North, Daily NK (https://www.dailynk.com), Korea Herald, Yonhap (South Korean news agency).
- Defector organisations: Daily NK (sources inside DPRK), North Korea Strategy Center (https://nksc.co.kr).
- OSINT community: CSIS Beyond Parallel (https://beyondparallel.csis.org), Center for Strategic and International Studies Korea Chair.
Country-Specific OSINT Tools
- 38 North โ satellite imagery analysis of DPRK facilities.
- NK News โ comprehensive news aggregator.
- Daily NK โ sources inside DPRK.
- CSIS Beyond Parallel โ satellite imagery and analysis.
- OpenSanctions DPRK datasets โ UN sanctions list.
Legal & OPSEC Considerations
- Sanctions: North Korea is under comprehensive UN, US, EU sanctions. Any interaction with DPRK entities may violate sanctions.
- OPSEC: DPRK intelligence actively targets researchers, defectors, and journalists investigating the regime. Avoid contact with DPRK-affiliated entities.
Notable Cases
- Sony Pictures hack (2014). FBI attributed to North Korea's Bureau 121 (Lazarus Group). URL: https://www.fbi.gov/news/pressrel/press-releases/update-on-sony-investigation
- WannaCry ransomware (2017). Attributed to Lazarus Group by Google, Microsoft, and US government.
- DPRK IT worker fraud (2024-2025). DOJ indictments of DPRK IT workers using fake identities to obtain remote work at US companies. URL: https://www.fbi.gov/wanted/cyber/overview-of-dprk-it-worker-fraud-schemes
South Korea (ROK)
Digital Landscape
Internet penetration ~98% (KISA 2024). Naver (~70% market share) and Daum/Kakao dominate search over Google. KakaoTalk is the universal messaging app (~95% of smartphone users). X, Instagram, YouTube, Facebook are the main social platforms. South Korea has one of the world's most advanced OSINT ecosystems.
Intelligence Agency & OSINT Tradecraft
- Main agency: National Intelligence Service (NIS) โ https://www.nis.go.kr/ENG/main/main.do (URL returned 404 in our verification; official NIS site is at https://www.nis.go.kr, mostly Korean-language).
- Defence intelligence: Defence Intelligence Agency (๊ตญ๊ตฐ์ ๋ณด์ฌ๋ น๋ถ, KDIA).
- OSINT unit / tradecraft: NIS acknowledges OSINT collection; the public NIS Act regulates intelligence activity. The South Korean government has a sophisticated OSINT capability focused on DPRK monitoring.
- Publicly verifiable tradecraft points:
- Asia Society report on ROK intelligence โ https://asiasociety.org/korea/risks-intelligence-failure-rok-and-why-it-matters โ documents intelligence reform efforts.
- OSINT landscape in South Korea (Lukio blog) โ https://osintteam.blog/overview-of-the-osint-landscape-in-south-korea-61b699276339 โ โ comprehensive overview of OSINT tools for Korean sources.
Government Sources (Verified URLs)
| Source | URL | Function | Status |
|---|---|---|---|
| Hometax | https://www.hometax.go.kr | Tax authority, business registration | โ ๏ธ Timeout |
| data.go.kr | https://www.data.go.kr | Open data portal | โ ๏ธ Timeout |
| NICE (business credit) | https://www.nice.co.kr | Business credit information | โ ๏ธ Timeout |
| DART (financial disclosures) | https://dart.fss.or.kr | Financial Supervisory Service disclosures | โ ๏ธ Timeout |
| Koreabizwire | https://www.koreabizwire.com | Business news (English) | โ 200 |
Local Sources & Press
- Quality press: Hankyoreh, Chosun Ilbo, JoongAng Ilbo, Dong-a Ilbo, Korea Herald, Yonhap (news agency), Korea Joongang Daily (English).
- Investigative NGOs: Newstapa (https://www.newstapa.com), News Cokeba, SisaIN.
- OSINT community: OSINT Korea community, Lukio blog (https://osintteam.blog).
Country-Specific OSINT Tools
- Hometax โ tax authority business registration lookup.
- NICE โ business credit information.
- DART โ financial supervisory disclosures.
- YouthBoBo (์ ์ค๋ณด๋ณด) โ people search engine.
- KakaoTalk account lookup โ phone number to KakaoTalk account matching (grey-market).
Legal Considerations
- Personal Information Protection Act (PIPA, 2011) โ strict data protection law, stronger than GDPR in some aspects.
- Access to information: Official Information Disclosure Act (1998).
- National Security Law (1948) โ restricts content promoting North Korea; criminalises praise of DPRK.
- SLAPP risk: Criminal defamation suits are common against journalists.
Notable Cases
- 2016 Park Geun-hye scandal. Investigation led by JTBC journalist Seo Won-choi, using leaked tablet computer contents. URL: https://en.wikipedia.org/wiki/2016_South_Korean_political_scandal
๐ฏ๐ต Japan โ Click to expand
Digital Landscape
Internet penetration ~93% (MIC 2024). Google (~75%) and Yahoo! Japan (~25%) dominate search. LINE is the dominant messaging app (~85 million users). X (Twitter) is unusually popular in Japan (~60 million users); Facebook, Instagram, TikTok are major platforms. Japan has a strong cybersecurity community and is building up its intelligence apparatus.
Intelligence Agency & OSINT Tradecraft
- Cabinet Intelligence and Research Office (CIRO) โ https://www.cas.go.jp/jp/gaiyou/jimu/jyouhoutyousa/en/index.html โ โ Japan's primary intelligence coordinating body.
- Public Security Intelligence Agency (PSIA) โ https://www.moj.go.jp/ENGLISH/information/psia.html (URL returned 404 in our verification; the actual PSIA English page is at https://www.moj.go.jp/psia/).
- Defence intelligence: Defence Intelligence Headquarters (DIH / ่ชฟๆป้จ).
- NEW: Japan announced in July 2026 the creation of its first centralised intelligence agency โ https://www.aljazeera.com/news/2026/7/13/what-is-japans-new-intelligence-agency-and-why-is-tokyo-building-it
- OSINT unit / tradecraft: CIRO has an OSINT section. Japan's intelligence apparatus is being re-engineered (https://thediplomat.com/2026/06/japan-is-re-engineering-its-intelligence-apparatus).
- Publicly verifiable tradecraft points:
- The 2022 National Security Strategy explicitly elevated intelligence reform.
- CIRO public information โ https://www.cas.go.jp/jp/gaiyou/jimu/jyouhoutyousa/en/index.html โ โ public-facing CIRO information.
Government Sources (Verified URLs)
| Source | URL | Function | Status |
|---|---|---|---|
| National Tax Agency | https://www.nta.go.jp/english | Tax authority | โ ๏ธ 403, live in browser |
| corporate.no.jp | https://houmu-bunshou.com | Corporate registry (commercial) | โ ๏ธ Timeout |
| e-Gov Japan | https://www.e-gov.go.jp | Legal portal | โ 200 |
| e-Stat | https://www.e-stat.go.jp | Statistics portal | โ 200 |
| Japan Patent Office | https://www.jpo.go.jp | Patent registry | โ 200 |
Note: Japan's corporate registry (ๆณๅๅฑ, Hลmukyoku) is not freely accessible online โ it requires physical visit or proxy request. Commercial aggregators like Teikoku Databank, TDB, and Tokyo Shoko Research (TSR) provide business information for a fee.
Local Sources & Press
- Quality press: Yomiuri Shimbun, Asahi Shimbun, Mainichi Shimbun, Nihon Keizai Shimbun (Nikkei), NHK (public broadcaster), Japan Times (English), Kyodo News (news agency).
- Investigative NGOs: FactCheck Center (https://factcheckcenter.jp), FactCheck Initiative Japan (FIJ).
- OSINT community: Japan OSINT community (Twitter/X, Discord), Japan Cybersecurity Conference.
Country-Specific OSINT Tools
- Teikoku Databank โ commercial corporate information database.
- Tokyo Shoko Research (TSR) โ commercial business information.
- JPO (Japan Patent Office) โ patent search.
- e-Stat โ official government statistics portal.
- LINE account lookup โ phone number to LINE account matching (grey-market, similar to Kakao).
- FactCheck Center โ Japanese fact-checking organisation.
Legal Considerations
- Act on the Protection of Personal Information (APPI, 2003, amended 2022) โ Japan's data protection law. Regulated by Personal Information Protection Commission (PPC).
- Access to information: Act on Access to Information Held by Administrative Organs (1999).
- Specially Designated Secrets Act (2013) โ criminalises leaking of national security secrets, including by journalists who report on them.
- SLAPP risk: Low. Defamation cases typically result in monetary damages.
- Note on corporate registries: Japan's corporate registry is notably less accessible than Western equivalents; physical presence or paid proxy is required for full access.
Notable Cases
- AUM Shinrikyo sarin attack (1995). Investigation used OSINT on the cult's publications to build understanding of the attack.
- 2024-2026 Japan intelligence reform โ creation of new centralised agency is in response to changing regional security environment.
46.5 Middle East
๐ฎ๐ฑ Israel โ Click to expand
Digital Landscape
Internet penetration ~90% (Central Bureau of Statistics 2024). Google dominates search. WhatsApp is the dominant messaging app (~80% of smartphone users); Telegram has significant penetration. X, LinkedIn, Facebook, Instagram are the main social platforms. Israel has one of the world's most advanced cybersecurity and OSINT ecosystems (Check Point, NSO Group, Cellebrite, Cobwebs, Toka).
Intelligence Agency & OSINT Tradecraft
- External intelligence agency: The Mossad (HaMossad leModi'in uleTafkidim Meyuchadim) โ https://www.mossad.gov.il/eng โ .
- Internal security service: Shabak / Israel Security Agency (ISA) โ https://www.shabak.gov.il.
- Signals intelligence: Unit 8200 (military intelligence unit under IDF).
- OSINT unit / tradecraft: Israel does not publicly detail OSINT directorates. Unit 8200 is widely understood to have sophisticated OSINT capabilities alongside SIGINT, but specific tradecraft is classified.
- Publicly verifiable tradecraft points:
- Israel's intelligence community is the subject of extensive academic and journalistic coverage (Ronen Bergman's Rise and Kill First, 2018 โ public source).
- Bellingcat Israel/Palestine investigations โ https://www.bellingcat.com/category/regions/mena/israel-palestine/ โ demonstrate OSINT methodology applied to the region.
- What is NOT verified (myth-busting):
- "Mossad taught the CIA everything" โ this is myth; both agencies developed independently with periods of cooperation and competition.
- "Unit 8200 produces all cybersecurity CEOs" โ many Israeli cybersecurity founders are Unit 8200 alumni, but this is correlation not causation; many non-alumni are also successful.
- Specific Mossad operations depicted in films (Munich, Operation Finale) are dramatised versions of real events; do not treat dramatisations as accurate tradecraft.
Government Sources (Verified URLs)
| Source | URL | Function | Status |
|---|---|---|---|
| Israel Companies Registrar | https://ica.justice.gov.il | Corporate registry | โ 200 |
| Nevo (legal database) | https://www.nevo.co.il | Court decisions, official publications | โ 200 |
| data.gov.il | https://data.gov.il | Government open data | โ 200 |
| Israel Land Authority | https://mmi.gov.il | Land registry | โ ๏ธ Timeout |
| Bank of Israel | https://www.boi.org.il | Central bank | โ 200 |
| Knesset | https://main.knesset.gov.il | Parliamentary records | โ ๏ธ Timeout |
Local Sources & Press
- Quality press (English): Haaretz (https://www.haaretz.com), Jerusalem Post (https://www.jpost.com), Times of Israel (https://www.timesofisrael.com), Ynet News (https://www.ynetnews.com).
- Quality press (Hebrew): Haaretz, Yedioth Ahronoth, Maariv, Israel Hayom.
- Investigative NGOs: +972 Magazine (https://972mag.com, independent), B'Tselem (https://www.btselem.org, human rights), Breaking the Defense (veterans' testimonies).
- OSINT community: IntelSky, FakeReporter (disinformation watchdog).
Country-Specific OSINT Tools
- Israel Companies Registrar (ica.justice.gov.il) โ corporate registry.
- Nevo โ comprehensive legal database.
- data.gov.il โ government open data.
- FakeReporter โ disinformation tracking.
- B'Tselem โ human rights documentation.
- +972 Magazine โ independent journalism.
Legal Considerations
- Privacy Protection Law (1981, amended 2017) โ Israel's data protection law. Regulated by the Privacy Protection Authority (PPA).
- Freedom of Information Law (1998) โ Israeli FOIA.
- Military censorship: Israel has a military censor with authority to review certain publications related to national security. Investigators should be aware of this if publishing on military affairs.
- Defamation: Strong defamation laws; criminal defamation is theoretically possible but rare.
- OPSEC: Israel is an active conflict zone; investigators should follow government safety guidelines.
Notable Cases
- Bellingcat Israel/Palestine investigations โ multiple OSINT investigations into specific incidents in the Israel-Palestine conflict. URL: https://www.bellingcat.com/category/regions/mena/israel-palestine/
- Pegasus Project (2021) โ Forbidden Stories and Amnesty International investigation into NSO Group's Pegasus spyware. URL: https://forbiddenstories.org/about-the-pegasus-project/
๐ฎ๐ท Iran โ Click to expand
Digital Landscape
Internet penetration ~84% (StatCounter 2024), but the internet is heavily filtered and slowed. Google, WhatsApp, Instagram and Telegram are the main platforms but are subject to frequent throttling and blocking. Telegram is the primary source of news for many Iranians (~50 million users pre-2022 blocking; many now use VPN). Domestic platforms include Eitaa, Bale, and Soroush (state-promoted alternatives). The 2022 Mahsa Amini protests saw near-total internet blackouts.
Intelligence Agency & OSINT Tradecraft
- Civilian intelligence agency: Ministry of Intelligence (MOIS, Vezarat-e Ettela'at) โ https://www.mois.ir (intermittently accessible).
- Revolutionary Guard intelligence: IRGC Intelligence Organization (ุณุงุฒู ุงู ุงุทูุงุนุงุช ุณูพุงู) โ increasingly powerful; parallel to MOIS.
- Cyber operations: IRGC Cyber Command conducts offensive cyber operations. Multiple APT groups attributed to Iran (APT33, APT34, APT35/Charming Kitten, APT39).
- OSINT unit / tradecraft: Iran uses OSINT for targeting dissidents abroad and monitoring domestic opposition. The IRGC has been documented using OSINT to identify protesters from social media posts.
- Publicly verifiable tradecraft points:
- FalconFeeds.io Iran cyber operatives report โ https://falconfeeds.io/blogs/iran-cyber-operatives-irgc-mois-state-attribution-2026 โ documents Iranian cyber operators.
- Iran International on Charming Kitten โ https://content.iranintl.com/secret-spy-unit-leads-irans-intel-gathering-for-surveillance-deadly-plots/ โ exposes Iranian surveillance unit.
- OSINT Industries webinar on Iran attribution โ https://www.osint.industries/webinar/unmasking-irans-cyber-fronts-an-osint-guide-to-irgc-attribution.
- What is NOT verified: Specific IRGC tradecraft details are largely speculative in open sources.
Government Sources (Verified URLs)
| Source | URL | Function | Status |
|---|---|---|---|
| Iranian Companies Registration | http://www.irsherkat.ssc.ir | Corporate registry | โ ๏ธ Timeout |
| Official Gazette | http://www.rrk.ir | Official gazette | โ ๏ธ Timeout |
| Iran Open Data | https://iranopendata.org | Open data portal | โ 200 |
| Central Bank of Iran | https://www.cbi.ir | Central bank | โ ๏ธ Timeout |
Note: Iranian government portals are intermittently accessible from outside Iran. Use Iranian diaspora sources for verification.
Local Sources & Press
- Independent (in exile): Iran International (https://iranintl.com โ ), Radio Farda (https://en.radiofarda.org), IranWire (https://iranwire.com), BBC Persian, Voice of America Persian.
- Domestic (state-controlled): IRNA, Tasnim, Fars News, ISNA.
- Investigative NGOs: Center for Human Rights in Iran (CHRI, https://www.iranhumanrights.org), Iran Human Rights (IHR, https://iranhr.net).
- OSINT community: Iran-discovery OSINT channels on Telegram, conflict OSINT communities.
Country-Specific OSINT Tools
- Iran International โ exile news with OSINT investigations.
- IranWire โ exile journalism.
- Iran Open Data โ https://iranopendata.org โ open data portal.
- Center for Human Rights in Iran โ human rights documentation.
- Telegram channels โ primary source for real-time OSINT on Iranian events.
- HackerTen โ Iranian hacker community tracker.
Legal & OPSEC Considerations
- Computer Crimes Law (2009) โ criminalises "spreading lies" online, posting content against the state.
- Press Law (1986) โ restricts journalism; licenses required.
- No GDPR-equivalent: Iran has limited personal data protection.
- OPSEC: Iranian intelligence actively targets diaspora investigators and journalists. Documented cases of kidnapping and assassination plots. Use sock puppets, VPN, encrypted communications. Do not contact sources via Iranian platforms (monitored).
- Sanctions: Iran is under comprehensive US, EU sanctions. Any interaction with Iranian entities may violate sanctions.
Notable Cases
- Mahsa Amini protests (2022). Extensive OSINT documentation of protests and repression, despite internet blackouts. NGOs like HRANA and Iran Human Rights compiled casualty lists using OSINT.
- Charming Kitten exposure (2024). Iran International exposed the IRGC surveillance unit behind targeting of dissidents.
๐ธ๐ฆ Saudi Arabia โ Click to expand
Digital Landscape
Internet penetration ~99% (CITC 2024, one of the highest in the world). Google dominates search. WhatsApp is the dominant messaging app; Snapchat is unusually popular (~20 million users). X (Twitter) is the main platform for political discourse. The Saudi government has invested heavily in Vision 2030 digital transformation.
Intelligence Agency & OSINT Tradecraft
- Main intelligence agency: General Intelligence Presidency (GIP, Ri'asat al-Istikhbarat al-'Amma) โ no public English website. URL: https://www.gip.gov.sa (intermittent).
- State Security: Presidency of State Security (PSS) โ established 2017 to oversee counter-terrorism and domestic intelligence.
- Cyber operations: Saudi Arabia has built up cyber capabilities; the National Cybersecurity Authority (NCA) regulates and oversees cyber defence.
- OSINT unit / tradecraft: GIP uses OSINT for monitoring domestic and regional opposition. Specific tradecraft is classified.
- Publicly verifiable tradecraft points:
- Saudi Arabia's use of Pegasus spyware (NSO Group) against dissidents is documented by Citizen Lab (https://citizenlab.ca/tag/saudi-arabia/).
- The 2018 Jamal Khashoggi assassination used OSINT to identify the Saudi hit team (Bellingcat investigation, https://www.bellingcat.com/news/mena/2018/10/24/the-mystery-of-the-first-saudi-hit-team-flight-to-istanbul/).
- What is NOT verified: Specific GIP tradecraft details are not publicly available.
Government Sources (Verified URLs)
| Source | URL | Function | Status |
|---|---|---|---|
| Ministry of Commerce | https://mc.gov.sa | Business registry | โ ๏ธ Timeout |
| Umm Al-Qura (official gazette) | https://www.ummulqura.org.sa | Official gazette | โ 200 |
| SDAIA Open Data | https://www.sdaia.gov.sa/en | Open data portal | โ ๏ธ Timeout |
| Saudi Open Data Portal | https://data.gov.sa | Open data portal | โ ๏ธ Timeout |
| Saudi Stock Exchange (Tadawul) | https://www.saudiexchange.sa | Stock exchange | โ ๏ธ Timeout |
Local Sources & Press
- Quality press: Arab News, Asharq Al-Awsat, Al Arabiya, Al Hadath, Saudi Gazette.
- Investigative NGOs: ALQST (https://alqst.org, human rights), Democracy for the Arab World Now (DAWN, https://dawnmena.org).
- OSINT community: Limited due to political restrictions; most Saudi OSINT analysis is done by exile organisations.
Country-Specific OSINT Tools
- Ministry of Commerce business registry โ corporate lookup.
- Umm Al-Qura โ official gazette.
- Saudi Open Data Portal โ government data.
- ALQST โ human rights documentation.
- DAWN โ advocacy and documentation.
Legal & OPSEC Considerations
- Anti-Cyber Crime Law (2007) โ broad provisions criminalising "production, preparation, transmission, or storage of material impinging on public order, religious values, public morals, and privacy".
- Personal Data Protection Law (PDPL, 2021, amended 2023) โ Saudi Arabia's data protection law. Regulated by SDAIA.
- Counter-Terrorism Law (2017) โ broad provisions used against dissidents and investigators.
- OPSEC: Saudi Arabia has documented history of targeting dissidents abroad (Khashoggi case). Investigators should use sock puppets, VPN, encrypted communications. Avoid travel to Saudi Arabia if investigating sensitive topics.
- Defamation: Criminal defamation with prison sentences; blasphemy punishable by death.
Notable Cases
- Jamal Khashoggi assassination (2018). Bellingcat identified the Saudi hit team through flight manifests and passport photos. URL: https://www.bellingcat.com/news/mena/2018/10/24/the-mystery-of-the-first-saudi-hit-team-flight-to-istanbul/
- Pegasus surveillance (2019-2024). Citizen Lab documented Saudi use of Pegasus against dissidents. URL: https://citizenlab.ca/tag/saudi-arabia/
๐น๐ท Turkey โ Click to expand
Digital Landscape
Internet penetration ~83% (BTK 2024). Google dominates search; Yandex has ~20% market share. WhatsApp is the dominant messaging app (~75% of smartphone users); Telegram is widely used. X (Twitter) is the primary political discourse platform (~16 million users); YouTube, Instagram, Facebook, TikTok are major platforms. Turkey has a vibrant but heavily pressured media ecosystem.
Intelligence Agency & OSINT Tradecraft
- Main intelligence agency: Millรฎ ฤฐstihbarat Teลkilatฤฑ (MIT, National Intelligence Organization) โ https://www.mit.gov.tr โ ๏ธ Timeout.
- Military intelligence: Intelligence Department of General Staff (now under Ministry of National Defence).
- OSINT unit / tradecraft: MIT has an OSINT branch. Turkish intelligence has been documented using OSINT to identify coup plotters, Kurdish activists, and Gรผlen movement members.
- Publicly verifiable tradecraft points:
- MIT's legal basis is Law No. 2937 on the State Intelligence Services and the National Intelligence Organization (https://www.mevzuat.gov.tr/mevzuatmetin/1.5.2937.pdf).
- Turkey has been documented using Pegasus spyware (Citizen Lab reports).
- MIT informant leaks (2020-2022) โ Nordic Monitor (https://nordicmonitor.com) published leaked MIT documents revealing OSINT-based targeting of dissidents abroad.
Government Sources (Verified URLs)
| Source | URL | Function | Status |
|---|---|---|---|
| MERSฤฐS (Central Registry System) | https://www.mersis.gov.tr | Business registry | โ ๏ธ Timeout |
| e-Devlet (e-Government) | https://www.turkiye.gov.tr | Government services portal | โ 200 |
| Trade Registry Gazette | https://tobb.org.tr | Chamber of commerce | โ 200 |
| Resmi Gazete | https://www.resmigazete.gov.tr | Official gazette | โ 200 |
| TUฤฐK | https://www.tuik.gov.tr | Statistics institute | โ 200 |
Local Sources & Press
- Quality press (pro-government): Sabah, Daily Sabah (English), Yeni ลafak, Anadolu Agency (state news).
- Quality press (independent/opposition): Sรถzcรผ, Cumhuriyet, BirGรผn, Diken, T24, Artฤฑ Gerรงek (https://artigercek.com).
- Investigative NGOs: P24 (Platform for Independent Journalism, https://p24.com.tr), Stockholm Center for Freedom (https://stockholmcf.org, exile), Nordic Monitor (https://nordicmonitor.com, exile).
- OSINT community: Limited due to political pressure; exile OSINT communities like SCF and Nordic Monitor fill the gap.
Country-Specific OSINT Tools
- MERSฤฐS โ Central Registry System for business lookup.
- e-Devlet โ government services portal (requires Turkish ID).
- Trade Registry Gazette โ official commercial announcements.
- Resmi Gazete โ official gazette.
- Nordic Monitor โ leaked MIT documents.
- Stockholm Center for Freedom โ exile human rights documentation.
Legal & OPAC Considerations
- Personal Data Protection Law (KVKK, 2018) โ Turkey's data protection law. Regulated by KVKK Authority.
- Law on the Right to Information (2003) โ Turkish FOIA.
- Anti-Terror Law (1991) โ broad provisions used against journalists and investigators.
- Disinformation law (October 2022) โ criminalises "disinformation" with up to 3 years imprisonment.
- OPSEC: Turkey has documented history of targeting dissidents abroad (kidnappings of Gรผlenists). Investigators should use sock puppets, VPN, encrypted communications.
- SLAPP risk: High. Turkey is one of the world's largest jailers of journalists.
Notable Cases
- 2016 coup attempt investigation โ MIT used OSINT to identify coup plotters; thousands were arrested based on this analysis.
- Nordic Monitor MIT leaks (2020-2022) โ exposed MIT informant network and targeting of dissidents abroad. URL: https://nordicmonitor.com.
46.6 Oceania
๐ฆ๐บ Australia โ Click to expand
Digital Landscape
Internet penetration ~91% (ABS 2024). Google dominates search. WhatsApp, iMessage, Messenger dominate messaging. X, LinkedIn, Facebook, Instagram, Reddit are the main social platforms. Australia has a strong OSINT and intelligence studies community (ASPI, Australian National University, ANU National Security College).
Intelligence Agency & OSINT Tradecraft
- Domestic security agency: Australian Security Intelligence Organisation (ASIO) โ https://www.asio.gov.au
- External intelligence agency: Australian Secret Intelligence Service (ASIS) โ https://www.asis.gov.au
- Signals intelligence: Australian Signals Directorate (ASD) โ https://www.asd.gov.au
- Intelligence coordination: Office of National Intelligence (ONI) โ https://www.ni.gov.au โ includes the Open Source Centre (OSC) which coordinates OSINT across the Australian Intelligence Community.
- OSINT unit / tradecraft: ONI's Open Source Centre is the publicly attributed Australian OSINT body. It was established in 2019 (modeled on CIA OSE).
- Publicly verifiable tradecraft points:
- Intelligence Services Act 2001 โ https://www.legislation.gov.au/Details/C2018C00384 โ regulates Australian intelligence agencies including OSINT collection.
- ASD's Annual Cyber Threat Report โ https://www.cyber.gov.au/about-us/reports-and-statistics/asds-annual-cyber-threat-report โ uses OSINT alongside classified sources.
Government Sources (Verified URLs)
| Source | URL | Function | Status |
|---|---|---|---|
| ABN Lookup | https://abr.business.gov.au | Australian Business Register | โ 200 |
| ASIC Connect | https://connectonline.asic.gov.au | Business registry | โ 200 |
| data.gov.au | https://data.gov.au | Government open data | โ 200 |
| Federal Register of Legislation | https://www.legislation.gov.au | Legislation database | โ 200 |
| Australian Business Register | https://abr.business.gov.au | ABN lookup | โ 200 |
Local Sources & Press
- Quality press: ABC (Australian Broadcasting Corporation, https://www.abc.net.au โ ), The Guardian Australia (https://www.theguardian.com/au), Sydney Morning Herald (https://www.smh.com.au), The Age, The Australian.
- Investigative NGOs: Australian Strategic Policy Institute (ASPI, https://www.aspi.org.au), International Consortium of Investigative Journalists (ICIJ, Australian involvement).
- OSINT community: ASPI, Australian National University National Security College, OSINT Australia community.
Country-Specific OSINT Tools
- ABN Lookup โ free business registry lookup.
- ASIC Connect โ corporate registry.
- Open Politics โ https://openpolitics.au/search โ Australian political donations and interests.
- Ryerson Index โ http://ryersonindex.org/search.php โ death notices index.
- ASPI Xinjiang Data Project โ https://xjdp.aspi.org.au โ Xinjiang detention camps database.
Legal Considerations
- Privacy Act 1988 โ Australia's federal data protection law. Regulated by Office of the Australian Information Commissioner (OAIC).
- Freedom of Information Act 1982 โ federal FOIA.
- Defamation law (reformed 2021) โ added "serious harm" threshold; anti-SLAPP provisions in some states.
- OPSEC: Generally safe environment for investigators.
Notable Cases
- ASPI Xinjiang Data Project (2020). Mapped 380+ detention camps in Xinjiang using satellite imagery, government procurement documents, and leaked construction bids. URL: https://xjdp.aspi.org.au
- Australian SIGNT/OSINT investigation into MH17 โ ASD contributed OSINT to the joint investigation.
47. Corporate OSINT Tradecraft
Public methodology of leading OSINT / threat intelligence companies. Each section below distils the publicly documented methodology from vendor blogs, reports and academic case studies. Marketing claims are flagged explicitly. Workflows are descriptive of what the company publishes โ they are not leaks of internal SOPs.
47.1 Tier 1 Vendors
Bellingcat (Investigative Journalism NGO)
Briefing: Independent, Netherlands-based investigative journalism NGO founded 2014 by Eliot Higgins. Uses open-source and social-media content (photos, videos, satellite imagery, leaked databases, flight records, court filings) to investigate armed conflicts, human-rights abuses, state-sponsored assassinations and environmental crimes. Operates a small staff plus a global network of volunteer researchers; publishes its tools and methods openly. Combines geolocation, chronolocation, content verification and structured cross-referencing of leaked or paid-data sources.
Landmark public cases (with verifiable URLs):
- MH17 downing (2014-2017) โ linked the Buk missile launcher to the Russian 53rd Anti-Aircraft Missile Brigade.
- Skripal poisoning (2018) โ identified Salisbury suspects as GRU officers Chepiga and Mishkin.
- Navalny poisoning (2020) โ identified the FSB chemical-weapons team.
- Bucha/Ukraine monitoring (2022-) โ real-time verification of civilian casualties.
Reproducible 12-step methodology (as published):
- Define the question and the verifiable hypothesis.
- Collect primary open sources โ Telegram, VK, X, passenger manifests, leaked phone-call metadata, satellite imagery, court records. Bellingcat explicitly relies on the Russian "probiv" data market (Telegram bots returning passport/phone/vehicle records).
- Cross-reference every single data point against a second source.
- Use leaked databases as anchor sources โ they are immutable snapshots that cannot be retroactively edited.
- Pivot on travel records โ examine passenger manifests of parallel flights (one day earlier/later).
- Pivot on phone records โ list every number called; reverse-lookup each (GetContact, Telegram bots).
- Use address and vehicle registration to identify employer โ when an FSB/GRU officer registers a vehicle at a government facility, enumerate every other vehicle at that address (Bellingcat found 191).
- Use parking-payment databases for geolocation.
- Reverse-engineer alias-generation patterns โ FSB/GRU algorithm: same first name, same day/month of birth (year shifted ยฑ1), last name = wife's/girlfriend's maiden name.
- Geolocate imagery when needed โ Yandex Images, Google Lens, SunCalc, Google Earth, Mapillary.
- Cluster suspects by repeated co-travel and communication โ graph of who communicated with whom, who flew with whom, who shared addresses.
- Publish the full evidence chain โ methodology, screenshots, redacted raw data, names โ alongside partner outlets (The Insider, CNN, Der Spiegel) for auditability.
Tools Bellingcat publicly mentions:
- Bellingcat Online Investigation Toolkit (https://bellingcat.gitbook.io/toolkit)
- Telegram probiv bots (paid, grey-market)
- GetContact, Yandex Maps/Images, Google Earth Pro, Sentinel Hub, Copernicus EMS, NASA FIRMS, SunCalc, FlightRadar24, ADS-B Exchange, OpenSky Network, OpenCorporates, Wayback Machine, archive.today, Hunchly, InVID-WeVerify, FotoForensics, Forensically, Maltego, Spiderfoot, theHarvester.
Limitations & ethics:
- Reliance on Russian grey-market data. Bellingcat explicitly acknowledges the privacy and ethics concerns of buying leaked phone records and passport files; the practice would be illegal in most Western jurisdictions (GDPR).
- Geographic bias. Strongest cases involve Russia, Syria, Ukraine โ regions with porous data protection and active conflicts. China, North Korea and Iran are far harder.
- NGO, not forensic lab. Their findings are journalistic conclusions, not chain-of-custody evidence admissible in court without corroboration.
- Volunteer model means variable quality control; the editorial team applies the same 12-step cross-referencing standard before publication.
Mandiant (Google Cloud)
Briefing: Mandiant was acquired by Google in September 2022 for $5.4B and is now part of Google Threat Intelligence (GTI). Its methodology is incident-response-led threat-actor clustering using the UNC (UNCategorized) taxonomy. Novel malicious activity is grouped into a temporary UNC#### cluster; when enough TTP, infrastructure and code overlap accumulates, the cluster is merged into an existing named group (APT## for state-sponsored, FIN## for financially motivated).
Landmark public cases (with verifiable URLs):
- SolarWinds / UNC2452 โ APT29 (2020-2021). https://cloud.google.com/blog/topics/threat-intelligence/unc2452-merged-into-apt29
- M-Trends 2025 annual report โ Mandiant tracked 302 different threat groups in 2024. PDF: https://services.google.com/fh/files/misc/m-trends-2025-en.pdf
- APT groups catalogue: https://cloud.google.com/security/resources/insights/apt-groups
- Trade-Offs of Cyber Attribution (methodology paper): https://cloud.google.com/blog/topics/threat-intelligence/trade-offs-attribution
Public 12-step workflow (reconstructed from public blog posts):
- Triage an incident / sample submission. A new artefact enters via Mandiant Consulting IR engagements, the VirusTotal corpus, or Google telemetry. Compute hashes, extract strings, run YARA rules.
- Pivot through VirusTotal Graph. Walk from the artefact to related files, URLs, contact domains and IPs that share behaviour, submission timing or first-seen dates.
- Cluster the activity into a UNC. If the TTPs do not match an existing named group, a new
UNC####designator is created. - Accumulate evidence over time. Overlap dimensions: code sharing, infrastructure reuse (registrant info, SSL certs, ASN patterns), victimology, attack lifecycle, timing.
- Apply the Suspected/Possible confidence scale. Analysts score overlaps as
Possible Association(weak) orSuspected Association(strong). https://gtidocs.virustotal.com/docs/suspected-attribution - Test the merge hypothesis. Compare the UNC against every named
APT##/FIN##in the catalogue. - Peer-review within Mandiant Intelligence. Other analysts challenge the merge โ looking for counter-evidence (tool sharing between unrelated groups, false-flag indicators).
- Publish attribution with confidence label. Mandiant reports use "assessed with high/moderate/low confidence" language aligned with ICD-203.
- Public merge announcement. When attribution is final, Mandiant publishes a blog post announcing the merge.
- Update YARA rules and detection content. IOCs, YARA, STIX/TAXII feeds updated.
- Brief IR consultants and customers.
- Re-evaluate periodically. If new evidence contradicts the merge, Mandiant can split the cluster again.
Tools Mandiant publicly mentions:
- VirusTotal (public + Enterprise), VirusTotal Graph, Mandiant Advantage, Google Chronicle / Google Security Operations, YARA, FLARE-VM, capa, Google telemetry (Gmail, Chrome Safe Browsing, Android Play Protect).
Limitations:
- Product-vs-research blur. Public reports mix commercial positioning with actual methodology.
- Confidence is explicitly graded. Mandiant does not claim 100% attribution.
- VirusTotal dataset bias. VT submissions skew Western; actors who avoid AV and submission to VT are under-represented.
- Acquisition friction. Pre-2022 Mandiant publications (Equation Group, APT1, FIN7) were produced when Mandiant was independent; post-acquisition work is integrated with Google telemetry.
CrowdStrike
Briefing: Endpoint protection + threat intelligence company famous for the adversary naming convention where every tracked actor gets a name composed of an animal + a weather/event term: BEAR (Russia), PANDA (China), SPIDER (eCrime), KITTEN (Iran), CHOLLIMA (North Korea), HAWK (India). CrowdStrike's methodology is centred on Falcon endpoint telemetry + analyst cells.
Landmark public cases:
- DNC hack (2016). CrowdStrike attributed the breach to FANCY BEAR (APT28) and COZY BEAR (APT29).
- Fancy Bear Ukrainian artillery (2016). https://www.crowdstrike.com/blog/bears-midst-intrusion-disclosure/
- Global Threat Report (annual). https://www.crowdstrike.com/en-us/global-threat-report/
Public 10-step attribution methodology:
- Falcon telemetry ingestion โ endpoint sensors collect process, network, file, registry events.
- ML + analyst cells triage โ machine learning flags suspicious patterns; human analysts review.
- Activity clustering โ group observed activity into clusters based on shared TTPs.
- Geopolitical overlay โ apply country attribution based on victimology, language indicators, working hours.
- Adversary naming โ assign a new name (BEAR/PANDA/SPIDER/KITTEN/CHOLLIMA/HAWK + suffix).
- Peer review โ other analysts challenge the attribution.
- Independent verification policy โ CrowdStrike publishes enough detail for independent verification.
- Publish adversary profile โ full TTPs, IOCs, MITRE ATT&CK mapping.
- Update detection content โ Falcon platform updated to detect the new adversary.
- Adversary Universe โ public web page documenting all tracked adversaries. https://www.crowdstrike.com/en-us/adversaries/
Limitations:
- Endpoint bias โ CrowdStrike's visibility is endpoint-centric; network-only attacks may be missed.
- Marketing of "Adversary Universe" โ branding on real process; the methodology is real but the public site is partly marketing.
- Naming complexity โ same actor = FANCY BEAR / APT28 / Forest Blizzard / Strontium / Sofacy / Pawn Storm / Sednit. The 2025 Microsoft-CrowdStrike shared glossary (https://www.crowdstrike.com/blog/crowdstrike-microsoft-naming-glossary/) is an attempt to harmonise.
Recorded Future
Briefing: Threat intelligence platform using NLP + machine learning over OSINT masivo. The Insikt Group is the research arm. Markets the "centaur model" (human + AI) and the "Intelligence Graphยฎ" (trademarked marketing terms wrapping real methodology).
Landmark public cases:
- Insikt Group research portal โ https://www.recordedfuture.com/research
- Iran AI report โ Recorded Future's research on Iranian AI capabilities.
- CopyCop disinformation โ analysis of an AI-generated disinformation network.
Public 4-pillar methodology (per Insikt Group's published description):
- Infrastructure detection and pivoting โ auto-detection of malicious infrastructure, pivot to related domains/IPs.
- Victim identification โ automatic identification of victims from breach reports, dark web posts.
- Network traffic analysis โ analyse C2 traffic patterns.
- Multi-source validation โ the centaur model: AI proposes, human analyst verifies.
Output formats: 7 standard formats โ Intelligence Brief, Full Report, Flash Report, Special Report, Cyber Daily newsletter, Weekly Cyber Exploits, Monthly Threat Forecast.
Limitations:
- Enterprise pricing ($$$) โ Recorded Future platform is enterprise-priced. Recommend the free Community Edition only as a teaser, not a working tool.
- "Centaur model" and "Intelligence Graphยฎ" are trademarked marketing terms wrapping real methodology.
- AI bias โ NLP models can amplify biased sources if training data skews Western.
47.2 Tier 2 Vendors
Google Threat Intelligence (GTI / ex-Mandiant + VirusTotal)
Briefing: Unified commercial brand launched April 2024 after folding together Chronicle (cloud-native SIEM, 2018), VirusTotal (acquired by Google in 2012, >2 billion analysed files/URLs/domains/IPs) and Mandiant (acquired September 2022). GTI's research methodology is essentially Mandiant's methodology โ IR-led threat-actor clustering using the UNC taxonomy.
Public emblematic cases:
- SolarWinds / UNC2452 โ APT29 โ https://cloud.google.com/blog/topics/threat-intelligence/unc2452-merged-into-apt29
- M-Trends 2025 โ https://services.google.com/fh/files/misc/m-trends-2025-en.pdf
- APT groups catalogue โ https://cloud.google.com/security/resources/insights/apt-groups
- Suspected Attribution API โ https://gtidocs.virustotal.com/docs/suspected-attribution
Methodology: Same as Mandiant (see above) + Google's corpus (VT + Gmail + Chrome + Android telemetry) as the corroborating evidence base.
Useful public resources:
| Resource | URL |
|---|---|
| Google Cloud TI blog | https://cloud.google.com/blog/topics/threat-intelligence |
| M-Trends 2025 PDF | https://services.google.com/fh/files/misc/m-trends-2025-en.pdf |
| APT groups catalogue | https://cloud.google.com/security/resources/insights/apt-groups |
| GTI documentation portal | https://gtidocs.virustotal.com/ |
| VirusTotal (free) | https://www.virustotal.com/ |
| Mandiant GitHub (open-source tools) | https://github.com/mandiant |
Microsoft Threat Intelligence (MSTIC)
Briefing: In-house research team that tracks nation-state and criminal actors across Microsoft's vast telemetry surface โ Windows, Office 365 email, Azure, Microsoft Defender for Endpoint, LinkedIn, Bing and Xbox. According to the 2024 Microsoft Digital Defense Report, MSTIC observes ~600 million cyberattacks per day.
Adversary naming convention (2 eras):
- 2015-April 2023: Chemical elements (typosquatted) โ Strontium (APT28), Nobelium (APT29), Zinc, Chromium, Thallium, Hafnium, Phosphorus, Bismuth. Microsoft deliberately misspelled real chemical element names so they could register matching domains/handles without impersonating the real-element websites.
- April 2023-present: Weather taxonomy โ Russian actors =
* Blizzard, Chinese =* Typhoon, Iranian =* Sandstorm, Lebanese =* Rain, North Korean =* Sleet, Indian =* Hawk. Replaced the element scheme for clarity.
Public emblematic cases:
- SolarWinds / NOBELIUM / APT29 (2020-2021) โ MSTIC was the first to publicly name the actor.
- Volt Typhoon (2023) โ Chinese critical-infrastructure targeting disclosure.
- Forest Blizzard / APT28 (2024) โ Russian military intelligence.
- Microsoft Digital Defense Report 2024 โ https://www.microsoft.com/en-us/security/business/microsoft-digital-defense-report-2024
- MS-CrowdStrike shared naming glossary (2025) โ https://www.crowdstrike.com/blog/crowdstrike-microsoft-naming-glossary/
Public 12-step workflow (reconstructed from MSTIC blog posts):
- Telemetry ingestion from Windows, O365, Azure, Defender, LinkedIn, Bing, Xbox.
- ML + analyst triage โ anomaly detection, then human review.
- MITRE ATT&CK mapping โ map observed TTPs to ATT&CK techniques.
- Country assessment โ based on victimology, language, working hours, infrastructure.
- Weather naming โ assign a name based on country of origin + weather phenomenon.
- Government coordination โ MSTIC frequently discloses nation-state activity in coordination with US government (CISA, FBI).
- Publish technical blog post with IOCs, YARA, detection queries.
- Update Defender detections โ push detection content to Defender for Endpoint customers.
- Brief government partners โ CISA, NSA, FBI.
- Publish Digital Defense Report โ annual public summary.
- Update threat actor encyclopedia โ https://learn.microsoft.com/en-us/defender/threat-intelligence/.
- Re-evaluate periodically โ splits/merges as evidence accumulates.
Limitations:
- Naming churn โ chemicalโweather (April 2023) caused industry confusion.
- US-gov alignment appearance โ MSTIC's nation-state disclosures often align with US foreign policy; this is correlation (shared goals) but critics see it as politicisation.
- Marketing vs research blur โ Digital Defense Report mixes commercial positioning with actual research.
Useful public resources:
| Resource | URL |
|---|---|
| Microsoft Security blog | https://www.microsoft.com/en-us/security/blog |
| Digital Defense Report 2024 | https://www.microsoft.com/en-us/security/business/microsoft-digital-defense-report-2024 |
| MSTIC threat actor encyclopedia | https://learn.microsoft.com/en-us/defender/threat-intelligence/ |
| MSRC (Microsoft Security Response Center) | https://msrc.microsoft.com/ |
Cisco Talos
Briefing: Cisco's threat intelligence team. Specialises in malware analysis, threat hunting, and network intelligence. Publishes daily blog posts and an annual Year in Review.
Public emblematic cases:
- Cisco Talos 2025 Year in Review โ https://blog.talosintelligence.com/
- Threat Hunting programme โ public methodology posts.
- GhIDA โ Ghidra + IDA Pro integration tool (open source).
- LLM-as-RE-sidekick โ research on using LLMs in reverse engineering.
- Cisco Live BRKSEC-2884 โ public threat-hunting training.
Public 12-step workflow (reconstructed from Talos blog posts):
- Sample intake โ from Cisco Secure endpoints, customer IR engagements, VirusTotal, spam traps.
- Static triage โ hash check, strings, imports, sections.
- Sandbox detonation โ ThreatGrid (Cisco's sandbox) analysis.
- Umbrella network pivot โ use Cisco Umbrella DNS data to find related domains/IPs.
- IDA Pro + Ghidra RE โ deep reverse engineering with GhIDA integration.
- Behavioural analysis โ dynamic analysis in VM, API call tracing.
- Snort/ClamAV signature creation โ write detection rules.
- Threat brief publication โ blog post at blog.talosintelligence.com.
- Year in Review โ annual summary report.
- Customer push โ push detections to Cisco Secure customers.
- Open-source tool release โ tools like GhIDA published to GitHub.
- Re-evaluate periodically โ track malware family evolution.
Limitations:
- Network-edge bias โ Talos visibility is network-centric (Cisco routers, firewalls); endpoint-only attacks may be under-represented.
- Commercial tie-ins โ Talos reports often reference Cisco Secure products.
Useful public resources:
| Resource | URL |
|---|---|
| Talos blog | https://blog.talosintelligence.com/ |
| Talos Year in Review | https://blog.talosintelligence.com/year-in-review/ |
| Talos GitHub | https://github.com/Cisco-Talos |
Kaspersky GReAT (Global Research & Analysis Team)
Briefing: Kaspersky's elite research team responsible for tracking the most sophisticated APTs (Stuxnet, Flame, Equation Group). Publishes on Securelist (https://securelist.com).
Public emblematic cases:
- Stuxnet (2010) โ analysis of the first cyber-physical weapon. https://securelist.com/stuxnet-zero-victims/67483/
- Flame (2012) โ discovery of a sophisticated espionage toolkit. https://securelist.com/the-flame-questions-and-answers/34344/
- Gauss (2012) โ discovery of nation-state banking malware. https://securelist.com/gauss-nation-state-cyber-espionage-banking-trojan/36620/
- Equation Group (2015) โ Q&A PDF documenting the most sophisticated APT group yet discovered. https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07205555/Equation_group_questions_and_answers.pdf
- Securelist RE workshop โ public training materials.
Public 12-step workflow (reconstructed from Securelist publications):
- KSN (Kaspersky Security Network) telemetry โ telemetry from Kaspersky endpoint products worldwide.
- Victimology analysis โ identify targeted victims, geographic and sectoral patterns.
- Static analysis โ hash, strings, imports, sections.
- Unpacking โ multi-stage unpacking for packed malware.
- Behavioural analysis โ dynamic analysis in sandbox.
- IDA Pro / Binary Ninja / Ghidra RE โ deep reverse engineering.
- Decompilation โ high-level reconstruction of malware logic.
- C2 protocol analysis โ reverse-engineer command-and-control protocol.
- Capability analysis โ identify exploit payloads, lateral movement tools, persistence mechanisms.
- Clustering โ group malware samples into families based on code/infrastructure overlap.
- Cautious attribution โ Kaspersky is more conservative than US vendors in naming specific countries; uses "actor X" or "the malware's authors" rather than direct nation-state attribution.
- Securelist publication โ detailed technical blog post with IOCs, YARA, source code samples.
Limitations & controversies:
- US bans (2017 + 2024): DHS banned Kaspersky products from US federal networks in 2017 (BND 2017-138). BIS (Bureau of Industry and Security) extended the ban to all US consumer and commercial sales in 2024. URL: https://www.bis.doc.gov/index.php/documents/bis-newsroom/press-releases/2024-kaspersky-lab-final-determination-62624/file.
- Kaspersky's denial: Company has consistently denied improper ties to Russian intelligence. NPR interview: https://www.npr.org/2024/06/20/nx-s1-5013739/biden-administration-bans-kaspersky-lab-antivirus-software-citing-russian-ties
- Global Transparency Initiative (GTI): Kaspersky launched the GTI in 2018 to address trust concerns: moved data processing to Zurich (2018), opened Transparency Centers in multiple countries (https://gti.kaspersky.com). URL: https://www.kaspersky.com/transparency-center
- Bias check: Despite governance concerns, Kaspersky's technical research quality is widely respected. Mandiant, CrowdStrike and other Western vendors continue to cite Kaspersky research in their own publications. The technical research and the governance/jurisdiction risk are separate issues โ investigators should evaluate the technical content on its merits while being aware of the geopolitical context.
Useful public resources:
| Resource | URL |
|---|---|
| Securelist (Kaspersky blog) | https://securelist.com |
| Kaspersky threat intelligence | https://www.kaspersky.com/enterprise-security/threat-intelligence |
| Kaspersky GTI | https://gti.kaspersky.com |
| Kaspersky GitHub (open-source tools) | https://github.com/kaspersky |
47.3 Cross-Vendor Comparison
| Dimension | Bellingcat | Mandiant/GTI | CrowdStrike | Recorded Future | MSTIC | Talos | Kaspersky |
|---|---|---|---|---|---|---|---|
| Primary discipline | Visual GEOINT | IR-led threat intel | Endpoint telemetry | NLP on OSINT | Telemetry | Network + malware | RE + malware |
| Attribution method | Public cross-ref | UNC clustering | Adversary naming | Centaur model | Weather naming | Sample clustering | Cautious, country-agnostic |
| Naming system | None | APT##/FIN##/UNC## | BEAR/PANDA/SPIDER | None (uses others') | Weather (was chemical) | None | None (uses others') |
| Reproducibility | High (workflow published) | Low (needs platform) | Low (needs Falcon) | Low (needs platform) | Low (needs telemetry) | Medium | Medium |
| Geographic bias | Russia/Syria/Ukraine strong; China/NK/Iran weak | Strong Western | Strong Western | Strong Western | Strong Western | Strong Western | Strong Russia/Asia |
| Free tier | All toolkit free | VirusTotal free | Adversary Hub free | Community Edition (limited) | Threat encyclopedia free | Blog free | Securelist free |
| Government alignment | None (NGO) | US-aligned (post-acquisition) | US-aligned | US-aligned | US-aligned | US-aligned | Russian (controversial) |
Appendix B. Structured Analytic Techniques (SATs)
Structured Analytic Techniques are mental tools to reduce analytical biases and produce more defensible conclusions. Popularised by Richards Heuer Jr. (Psychology of Intelligence Analysis, 1999) and by Heuer & Pherson (Structured Analytic Techniques for Intelligence Analysis, 3rd ed. 2020, CQ Press). These techniques are in the public domain of professional analytical literature โ they are not attributed to specific agencies.
B.1 ACH (Analysis of Competing Hypotheses)
What it is: Systematic method to evaluate multiple explanatory hypotheses against the same set of evidence, instead of seeking evidence for the preferred hypothesis. Combats confirmation bias.
When to use: When analysis has high consequences (strategic decisions, judicial conclusions, public conclusions that damage reputations) and multiple plausible hypotheses compete.
The 8 steps:
- List all plausible hypotheses (3-7) without premature discard. Force inclusion of 1-2 "unlikely" ones to avoid tunnel vision.
- List all significant evidence (facts, not inferences) + arguments.
- Build a hypothesis ร evidence matrix. Rows = evidence. Columns = hypotheses.
- For each cell, evaluate consistency:
+consistent ยทโinconsistent ยท?indeterminate. Crucial: evaluate whether the evidence is INCONSISTENT with the hypothesis, not whether it supports it. This inversion breaks confirmation bias. - Refine the matrix: remove evidence that does not discriminate between hypotheses.
- Compute the "inconsistency score" per hypothesis. The hypothesis with FEWER inconsistencies is the most robust (NOT the most consistent).
- Analyse sensitivity: "What evidence, if false, would change the conclusion?"
- Report with uncertainty: do not eliminate alternative hypotheses, report them with their relative probabilities.
Minimum ACH template:
| H1: fraud | H2: error | H3: external
| intentional | accounting | malicious
--------------|-------------|---------------|------------
E1: balancing | โ | + | ?
E2: timing | + | โ | +
E3: motive | + | ? | +
E4: auditor | + | + | โ
E5: access | + | + | โ
--------------|-------------|---------------|------------
# Inconsistencies | 1 | 2 | 2
Conclusion: | H1 most robust (fewest inconsistencies);
| H3 plausible if E4 (auditor) breaks
B.2 Key Assumptions Check
What it is: Explicit identification of the unverified assumptions on which an analysis rests. Combats anchoring bias.
When to use: At the start of any non-trivial analysis. Prerequisite for ACH and Devil's Advocacy.
| # | Assumption | Why I assumed it | Source/Evidence | If false, impact on conclusion | Action to verify |
|---|---|---|---|---|---|
| 1 | "Entity X is still active" | Listed in registry 6 months ago | Last query | Change of main hypothesis | Re-query today |
| 2 | "Identified UBO is correct" | Listing in PSC Register | Companies House | Lower confidence overall | Cross-check ICIJ + adverse media |
| 3 | "Applicable sanctions are EU" | Client in EU | Contract | Re-evaluate with OFAC/UK | Confirm with client |
Rules: minimum 5-8 assumptions per analysis ยท assign confidence High/Medium/Low ยท if โฅ2 assumptions are "Low", the overall conclusion cannot be "High Confidence" ยท review at the end of the analysis.
B.3 Devil's Advocacy
What it is: Designating a person (or role) to systematically criticise the dominant conclusion. Combats groupthink and premature closure.
How to implement individually:
- Assume the role explicitly. Write "Devil's Advocacy exercise" in the document.
- Identify 3-5 weak points in your own argument. Questions: What evidence do I NOT have? What alternative conclusion would explain the same data? What fails if my main source lied?
- Build the best possible counter-argument. Not a strawman โ a strong argument that an intelligent critic would build. If you cannot build it, you do not understand the case well enough.
- Honestly evaluate whether the counter-argument has merit. Modify conclusion or confidence if it does.
- Document in the deliverable: "Devil's Advocacy applied; alternative hypothesis X considered and rejected for Y / accepted partially, adjusting confidence from High to Moderate".
Traps: If it NEVER changes the conclusion, you are doing it wrong ยท Do not just aim at minor flaws, aim at the pillars.
B.4 Indicators & Warnings (I&W)
What it is: Monitoring system that defines in advance what observable signals would indicate a scenario is materialising. Enables early detection.
When to use: Continuous surveillance of scenarios (sanctions, internal fraud, geopolitical conflict, competitor reputational crisis).
SCENARIO MONITORED: "Entity X is sanctioned by OFAC within next 6 months"
INITIAL CONFIDENCE: Low (no active indicators)
MONITORING OWNER: [analyst]
REVIEW FREQUENCY: weekly
INDICATORS (in increasing specificity order):
Level 1 โ Background indicators (long duration, low specificity):
[ ] Entity X appears in quality adverse media โฅ3 times in 30 days
[ ] Entity X's main jurisdiction added to FATF grey list
[ ] Close commercial partner of Entity X designated by OFAC
Level 2 โ Tactical indicators (medium specificity, weeks):
[ ] Entity X changes auditor or correspondent bank without public reason
[ ] Entity X transfers assets to risk jurisdiction (RUS, IRN, PRK)
[ ] Civil litigation filed against Entity X in extraterritorial jurisdiction
Level 3 โ Strategic indicators (high specificity, days):
[ ] US State Department issues statement mentioning Entity X
[ ] OFAC publishes sector-specific guidance
[ ] US Congress introduces legislation naming Entity X
ACTIVATION MATRIX:
- 1 Level 1 indicator โ re-evaluate LowโModerate, daily monitoring
- 2+ Level 1 or 1 Level 2 โ ModerateโHigh, deep DD
- 1 Level 3 โ High confidence of imminent designation; activate contingency plan
Principles: Indicators must be observable ยท Activation matrix defined BEFORE any indicator occurs ยท System has value only if reviewed at the committed frequency.
๐ค Contribute
- Fork โ 2. Branch
new-toolโ 3. PR with tested URL (screenshot mandatory)
Read CONTRIBUTING.md before.
๐ License
GPL-3 โ Educational and research use. Don't be naughty.
ยซInformation wants to be free, but privacy wants to be respected.ยป
โ unknown