๐Ÿ•ต๏ธโ€โ™‚๏ธ OSINT Bible 2026

August 9, 2026 ยท View on GitHub

Compilation, procedures, tools and ethics for open source research

โš ๏ธ Ethical Disclaimer

This repository is dedicated to the responsible and ethical practice of Open-Source Intelligence (OSINT). All information, tools, and methodologies provided herein are intended solely for educational, research, and lawful investigative purposes. Users are strongly encouraged to adhere to ethical guidelines, respect privacy rights, comply with applicable laws and regulations, and obtain necessary permissions before conducting any investigations. Misuse of this information for illegal activities, harassment, or violation of privacy is strictly prohibited and may result in legal consequences. By accessing this repository, you agree to use the content responsibly and ethically.


๐Ÿงญ Quick Index with Buttons

Foundations

1. Fundamentals | 2. 4-Step Methodology | 3. Tools Mind Map | 11. Legal Considerations | 28. Professional Methodologies

Investigation Techniques

4. Internet Search | 5. Social Networks | 6. GEOINT & Images | 7. Domain / IP / DNS | 15. Email/Phone Investigation | 17. Blockchain/Crypto | 18. Transport OSINT | 19. WiFi/Wardriving | 20. Content Verification | 21. Username Enumeration | 22. Web Scraping | 23. Metadata Extraction | 24. Network Scanning | 29. Advanced Google Dorks | 31. People Investigations | 32. Company Research

Sources & Data

8. Deep & Dark Web | 16. Data Breaches | 25. Dark Web | 30. Learning Resources | 12. Extra Resources

Frameworks & Automation

9. Automation (Python) | 10. Report Templates | 13. AI Intelligence | 14. Facial Recognition | 26. All-in-One Frameworks | 27. Advanced Maltego

Specialized

33. Threat Intelligence Feeds | 34. ICS/OT & Critical-Infrastructure OSINT | 35. AI Agent Skills & MCP

2026 Expansion

36. Financial OSINT | 37. Investigator OPSEC & Sock Puppets | 38. Cloud Storage OSINT | 39. Mobile App OSINT | 40. Decentralized Social OSINT | 41. Counter-OSINT Self-Audit | 42. Discord & Telegram OSINT 2026 | 43. Satellite OSINT 2026 | 44. C2PA + SynthID + Deepfake Detection 2026 | 45. Professional Templates & Deliverables | 46. Regional OSINT | 47. Corporate OSINT Tradecraft | Appendix B. Structured Analytic Techniques

Tip

Extend OSINT-BIBLE with the companion tools that fit your workflow:


1. Fundamentals

ConceptQuick Definition
OSINTIntelligence obtained from public sources without violating logical or physical access
OPSECMinimize footprint: VPN โ†’ VM โ†’ alias โ†’ metadata strip
Intelligence CycleDirection โ†’ Collection โ†’ Processing โ†’ Analysis โ†’ Dissemination
PIIInformation that identifies: email, phone, RFC, CURP, IP, IMEI, MAC
Primary SourceOriginal publication (tweet, official PDF, photo EXIF)
Secondary SourceArticle citing the primary (validate)

2. 4-Step Methodology

  1. Define question โ†’ What do I want to know?
  2. Identify sources โ†’ Table below |
  3. Collect โ†’ Manual + automations |
  4. Validate and document โ†’ Screenshots, hash, date, URL, archive.org |
Data TypeUsual LocationStar Tool
NameLinkedIn, FacebookMaigret
EmailData breaches, newslettersHIBP
PhoneWhatsApp Business, TrueCallerInfobel
UsernameForums, gaming, GitHubSnoop
PhotoGeolocation, EXIFExiftool
DomainWHOIS, certificatesAmass
IPScanning, ShodanShodan
Crypto walletBlockchain explorersBlockCypher

3. Tools Mind Map

graph TD
    A[OSINT] --> B(Search)
    A --> C(Social Networks)
    A --> D(Geo)
    A --> E(Domain/IP)
    A --> F(DeepDark)
    A --> G(Automate)
    B --> B1(Google Dorks)
    B --> B2(Useful Dorks)
    C --> C1(Twint-fork)
    C --> C2(Maigret)
    C --> C3(Instaloader)
    D --> D1(Overpass-turbo)
    D --> D2(Satellites.pro)
    D --> D3(ExifTool)
    E --> E1(Amass)
    E --> E2(CRT.sh)
    E --> E3(DNSDumpster)
    F --> F1(Onionscan)
    F --> F2(Ahmia)
    G --> G1(Recon-ng)
    G --> G2(SpiderFoot)

4.1 Google Dorks โ€“ 20 essentials

ObjectiveDorkExample
Government PDFssite:gov filetype:pdf "contract"Mexico
Exposureintitle:"index of" passwords.txtโ€”
IP Camerasinurl:viewer/live/index.htmlโ€”
Emailssite:linkedin.com "@company.com"โ€”
Subdomainssite:*.target.com -wwwโ€”

4.2 Alternative Search Engines

4.3 Archives and snapshots


5. Social Networks

5.1 Facebook

  1. Facebook Recover Lookup - Link: Facebook Recover Lookup - Description: Used to check if a given email or phone number is associated with any Facebook account or not.
  2. Social Searcher - Link: Social Searcher - Description: Allows you to monitor all public social mentions in social networks and the web.
  3. Lookup-id.com - Link: Lookup-id.com - Description: Helps you find the Facebook ID of anyone's profile or a Group.
  4. Who posted this - Link: Who posted this - Description: Facebook keyword search for people who work in the public interest. It allows you to search keywords on specific dates.
  5. Facebook Search - Link: Facebook Search - Description: Allows you to search on Facebook for posts, people, photos, etc., using some filters.
  6. Facebook Graph Searcher - Link: Facebook Graph Searcher - Description: To search someone on Facebook.
  7. Facebook People Search - Link: Facebook People Search - Description: Search on Facebook by victim's name.
  8. DumpItBlue - Link: DumpItBlue+ - Description: helps to dump Facebook stuff for analysis or reporting purposes.
  9. Export Comments - Link: Export Comments - Description: Easily exports all comments from your social media posts to Excel file.
  10. Facebook Applications - Link: Facebook Applications - Description: A collection of online tools that automate and facilitate Facebook.
  11. Social Analyzer - Link: SocialAnalyzer - Social Sentiment & Analysis - Description: a free tool of social media monitoring and analysis.
  12. AnalyzeID - Link: AnalyzeID - Description: Just looking for sites that supposedly may have the same owner. Including a FaceBook App ID match.
  13. SOWsearch - Link: sowsearch - Description: a simple interface to show how the current Facebook search function works.
  14. Facebook Matrix - Link: FacebookMatrix - Description: Formulas for Searching Facebook.
  15. Who posted what - Link: Who Posted What - Description: A non public Facebook keyword search for people who work in the public interest. It allows you to search keywords on specific dates.
  16. StalkFace - Link: StalkFace - Description: Toolkit to stalk someone on Facebook.
  17. Search is Back - Link: Search is Back - Description: ind people and events on Facebook Search by location, relationships, and more!.
  18. FB-Search - Link: FB-Search - Description: busca por telรฉfono o correo.
  19. FB-Posts-scraper - Link: FB-Posts-scraper - Description: (Python).
  20. FB-Video-downloader - Link: FB-Video-downloader - Description: .

5.2 Instagram

  1. IFTTT Integrations - Link: IFTTT Instagram integrations - Description: Popular Instagram workflows & automations.
  2. IMGinn.io - Link: IMGinn.io - Description: view and download all the content on the social network Instagram all at one place.
  3. Instaloader - Link: Instaloader - Description: Download pictures (or videos) along with their captions and other metadata from Instagram.
  4. SolG - Link: SolG - Description: The Instagram OSINT Tool gets a range of information from an Instagram account that you normally wouldn't be able to get from just looking at their profile.
  5. Osintgram - Link: Osintgram - Description: Osintgram is an OSINT tool on Instagram to collect, analyze, and run reconnaissance.
  6. Toutatis - Link: toutatis - Description: It is a tool written to retrieve private information such as Phone Number, Mail Address, ID on Instagram accounts via API.
  7. instalooter - Link: instalooter - Description: InstaLooter is a program that can download any picture or video associated from an Instagram profile, without any API access.
  8. Exportgram - Link: Exportgram - Description: A web application made for people who want to export instagram comments into excel, csv and json formats.
  9. Profile Analyzer - Link: Profile Analyzer - Description: Analyze any public profile on Instagram โ€“ the tool is free, unlimited, and secure. Enter a username to take advantage of precise statistics.
  10. Find Instagram User Id - Link: Find Instagram User Id - Description: This tool called "Find Instagram User ID" provides an easy way for developers and designers to get Instagram account numeric ID by username.
  11. Instahunt - Link: Instahunt - Description: Easily find social media posts surrounding a location.
  12. Musicaldown - Link: Musicaldown - Description: web.

5.3 LinkedIn

  1. RecruitEm - Link: RecruitEm - Description: Allows you to search social media profiles. It helps recruiters to create a Google boolean string that searches all public profiles.
  2. RocketReach - Link: RocketReach - Description: Allows you to programmatically search and lookup contact info over 700 million professionals and 35 million companies.
  3. Phantom Buster - Link: Phantom Buster - Description: Automation tool suite that includes data extraction capabilities.
  4. linkedprospect - Link: LinkedIn Boolean Search - Description: Build a targeted list of LinkedIn people using boolean search.
  5. ReverseContact - Link: Reverse Email Lookup - Description: Find Linked Profiles associated with any email.
  6. LinkedIn Search Engine - Link: Programmable Search Engine - Description: Programmable Search Engine for LinkedIn profiles.
  7. Free People Search Tool - Link: Free People Search Tool - Description: Find people easily online.
  8. IntelligenceX Linkedin - Link: IntelligenceX Linkedin - Description: A webbased tool for searching someone on Linkedin.
  9. Linkedin Search Tool - Link: Linkedin Search Tool - Description: Provides you a interface with various tools for Linkedin Osint.
  10. LinkedInt - Link: LinkedInt - Description: Providing you with Linkedin Intelligence.
  11. InSpy - Link: InSpy - Description: InSpy is a python based LinkedIn enumeration tool.
  12. CrossLinked - Link: CrossLinked - Description: CrossLinked is a LinkedIn enumeration tool that uses search engine scraping to collect valid employee names from an organization.
  13. Hunter.io - Link: Hunter.io - Description: Find and verify corporate email patterns. 25 free searches per month.

5.4 Twitter/X

  1. TweetDeck - Link: TweetDeck - Description: Offers a more convenient Twitter experience by allowing you to view multiple timelines in one easy interface.
  2. FollowerWonk - Link: FollowerWonk - Description: Helps you find Twitter accounts using bio and provides many other useful features.
  3. Twitter Advanced Search - Link: Twitter Advanced Search - Description: Allows you to search on Twitter using filters for better search results.
  4. memory.lol - Link: memory.lol - Description: a tiny web service that provides historical information about twitter users.
  5. SocialData API - Link: SocialData API - Description: an unofficial Twitter API alternative that allows scraping historical tweets, user profiles, lists and Twitter spaces without using Twitter's API.
  6. Social Bearing - Link: Social Bearing - Description: Insights & analytics for tweets & timelines.
  7. Tinfoleak - Link: Tinfoleak - Description: Search for Twitter users leaks.
  8. Network Tool - Link: Network Tool - Description: Explore how information spreads across Twitter with an interactive network using OSoMe data.
  9. Foller - Link: Foller - Description: Looking for someone in the United States? Our free people search engine finds social media profiles, public records, and more!
  10. SimpleScraper OSINT - Link: SimpleScraper OSINT - Description: This Airtable automatically scrapes OSINT-related twitter accounts ever 3 minutes and saves tweets that contain coordinates.
  11. Deleted Tweet Finder - Link: Deleted Tweet Finder - Description: Search for deleted tweets across multiple archival services.
  12. Twitter Search Tool - Link: Twitter search tool - Description: On this page you can create advanced search queries within Twitter.
  13. Twitter Video Downloader - Link: Twitter Video Downloader - Description: Download Twitter videos & GIFs from tweets.
  14. Download Twitter Data - Link: Download Twitter Data - Description: Download Twitter data in csv format by entering any Twitter handle, keyword, hashtag, List ID or Space ID.
  15. Twitonomy - Link: Twitonomy - Description: Twitter #analytics and much more.
  16. tweeterid - Link: tweeterid - Description: Type in any Twitter ID or @handle below, and it will be converted into the respective ID or username.
  17. BirdHunt - Link: BirdHunt - Description: Easily find social media posts surrounding a location.
  18. Twint-docker - Link: Twint-docker - Description: Download all tweets from a user without API access.
  19. Sentiment140 - Link: Sentiment140 - Description: Bulk sentiment analysis for tweets via CSV.
  20. Xquik - Link: Xquik - Description: 122 API endpoints for search, user, post and monitor. API key, USD 0.00015/read.

5.5 Pinterest

  1. DownAlbum - Link: DownAlbum - Description: Google Chrome extension for downloading albums of photos from various websites, including Pinterest.
  2. Experts PHP: Pinterest Photo Downloader - Link: Pinterest Photo Downloader - Description: Website providing a tool to download photos from Pinterest.
  3. Pingroupie - Link: Pingroupie - Description: A Meta Search Engine for Pinterest that lets you discover Collaborative Boards, Influencers, Pins, and new Keywords.
  4. Tailwind - Link: Tailwind - Description: Social media scheduling and management tool that supports Pinterest.
  5. Pinterest Guest - Link: Pinterest Guest - Description: Mozilla Firefox add-on for browsing Pinterest without logging in or creating an account.

5.6 Reddit

  1. F5BOT - Link: F5BOT - Description: Receive notifications for new Reddit posts matching specific keywords.
  2. Mostly Harmless - Link: Mostly Harmless - Description: A suite of tools for Reddit, including user analysis, subreddit comparison, and more.
  3. OSINT Combine: Reddit Post Analyzer - Link: OSINT Combine: Reddit Post Analyzer - Description: Analyze and gather information from Reddit posts for OSINT purposes.
  4. Phantom Buster - Link: Phantom Buster - Description: Automation tool suite that includes Reddit data extraction capabilities.
  5. rdddeck - Link: rdddeck - Description: Real-time dashboard for monitoring multiple Reddit communities.
  6. Readr for Reddit - Link: Readr for Reddit - Description: Google Chrome extension for an improved reading experience on Reddit.
  7. Reddit Archive - Link: Reddit Archive - Description: Archive of Reddit posts and comments for historical reference.
  8. Reddit Comment Search - Link: Reddit Comment Search - Description: Search for specific comments and conversations on Reddit.
  9. Redditery - Link: Redditery - Description: Explore Reddit posts and comments based on various criteria.
  10. Reddit Hacks - Link: Reddit Hacks - Description: Collection of Reddit hacks and tricks for advanced users.
  11. Reddit List - Link: Reddit List - Description: Directory of popular subreddits organized by various categories.
  12. reddtip - Link: reddtip - Description: Show appreciation to Reddit users by sending them tips in cryptocurrencies.
  13. Reddit Search - Link: Reddit Search (realsrikar) - Description: Various tools and websites for searching and discovering content on Reddit.
  14. Reddit Shell - Link: Reddit Shell - Description: Command-line interface for browsing and interacting with Reddit.
  15. Reddit Stream - Link: Reddit Stream - Description: Live-streaming of Reddit comments for real-time discussions.
  16. Reddit Suite - Link: Reddit Enhancement Suite (Chrome Extension) - Description: Browser extension that enhances the Reddit browsing experience with additional features.
  17. Reddit User Analyser - Link: Reddit User Analyser - Description: Analyze and visualize the activity and behavior of Reddit users.
  18. redditvids - Link: redditvids - Description: Watch Reddit videos and browse popular video subreddits.
  19. Reditr - Link: Reditr - Description: Desktop Reddit client with a clean and intuitive interface.
  20. Reeddit - Link: Reeddit - Description: Simplified and clean Reddit web interface for a distraction-free browsing experience.
  21. smat - Link: smat - Description: Social media analytics tool that includes Reddit for tracking trends and engagement.
  22. socid_extractor - Link: socid_extractor - Description: Extract user information from Reddit and other social media platforms.
  23. Suggest me a subreddit - Link: Suggest me a subreddit - Description: Get recommendations for new subreddits to explore based on your preferences.
  24. Subreddits - Link: Subreddits - Description: Directory of active subreddits organized by various categories.
  25. uforio - Link: uforio - Description: Generate word clouds from Reddit comment threads.
  26. Universal Reddit Scraper (URS) - Link: Universal Reddit Scraper (URS) - Description: Python-based tool for scraping Reddit data for analysis.
  27. Vizit - Link: Vizit - Description: Visualize and analyze relationships between Reddit users and subreddits.
  28. Wisdom of Reddit - Link: Wisdom of Reddit - Description: Curated collection of insightful quotes and comments from Reddit.

5.7 Github Leak Detection

  1. Awesome Lists - Link: Awesome Lists - Description: A curated list of awesome lists for various programming languages, frameworks, and tools.
  2. CoderStats - Link: CoderStats - Description: A platform for developers to track and showcase their coding activity and statistics from GitHub.
  3. Digital Privacy - Link: Digital Privacy - Description: A collection of resources and tools for enhancing digital privacy and security.
  4. Find Github User ID - Link: Find Github User ID - Description: A web tool for finding the unique identifier (ID) of a GitHub user.
  5. GH Archive - Link: GH Archive - Description: A project that provides a public dataset of GitHub activity, including events and metadata.
  6. GitGot - Link: GitGot - Description: A semi-automated, feedback-driven tool for auditing Git repositories.
  7. gitGraber - Link: gitGraber - Description: A tool for searching and cloning sensitive information in GitHub repositories.
  8. git-hound - Link: git-hound - Description: A tool for finding sensitive information exposed in GitHub repositories.
  9. Github Dorks - Link: Github Dorks - Description: A collection of GitHub dorks, which are search queries to find sensitive information in repositories.
  10. Github Stars - Link: Github Stars - Description: A website that showcases GitHub repositories with the most stars and popularity.
  11. Github Trending RSS - Link: Github Trending RSS - Description: An RSS feed generator for trending repositories on GitHub.
  12. Github Username Search Engine - Link: Github Username Search Engine - Description: A search engine to find GitHub usernames based on various filters and criteria.
  13. Github Username Search Engine - Link: Github Username Search Engine - Description: Another search engine to find GitHub usernames with advanced filtering options.
  14. GitHut - Link: GitHut - Description: A website that provides statistics and visualizations of programming languages on GitHub.

5.7.x.1 Verified Tools

ToolURLFunction
GitGothttps://github.com/BishopFox/GitGotGitHub repo audit
gitGraberhttps://github.com/hisxo/gitGraberGitHub secrets search
GitHoundhttps://github.com/tillson/git-houndSensitive info search
TruffleHoghttps://github.com/trufflesecurity/trufflehogCredential detection with verification
Gitleakshttps://github.com/gitleaks/gitleaksFast secrets detection

5.7.x.2 GitHub Dorks โ€” 15 Practical Examples

1.  ORGNAME filename:.env AWS_SECRET_ACCESS_KEY
2.  ORGNAME filename:.env MAIL_PASSWORD
3.  ORGNAME filename:.npmrc _auth
4.  ORGNAME filename:.dockercfg
5.  ORGNAME filename:config.rb password
6.  ORGNAME filename:id_rsa BEGIN OPENSSH PRIVATE KEY
7.  ORGNAME filename:id_dsa BEGIN DSA PRIVATE KEY
8.  ORGNAME extension:pem PRIVATE KEY
9.  ORGNAME filename:.git-credentials
10. ORGNAME filename:settings.py SECRET_KEY
11. ORGNAME filename:wp-config.php DB_PASSWORD
12. ORGNAME filename:database.yml password
13. ORGNAME "api.openai.com" Authorization:Bearer
14. ORGNAME extension:sh AWS_ACCESS_KEY_ID
15. ORGNAME filename:terraform.tfvars

Variations: fork:true to include forks ยท archived:true for archived repos ยท pushed:>2026-01-01 for recent.

5.7.x.3 Tool Workflows

TruffleHog (active credential verification):

# Install
go install github.com/trufflesecurity/trufflehog/v3@latest

# Scan repo with full history:
trufflehog git https://github.com/ORGNAME/repo.git --only-verified

# Scan organisation:
trufflehog github --org=ORGNAME --only-verified

# JSON output:
trufflehog git https://github.com/ORGNAME/repo.git --json --only-verified > findings.json

The --only-verified flag filters only secrets confirmed active. Reduces false positives.

gitGraber (continuous monitoring in cron):

git clone https://github.com/hisxo/gitGraber.git
cd gitGraber

# Configure config.py with GITHUB_TOKENS, WORDLIST, SLACK_WEBHOOK

# First run:
python3 gitGraber.py --wordlist wordlists/your_wordlist.txt --output

# Cron every 6h:
# 0 */6 * * * cd /opt/gitGraber && python3 gitGraber.py --wordlist ...

GitGot (interactive audit):

pip install gitgot
python3 gitgot.py -q "ORGNAME"
# Interactive session: [i]gnore, [s]ave, [r]eview, [q]uit

5.7.x.4 Ethical Considerations

  • Accessing a public repo is legitimate. GitHub public is public.
  • NOT legitimate: using a found secret to escalate access. The difference between defensive OSINT and attack is use, not access.
  • Responsible disclosure: discovering a leak obliges you to notify the repo owner. 90 days before public disclosure (Project Zero standard).
  • Do not include the full secret in the client report. Format ghp_โ€ขโ€ขโ€ขโ€ขโ€ขโ€ข[last4].
  • GitHub Security Advisory for leaks in third-party repos.

5.8 Snapchat

  1. addmeContacts - Link: addmeContacts - Description: A platform to find and connect with new contacts on various social media platforms.
  2. AddMeSnaps - Link: AddMeSnaps - Description: A website for discovering and adding new Snapchat friends.
  3. ChatToday - Link: ChatToday - Description: An online chat platform for connecting and chatting with people from around the world.
  4. Gebruikersnamen: Snapchat - Link: Gebruikersnamen: Snapchat - Description: A website for finding Snapchat usernames.
  5. OSINT Combine: Snapchat MultiViewer - Link: OSINT Combine: Snapchat MultiViewer - Description: A tool for viewing multiple Snapchat accounts simultaneously.
  6. Snapchat-mapscraper - Link: Snapchat-mapscraper - Description: A tool for scraping public Snapchat Stories from the Snap Map.
  7. Snap Political Ads Library - Link: Snap Political Ads Library - Description: Snapchat's library of political ads displayed on the platform.
  8. Social Finder - Link: Social Finder - Description: A platform to search and discover social media profiles on various platforms.
  9. SnapIntel - Link: SnapIntel - Description: a python tool providing you information about Snapchat users.
  10. AddMeS - Link: AddMeS - Description: The 'Add Me' directory of Snapchat users on web.

5.9 WhatsApp

  1. checkwa - Link: checkwa - Description: An online tool to check the status and availability of WhatsApp numbers.
  2. WhatsApp Fake Chat - Link: WhatsApp Fake Chat - Description: An online tool to generate fake WhatsApp conversations for fun or pranks.
  3. whatsfoto - Link: whatsfoto - Description: A Python script to download profile pictures from WhatsApp contacts.
  4. CheckLeaked WhatsApp - Link: CheckLeaked WhatsApp - Description: An online tool to look up WhatsApp numbers โ€” download the current and historical profile pictures, read the About/bio text, and detect Business/Enterprise accounts. Free web interface with an optional API.

5.10 Skype

  1. addmeContacts - Link: addmeContacts - Description: A platform to find and connect with new contacts on various social media platforms.
  2. ChatToday - Link: ChatToday - Description: An online chat platform for connecting and chatting with people from around the world.
  3. Skypli - Link: Skypli - Description: A website for discovering and connecting with new Skype contacts.

5.11 Telegram

  1. ChatBottle: Telegram - Link: ChatBottle: Telegram - Description: A directory of Telegram bots for various purposes.
  2. ChatToday - Link: ChatToday - Description: An online chat platform for connecting and chatting with people from around the world.
  3. informer - Link: informer - Description: A Python library for retrieving information about Telegram channels, groups, and users.
  4. _IntelligenceX: Telegram - Link: _IntelligenceX: Telegram - Description: IntelligenceX's Telegram tool for searching and analyzing Telegram data.
  5. Lyzem.com - Link: Lyzem.com - Description: A website to search and find Telegram groups and channels.
  6. Telegram Channels - Link: Telegram Channels - Description: A directory of Telegram channels covering various topics.
  7. Telegram Channels - Link: Telegram Channels - Description: A platform to discover and browse Telegram channels.
  8. Telegram Channels Search - Link: Telegram Channels Search - Description: A search engine to find Telegram channels by keywords.
  9. Telegram Directory - Link: Telegram Directory - Description: A comprehensive directory of Telegram channels, groups, and bots.
  10. Telegram Group - Link: Telegram Group - Description: A website to search and join Telegram groups.
  11. telegram-history-dump - Link: telegram-history-dump - Description: A Python script to dump the history of a Telegram chat into a SQLite database.
  12. Telegram-osint-lib - Link: Telegram-osint-lib - Description: A Python library for performing open-source intelligence (OSINT) on Telegram.
  13. Telegram Scraper - Link: Telegram Scraper - Description: A powerful Telegram scraping tool for extracting user information and media.
  14. Tgram.io - Link: Tgram.io - Description: A platform to explore and search for Telegram channels, groups, and bots.
  15. Tgstat.com - Link: Tgstat.com - Description: A comprehensive platform for analyzing and tracking Telegram channels and groups.
  16. Tgstat RU - Link: Tgstat RU - Description: A Russian platform for analyzing and monitoring Telegram channels and groups.

5.12 Discord

  1. DiscordOSINT - Link: DiscordOSINT - Description: This Repository Will contain useful resources to conduct research on Discord.
  2. Discord.name - Link: Discord.name - Description: Discord profile lookup using user ID.
  3. Discord History Tracker - Link: Discord History Tracker - Description: Discord History Tracker lets you save chat history in your servers, groups, and private conversations, and view it offline.
  4. Top.gg - Link: Top.gg - Description: Explore millions of Discord Bots.
  5. Unofficial Discord Lookup - Link: Unofficial Discord Lookup - Description: Search for discord profile using id.
  6. Disboard - Link: Disboard - Description: DISBOARD is the place where you can list/find Discord servers.

5.13 ONLYFANS

  1. OnlyFans Finder - Link: The Favourite OnlyFans search - Description: The tools allow easy searching via advanced filtering capabilities and sorting functionality, making it easy to access desired material.
  2. OnlyFam - Link: OnlyFam - Description: OnlyFans Search & Model Finder - Find Creators in the World's Largest OnlyFans Database
  3. OnlyFinder - Link: OnlyFinder - Description: OnlyFans Search Engine - OnlyFans Account Finder.
  4. OnlySearch - Link: OnlySearch - Description: Find OnlyFans profiles by searching for key words.
  5. Sotugas - Link: SรณTugas - Description: Encontra Contas do OnlyFans Portugal ๐Ÿ‡ต๐Ÿ‡น.
  6. Fansmetrics - Link: Fansmetrics - Description: Use this OnlyFans Finder to search in 3,000,000 OnlyFans Accounts.
  7. Findr.fans - Link: Findr.fans - Description: Only Fans Search Tool.
  8. Hubite - Link: Hubite - Description: Advanced OnlyFans Search Engine.
  9. Similarfans - Link: Similarfans - Description: Blog for OnlyFans content creators.
  10. Fansearch - Link: Fansearch - Description: Fansearch is the best OnlyFans Finder to search in 3,000,000 OnlyFans Accounts.

5.14 TikTok

  1. Mavekite - Link: Mavekite - Description: Search the profile using username.
  2. TikTok hashtag analysis toolset - Link: TikTok hashtag analysis toolset - Description: The tool helps to download posts and videos from TikTok for a given set of hashtags over a period of time.
  3. TikTok Video Downloader - Link: TikTok Video Downloader - Description: ssstiktok is a free TikTok video downloader without watermark tool that helps you download TikTok videos without watermark (Musically) online.
  4. Exolyt - Link: exolyt - Description: The best tool for TikTok analytics & insights.

6. Geoint & Images

6.1 Metadata

exiftool -a -u foto.jpg | grep -i "gps\|date\|camera"
# strip before publishing
exiftool -all= foto_sanitizada.jpg

6.2 Geolocate

6.3 Satellite / Drone


6.4 Video OSINT & Chronolocation

Video as a specific OSINT source plus chronolocation (determining when material was recorded). Does not duplicate 6.1-6.3 (metadata, geolocation, satellite).

6.4.1 Video Geolocation Workflow โ€” 12 Steps

#StepTool
1Identify the geolocation objective (humanitarian/journalistic/military)โ€”
2Extract keyframes with FFmpeg: ffmpeg -i video.mp4 -vf "fps=1/10" frame_%04d.pngFFmpeg
3Extract EXIF metadata: exiftool video.mp4ExifTool
4Analyse audio: language, accent, calls to prayer (adhan = time + orientation to Mecca)โ€”
5Identify visual anchors: signs, licence plates, architecture, vegetationโ€”
6Geolocate anchors individually with Google Lens / Yandex Images + Overpass Turboโ€”
7Trace sight lines from each anchorGoogle Earth Pro
8Validate with Street ViewGoogle Street View
9Validate with historical satellite imageryGoogle Earth Pro + Copernicus Browser
10Determine camera cardinal orientation with SunCalcSunCalc
11Triangulate date (chronolocation)See 6.4.2
12Document with BLUF + evidence package (each anchor with frame + screenshot + URL + hash)โ€”

6.4.2 Shadow-Based Chronolocation โ€” 8 Steps

  1. Geolocate first (6.4.1). Without lat/long, solar position cannot be calculated.
  2. Identify vertical object with a sharp projected shadow. Pole, column, standing person.
  3. Measure cardinal direction of the shadow (azimuth in degrees from Google Earth Pro).
  4. Measure relative length: ratio shadow/object_height. Solar elevation = arctan(h/l).
  5. Compute solar position with SunCalc.org (move slider until azimuth+elevation match).
  6. Resolve symmetric date ambiguity with contextual clues (vegetation, snow, datable events).
  7. Validate with historical weather. Visual Crossing Weather History (free tier).
  8. Document margin of error. Typically ยฑ30-90 min of time, ยฑ2-7 days of date. Report with confidence level.

6.4.3 Verified Video OSINT Tools

ToolURLFunction
FFmpeghttps://ffmpeg.orgVideo analysis and processing
FotoForensicshttps://fotoforensics.comELA image analysis
Forensicallyhttps://29a.ch/photo-forensicsVisual analysis suite
ExifToolhttps://exiftool.orgMetadata
SunCalchttps://www.suncalc.orgSolar position
Google Earth Prohttps://www.google.com/earthHistorical satellite
Sentinel Hubhttps://www.sentinel-hub.comSentinel-2 imagery
yt-dlphttps://github.com/yt-dlp/yt-dlpVideo download
GeoConfirmedhttps://geoconfirmed.orgCollaborative geolocation

6.4.4 Real Case โ€” Bellingcat Bucha 2022

Following the withdrawal of Russian troops from Bucha (Ukraine) in March 2022, images of civilian bodies in Yablunska Street appeared. Russia denied responsibility. Bellingcat and The New York Times published on 4 April 2022 an analysis demonstrating that the bodies were already present during the Russian occupation, using Maxar satellite imagery from 19 March.

Methodology:

  1. Geolocation of each frame with a visible body in Yablunska Street.
  2. Acquisition of Maxar imagery from 19 March (during Russian occupation).
  3. Frame-by-frame comparison: dark objects on the street in the same locations where the 2 April video showed bodies. One-to-one correspondence.
  4. Validation with second satellite (Planet Labs, 21 March).
  5. Conclusion: bodies were already on the street on 19 March (Russian control). High confidence (cross-corroboration of satellite + video + testimonies).

Sources:


7. Domain / IP / DNS

ObjectiveToolQuick Command
SubdomainsAmassamass enum -d target.com -o subs.txt
CertificatesCRT.shcurl https://crt.sh/?q=%25.target.com&output=json
Historical DNSSecurityTrailsFree API 50/month
Neighbor IPsBGP.heCIDR
ReputationVirusTotalvt ip_info <ip>
Quick scanNmap-onlineno VPN
SubdomainsSubdomain Centerhttps://www.subdomain.center
SubdomainsSubdomainRadarhttps://www.subdomainradar.io
Historical DNSDNS Historyhttp://dnshistory.org
ReputationTaloshttps://www.talosintelligence.com/
ScanBinary Defensehttps://www.binarydefense.com/banlist.txt
BGP RankingCIRCL BGPhttps://bgpranking.circl.lu
Botnet TrackerMalwareTechhttps://intel.malwaretech.com/
BOTVRIJ.EUBOTVRIJhttp://www.botvrij.eu/
C&C TrackerBambenekhttp://osint.bambenekconsulting.com/feeds/c2-ipmasterlist.txt
CertStreamCertStreamhttps://certstream.calidog.io/
CCSS ForumCCSS Forumhttp://www.ccssforum.org/malware-certificates.php
CI Army ListCINS Scorehttp://cinsscore.com/#list
Cisco UmbrellaCisco Umbrellahttp://s3-us-west-1.amazonaws.com/umbrella-static/index.html
CloudmersiveCloudmersivehttps://cloudmersive.com/virus-api
Critical StackCritical Stackhttps://intelstack.com/
CrowdSecCrowdSechttps://app.crowdsec.net/
Cyber CureCyber Curehttps://www.cybercure.ai/
DataPlaneDataPlanehttps://dataplane.org/
FocsecFocsechttps://focsec.com
Disposable DomainsDisposable Domainshttps://github.com/martenson/disposable-email-domains
Emerging ThreatsEmerging Threatshttp://rules.emergingthreats.net/fwrules/
ExoneraTorExoneraTorhttps://exonerator.torproject.org/
ExploitalertExploitalerthttp://www.exploitalert.com/
FastInterceptFastIntercepthttps://intercept.sh/threatlists/
Feodo TrackerFeodo Trackerhttps://feodotracker.abuse.ch/
FireHOLFireHOLhttp://iplists.firehol.org/
FraudGuardFraudGuardhttps://fraudguard.io/
Grey NoiseGrey Noisehttp://greynoise.io/
HoneyDBHoneyDBhttps://riskdiscovery.com/honeydb/
IcewaterIcewaterhttps://github.com/SupportIntelligence/Icewater
InQuest LabsInQuest Labshttps://labs.inquest.net
I-BlocklistI-Blocklisthttps://www.iblocklist.com/lists
IPsumIPsumhttps://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt
James BrineJames Brinehttps://jamesbrine.com.au
Kaspersky FeedsKasperskyhttps://support.kaspersky.com/datafeeds
MalpediaMalpediahttps://malpedia.caad.fkie.fraunhofer.de/
MalShareMalSharehttp://www.malshare.com/
MaltiverseMaltiversehttps://www.maltiverse.com/
MalwareBazaarMalwareBazaarhttps://bazaar.abuse.ch/
Malware Domain ListMalware Domain Listhttps://www.malwarepatrol.net/
MetaDefenderMetaDefenderhttps://www.opswat.com/developers/threat-intelligence-feed
Netlab OpenDataNetlabhttps://data.netlab.360.com/
NoThink!NoThink!http://www.nothink.org
ObstractsObstractshttps://www.obstracts.com/
OpenPhishOpenPhishhttps://openphish.com/phishing_feeds.html
0xSI_f33d0xSI_f33dhttps://feed.seguranca-informatica.pt/index.php
PhishTankPhishTankhttps://www.phishtank.com/developer_info.php
PickupSTIXPickupSTIXhttps://www.celerium.com/pickupstix
RST CloudRST Cloudhttps://rstcloud.net/
SecurityScorecardSecurityScorecardhttps://github.com/securityscorecard/SSC-Threat-Intel-IoCs
StixifyStixifyhttps://www.stixify.com/
signature-basesignature-basehttps://github.com/Neo23x0/signature-base
SpamhausSpamhaushttps://www.spamhaus.org/
Sophos IntelixSophoshttps://www.sophos.com/intelix
SpurSpurhttps://spur.us
SSL BlacklistSSL Blacklisthttps://sslbl.abuse.ch/
StatvooStatvoohttps://statvoo.com/dl/top-1million-sites.csv.zip
StrongarmStrongarmhttps://strongarm.io
SIEM RulesSIEM Ruleshttps://www.siemrules.com
TalosTaloshttps://www.talosintelligence.com/
threatfeeds.iothreatfeeds.iohttps://threatfeeds.io
threatfoxthreatfoxhttps://threatfox.abuse.ch/
Technical Blogs (Dataminr)Technical Blogshttps://www.dataminr.com/blog/
ThreatMinerThreatMinerhttps://www.threatminer.org/
ThreatExchangeThreatExchangehttps://developers.facebook.com/docs/threat-exchange/
TypeDB CTITypeDB CTIhttps://github.com/typedb-osi/typedb-cti
XFEXFEhttps://exchange.xforce.ibmcloud.com/
YetiYetihttps://yeti-platform.github.io/
1st Dual Stack1st Dual Stackhttps://IOCFeed.mrlooquer.com/
Yara-RulesYara-Ruleshttps://github.com/Yara-Rules/rules
VirusShareVirusSharehttps://virusshare.com/
CIRCL PDNSCIRCL PDNShttps://www.circl.lu/services/passive-dns
InTheWildInTheWildhttps://inthewild.io
360 Quake360 Quakehttps://quake.360.net
Cloudflare RadarCloudflare Radarhttps://radar.cloudflare.com/traffic
ValidinValidinhttps://app.validin.com
OSVOSVhttps://osv.dev
Coalition ESSCoalition ESShttps://ess.coalitioninc.com
WHOIS & Domain HistoryWhoisFreakshttps://whoisfreaks.com
IP Geolocation & Threat Intelipgeolocation.iohttps://ipgeolocation.io

7.1 Google Dorks โ€“ Domains

site:*.target.com filetype:pdf
site:*.target.com intitle:"dashboard"
site:*.target.com intext:"confidential"

8. Deep & Dark Web

NeedSolutionURL
Search .onionAhmiaclean index
IOC aggregationDeepTrawl (author's)https://github.com/frangelbarrera/deepweb-leak-search
Check if data leakedHaveIBeenPwnedAPI
MarketsDarkOwl (paid)โ€”
CredentialsDeHashed (freemium)โ€”
Search .onionTOR Linkhttps://tor.link
Scanner servicesOnionScanhttps://github.com/s-rah/onionscan
Verified directoryDark.failhttps://dark.fail
Old searcherTorch(only .onion)
Scraper onionDarkDumphttps://github.com/josh0xA/darkdump
Tor ProjectTor Projecthttps://torproject.org
Public webcamsTWNhttp://www.the-webcam-network.com
Public webcamsOpentopiahttp://www.opentopia.com
World webcamsWorldCamhttps://worldcam.eu
WebcamsWebcam Galorehttps://www.webcamgalore.com
Traffic camerasOpenTrafficCamMaphttps://otc.armchairresearch.org/map
Skyline webcamsSkyline Webcamshttps://www.skylinewebcams.com/en/webcam
World webcamsPictimohttps://www.pictimo.com
Public webcamsCamHackerhttps://www.camhacker.com
Surveillance camerasSUNDERShttps://sunders.uber.space
Ukraine camerasUkraine Live Camshttps://nagix.github.io/ukraine-livecams

OPSEC for .onion

  • TailsOS โ†’ USB โ†’ bridge-Tor โ†’ NO extra proxies
  • Disable scripts Noscript โ†’ max
  • Never maximize window (fingerprint)
  • Never use VPN + Tor (traffic correlation)
  • Use bridges if Tor is blocked
  • NoScript to max
  • No window resizing
  • No downloading to persistent disk

9. Automation (Python)

9.1 Minimum Stack

python -m venv osint-env
source osint-env/bin/activate
pip install twint-fork recon-ng selenium requests beautifulsoup4 shodan

9.2 Mini-OSINT Script โ€“ unifies 5 sources

#!/usr/bin/env python3
# mini_osint.py
import shodan, requests, json, sys
from bs4 import BeautifulSoup

API_KEY = 'YOUR_SHODAN_API'
s = shodan.Shodan(API_KEY)
domain = sys.argv[1]

# 1. Subdomains via CRT.sh
crt = requests.get(f'https://crt.sh/?q=%25.{domain}&output=json').json()
subs = sorted(set([r['name_value'] for r in crt]))
print('[+] Found subdomains:', len(subs))

# 2. IPs from resolution
ips = set()
for sub in subs[:20]:  # demo limit
    try:
        ips.add(socket.gethostbyname(sub))
    except:
        pass

# 3. Shodan quick look
for ip in ips:
    try:
        info = s.host(ip)
        print(ip, info['org'], info.get('vulns', 'N/A'))
    except:
        pass

9.3 Recon-ng โ€“ fast workflow

recon-ng
> marketplace install all
> workspaces add target
> use domains-domains/brute_force
> set SOURCE target.com
> run
> use hosts-hosts/resolve
> run
> use reporting/csv
> run

10. Report Templates

Folder /templates/ in your repo. Mandatory YAML front-matter:

---
investigator: your-alias
date: 2025-12-16
objective: "Target Name"
scope: domain + RRSS
status: draft # draft | reviewed | delivered
---

# Executive Summary
(5 lines)

# Primary Sources
- URL | date | capture hash

# Chronology
- 2024-10-01: Domain registration
- 2025-01-15: First leak

# Annexes
- Screenshots folder `/annexes/`
- CSV extracts

CountryFrameworkKey
MexicoPDP Law 2018Explicit consent for PII
SpainLOPD-GDPRArt. 6.1-f: legitimate interest (research)
USACFAANo bypass to authentication
EuropeGDPRDPIA if >1000 people
โ€”OSINT-Code-EthicsNo doxxing, no stalking, no data selling

Ethical checklist โ˜ Is the source 100% public? โ˜ Is the data sensitive PII? โ†’ minimize โ˜ Is there verifiable public interest? โ˜ Can it be de-identified?


12. Extra Resources

Free Books

Courses / Certifications

Communities


13. AI Intelligence

AI-powered tools for OSINT 2025:

ToolFunctionURLNote
anonchatgptAnonymous ChatGPT clienthttps://anonchatgpt.comNo account needed
ai-toolkitEssential AI toolkit for journalistshttps://huggingface.co/spaces/JournalistsonHF/ai-toolkitFree and open-source
ChatPDFAsk questions to PDFshttps://www.chatpdf.com/Simple and free
MonicaChatGPT copilot in Chromehttps://monica.im/Summarize, translate
BabelXMultilingual OSINT platformhttps://www.babelstreet.com200+ languages
FivecastPredictive analysis with MLhttps://www.fivecast.comReal-time threat detection
HyperVergeDeepfake detectionhttps://hyperverge.coAI biometric verification
ShadowDragonSocial Darkint with AIhttps://shadowdragon.ioBehavior analysis
TalkwalkerMedia monitoring with AIhttps://www.talkwalker.comSentiment analysis
DorkGPTAI dork generatorhttps://www.dorkgpt.comAuto-creates Google dorks
SearchDorksDorks for multiple engineshttps://kriztalz.sh/search-dorksFOFA, Shodan, Censys
Sensity AIDeepfake detectionhttps://sensity.aiProfessional
Full FactAI fact-checking (UK)https://fullfact.orgFree
LogicallyAI disinfo detectionhttps://logically.comFree tier

13.1 Curated AI directories (cross-references)

DirectoryCoverageURL
Artificial-Intelligence-Universe800+ AI toolshttps://github.com/frangelbarrera/Artificial-Intelligence-Universe
awesome-ai-agents132 AI agents, 22 categorieshttps://github.com/frangelbarrera/awesome-ai-agents
Awesome-Hacking-with-AIAI-powered offensive securityhttps://github.com/frangelbarrera/Awesome-Hacking-with-AI
osint-agent-skillsMCP server for OSINT agentshttps://github.com/frangelbarrera/osint-agent-skills

14. Facial Recognition

Beyond basic searches:

ToolCapabilityURLCost
PimEyesFacial search on internethttps://pimeyes.com/enFreemium
OSINT by PimEyesPro version for professionalshttps://osint.pimeyes.comPaid
FaceCheck.IDSearch in social networkshttps://facecheck.idFreemium
Clearview AIPolice facial recognition(Requires authorization)Professional

Usage methodology:

  1. Capture high-quality image
  2. Use FaceCheck.ID for social networks
  3. PimEyes for broad web search
  4. Validate results by crossing platforms

15. Email/Phone Investigation

๐Ÿ“ง Email OSINT Tools

ToolFunctionURL
HoleheFind associated accounts to emailhttps://github.com/megadose/holehe
GHuntInvestigate Google accountshttps://github.com/mxrch/GHunt
EpieosEmail + phone reverse lookuphttps://epieos.com
h8mailSearch in data breacheshttps://github.com/khast3x/h8mail
EmailHippoEmail verificationhttps://tools.emailhippo.com
Hunter.ioFind corporate emailshttps://hunter.io

๐Ÿ“ฑ Phone OSINT Tools

ToolFunctionURL
PhoneinfogaInvestigation frameworkhttps://github.com/sundowndev/phoneinfoga
TruecallerCall identifierhttps://www.truecaller.com
InfobelInternational searchhttps://www.infobel.com
NumverifyValidation APIhttps://numverify.com

Automation script (Python):

# email_osint_checker.py
import holehe
import requests

def check_email_accounts(email):
    """Checks in 120+ platforms"""
    modules = holehe.import_submodules('holehe.modules')
    for module in modules:
        # Execute verification
        pass

16. Data Breaches

Alternatives and complements to HIBP:

PlatformDatabaseURLAccess
DeHashed17+ billion recordshttps://dehashed.comFreemium
SnusbaseRecent breacheshttps://snusbase.comPaid
LeakCheckReal-time searchhttps://leakcheck.ioFreemium
Intelligence XDark web + breacheshttps://intelx.ioFreemium
h8mailLocal breach searchGitHubFree
Hudson RockInfostealer intelligencehttps://www.hudsonrock.com/threat-intelligence-cybercrime-toolsFree
LeakRadar290B+ stealer logs & breacheshttps://leakradar.ioFreemium
CheckLeakedReal-time email/username/phone/password searchhttps://checkleaked.ccFreemium

Quick command:

# h8mail - mass search
h8mail -t targets.txt -bc local_breach_folder/ --power-all

17. Blockchain/Crypto

Specialized tools:

ToolBlockchainURLFunction
Chainalysis ReactorMulti-chainhttps://www.chainalysis.comForensic analysis professional
EllipticBitcoin, Ethereumhttps://www.elliptic.coMoney laundering detection
Arkham IntelligenceMulti-chainhttps://www.arkhamintelligence.comEntity mapping with AI
GlassnodeOn-chain analyticshttps://glassnode.comAdvanced metrics
EtherscanEthereumhttps://etherscan.ioMain explorer
Blockchain.infoBitcoinhttps://www.blockchain.com/explorerClassic explorer
BlockCypherMulti-chain APIhttps://www.blockcypher.comFree API
Wallet ExplorerBitcoinhttps://www.walletexplorer.comWallet analysis

Investigation methodology:

1. Identify wallet address
2. Search in Arkham Intelligence (known labels)
3. Analyze transactions in Etherscan/Blockchain.info
4. Trace fund flow with BlockCypher
5. Check in Chainalysis if available

18. Transport OSINT

๐Ÿš— Vehicle Investigation

ToolFunctionURL
OpenALPRLicense plate recognitionhttps://github.com/openalpr/openalpr
CarfaxVehicle history (US)https://www.carfax.com

โœˆ๏ธ Aviation - FlightRadar and ADS-B

ToolFunctionURL
FlightRadar24Live trackinghttps://www.flightradar24.com
ADS-B ExchangeNo military filtershttps://globe.adsbexchange.com
FlightAwareFlight historyhttps://flightaware.com
Phantom TideRestricted airspace, maritime, and incident maphttps://phantom.labs.jamessawyer.co.uk
PiAware (Raspberry Pi)Own ADS-B receiverhttps://flightaware.com/adsb/piaware

Setup of homemade ADS-B receiver:

# Configure PiAware on Raspberry Pi
sudo apt-get install piaware
sudo piaware-config <options>
sudo systemctl restart piaware

๐Ÿšข Maritime - AIS Tracking

ToolFunctionURL
MarineTrafficGlobal AIS trackinghttps://www.marinetraffic.com
VesselFinderFree alternativehttps://www.vesselfinder.com
ShipSpottingPhoto databasehttp://www.shipspotting.com

19. WiFi/Wardriving

ToolFunctionURL/Installation
WiGLEGlobal WiFi databasehttps://wigle.net
WiGLE WiFi Wardriving (Android)Mapping appGoogle Play
KismetWiFi/Bluetooth detectorhttps://www.kismetwireless.net
Aircrack-ngWiFi audit suitehttps://www.aircrack-ng.org

OSINT use case:

1. Search unique SSID in WiGLE
2. Find approximate router location
3. Correlate with other geolocation data
4. Identify movements/locations of target

20. Content Verification

Fact-checking tools:

ToolFunctionURLType
InVID & WeVerifyVideo verification pluginhttps://weverify.eu/verification-pluginExtension
FotoForensicsELA image analysishttps://fotoforensics.comWeb
ForensicallyVisual analysis suitehttps://29a.ch/photo-forensicsWeb
HyperVerge Deepfake DetectorAI detectionhttps://hyperverge.coAPI
Sensity AIDeepfakes detectionhttps://sensity.aiProfessional
Content Authenticity InitiativeOrigin verificationhttps://contentauthenticity.orgStandard

Verification process:

1. Extract metadata with ExifTool
2. Analyze with FotoForensics (ELA)
3. Check consistencies with Forensically
4. For video: use InVID for keyframes
5. Reverse image search in TinEye/Google

21. Username Enumeration

Beyond Maigret and Sherlock:

ToolPlatformsURLHighlight
Sherlock400+ platformshttps://github.com/sherlock-project/sherlockFaster
Maigret500+ platformshttps://github.com/soxoj/maigretMore precise
WhatsMyName600+ platformshttps://github.com/WebBreacher/WhatsMyNameMost complete
Snoop320+ (RU/CIS emphasis)https://github.com/snooppr/snoopRussian/CIS
Blackbird200+ with PDF reporthttps://github.com/p1ngul1n0/blackbirdExport
UserSearch600+ platformshttps://usersearch.orgLargest Reverse User Search Online

Speed comparison:

# Benchmark (10 usernames)
sherlock: ~45 seconds
maigret: ~90 seconds (more precise)
blackbird: ~60 seconds (with report)

22. Web Scraping

ToolFunctionURLLevel
PhotonUltra-fast crawlerhttps://github.com/s0md3v/PhotonIntermediate
ScrapyComplete frameworkhttps://scrapy.orgAdvanced
PlaywrightBrowser automationhttps://playwright.devAdvanced
SeleniumClassic automationhttps://www.selenium.devIntermediate
Beautiful SoupHTML/XML parserhttps://www.crummy.com/software/BeautifulSoupBasic

Basic Photon script:

python photon.py -u https://target.com \
  --export=json \
  --dns \
  --keys \
  --threads 10

23. Metadata Extraction

Complete suite:

ToolFile TypeURLPlatform
ExifToolImages, PDF, Officehttps://exiftool.orgCLI
FOCAOffice, PDF (GUI)https://github.com/ElevenPaths/FOCAWindows
MetagoofilPublic documentshttps://github.com/laramies/metagoofilCLI
MAT2Metadata cleanerhttps://0xacab.org/jvoisin/mat2CLI

Metadata workflow:

# 1. Extract metadata
exiftool -a -u -g1 document.pdf > metadata.txt

# 2. Search sensitive info
grep -i "author\|creator\|email\|gps" metadata.txt

# 3. Clean before publishing
mat2 --inplace clean_document.pdf

24. Network Scanning

Advanced tools:

ToolSpeedURLIdeal Use
NmapMediumhttps://nmap.orgComplete scan
MasscanVery fasthttps://github.com/robertdavidgraham/masscanInternet-scale
RustScanVery fasthttps://github.com/RustScan/RustScanModern port
NucleiTemplateshttps://github.com/projectdiscovery/nucleiVulnerabilities

Speed comparison:

# Scan 65k ports on 1 IP
nmap: ~5 minutes
rustscan: ~10 seconds โ†’ then nmap
masscan: ~5 seconds (less detail)

25. Dark Web

Specialized tools:

ToolFunctionURLRequirement
Ahmia.onion searcherhttps://ahmia.fiWeb browser
OnionScanService scannerhttps://github.com/s-rah/onionscanTor installed
Dark.failVerified directoryhttps://dark.failTor Browser
TorchOld searcher(only .onion)Tor Browser
DarkDumpOnion scraperhttps://github.com/josh0xA/darkdumpPython + Tor
DeepTrawlTor-routed IOC aggregator + BTC/XMR wallet extractionhttps://github.com/frangelbarrera/deepweb-leak-searchPython + Tor + PostgreSQL

Dark Web OPSEC:

1. Operating system: Tails OS (amnesic)
2. Never use VPN + Tor (traffic correlation)
3. Use bridges if Tor is blocked
4. NoScript to max
5. No window resizing
6. No downloading to persistent disk

26. All-in-One Frameworks

All-in-one platforms:

FrameworkLanguageURLStrength
Abster IntelligenceTypeScript / Next.jshttps://github.com/frangelbarrera/Abster-IntelligenceLocal-first, graph engine, BYOK-LLM, privacy-first
UbikronBrowser Exthttps://ubikron.comAI-powered case management & entity extraction
SpiderFootPythonhttps://github.com/smicallef/spiderfootTotal automation
Recon-ngPythonhttps://github.com/lanmaster53/recon-ngModular
theHarvesterPythonhttps://github.com/laramies/theHarvesterEmail/subdomain
MaltegoJavahttps://www.maltego.comVisualization
SentinelScopePythonhttps://github.com/frangelbarrera/sentinelscopeLightweight Recon-ng alternative, modular

SpiderFoot setup:

git clone https://github.com/smicallef/spiderfoot.git
cd spiderfoot
pip3 install -r requirements.txt
python3 sf.py -l 127.0.0.1:5001

27. Advanced Maltego

Essential plugins:

Transform HubFunctionNote
Standard Transforms150+ official transformsFree
Shodan TransformShodan integrationRequires API
VirusTotalMalware/URL analysisRequires API
Netlas TransformSimilar to Shodanhttps://netlas.io
Hunter.ioEmail searchRequires account
BuiltwithSite technologiesRequires API

Create custom transform:

# my_transform.py
from maltego_trx.entities import Person, EmailAddress
from maltego_trx.transform import DiscoverableTransform

class PersonToEmail(DiscoverableTransform):
    @classmethod
    def create_entities(cls, request, response):
        person_name = request.Value
        # Your logic here
        response.addEntity(EmailAddress, f"{person_name}@example.com")
        return response

28. Professional Methodologies

Bellingcat Methodology

1. Identification: What are we investigating?
2. Preservation: Archive EVERYTHING (archive.is, wayback)
3. Verification: Triangulate with 3+ sources
4. Contextualization: Complete chronology
5. Documentation: Screenshots + hash + timestamp
6. Validation: Peer review before publishing

Professional OSINT Cycle (5 Phases)

PHASE 1: DIRECTION
โ”œโ”€โ”€ Define questions (RFI)
โ”œโ”€โ”€ Establish legal limits
โ””โ”€โ”€ Approve scope

PHASE 2: COLLECTION
โ”œโ”€โ”€ Passive sources
โ”œโ”€โ”€ Semi-passive sources
โ””โ”€โ”€ Save evidence

PHASE 3: PROCESSING
โ”œโ”€โ”€ Normalize data
โ”œโ”€โ”€ Translate languages
โ””โ”€โ”€ Structure information

PHASE 4: ANALYSIS
โ”œโ”€โ”€ Link analysis (Maltego)
โ”œโ”€โ”€ Timeline creation
โ”œโ”€โ”€ Pattern recognition
โ””โ”€โ”€ Cross validation

PHASE 5: DISSEMINATION
โ”œโ”€โ”€ Executive report
โ”œโ”€โ”€ Technical report
โ”œโ”€โ”€ Visual presentation
โ””โ”€โ”€ Evidence archive

29. Advanced Google Dorks

2025 Dorks (specific):

# Sensitive information leaks
site:pastebin.com "password" "@company.com"
site:github.com "api_key" OR "api_secret" "company"
site:trello.com intext:"password" OR intext:"passwd"

# Exposed corporate documents
site:*.s3.amazonaws.com ext:xls | ext:xlsx "confidential"
filetype:pdf intext:"internal use only" site:gov

# IP cameras and IoT devices
inurl:/view/view.shtml
intitle:"webcamXP 5"

# Exposed admin panels
intitle:"index of" "admin"
intitle:"Dashboard" inurl:login
inurl:wp-admin intitle:"Dashboard"

# Exposed databases
intitle:"phpMyAdmin" "Welcome to phpMyAdmin"
inurl:"/phpmyadmin/index.php"
"#mysql dump" filetype:sql

# Employee information
site:linkedin.com "company name" "CEO" | "CTO" | "CISO"
site:*.linkedin.com "@companymail.com"

# Subdomains (combine with crt.sh)
site:*.target.com -www
site:*.*.target.com

30. Learning Resources

๐Ÿ“บ YouTube Channels (Spanish):

  • Ethical Hacking - Pablo Gonzรกlez
  • CyberSecurityJobs
  • DragonJAR
  • Josรฉ Luis Garcรญa
  • Security Hacklabs

๐Ÿ“š Recommended Books:

  1. "Open Source Intelligence Techniques" - Michael Bazzell (8th ed., 2024)
  2. "OSINT for Threat Intelligence" - Scott J Roberts
  3. "The OSINT Handbook" - i-intelligence

๐ŸŽ“ Certifications:

  • GOSI (GIAC Open Source Intelligence) - SANS
  • CSCTP (Certified Social Media Intelligence Expert) - McAfee Institute
  • OSINT Professional Certification - OSINT Combine

๐Ÿ”— Communities:

  • Reddit: r/OSINT, r/OpenSourceIntelligence
  • Discord: IntelTechniques Server, OSINT-FR
  • Telegram: OSINT Latam, OSINT Dojo
  • Twitter/X: #OSINT, #OSINTfor Good

31. People Investigations

Tools for investigating individuals:

ToolFunctionURL
PiplPeople search enginehttps://pipl.com
SpokeoBackground checkshttps://www.spokeo.com
BeenVerifiedPublic records searchhttps://www.beenverified.com
InteliusPeople finderhttps://www.intelius.com
WhitepagesPhone and address lookuphttps://www.whitepages.com
ZabaSearchFree people searchhttps://www.zabasearch.com
PeopleFinderComprehensive searchhttps://www.peoplefinder.com
Instant CheckmateBackground reportshttps://www.instantcheckmate.com
TruthFinderPublic recordshttps://www.truthfinder.com
US SearchPeople searchhttps://www.ussearch.com

32. Company Research

Tools for investigating companies:

ToolFunctionURL
CrunchbaseCompany databasehttps://crunchbase.com
WellFound (formerly AngelList)Startup databasehttps://wellfound.com
PitchBookPrivate company datahttps://pitchbook.com
ZoomInfoBusiness contactshttps://www.zoominfo.com
D&B HooversCompany profileshttps://app.dnbhoovers.com
Dun & BradstreetBusiness credit reportshttps://www.dnb.com
EDGARSEC filingshttps://www.sec.gov/edgar
OpenCorporatesGlobal company registryhttps://opencorporates.com
Company HouseUK company registryhttps://find-and-update.company-information.service.gov.uk
BloombergFinancial datahttps://www.bloomberg.com

33. Threat Intelligence Feeds

Consolidated IoC feeds for threat intelligence :

33.1 Malware & C2 Feeds

FeedTypeURL
MalwareBazaarMalware sampleshttps://bazaar.abuse.ch
ThreatFoxIoC aggregatorhttps://threatfox.abuse.ch
Feodo TrackerC2 IPshttps://feodotracker.abuse.ch
SSL BlacklistMalicious SSL certshttps://sslbl.abuse.ch
URLhausMalware URLshttps://urlhaus.abuse.ch
MalShareMalware repositoryhttp://www.malshare.com
VirusShareSample sharinghttps://virusshare.com
Malware Domain ListMalicious domainshttps://www.malwarepatrol.net
AlienVault OTXCommunity threat intelhttps://otx.alienvault.com
IBM X-ForceThreat exchangehttps://exchange.xforce.ibmcloud.com
Recorded FutureCommercial feed (free blog)https://www.recordedfuture.com
Microsoft Threat IntelligenceMS-curatedhttps://www.microsoft.com/en-us/wdsi
CISA Known Exploited VulnerabilitiesKEV cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
VulnrichmentCISA enriched CVEshttps://github.com/cisagov/vulnrichment

33.2 Phishing & Fraud Feeds

FeedTypeURL
PhishTankPhishing URLshttps://www.phishtank.com
OpenPhishPhishing URLshttps://openphish.com
FraudGuardFraud intelligencehttps://fraudguard.io
HaveIBeenPwnedBreach notificationhttps://haveibeenpwned.com
DeHashedBreach searchhttps://dehashed.com
IntelligenceXDark web + leakshttps://intelx.io
LeakCheckReal-time breachhttps://leakcheck.io
SnusbaseRecent breacheshttps://snusbase.com
Hudson RockInfostealer intelhttps://www.hudsonrock.com

33.3 IP & Domain Reputation

FeedTypeURL
SpamhausIP/domain reputationhttps://www.spamhaus.org
FireHOLIP blocklistshttp://iplists.firehol.org
AbuseIPDBIP abuse reportshttps://www.abuseipdb.com
GreyNoiseInternet scanner noisehttps://www.greynoise.io
CINS ScoreBotnet IPshttp://cinsscore.com/#list
Binary DefenseBanlisthttps://www.binarydefense.com/banlist.txt
IPsumCurated IPshttps://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt

33.4 CTI Platforms (ingest & correlate)

PlatformTypeURL
MISPOpen-source CTI platformhttps://www.misp-project.org
OpenCTICTI platformhttps://www.opencti.io
YetiIoC platformhttps://yeti-platform.github.io
aegistrace-threat-intelligencePython CTI pipeline (author's)https://github.com/frangelbarrera/aegistrace-threat-intelligence
ThreatMinerThreat intel searchhttps://www.threatminer.org
PulseDiveIoC enrichmenthttps://pulsedive.com
AlienVault OTXThreat exchangehttps://otx.alienvault.com

34. ICS/OT & Critical-Infrastructure OSINT

OSINT for industrial control systems, SCADA, and critical infrastructure:

34.1 Methodology & Frameworks

ResourceTypeURL
ICS-Cybersecurity-Audit (author's)5-phase audit methodology, IEC 62443 / NIST 800-82https://github.com/frangelbarrera/ICS-Cybersecurity-Audit
MITRE ATT&CK for ICSTactics & techniques matrixhttps://attack.mitre.org/matrices/ics
CISA ICS AdvisoriesVulnerability advisorieshttps://www.cisa.gov/news-events/cybersecurity-advisories
ICS-CERTUS-CERT industrial alertshttps://us-cert.cisa.gov/ics

34.2 Scanners & Tools

ToolFunctionURL
IndustrialScanner-Lite (author's)Modbus/S7Comm/DNP3 PCAP analyzerhttps://github.com/frangelbarrera/IndustrialScanner-Lite
Shodan ICS filtersICS device searchhttps://www.shodan.io/search?query=port%3A502
Censys ICSICS device searchhttps://search.censys.io/search?resource=hosts&q=tags%3A%22ics%22
ClarotyOT security (vendor)https://claroty.com
Nozomi NetworksOT security (vendor)https://www.nozominetworks.com

34.3 Notable ICS Incidents (Case Studies)

YearIncidentTargetLesson
2010StuxnetNatanz uranium enrichment (IR)First digital weapon, S7 PLC reprogramming
2015BlackEnergyUkraine power gridFirst confirmed cyber-physical blackout
2016Industroyer/CrashOverrideUkraine power gridAutomated ICS protocol abuse
2017TRITON/TRISISSaudi Petrochemical (SIS)First attack on Safety Instrumented Systems
2021Colonial PipelineUS fuel pipeline (IT-side)Ransomware OT impact without direct compromise
2022Industroyer2Ukraine energy sectorModular ICS malware evolution

Full case studies: https://github.com/frangelbarrera/ICS-Cybersecurity-Audit/tree/main/docs/case-studies

34.4 Protocol-specific Dorks (Shodan)

port:502 country:DE        # Modbus
port:102 country:ES        # S7Comm
port:20000                 # DNP3
port:47808                 # BACnet
port:4840                  # OPC UA
"Schneider Electric"       # Quantum PLCs
"Siemens" port:102         # S7 devices

35. AI Agent Skills & MCP

Run OSINT workflows inside Claude Code, Cursor, Ollama, or any MCP-compatible client:

35.1 MCP Servers & Skill Packs

ResourceTypeURL
osint-agent-skills (author's)22 MCP tools + 295-line system prompt + 9 pivot playbookshttps://github.com/frangelbarrera/osint-agent-skills
PulseMCPMCP server directoryhttps://www.pulsemcp.com
MCP Server Finder (Glama)Directoryhttps://glama.ai/mcp/servers
awesome-mcp-serversCurated listhttps://github.com/punkpeye/awesome-mcp-servers

35.2 MCP Servers for Specific OSINT Tools

MCP ServerWrapsURL
Brave Search MCPBrave Searchhttps://github.com/brave/brave-search-mcp-server
Fetch MCPWeb fetcherhttps://github.com/modelcontextprotocol/servers/blob/main/src/fetch
SQLite MCPLocal DBhttps://github.com/modelcontextprotocol/servers-archived/tree/main/src/sqlite

35.3 Agent Frameworks for OSINT Orchestration

FrameworkLanguageURLHighlight
AutoGPTPythonhttps://github.com/Significant-Gravitas/AutoGPTAutonomous goal-driven agents
CrewAIPythonhttps://github.com/crewAIInc/crewAIRole-based multi-agent
LangGraphPythonhttps://github.com/langchain-ai/langgraphStateful agent graphs
n8nTypeScripthttps://n8n.ioVisual workflow + AI nodes
DifyPythonhttps://dify.aiOpen-source LLM app platform
secure-agent-orchestrator (author's)Pythonhttps://github.com/frangelbarrera/secure-agent-orchestratorLightweight SOAR for distributed security agents

35.4 Local & Sovereign LLMs (OPSEC for sensitive investigations)

ToolTypeURL
OllamaLocal LLM runnerhttps://ollama.com
LM StudioDesktop GUIhttps://lmstudio.ai
vLLMProduction serverhttps://github.com/vllm-project/vllm
JanOffline assistanthttps://jan.ai

35.5 Quick Start (Claude Code)

# 1. Clone the skills repo
git clone https://github.com/frangelbarrera/osint-agent-skills.git
cd osint-agent-skills

# 2. Add to .claude/settings.json
{
  "mcpServers": {
    "osint": {
      "command": "node",
      "args": ["./tools/mcp-server.js"],
      "env": {
        "SHODAN_KEY": "your-key",
        "VT_API_KEY": "your-key",
        "GITHUB_TOKEN": "your-token"
      }
    }
  }
}

# 3. Launch Claude Code โ€” tools will be auto-discovered

36. Financial OSINT

36.1 UBO Tracing Workflow (Ultimate Beneficial Owner) โ€” 12 Steps

StepActionTool / Source
1Identify initial entity: legal name, jurisdiction, registration numberOpenCorporates ยท Companies House UK
2Obtain incorporation documentNational public registry ยท OCCRP Aleph
3Identify active AND historical directorsOpenCorporates ยท SEC EDGAR
4Identify declared shareholdersOpenOwnership Register ยท GLEIF
5Detect nominees and trustsICIJ Offshore Leaks
6Verify physical-person identitiesLittleSis ยท national civil registries
7Walk the chain to next level (iterate to person or 5 levels max)Maltego ยท Obsidian
8Cross-check against sanctions (incl. OFAC 50 Percent Rule)OpenSanctions ยท OFAC SDN
9Verify UBO tax-residency transparencyFATF High-Risk Jurisdictions
10Search adverse media and litigationOpenSanctions PEPs ยท CourtListener
11Validate with blockchain/crypto if applicableArkham Intelligence ยท Etherscan
12Document final ownership chain (nodes, edges, %, dates, hashes)Maltego + Obsidian + SHA-256 per document

36.2 Verified Financial OSINT Tools

ToolURLFunction
OpenCorporateshttps://opencorporates.comGlobal corporate registry (140M+ entities)
OpenOwnership Registerhttps://register.openownership.orgPublic UBO registers
OpenSanctionshttps://www.opensanctions.orgAggregated sanctions + PEPs
OCCRP Alephhttps://aleph.occrp.orgCross-border asset investigation
ICIJ Offshore Leakshttps://offshoreleaks.icij.orgPandora / Panama / Paradise Papers
LittleSishttps://littlesis.orgUS peopleโ€“power connections
FollowTheMoneyhttps://followthemoney.techOpenSanctions data model
FinCENhttps://www.fincen.govUS financial records portal
SEC EDGARhttps://www.sec.gov/edgarUS corporate filings
GLEIFhttps://www.gleif.orgLegal Entity Identifier registry
OFAC SDN Listhttps://ofac.treasury.govUS Treasury sanctions
EU Sanctions Maphttps://www.sanctionsmap.euInteractive EU sanctions map
CourtListenerhttps://www.courtlistener.comUS federal court records
OpenSecretshttps://www.opensecrets.orgUS money-in-politics
Sayarihttps://sayari.comCommercial corporate-network intel
Equasishttps://www.equasis.orgGlobal merchant vessel registry
Arkham Intelligencehttps://www.arkhamintelligence.comOn-chain wallet attribution
Dune Analyticshttps://dune.comSQL across 100+ blockchains (free tier)
Nansenhttps://nansen.aiSmart-money signals ($49/mo)
Arbiscanhttps://arbiscan.ioArbitrum L2 explorer
Basescanhttps://basescan.orgBase L2 explorer
Optimistic Etherscanhttps://optimistic.etherscan.ioOptimism L2 explorer

36.3 Common Errors in Financial OSINT

  1. Confusing director with UBO. A director signs minutes; a UBO economically controls. In offshore shells the director is usually a professional nominee with 200+ companies.
  2. Not handling transliterations. Mohammed / Muhammad / Mohamad / Mehmet โ€” exact match fails. Use ISO 9 (Russian) or Hanyu Pinyin (Chinese).
  3. Trusting PSC Register as ground truth. The UK PSC Register is self-reported; real UBOs hide behind nominees. Always cross-check with ICIJ.
  4. Treating sanctions lists as binary. "Not listed" โ‰  "clean". Designation takes monthsโ€“years. Use adverse media + peer designations.
  5. Mixing accusation with conviction. A DOJ forfeiture complaint is a civil allegation, not a conviction. Cite as "the DOJ alleges in its 2016 complaint...".
  6. Forgetting OFAC 50 Percent Rule. An unlisted entity owned 50%+ in aggregate by sanctioned persons is legally blocked.
  7. Treating blockchain analytics as absolute truth. Wallet attributions (Arkham, Chainalysis) are heuristics. Always document source and confidence level.
  8. No chain-of-custody. A screenshot without URL, date, and hash is not admissible. For formal DD: archive.org snapshot + timestamped screenshot + SHA-256.

36.4 Case Study โ€” 1MDB ($4.5B Misappropriated)

1Malaysia Development Berhad (1MDB) was a Malaysian sovereign wealth fund established in 2009. Between 2009 and 2015, approximately USD 4.5 billion was misappropriated according to the US Department of Justice. The DOJ filed civil forfeiture complaints in 2016, 2017 and 2019 seeking to recover more than USD 1.7 billion in assets.

Public money flow reconstructed from open sources:

  1. Origin: Bonds issued by 1MDB (2009-2013) under joint management with Goldman Sachs.
  2. First shell layer: Transfers to Good Star Limited (Seychelles), controlled by Jho Low (Low Taek Jho).
  3. Intermediate layer: Good Star โ†’ Wynton Trading (BVI) โ†’ Black Rock Asia (HK) โ†’ accounts linked to Malaysian PM Najib Razak. Part reached Najib's personal AmBank account (USD 681M in 2013, the "Saudi donation").
  4. Final destination: Real estate in NY / Beverly Hills (USD 100M+), the yacht Equanimus (USD 250M), rights to The Wolf of Wall Street, art works.

Verified public sources:


37. Investigator OPSEC & Sock Puppets

37.1 Browser Fingerprinting โ€” Audit & Mitigation

ToolURLFunction
Cover Your Tracks (EFF)https://coveryourtracks.eff.orgBrowser fingerprinting test
CreepJShttps://github.com/AbrahamJuliot/creepjsAdvanced Trust Score analysis
Mullvad Browserhttps://mullvad.net/en/browserAnti-fingerprinting browser (Tor Project + Mullvad VPN)
LibreWolfhttps://librewolf.netHardened Firefox for privacy
Whonixhttps://www.whonix.orgTwo-VM Tor workstation

37.2 Pre-Investigation OPSEC Workflow โ€” 10 Steps

  1. Audit your current fingerprint with Cover Your Tracks + CreepJS. Document the baseline.
  2. Decide OPSEC level: Low (normal browser + VPN), Medium (Mullvad Browser + VPN), High (Whonix gateway + Workstation VM).
  3. Create an isolated research identity: dedicated email, no reuse of personal identity elements.
  4. For sensitive investigations: use Tails OS on a bootable USB, no persistence.
  5. Rotate identity periodically (every 30โ€“90 days for long-running investigations).
  6. Never mix identities: each sock puppet lives in its own browser profile / VM.
  7. Network hygiene: trusted VPN + DNS over HTTPS. Do not use ISP DNS.
  8. Metadata strip: MAT2 or ExifTool before uploading any file.
  9. Communications: Signal or Session for source contact. Not personal WhatsApp.
  10. Document OPSEC decisions in the final report: what level was used, why, what was done if something failed.

37.3 Sock Puppet Methodology (Updated 2026)

Rule 1: Never use real personal identity. Create a consistent fictitious identity (age, interests, plausible location).

Rule 2: The sock puppet needs a "digital history" โ€” it cannot be born the day of the investigation. Buy accounts with 1โ€“2 years of age or cultivate identities in standby.

Rule 3: Human behaviour. Do not do 200 searches in an hour. Respect plausible hours. Interact with irrelevant content to mix signal.

Rule 4: Consistent device fingerprint. If the sock puppet "lives" in Madrid, the browser must have timezone Europe/Madrid, locale es-ES, no obvious extensions.

Rule 5: Do not cross the line. Sock puppets for verifying public accounts = legitimate. Sock puppets to deceive, manipulate or extract information from people = ethically problematic and legally risky in many jurisdictions.

37.4 VPN & Anti-Correlation

ResourceURLFunction
Mullvad VPNhttps://mullvad.netNo-log VPN, anonymous cash payment
IVPNhttps://www.ivpn.netAudited no-log VPN
ProtonVPNhttps://protonvpn.comSwiss VPN, freemium
Tor Projecthttps://www.torproject.orgNetwork anonymity
Snowflakehttps://snowflake.torproject.orgWebRTC pluggable transport
obfs4 bridgeshttps://bridges.torproject.orgAnti-censorship Tor bridges

38. Cloud Storage OSINT

38.1 Verified Tools

ToolURLFunction
GrayhatWarfarehttps://buckets.grayhatwarfare.com712K+ indexed buckets (2K free, premium paid)
osint.sh/bucketshttps://osint.sh/bucketsKeyword search across AWS+Azure buckets
cloud_enumhttps://github.com/initstring/cloud_enumMulti-cloud enumeration (AWS / Azure / GCP)
GrayhatWarfare Shortenershttps://grayhatwarfare.comURL shortener enumeration

38.2 Cloud Storage OSINT Workflow โ€” 8 Steps

  1. Identify candidate bucket names based on target domain (e.g. acmecorp-backups, acme-assets, acme-public).
  2. Search GrayhatWarfare by target keyword.
  3. Validate with cloud_enum (permutation brute-force of plausible names).
  4. If an open bucket is found, enumerate objects with aws s3 ls --no-sign-request s3://bucket-name/ --recursive.
  5. Document timestamp + hash before downloading evidence.
  6. For Azure: use Azure Storage Explorer or az storage blob list --account-name X --container-name Y --auth-mode login.
  7. For GCP: gsutil ls gs://bucket-name/ (without auth shows public objects).
  8. Responsible disclosure if sensitive data is found exposed.

38.3 Cloud Storage Google Dorks

site:s3.amazonaws.com "target"
site:blob.core.windows.net "target"
site:storage.googleapis.com "target"
site:amazonaws.com filetype:pdf "confidential"
  • Accessing a public bucket is legitimate. If the bucket is open, it is the owner's responsibility.
  • Downloading sensitive data (PII, credentials) and publishing it = illegal in most jurisdictions.
  • Report to the owner via responsible disclosure (security.txt of the domain).
  • Do not use found credentials to escalate access. That crosses from OSINT into attack.

39. Mobile App OSINT

39.1 Verified Tools

ToolURLFunction
MobSFhttps://github.com/MobSF/Mobile-Security-Framework-MobSFAutomated static/dynamic analysis framework
jadxhttps://github.com/skylot/jadxJava decompiler for APKs
apktoolhttps://ibotpeaches.github.io/Apktool/APK resource decoder
dex2jarhttps://github.com/pxb1988/dex2jar.dex โ†’ .jar converter
APKPurehttps://apkpure.comAlternative APK source to Google Play
APKMirrorhttps://www.apkmirror.comHistorical APK archive

39.2 Mobile App OSINT Workflow โ€” 6 Steps

  1. Download APK from APKPure, APKMirror or Google Play (with apkeep or gplaycli).
  2. Load into MobSF for an automatic report: permissions, components, hardcoded secrets, URLs in code.
  3. Decompile with jadx for manual inspection: search for api_key|secret|token|password|AWS_|STRIPE_ with grep.
  4. Audit AndroidManifest.xml for excessive permissions (location + contacts + SMS in an app that doesn't need them).
  5. Identify third-party SDKs (analytics, ads, trackers): Facebook SDK, Google Analytics, Firebase, AppsFlyer, Adjust.
  6. Document findings with code captures + file names + line numbers.

39.3 Use Cases

  • Government / banking apps: audit permissions and SDKs to see what data they collect.
  • Competitor apps: identify internal APIs (hardcoded URLs) for competitive intelligence.
  • Dating / social apps: find undocumented endpoints (useful for safety investigations).
  • Tracking apps: verify what data from minors educational apps collect.

39.4 Ethical Considerations

  • Static analysis is legitimate. The APK is distributable and public.
  • Dynamic analysis on your own device is legitimate.
  • Publicly sharing decompiled code may violate copyright and Terms of Service.
  • Do not use discovered internal APIs for mass scraping or abuse.

40. Decentralized Social OSINT

40.1 Verified Tools

ToolURLFunction
Bluesky Firehose (official)https://docs.bsky.app/docs/advanced-guides/firehoseAuthenticated stream of ALL events
AT Protocol SDKhttps://atproto.blue/en/latest/atproto_firehose/index.htmlPython SDK for the firehose
Reaper Socialhttps://reaper.socialMastodon / Fediverse search & investigation
DigitalStakeout Bluesky monitoringhttps://www.digitalstakeout.com/blog/bluesky-firehose-integrationCommercial monitoring
Nostrhttps://nostr.orgProtocol + NIP-05 identity verification

40.2 Minimum Methodology

  1. Bluesky real-time: subscribe to the firehose with a keyword/user filter. For historical data, Bluesky has no native search API โ€” use third-party (Reaper Social).
  2. Mastodon: each instance has its own API. Federated search is limited. List instances relevant to the target (e.g. infosec.exchange, mas.to).
  3. Nostr: NIP-05 verification exposes domain-linked identity. Allows pivoting from handle to verified domain.
  4. Farcaster: Warpcast is the main client. Public API for feeds.

40.3 Use Cases

  • Extremism monitoring: migration of accounts banned from X to Mastodon / Nostr.
  • Geopolitical investigations: Russian / Chinese actors moving to decentralized platforms after blocks on Western ones.
  • Crypto communities: many Web3 projects use Farcaster and Nostr natively.

41. Counter-OSINT Self-Audit

41.1 Verified Tools

ToolURLFunction
Have I Been Pwnedhttps://haveibeenpwned.comFree personal breach check (1018+ sites)
DeHashedhttps://dehashed.comDeep-web scans (freemium)
Intelligence Xhttps://intelx.ioDark web + breaches
JustDeleteMehttps://justdeleteme.xyzDirect deletion links for 500+ services
JustGetMyDatahttps://justgetmydata.comGDPR data request links
Hudson Rockhttps://www.hudsonrock.com/threat-intelligence-cybercrime-toolsInfostealer free lookup

41.2 Self-Doxxing Audit Workflow โ€” 6 Steps

  1. Initial self-audit: search your email, username, real name in HIBP + DeHashed + IntelX + Google ("your name" filetype:pdf).
  2. Identify forgotten accounts via JustDeleteMe โ€” list of services where you ever registered.
  3. Request personal data download via JustGetMyData (GDPR gives right to data export in 30 days).
  4. Delete unnecessary accounts with priority: old social networks, abandoned forums, duplicate services.
  5. Rotate compromised passwords with a password manager (Bitwarden, 1Password, KeePassXC).
  6. Document your own footprint BEFORE starting a sensitive investigation โ€” knowing your exposure prevents surprises.

41.3 Per-Service Privacy

  • Google Account: Activity Controls (disable Web & App Activity, Location History, YouTube History).
  • Facebook: review privacy settings, download data, disable facial recognition.
  • LinkedIn: review profile visibility, hide connections if you investigate sectors where your network may be a signal.
  • Telegram: use a virtual number, not your main one. Enable 2FA.
  • WhatsApp: review profile photo visibility, last connection, status. For investigations: secondary account with virtual number.

42. Discord & Telegram OSINT 2026

42.1 Verified Tools

ToolURLFunction
Telepathy v2.3.4https://github.com/prose-intelligence-ltd/Telepathy-CommunityTelegram OSINT toolkit (Jordan Wildon)
Telegago (Google CSE)https://cse.google.com/cse?cx=006368593537057042503:efxu7xprihgGoogle CSE for Telegram (do NOT use telegago.com โ€” hijacked)
TelegramDBhttps://telegramdb.orgTelegram channel search engine
TGStathttps://tgstat.comTelegram statistics
DiscordLeaks (Unicorn Riot)https://discordleaks.unicornriot.ninja/Discord server leaks

42.2 Telegram OSINT Workflow

  1. Get API credentials at https://my.telegram.org (real, valid phone number required).
  2. Install Telepathy: pip install telepathy.
  3. Basic commands: telepathy -c channel_name (channel info), telepathy -u username (user info), telepathy -g group_id --members (memberlist).
  4. Mass archiving: telepathy -c channel --export json.
  5. Location lookup: Telegram users may expose approximate location via the "People Nearby" feature.

42.3 Discord OSINT Workflow

  1. Server discovery via https://disboard.org and https://discordservers.com (third-party search engines).
  2. Discord API v10 with correct intents: GUILD_MESSAGES to read messages, GUILD_MEMBERS for memberlist (requires verification if bot is in >100 servers).
  3. Audit log analysis if you have admin in the server: discord.com/api/v10/guilds/{guild.id}/audit-logs.
  4. User ID lookup: https://discord.id (decodes snowflake to creation timestamp).
  5. OPSEC: NEVER join a target server with your personal account. Create a sock puppet with a dedicated email.

42.4 Verified Learning Resources


43. Satellite OSINT 2026

Critical context (2026): The Economist (15 March 2026) documented "Open-source intelligence shuts down" โ€” Planet Labs enacted an indefinite blackout over the Middle East following the Gaza war; Maxar, Planet and BlackSky restricted commercial imagery. In parallel, democratization via SkyFi ($15 per image) and Copernicus Browser (ESA, free) continues. This is the defining tension of GEOINT in 2026.

43.1 Verified Tools

ToolURLFunction
Copernicus Browserhttps://browser.dataspace.copernicus.euSentinel-1/2/3/5P free, full resolution
SkyFihttps://skyfi.comMulti-provider marketplace ($15/image)
Sentinel Hubhttps://www.sentinel-hub.comCommercial over Sentinel data
NASA Worldviewhttps://worldview.earthdata.nasa.govNear-real-time satellite
USGS Earth Explorerhttps://earthexplorer.usgs.govUSGS catalogue (Landsat, MODIS)
Planet Labshttps://www.planet.comDaily commercial satellite (may be restricted)
Maxarhttps://www.maxar.comHigh resolution (may be restricted post-Gaza)
Umbra Spacehttps://www.umbra.spaceHigh-resolution SAR

43.2 Satellite OSINT Workflow โ€” 7 Steps

  1. Start with Copernicus Browser (free, historical archive from 2015+, Sentinel-2 at 10 m resolution).
  2. If you need near-real-time: NASA Worldview (latency <3 hours for MODIS).
  3. For new tasking or sub-meter resolution: SkyFi ($15+ per selective image, multi-provider).
  4. Before publishing: verify the provider's EULA (Planet/Maxar may revoke publication rights).
  5. Document source + timestamp + cloud cover % for every image used.
  6. For chronolocation: combine with historical imagery from Google Earth Pro (free).
  7. For SAR (cloud-penetrating): Copernicus Sentinel-1 or Umbra (commercial).

43.3 Verified Learning Resources


44. C2PA + SynthID + Deepfake Detection 2026

Industrial milestone (Mayโ€“August 2026): OpenAI joined the C2PA steering committee and adopted Google DeepMind's SynthID. Google announced native C2PA + SynthID verification in Search and Chrome (Google I/O 2026). Reality Defender was named "Market Shaper" by Gartner. This is the industry's scalable response to the deepfake arms race.

44.1 Verified Standards & Tools

ToolURLFunction
C2PA viewerhttps://c2paviewer.comVisual verifier of C2PA manifests
Content Credentialshttps://contentcredentials.orgOfficial C2PA standard
SynthID (Google DeepMind)https://deepmind.google/technologies/synthid/AI content watermarking
Reality Defenderhttps://www.realitydefender.comDeepfake detection (free API 50/mo)
Truepichttps://truepic.comContent credentials platform
Sensity AIhttps://sensity.aiDeepfake detection

44.2 Layered Verification Methodology

  1. Verify C2PA Content Credentials with c2paviewer.com before any analysis.
  2. Detect SynthID watermark if present (Google SynthID detector).
  3. If no credentials, run Reality Defender / Sensity for forensic analysis.
  4. Document absence of credentials as an indicator (not proof) of manipulation.
  5. Cross-check with reverse image search (Google Lens, Yandex, TinEye).
  6. For video: extract keyframes with FFmpeg and analyse each one.

45. Professional Templates & Deliverables

45.1 Intelligence Information Report (IIR) โ€” NATO/OSINT Adapted Format

The IIR is the atomic deliverable: one question, one source, one time, one evaluation. It is not a dossier (that is the Target Package). The IIR feeds a dossier.

====================================================================
INTELLIGENCE INFORMATION REPORT (IIR)
====================================================================

--- HEADER ---
REPORT NUMBER:        [ORG]-IIR-[YYYY]-[NNNN]
CLASSIFICATION:       UNCLASSIFIED // FOR OFFICIAL USE ONLY
SUBJECT COUNTRY:      [Country ISO 3166-1 alpha-3]
PREPARED BY:          [Analyst name or team]
REPORT DATE:          [ISO 8601: YYYY-MM-DDThh:mmZ]
PERIOD OF REPORT:     [Start date โ†’ End date]
REQUESTING OFFICE:    [Team/Department that requested the analysis]

--- SOURCE EVALUATION (NATO A-F / 1-6 system) ---
SOURCE RELIABILITY:   [A/B/C/D/E/F]
  A=Confirmed ยท B=Usually reliable ยท C=Fairly reliable
  D=Not usually reliable ยท E=Unreliable ยท F=Cannot be judged
INFO CREDIBILITY:     [1/2/3/4/5/6]
  1=Confirmed by others ยท 2=Probably true
  3=Possibly true ยท 4=Doubtfully true ยท 5=Improbable
  6=Cannot be judged
SOURCE DESCRIPTION:   [One line, do not expose sensitive source]
SOURCE ACCESS:        [Public / Aggregated / Paid / Provided by third party]

--- CONFIDENCE LEVEL (ICD 203) ---
CONFIDENCE:           [HIGH / MODERATE / LOW]
JUSTIFICATION:        [2-3 lines. High = corroborated by โ‰ฅ2 independent sources
                       with solid causal logic. Moderate = 1 reliable or 2 moderate.
                       Low = single or weak source]
KEY ASSUMPTIONS:      [List of assumptions that, if broken, lower confidence]

--- BODY ---
BLUF (Bottom Line Up Front):
   [1-3 sentences. The reader must understand the critical finding from this alone.]

KEY FINDINGS (numbered, max 5):
   1. [Critical finding #1]
   2. [Critical finding #2]
   3. [Critical finding #3]

EVIDENCE (each finding with support):
   - Finding #1:
       * Sources: [URL + capture date]
       * Capture: [SHA-256 of original document / screenshot]
       * Archive: [archive.org snapshot URL if applicable]

ANALYSIS (interpretation, not evidence):
   [What it means, what it implies, what it does not imply. Apply SATs from Appendix B]

KNOWLEDGE GAPS (what you DO NOT know):
   - [Gap 1]
   - [Gap 2]

RECOMMENDATIONS (prioritized next steps):
   1. [Action โ€” who, what, when]
   2. [Action]
   3. [Action]

--- ANNEXES ---
A. Sources list (URLs, dates, hashes)
B. Charts/maps/graphs (ownership diagram, timeline, geo)
C. Raw data (PDFs, screenshots, exports)
D. Methodology note (which SATs were applied)
E. Chain of Custody log (see 45.5)

--- DISTRIBUTION ---
TO:    [Nominal list]
CC:    [Nominal list]
NOFORN: [Y/N]

--- REVISION HISTORY ---
| Rev | Date       | Author              | Changes                       |
|-----|------------|---------------------|-------------------------------|
| 0.1 | 2026-07-19 | A. Senior           | Initial draft                 |
| 1.0 | 2026-07-20 | A. Senior+Reviewer  | Peer review, approval         |
====================================================================

45.2 Target Package (Person) Template โ€” 20 Fields

#FieldTypical Source
1Full canonical name + aliasesLinkedIn, civil registry
2Date and place of birthAdverse media, public records
3Nationality(ies)Public visas, public records
4Official identifiers (RFC/CURP/CPF/CUIT/DNI)Public registry
5Reference photo(s) (min. 1 frontal)LinkedIn, press
6Chronological professional bioLinkedIn, OCCRP Aleph
7Current positionsLinkedIn, corporate registry
8Relevant historical positions (10 years)OpenCorporates, EDGAR
9Key personal relationshipsLittleSis, adverse media
10Corporate relationships (UBO/director)OpenOwnership, OpenCorporates
11PEP status + since when + levelOpenSanctions PEP
12Sanctions status + designation dateOpenSanctions aggregator
13Adverse media (3-5 incidents)Google News, OCCRP, ICIJ
14Litigation (civil/criminal/admin)PACER, local judicial registry
15Digital footprint (email/phone/domains)Maigret, HIBP, WhoisXML
16Real estate footprintProperty registry
17Declared net worth (if PEP)Asset declaration
18Travel and residences (5 years)Press, Instagram geotags
19Identified associated risksOutput of analysis
20Analytic confidence + gap listโ€”

45.3 Executive Briefing Template (1 Page)

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ EXECUTIVE BRIEFING โ€” [Topic]                                      โ”‚
โ”‚ Classification: CONFIDENTIAL // C-Suite only    Date: YYYY-MM-DD โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚                                                                   โ”‚
โ”‚ BLUF (Bottom Line Up Front):                                      โ”‚
โ”‚ [2-3 sentences, no jargon]                                        โ”‚
โ”‚                                                                   โ”‚
โ”‚ Confidence: HIGH โ–“โ–“โ–“ / MODERATE โ–“โ–“โ–‘ / LOW โ–“โ–‘โ–‘                     โ”‚
โ”‚                                                                   โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ 1. CONTEXT (what was investigated and why)          [3-4 lines]  โ”‚
โ”‚                                                                   โ”‚
โ”‚ 2. KEY FINDING                                      [4-6 lines]  โ”‚
โ”‚    - Central fact                                                 โ”‚
โ”‚    - Source(s)                                                    โ”‚
โ”‚    - Implication for the organization                             โ”‚
โ”‚                                                                   โ”‚
โ”‚ 3. RISK AND IMPACT (financial/reputational/operational/legal)    โ”‚
โ”‚    [2x2 table or list; A/B/C marks by severity/probability]     โ”‚
โ”‚                                                                   โ”‚
โ”‚ 4. RECOMMENDATIONS (3, prioritized)                              โ”‚
โ”‚    1. [Immediate action โ€” 24-72h]                                โ”‚
โ”‚    2. [30-day action]                                             โ”‚
โ”‚    3. [90-day action]                                             โ”‚
โ”‚                                                                   โ”‚
โ”‚ 5. NEXT STEPS / KNOWLEDGE GAPS                                    โ”‚
โ”‚    - What is missing and how to close it (cost/effort estimate)   โ”‚
โ”‚                                                                   โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Full annex: [link to full IIR / Target Package]                   โ”‚
โ”‚ Analyst contact: [name, email, phone]                            โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

45.4 Fact-Check Report Template (Journalism)

FACT-CHECK REPORT
=================

1. CLAIM (the verified statement)
   Literal text: "..."
   Claim source: [URL + date + capture]
   Who said it: [person/entity + position]

2. VERIFICATION DATE: YYYY-MM-DD
3. VERIFIER(S): [name(s)]
4. VERIFICATION STATUS:
   [ ] True        [ ] Mostly true
   [ ] Misleading  [ ] Mostly false
   [ ] False       [ ] Unverifiable

5. EVIDENCE COLLECTED
   5.1 Source 1: [type, URL, date, hash]
   5.2 Source 2: ...
   5.3 Source 3: ...

6. ANALYSIS (what weighs more and why)

7. OMITTED CONTEXT (what the claim does not say)

8. CONTACT WITH ORIGINAL SOURCE
   Was the claimant contacted? Yes/No ยท Response: [...]

9. REFERENCES [verifiable URLs]

10. POST-PUBLICATION CORRECTIONS [log]

11. LICENSE AND REUSE

45.5 Digital Chain of Custody Checklist โ€” 12 Steps

Before capturing:

  • 1. Synchronise the device clock with NTP (difference <1s).
  • 2. Verify the browser is clean (no logged-in session that biases served content).
  • 3. Log pre-capture: exact URL, date/time with explicit timezone, public IP, access method (direct/VPN/Tor).

During capture:

  • 4. Capture with visible timestamp on screen.
  • 5. Save original format: complete HTML ("Save Page As โ†’ Webpage, Complete") + uncropped PNG screenshot.
  • 6. Generate a snapshot on archive.org / archive.today and save the returned URL.
  • 7. For video: download with yt-dlp preserving original metadata; do not re-encode.

Immediately after:

  • 8. Compute SHA-256 of the original file and log: filename, hash, size, UTC capture date.
  • 9. For JS-heavy captures: also save HAR file (Network โ†’ Save All as HAR) and WARC if using wpull or archiveweb.
  • 10. Rename files with convention {YYYYMMDDTHHMMZ}_{slug}.{ext} (no spaces or accents).

Storage:

  • 11. Store in an append-only repository (git with tags or WORM system). Never overwrite, only version. Second offline repository recommended.
  • 12. Maintain a master CSV/JSON log with columns: case_id ยท filename ยท sha256 ยท capture_url ยท capture_timestamp_utc ยท capture_method ยท analyst ยท notes. One master file per case.

45.6 Verified Templates & Deliverables Tools

ToolURLFunction
Obsidianhttps://obsidian.mdLinked notes with graphs
TimelineJShttps://timeline.knightlab.comInteractive timelines
Aeon Timelinehttps://www.aeontimeline.comComplex timelines
Draw.io / diagrams.nethttps://www.diagrams.netDiagrams and flows
Zoterohttps://www.zotero.orgReference management
CryptPadhttps://cryptpad.frEncrypted collaboration
Standard Noteshttps://standardnotes.comE2E encrypted notes
VeraCrypthttps://www.veracrypt.frContainer encryption
MAT2https://0xacab.org/jvoisin/mat2Metadata stripping
ExifToolhttps://exiftool.orgMetadata extraction
OpenTimestampshttps://opentimestamps.orgBlockchain timestamping
Hunchlyhttps://www.hunchly.comWeb capture with OPSEC ($129/yr)
archive.org Waybackhttps://web.archive.orgHistorical web archive
Archive.todayhttps://archive.todayWayback alternative
Maltegohttps://www.maltego.comLink analysis and visualization
Datasettehttps://datasette.ioExplore CSV/SQLite
Gephihttps://gephi.orgGraph analysis
RAWGraphshttps://rawgraphs.ioCharts from CSV
Datawrapperhttps://www.datawrapper.deVisualization for reports
QGIShttps://qgis.orgDesktop GIS
Mapillaryhttps://www.mapillary.comCrowdsourced street-view
Atloshttps://www.atlos.orgCollaborative investigation
Auto-Archiver (Bellingcat)https://github.com/bellingcat/auto-archiverAutomatic archiving
4CAThttps://github.com/digitalmethodsinitiative/4catSocial data analysis
Pinpoint (Google Journalist Studio)https://journaliststudio.google.com/pinpoint/Document analysis

45.7 Common Errors in OSINT Deliverables

  1. BLUF absent or buried. The executive reader has no time. If the critical finding is on page 7, it does not exist.
  2. Confusing fact with inference. "Company X is owned by Y" (fact) vs. "probably controlled by Y" (inference). Use markers [FACT] vs [ANALYSIS].
  3. No chain of custody. A screenshot without URL, date and hash is anecdotal.
  4. Overloading with tools. The C-Suite does not care which tools you used, only the findings.
  5. Not declaring knowledge gaps. A senior declares what they do not know; a junior hides it.
  6. Unjustified confidence. "High Confidence" without justification = suspicious.
  7. Wrong format scaling. A 30-page IIR to a CFO = won't be read. A 1-page executive briefing to an auditor = useless.
  8. No versioning. Without revision history, no one knows if they are reading version 0.1 or 1.4.

46. Regional OSINT

Each country below is in a collapsible block โ€” click to expand. Country selection criteria: digital footprint, OSINT practitioner community, geopolitical relevance, and verifiable public sources. All URLs were verified on 2026-07-19. Status legend: โœ… 200 OK ยท โš ๏ธ 403/401 (bot-blocked at edge, live in browser) ยท โš ๏ธ Timeout (slow gov site, works with patience).

46.1 Americas

๐Ÿ‡บ๐Ÿ‡ธ United States โ€” Click to expand

Digital Landscape

Internet penetration ~93% of ~335M (Pew/ITU). Google (~88% market share), Bing, DuckDuckGo and Brave dominate search. Facebook, Instagram, X/Twitter, TikTok, Reddit, LinkedIn, Snapchat and Discord are the dominant social platforms; messaging skews to iMessage, WhatsApp, SMS (still heavily used for 2FA), Signal (journalistic) and Telegram (extremist/cyber-criminal). The US is also headquarters to most of the global OSINT-vendor stack (Palantir, Recorded Future, Sayari, Maltego ownership, Blackbird.AI, OSINT Industries).

Intelligence Agency & OSINT Tradecraft

  • Lead civilian foreign-intelligence agency: Central Intelligence Agency (CIA) โ€” https://www.cia.gov โœ…
  • Lead signals-intelligence agency: National Security Agency (NSA) โ€” https://www.nsa.gov
  • Federal law-enforcement & domestic intel: Federal Bureau of Investigation (FBI) โ€” https://www.fbi.gov
  • OSINT dedicated unit: Open Source Enterprise (OSE), organisational descendant of the Open Source Center (OSC, est. 2005), itself descended from the Foreign Broadcast Information Service (FBIS, est. 1941). OSE sits under the CIA's Directorate of Digital Innovation (DDI) but coordinates across the IC through the Open Source Inter-Agency Center (OSIAC) reporting to the Director of National Intelligence.
  • Publicly verifiable tradecraft points:
    • ODNI Intelligence Community Open Source Strategy 2024-2026 โ€” https://www.dni.gov/files/ODNI/documents/IC_OSINT_Strategy.pdf โš ๏ธ 403 to bots, downloadable in any browser. This is the first public IC document that formally elevates OSINT to a first-tier INT alongside HUMINT/SIGINT/GEOINT/MASINT.
    • State Department OSINT Strategy 2024-2026 โ€” corroborates the IC-wide elevation.
    • FBIS historical lineage (declassified): CIA Historical Review Program released the FBIS collection guide and millions of translated foreign-broadcast transcripts (1941-1995).
    • WMD Commission (Silberman-Robb, 2005): publicly recommended elevating OSINT โ€” documented origin of the Open Source Center.
  • What is NOT verified (myth-busting):
    • There is no public confirmation that the CIA runs sockpuppet armies at scale. The single documented case is the 2014 AP story on "ZunZuneo", a fake Cuban Twitter.
    • "The NSA reads every email" โ€” actual Snowden-disclosed programs (PRISM, UPSTREAM, XKEYSCORE) targeted traffic under FISA ยง702; bulk domestic collection was narrowed by the USA FREEDOM Act 2015.
    • The CIA did not create the internet (DARPA did, 1969). CIA venture arm In-Q-Tel did fund Keyhole (โ†’ Google Earth) and Palantir.

Government Sources (Verified URLs)

SourceURLFunctionStatus
SEC EDGARhttps://www.sec.gov/edgarCorporate filings (10-K, 10-Q, 13D, S-1)โš ๏ธ 403 bot-block, live in browser
PACERhttps://pacer.uscourts.govFederal court recordsโœ… 200
OFAC SDN searchhttps://sanctionssearch.ofac.treas.govSanctions / PEP screeningโœ… 200
Data.govhttps://www.data.govFederal open data portalโœ… 200
FOIA.govhttps://www.foia.govFOIA portal & requester infoโœ… 200
Federal Registerhttps://www.federalregister.govPresidential docs, rules, noticesโœ… 200
USCourts.govhttps://www.uscourts.govFederal case statistics & finderโœ… 200
SAM.govhttps://sam.govFederal contractor registry + exclusionsโœ… 200
FEChttps://www.fec.gov/data/Campaign finance dataโœ… 200

State-level company registers: The US has no federal companies register. Each state runs its own Secretary of State business search (e.g. California https://businesssearch.sos.ca.gov, Delaware https://icis.corp.delaware.gov/ecorp/entitysearch/namesearch.aspx, New York https://apps.dos.ny.gov/publicInquiry/).

Local Sources & Press

  • Quality press: New York Times, Washington Post, Wall Street Journal, ProPublica, Reuters, AP, Bloomberg, Los Angeles Times, Miami Herald, Texas Tribune, CALmatters.
  • Investigative NGOs: ProPublica (Pulitzer-winning nonprofit), International Consortium of Investigative Journalists (ICIJ) โ€” https://www.icij.org โœ…, Center for Public Integrity, OpenSecrets (https://www.opensecrets.org โš ๏ธ 403, live in browser), LittleSis (https://littlesis.org โœ…).
  • OSINT community: Bellingcat (US-originated, Amsterdam-based since 2018), IntelTechniques (Michael Bazzell), OSINT Framework (Lockfale), SANS SEC497/SEC487 training, Trace Labs, OSINT Curious, The OSINT Newsletter.
  • Academic OSINT: National Security Institute (George Mason U.), Harvard Belfer Center, Stanford Internet Observatory, Texas A&M Scowcroft Institute.

Country-Specific OSINT Tools

  • First Amendment protects newsgathering broadly but is not absolute.
  • Computer Fraud and Abuse Act (CFAA), 18 U.S.C. ยง 1030 โ€” https://www.law.cornell.edu/uscode/text/18/1030 โœ…. Post-Van Buren v. United States (2021) the Supreme Court narrowed "exceeds authorised access" but ToS-violation scraping with a login remains risky.
  • Electronic Communications Privacy Act (ECPA) and Stored Communications Act (SCA) govern interception and access to stored comms.
  • FOIA (1966) โ€” https://www.foia.gov โœ… โ€” the strongest federal transparency lever. State public-records laws vary (California PRA, Texas PIA, Florida Sunshine Law).
  • State privacy laws: California CCPA/CPRA (2020/2023), Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA (2024).
  • No federal GDPR-equivalent. Investigators publishing personal data of US persons are largely constrained by defamation, false-light and tortious-interference law.
  • SLAPP risk: 32 states have anti-SLAPP statutes (California, Texas, New York, Florida among the strongest).
  • State secret / classification: 18 U.S.C. ยง 798 (Espionage Act) relevant if an investigator receives leaked classified docs.
  • OPSEC: US-based investigators can be subpoenaed by grand jury. Border searches under 8 CFR 287 โ€” devices can be searched at the US border without reasonable suspicion.

Notable Cases

  • MH17 (2014, Netherlands-led but Bellingcat-driven). Bellingcat used open VK posts, satellite imagery, geolocation of a Buk TELAR transport and matched social-media timestamps to attribute the downing of MH17 to Russian forces. Methodology PDF: https://www.bellingcat.com/app/uploads/2015/10/MH17-The-Open-Source-Evidence-EN.pdf โœ…. The case is the textbook example of OSINT-as-evidence (used by the JIT and cited in the Dutch court verdict in absentia against Russians Girkin/Dubinsky/Pulatkij in 2022).
  • 1MDB kleptocracy asset recovery (2016-2024). DOJ Civil forfeiture complaints โ€” https://www.justice.gov/criminal/criminal-mlnsa/kleptocracy-asset-recovery-initiative โš ๏ธ โ€” used leaked bank records, SEC filings, real-estate records from NYC registry and shell-company filings from BVI/Seychelles.
  • Boston Marathon bombing misidentification (2013). The cautionary counter-example: Reddit/Twitter crowd-sleuths wrongly identified missing student Sunil Tripathi as a suspect; he was later found dead by suicide. Teaching case on confirmation bias in OSINT.
  • January 6 Capitol riot (2021). Sedition Hunters (https://seditionhunters.org) and the FBI used Parler video metadata and facial matches to identify >1,400 suspects.
๐Ÿ‡ง๐Ÿ‡ท Brazil โ€” Click to expand

Digital Landscape

Brazil had 187.9 million internet users at the start of 2024 (86.6% penetration) per DataReportal's Digital 2024: Brazil. WhatsApp is the dominant communication layer โ€” roughly 147โ€“148 million users, ~93% of internet users send messages online โ€” making it the primary OSINT surface. Google dominates search; YouTube is the second social platform after WhatsApp.

Intelligence Agency & OSINT Tradecraft

  • Main agency: Agรชncia Brasileira de Inteligรชncia (ABIN), subordinated to the Institutional Security Cabinet (GSI/PR). Public site: https://www.gov.br/abin/en
  • OSINT unit / tradecraft: ABIN does not publicly advertise a dedicated OSINT directorate. Its Desafios de Inteligรชncia โ€“ Ediรงรฃo 2026 public report describes OSINT as a collection discipline integrated into its Obtaining (Obtenรงรฃo) area, but no named OSINT unit is publicly attributed. The Brazilian intelligence community (SISBIN) coordinates civilian + military intelligence; ABIN is the central body.
  • Publicly attributable tradecraft: None specifically attributable beyond ABIN's public acknowledgement that it collects open-source information as part of its mandate. The most mature Brazilian OSINT tradecraft is practised by investigative journalists (Agรชncia Pรบblica, Piauรญ) and civil-society investigators, not by ABIN.

Government Sources (Verified URLs)

SourceURLFunction
Receita Federal โ€” CNPJhttps://www.gov.br/receitafederal/pt-br/servicos/cadastro/cnpjBusiness registry lookup
CNPJ Comprovantehttps://solucoes.receita.fazenda.gov.br/servicos/cnpjreva/cnpjreva_solicitacao.aspRegistration/situation certificate
Diรกrio Oficial da Uniรฃo (DOU)https://in.gov.br/servicos/diario-oficial-da-uniaoFederal official gazette
Imprensa Nacionalhttps://www.gov.br/imprensanacional/pt-brPrint house & gazette archive
Portal de Compras (Comprasnet)https://www.gov.br/compras/pt-brFederal procurement contracts
Portal da Transparรชnciahttps://www.portaltransparencia.gov.brCEIS (sanctioned companies), public spending

Court records: Jusbrasil (https://www.jusbrasil.com.br/consulta-processual) and Escavador (https://www.escavador.com) are the two principal case-law aggregators; both index CNJ-connected tribunals. The official CNJ platform is https://www.cnj.jus.br.

Property registry: Brazil has no unified federal property registry; each Cartรณrio de Registro de Imรณveis (notary office) keeps its own records.

Local Sources & Press

Country-Specific OSINT Tools

  • Jusbrasil & Escavador โ€” case-law search (the closest Brazilian equivalent to US PACER).
  • Consulta CNPJ Receita โ€” corporate registry lookup (free; CAPTCHA-protected).
  • CNPJ.biz / ReceitaAWS โ€” community wrappers over the Receita Federal CNPJ API.
  • TSE DivulgaCandContas โ€” campaign finance & candidate asset declarations.
  • OSINT-Tools-Brazil (GitHub: bgmello/OSINT-Tools-Brazil) โ€” community-curated list.
  • OSINT Brasil blog (https://osintbrasil.blogspot.com) โ€” practitioner write-ups.
  • Data protection: LGPD โ€” Lei Geral de Proteรงรฃo de Dados, Law 13.709/2018, in force since 18 Sep 2020. Enforced by ANPD (https://www.gov.br/anpd).
  • Access to information: Lei de Acesso ร  Informaรงรฃo (LAI), Law 12.527/2011 โ€” every citizen can request government records; FalaBR (https://falabr.cgu.gov.br) is the central portal.
  • SLAPP risk: No dedicated anti-SLAPP statute; journalists face criminal defamation suits under the Cรณdigo Penal (arts. 138โ€“145).
  • Internet regulation: Marco Civil da Internet (Law 12.965/2014) governs intermediary liability and data retention.

Notable Cases

  • Operaรงรฃo Lava Jato (Operation Car Wash) โ€” 2014โ€“2021 anti-corruption task force led by the Curitiba federal court (Judge Sรฉrgio Moro) and the Ministรฉrio Pรบblico Federal. Convictions included former president Lula (later annulled by STF in 2021), Odebrecht/Novonor executives, and Petrobras directors. OSINT tradecraft was light; the case was built on plea bargains (delaรงรฃo premiada) and leaks. Verified URLs: https://en.wikipedia.org/wiki/Operation_Car_Wash ยท https://apublica.org/especial/vaza-jato (the "Vaza Jato" leak archive).
๐Ÿ‡ฒ๐Ÿ‡ฝ Mexico โ€” Click to expand

Digital Landscape

Mexico has ~96 million internet users (~75% penetration per DataReportal Digital 2024 Mexico). WhatsApp is the dominant communication channel; Facebook, Instagram, X (Twitter) and TikTok follow. Google holds >90% search share. Internet penetration is highly uneven โ€” urban vs rural gap is significant.

Intelligence Agency & OSINT Tradecraft

  • Main agency: Centro de Investigaciรณn y Seguridad Nacional (CISEN) was replaced in December 2018 by the Centro Nacional de Inteligencia (CNI) under the Secretariat of Security and Citizen Protection (SSPC). Public reference: https://www.gob.mx/sspc/cni
  • OSINT unit / tradecraft: No publicly attributed OSINT directorate. Mexican intelligence is widely regarded as under-resourced on technical collection; the public-record consensus is that Mexico "lacks a robust external intelligence capability" comparable to its partners in the region.
  • Verified URLs:

Government Sources (Verified URLs)

SourceURLFunction
SAT (Servicio de Administraciรณn Tributaria)https://www.sat.gob.mxTax authority, RFC lookup, e.factura
DOF (Diario Oficial de la Federaciรณn)https://www.dof.gob.mxFederal official gazette
INEGIhttps://www.inegi.org.mxDENUE business directory, census, statistics
Compranethttps://www.gob.mx/compranetFederal public procurement
INAIhttps://www.inai.org.mxTransparency / FOIA portal
Plataforma Digital Nacionalhttps://plataformadigitalnacional.orgAsset declarations, sanctions
RNIEhttps://www.rnie.sems.gob.mxNational educational institutions registry

Local Sources & Press

  • Quality press: Proceso, Animal Polรญtico, Latinus, Emeequis, Reforma, El Universal, Milenio.
  • Investigative / non-profit: MexicanLeaks (https://mexicanleaks.mx), Quinto Elemento Lab, Article 19 Mรฉxico (https://article19.org/offices/mexico-office).
  • OSINT community: OSINT Espaรฑol, OSINT Mรฉxico communities on Telegram/Discord.

Country-Specific OSINT Tools

  • INEGI DENUE โ€” Directorio Estadรญstico Nacional de Unidades Econรณmicas (business directory).
  • SAT RFC lookup โ€” tax ID verification.
  • MexicanLeaks โ€” anonymous leak submission platform.
  • Plataforma Digital Nacional โ€” asset declarations of public officials, sanctioned entities.
  • Article 19 Mรฉxico โ€” attacks on journalists tracker.
  • Data protection: LFPDPPP โ€” Ley Federal de Protecciรณn de Datos Personales en Posesiรณn de los Particulares (2010), reformed in 2025 for the private sector. ARCO rights (Acceso, Rectificaciรณn, Cancelaciรณn, Oposiciรณn). INAI is the authority (when in operation โ€” INAI was paralysed for months in 2024-2025 due to lack of commissioners).
  • Access to information: Ley General de Transparencia y Acceso a la Informaciรณn Pรบblica (2015).
  • SLAPP risk: High. Mexico is one of the most dangerous countries for journalists (Article 19, CPJ). Criminal defamation suits are used to silence investigators.
  • OPSEC: Critical. Investigating cartels or political corruption carries physical risk.

Notable Cases

  • Ayotzinapa case (2014). 43 student teachers from the Ayotzinapa Rural Teachers' College disappeared in Iguala, Guerrero. The official "Historical Truth" (Verdad Histรณrica) was challenged by the GIEI (Grupo Interdisciplinario de Expertos Personas) report, which used OSINT (satellite imagery, phone records, geolocation of security forces) to contradict the government narrative. Verified URLs: https://en.wikipedia.org/wiki/2014_Iguala_mass_kidnapping ยท https://gieicom.org/informes/.
  • MexicanLeaks investigations โ€” multiple investigations into political corruption published through the platform.
๐Ÿ‡ฆ๐Ÿ‡ท Argentina โ€” Click to expand

Digital Landscape

Argentina has ~37 million internet users (~83% penetration per DataReportal Digital 2024 Argentina). WhatsApp is the dominant messaging channel; Facebook, Instagram and X (Twitter) follow. Google holds >90% search share.

Intelligence Agency & OSINT Tradecraft

Government Sources (Verified URLs)

SourceURLFunction
Boletรญn Oficial de la Repรบblica Argentinahttps://www.boletinoficial.gob.arNational official gazette
AFIP / ARCAhttps://www.afip.gob.arTax authority, CUIT lookup
IGJ (Inspecciรณn General de Justicia)https://www.jus.gob.ar/igjNational corporate registry
INDEChttps://www.indec.gob.arNational statistics
Datos Jus.Gob.Arhttps://www.datos.jus.gob.arJustice open data
Padrรณn Electoralhttps://www.padron.gob.arElectoral roll lookup

Local Sources & Press

  • Quality press: La Naciรณn, Clarรญn, Pรกgina/12, Infobae, Perfil.
  • Investigative / non-profit: Chequeado (https://chequeado.com, fact-checking), Revista Anfibia (https://revistaanfibia.com), Centro de Implementaciรณn de Polรญticas Pรบblicas para la Equidad y el Crecimiento (CIPPEC).
  • OSINT community: Hacks/Hackers Buenos Aires.

Country-Specific OSINT Tools

  • Chequeado โ€” Argentina's leading fact-checking organisation.
  • AFIP / ARCA CUIT lookup โ€” tax ID verification.
  • IGJ Sociedades โ€” corporate registry lookup.
  • Atlas ID โ€” forensic identification system (national registry).
  • Data protection: Ley 25.326 (2000), regulated by AAIP (https://www.argentina.gob.ar/aaip). Argentina has EU adequacy status.
  • Access to information: Ley 27.275 (2016) โ€” comprehensive FOIA law.
  • SLAPP risk: Moderate. Journalists face criminal defamation suits.

Notable Cases

  • Cuadernos de las coimas (Notebooks of the bribes, 2018). Chauffeur Oscar Centeno's notebooks documented bribes from public-works contractors to Kirchner-era officials. Investigation led by journalist Diego Cabot (La Naciรณn) and Cynthia Garcรญa (C5N). Verified URL: https://en.wikipedia.org/wiki/Cuadernos_de_las_coimas.
๐Ÿ‡จ๐Ÿ‡ฆ Canada โ€” Click to expand

Digital Landscape

Canada has ~36 million internet users (~94% penetration). Google dominates search; Facebook, X, Instagram, Reddit and LinkedIn are the main social platforms. WhatsApp and iMessage dominate messaging. Local tech-OSINT ecosystem is concentrated in Toronto, Montreal and Vancouver.

Intelligence Agency & OSINT Tradecraft

Government Sources (Verified URLs)

SourceURLFunction
Corporations Canadahttps://www.ic.gc.ca/app/scr/cc/CorporationsCanada/feder.htmlFederal corporate registry
Industry Canada Open Datahttps://open.canada.caFederal open data portal
Canada Gazettehttps://gazette.gc.ca/rp-pr/p1/whats-new/index-eng.htmlOfficial gazette
CASL Registryhttps://crtc.gc.ca/eng/internet/anti.htmAnti-spam compliance
NSICOP reportshttps://www.canada.ca/en/parliament/information/publications/national-security-intelligence-committee-parliamentarians.htmlNational security oversight reports

Local Sources & Press

  • Quality press: CBC, Toronto Star, The Globe and Mail, La Presse (French), National Post.
  • Investigative / non-profit: CBC Investigates, Toronto Star Investigative, Discourse Media, The Pointer.
  • OSINT community: Canadian OSINT community on LinkedIn, SecTor conference.

Country-Specific OSINT Tools

  • Data protection: PIPEDA โ€” Personal Information Protection and Electronic Documents Act (2000). Provincial equivalents (Quebec Law 25, BC PIPA, Alberta PIPA).
  • Access to information: Access to Information Act (1985) โ€” federal FOIA.
  • SLAPP risk: Ontario has anti-SLAPP protections (Anti-SLAPP Act 2015). Other provinces vary.
  • OPSEC: Strong press protections. Source shield recognised by courts.

Notable Cases

  • NSICOP reports (2019-2024). The National Security and Intelligence Committee of Parliamentarians has published multiple reports on intelligence community activities, including the 2024 report on foreign interference in Canadian elections.
  • Hogue Commission (2024). Public inquiry into foreign interference in Canadian electoral processes, led by Justice Marie-Josรฉe Hogue.

46.2 Western Europe

๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom โ€” Click to expand

Digital Landscape

Internet penetration ~98% (Ofcom 2024); 5G nationwide; gigabit-fibre rollout ~80% by 2025. Google (~90%), Bing and DuckDuckGo dominate search. WhatsApp is dominant (~80% of UK smartphone users), with iMessage, Signal (journalists) and Telegram. London is Europe's largest LinkedIn market. The UK has a concentrated tech-OSINT ecosystem including Darktrace, BAE Systems Applied Intelligence, Cellebrite UK, DeepMind (now Google DeepMind) and Recorded Future UK.

Intelligence Agency & OSINT Tradecraft

  • Lead foreign-intelligence agency: Secret Intelligence Service (SIS / "MI6") โ€” https://www.sis.gov.uk โš ๏ธ 403 to bots, live in browser.
  • Lead signals-intelligence & cyber agency: Government Communications Headquarters (GCHQ) โ€” https://www.gchq.gov.uk โœ…. Includes the National Cyber Security Centre (NCSC) โ€” https://www.ncsc.gov.uk โœ….
  • Domestic security service: Security Service (MI5) โ€” https://mi5.gov.uk.
  • Military intelligence: Defence Intelligence (DI) sits under the Ministry of Defence.
  • OSINT dedicated unit: GCHQ Open Source Intelligence Hub (OSI Hub) โ€” publicly referenced in the 2023 GCHQ annual report and in the 2024 Intelligence and Security Committee report. Less publicly visible than CIA OSE. NCSC uses OSINT for threat-intel (weekly threat reports).
  • Publicly verifiable tradecraft points:
    • GCHQ's legal basis is the Investigatory Powers Act 2016 ("Snooper's Charter"); bulk personal datasets and bulk interception warrants are reviewed by the Investigatory Powers Commissioner's Office (IPCO) โ€” public reports at https://ipco.org.uk.
    • NCSC publishes the Early Warning service (free to UK organisations) which is OSINT + sinkhole data โ€” https://www.ncsc.gov.uk/section/services/early-warning.
    • GCHQ published "Pioneers, a UK strategy for AI" (2024) openly โ€” first IC in Five Eyes to do so.
  • What is NOT verified (myth-busting):
    • "GCHQ reads every email in the UK" โ€” actual programs target external traffic under RIPA/IPA warrants; bulk domestic collection requires specific authorization.
    • JTRIG (Joint Threat Research Intelligence Group) โ€” existence disclosed by Snowden; specific operations remain classified. Do not attribute specific operations without source.

Government Sources (Verified URLs)

SourceURLFunctionStatus
Companies Househttps://find-and-update.company-information.service.gov.ukUK companies registry (free, full, historical)โœ… 200
The Gazettehttps://www.thegazette.co.ukUK official public recordโœ… 200
HM Land Registryhttps://www.gov.uk/government/organisations/hm-land-registryProperty ownershipโœ… 200
data.gov.ukhttps://www.data.gov.ukUK open data portalโœ… 200
UK Parliamenthttps://parliament.ukHansard, committee reportsโœ… 200
National Archiveshttps://www.nationalarchives.gov.ukHistorical recordsโœ… 200
Find a Companyhttps://find-and-update.company-information.service.gov.ukSearch by name/numberโœ… 200
OpenOwnership Registerhttps://register.openownership.orgUK PSC registerโš ๏ธ 403, live in browser

Local Sources & Press

  • Quality press: The Guardian, BBC News, Reuters, Financial Times, The Times, The Telegraph, The Independent.
  • Investigative NGOs: Bureau of Investigative Journalism (https://www.thebureauinvestigates.com), OpenDemocracy, Finance Uncovered.
  • OSINT community: Bellingcat (Amsterdam-HQ since 2018, originally UK-founded), CIISec (Chartered Institute of Information Security), OSINT Curious UK chapter.

Country-Specific OSINT Tools

  • Companies House API โ€” free, comprehensive UK corporate registry with full historical filings.
  • OpenOwnership Register โ€” UK PSC (Person with Significant Control) register.
  • OpenSanctions UK datasets โ€” UK OFSI sanctions, Consolidated List.
  • Hansard API โ€” parliamentary debates (https://hansard.parliament.uk).
  • DueDil โ€” UK corporate intelligence aggregator (commercial).
  • Wayback Machine UK Government snapshot archive โ€” via UK Web Archive (https://www.webarchive.org.uk).
  • Data protection: UK GDPR (post-Brexit, retained EU GDPR) + Data Protection Act 2018. Regulated by ICO (https://ico.org.uk).
  • Access to information: Freedom of Information Act 2000 (https://www.legislation.gov.uk/ukpga/2000/36/contents).
  • Investigatory Powers Act 2016 โ€” regulates bulk interception and equipment interference.
  • Official Secrets Act 1989 โ€” protects state secrets; relevant for investigators handling leaked UK gov material.
  • SLAPP risk: UK has a libel tourism problem; Defamation Act 2013 added a "serious harm" threshold. UK recently published an anti-SLAPP bill proposal in 2024.

Notable Cases

๐Ÿ‡ฉ๐Ÿ‡ช Germany โ€” Click to expand

Digital Landscape

Internet penetration ~93% (Bitkom 2024). Google dominates search; alternative privacy-focused search engines (Ecosia, Metager) have notable market share. WhatsApp is the dominant messaging app; Telegram is notably stronger in Germany than in other Western European countries (used by political fringe, anti-vax, Reichsbรผrger). X and LinkedIn are the main professional networks.

Intelligence Agency & OSINT Tradecraft

Government Sources (Verified URLs)

SourceURLFunctionStatus
Unternehmensregisterhttps://www.unternehmensregister.de/enFederal business registryโœ… 200
Bundesanzeigerhttps://www.bundesanzeiger.de/pub/en/startFederal gazette (annual financial statements)โœ… 200
Transparenzregisterhttps://www.transparenzregister.deUBO register (implementing EU AMLD)โœ… 200
Datenportal der Bundesregierunghttps://www.govdata.deFederal open data portalโœ… 200
Destatishttps://www.destatis.deFederal statistics officeโœ… 200
Bundestaghttps://www.bundestag.deParliamentary records (DIP)โœ… 200

Local Sources & Press

  • Quality press: Sรผddeutsche Zeitung, Frankfurter Allgemeine Zeitung (FAZ), Die Zeit, Der Spiegel, Die Welt, Handelsblatt, Tagesschau (public broadcaster ARD), ZDF heute.
  • Investigative NGOs: Correctiv (https://correctiv.org/en โœ…), Netzpolitik.org, Frag Den Staat (https://fragdenstaat.de, FOIA platform), OCCRP Germany partner.
  • OSINT community: OSINT Deutsch (Telegram), IntelTechniques Germany, BSI Cyber-Sicherheitskonferenz.

Country-Specific OSINT Tools

  • Unternehmensregister โ€” official federal business registry (paid for full filings, free for basic info).
  • Bundesanzeiger โ€” federal gazette with annual financial statements of all German companies.
  • Transparenzregister โ€” UBO register (implementing EU 4th AMLD).
  • Frag Den Staat โ€” FOIA platform (https://fragdenstaat.de) โ€” sends and tracks freedom-of-information requests.
  • Correctiv Research Hub โ€” investigative OSINT tools and methodology.
  • Netzpolitik.org โ€” digital rights and surveillance investigative site.
  • Data protection: GDPR (DSGVO in German) + Bundesdatenschutzgesetz (BDSG). Regulated by BfDI (https://www.bfdi.bund.de).
  • Access to information: Informationsfreiheitsgesetz (IFG, 2005) โ€” federal FOIA. Each state (Land) has its own IFG.
  • Stasi files: The BStU (Federal Commissioner for the Stasi Records, now BStU archives at Bundesarchiv) holds millions of records of the former East German secret police โ€” accessible to researchers and individuals.
  • Network Enforcement Act (NetzDG, 2017) โ€” requires social platforms to remove "manifestly illegal" content within 24h.
  • SLAPP risk: No specific anti-SLAPP law, but criminal defamation is rarely used against journalists.

Notable Cases

๐Ÿ‡ซ๐Ÿ‡ท France โ€” Click to expand

Digital Landscape

Internet penetration ~85% (ARCEP 2024). Google dominates search; Qwant is the French-made privacy-focused alternative. WhatsApp, iMessage, and Signal (used by journalists) dominate messaging. X, LinkedIn, Facebook, Instagram are the main social platforms. France has a strong domestic tech ecosystem (Dassault Systรจmes, Thales, Mistral AI).

Intelligence Agency & OSINT Tradecraft

  • External intelligence agency: Direction Gรฉnรฉrale de la Sรฉcuritรฉ Extรฉrieure (DGSE) โ€” https://www.dgse.gouv.fr โœ…
  • Internal intelligence agency: Direction Gรฉnรฉrale de la Sรฉcuritรฉ Intรฉrieure (DGSI) โ€” https://www.dgsi.gouv.fr
  • Military intelligence: Direction du Renseignement et de la Sรฉcuritรฉ de la Dรฉfense (DRSD) and Direction du Renseignement Militaire (DRM).
  • OSINT unit / tradecraft: No publicly named OSINT directorate. DGSE and DGSI acknowledge OSINT as part of their collection disciplines in annual public reports to Parliament (https://www.assemblee-nationale.fr/dyn/15/rapplets).
  • Publicly verifiable tradecraft points:
  • What is NOT verified: "DGSE runs suitcase nuclear devices" โ€” this is fiction (referenced in films like La French) and not attributable.

Government Sources (Verified URLs)

SourceURLFunctionStatus
Infogreffehttps://www.infogreffe.frCommercial court registryโœ… 200
Pappershttps://www.pappers.frFree corporate data aggregatorโš ๏ธ 403, live in browser
data.gouv.frhttps://www.data.gouv.frFrench open data portalโœ… 200
Lรฉgifrancehttps://www.legifrance.gouv.frOfficial legal gazetteโœ… 200
INSEEhttps://www.insee.frNational statisticsโœ… 200
BODACChttps://www.bodacc.frBulletin officiel des annonces civiles et commercialesโœ… 200

Local Sources & Press

Country-Specific OSINT Tools

  • Pappers โ€” free corporate data aggregator (uses Infogreffe data).
  • Infogreffe โ€” official commercial court registry.
  • BODACC โ€” official bulletin of civil and commercial announcements.
  • Lรฉgifrance โ€” official legal database (laws, decrees, jurisprudence).
  • data.gouv.fr โ€” French open data portal.
  • INSEE Sirene database โ€” official business directory (https://www.sirene.fr).
  • Data protection: GDPR + Loi Informatique et Libertรฉs (1978, modified 2018). Regulated by CNIL (https://www.cnil.fr/en โœ…).
  • Access to information: Loi CADA (1978) โ€” French FOIA.
  • Secret dรฉfense: Classified defense information protected by law; relevant for investigators handling leaked French intel material.
  • SLAPP risk: France has strong defamation laws; recent reform is moving toward anti-SLAPP protections.
  • Loi Sรฉcuritรฉ Globale (2021) โ€” restricts publication of police officer images (controversial).

Notable Cases

  • Cahuzac case (2013). Budget Minister Jรฉrรดme Cahuzac was exposed for hiding money in Swiss bank accounts. Investigation led by Mediapart (Fabrice Arfi). URL: https://en.wikipedia.org/wiki/Jรฉrรดme_Cahuzac
  • CatalanGate (2022). Citizen Lab investigation into Pegasus spyware infections of Catalan politicians and civil society. URL: https://citizenlab.ca/2022/04/catalangate/
  • Panama Papers / Pandora Papers โ€” French persons featured prominently; ICIJ investigations.
๐Ÿ‡ช๐Ÿ‡ธ Spain โ€” Click to expand

Digital Landscape

Internet penetration ~93% (ONTSI 2024). Google dominates search. WhatsApp is the dominant messaging app; Telegram has high penetration (used by political groups). X, LinkedIn, Instagram are the main social platforms. Spain has active OSINT and hacking communities (DragonJAR, OSINT Espaรฑol).

Intelligence Agency & OSINT Tradecraft

  • National intelligence agency: Centro Nacional de Inteligencia (CNI) โ€” https://www.cni.es/en โœ…
  • Defence intelligence centre: Centro de Inteligencia de las Fuerzas Armadas (CIFAS).
  • OSINT unit / tradecraft: CNI acknowledges OSINT as part of its collection disciplines. The public Ley 11/1995 (https://www.boe.es/buscar/act.php?id=BOE-A-1995-22306) regulates intelligence activity including OSINT.
  • Publicly verifiable tradecraft points:
    • CCN-CERT (Centro Criptolรณgico Nacional) โ€” https://www.ccn-cert.cni.es/en/ โ€” public cybersecurity incidents and threat reports based on OSINT.
    • INCIBE (Instituto Nacional de Ciberseguridad) โ€” https://www.incibe.es โ€” public threat intel.
  • What is NOT verified: "CNI runs mass surveillance" โ€” the Catalangate Citizen Lab report documented Pegasus infections but did not attribute them directly to CNI; CNI's director Pablo Melgar was asked about this in parliamentary committee and neither confirmed nor denied.

Government Sources (Verified URLs)

SourceURLFunctionStatus
BORME (Boletรญn Oficial del Registro Mercantil)https://www.boe.es/datosabiertos/bormeCommercial registry bulletinโœ… 200
BOE (Boletรญn Oficial del Estado)https://www.boe.esState official gazetteโœ… 200
datos.gob.eshttps://datos.gob.es/enSpanish open data portalโœ… 200
Registro Mercantil Centralhttps://www.rmcerranet.esCentral commercial registryโš ๏ธ requires login
AEPDhttps://www.aepd.esData protection authorityโœ… 200
Congress of Deputieshttps://www.congreso.esParliamentary recordsโœ… 200

Local Sources & Press

  • Quality press: El Paรญs, El Mundo, La Vanguardia, ABC, La Razรณn, El Confidencial, El Diario.
  • Investigative NGOs: Civio (https://civio.es/en/ โœ…), eldiario.es, Newtral (fact-checking), Maldita (fact-checking).
  • OSINT community: OSINT Espaรฑol (Telegram/Discord), DragonJAR community.

Country-Specific OSINT Tools

  • BORME โ€” official commercial registry bulletin.
  • Civio โ€” civic tech and OSINT tools.
  • Maldita โ€” leading Spanish fact-checker.
  • AEPD โ€” Spanish data protection authority.
  • INCIBE Cybersecurity โ€” public threat intel.
  • Data protection: GDPR + LOPDGDD (Ley Orgรกnica de Protecciรณn de Datos Personales y garantรญa de los derechos digitales, 2018). Regulated by AEPD.
  • Access to information: Ley 19/2013 de transparencia.
  • Ley Mordaza (Gag Law, 2015) โ€” restricts photography of police officers (controversial).
  • SLAPP risk: Criminal defamation suits are used against journalists.

Notable Cases

  • CatalanGate (2022). Citizen Lab investigation documented Pegasus infections of 65+ Catalan politicians, civil society members, and European MPs. URL: https://citizenlab.ca/2022/04/catalangate/
  • Pandora Papers (2021) โ€” Spanish political figures exposed.
๐Ÿ‡ฎ๐Ÿ‡น Italy โ€” Click to expand

Digital Landscape

Internet penetration ~87% (AGCOM 2024). Google dominates search. WhatsApp is the dominant messaging app. X, LinkedIn, Instagram are the main social platforms. Italy has a strong cybersecurity and OSINT community (SANS Milan, Italian Cybersecurity Summit).

Intelligence Agency & OSINT Tradecraft

Government Sources (Verified URLs)

SourceURLFunctionStatus
Registro Impresehttps://www.registroimprese.itNational business registryโœ… 200
Gazzetta Ufficialehttps://www.gazzettaufficiale.itOfficial gazetteโœ… 200
INPShttps://www.inps.itSocial securityโœ… 200
ISTAThttps://www.istat.itNational statisticsโœ… 200
Garante Privacyhttps://www.garanteprivacy.itData protection authorityโœ… 200
dati.gov.ithttps://www.dati.gov.itItalian open data portalโœ… 200

Local Sources & Press

  • Quality press: Corriere della Sera, La Repubblica, La Stampa, Il Sole 24 Ore, Il Fatto Quotidiano, Internazionale.
  • Investigative NGOs: IRPI (Investigative Reporting Project Italy, https://irpimedia.irpi.eu/en/ โœ…), La Notizia (Fact-checking), FrontiereCriminali.
  • OSINT community: OSINT Italia community, Cybersecurity Italia Summit.

Country-Specific OSINT Tools

  • Registro Imprese โ€” national business registry (free for basic lookups, paid for full filings).
  • IRPI โ€” investigative reporting with OSINT methodology.
  • Garante Privacy โ€” data protection authority with public decisions.
  • ACN Cybersecurity Alerts โ€” public threat reports.
  • Data protection: GDPR + Codice Privacy (Decreto Legislativo 196/2003, modified 2018). Regulated by Garante per la Protezione dei Dati Personali.
  • Access to information: Decreto Legislativo 33/2013 (FOIA).
  • SLAPP risk: Italy has criminal defamation with prison sentences; multiple SLAPP cases against journalists documented by EFJ.
  • OPSEC: Anti-mafia investigations carry significant physical risk.

Notable Cases

๐Ÿ‡ต๐Ÿ‡ฑ Poland โ€” Click to expand

Digital Landscape

Internet penetration ~88% (GUS 2024). Google dominates search; presearch.com has small share. WhatsApp and Messenger dominate messaging; Signal is growing among journalists and activists. X, LinkedIn, Facebook are the main social platforms. Poland has a strong cybersecurity and OSINT community (CyberSec community, NASK, Sekurak).

Intelligence Agency & OSINT Tradecraft

  • External intelligence agency: Agencja Wywiadu (AW) โ€” https://www.aw.gov.pl
  • Internal intelligence agency: Agencja Bezpieczeล„stwa Wewnฤ™trznego (ABW) โ€” https://www.abw.gov.pl
  • Military intelligence: Sล‚uลผba Wywiadu Wojskowego (SWW) and Sล‚uลผba Kontrwywiadu Wojskowego (SKW).
  • OSINT unit / tradecraft: AW and ABW acknowledge OSINT collection. The annual Raport o stanie bezpieczeล„stwa (https://www.bbn.gov.pl) references OSINT analysis.
  • Publicly verifiable tradecraft points:

Government Sources (Verified URLs)

SourceURLFunctionStatus
eKRS (Krajowy Rejestr Sฤ…dowy)https://ekrs.ms.gov.plNational court registryโœ… 200
Biznes.gov.plhttps://biznes.gov.pl/en/wyszukiwarka-firmBusiness searchโœ… 200
dane.gov.plhttps://dane.gov.pl/en/datasetOpen data portalโœ… 200
Dziennik Ustawhttps://www.dziennikustaw.gov.plOfficial journal of lawsโœ… 200
UODOhttps://uodo.gov.pl/enData protection authorityโœ… 200
Sejmhttps://www.sejm.gov.plParliamentary recordsโœ… 200

Local Sources & Press

Country-Specific OSINT Tools

  • eKRS โ€” National Court Registry (free, comprehensive for Polish companies).
  • Biznes.gov.pl โ€” business search portal.
  • OKO.press โ€” investigative journalism with OSINT.
  • Sekurak โ€” OSINT and pentesting resources.
  • OSINT Poland GitHub (https://github.com/9wind/OSINT-Poland) โ€” curated list of Polish OSINT resources.
  • Data protection: GDPR + Polish Data Protection Act (2018). Regulated by UODO (https://uodo.gov.pl/en).
  • Access to information: Ustawa o dostฤ™pie do informacji publicznej (2001).
  • SLAPP risk: Multiple SLAPP cases against journalists documented by OKO.press and EFJ.
  • Hate speech laws: Strong regulations against defamation of religious and ethnic groups.

Notable Cases

  • Visegrad Insight / Notes from Poland โ€” investigations into rule-of-law backsliding using OSINT.
  • Aleksandra Gajewska corruption case โ€” OSINT used by OKO.press to expose political corruption.

46.3 Eastern Europe & Russia

๐Ÿ‡ท๐Ÿ‡บ Russia โ€” Click to expand

Digital Landscape

Internet penetration ~88% (RUNet 2024). Yandex dominates search (~65% market share). VKontakte (VK) is the dominant social network; Odnoklassniki (OK) for older demographic. Telegram is the dominant messaging app (post-2022 blocking of Western platforms). X, Facebook and Instagram are blocked (since March 2022). LinkedIn has been blocked since 2016.

Intelligence Agency & OSINT Tradecraft

  • External intelligence agency: Sluzhba Vneshney Razvedki (SVR) โ€” https://www.svr.gov.ru
  • Military intelligence: Glavnoye Upravleniye General'nogo Shtaba (GRU) โ€” https://structure.mil.ru/structure/forces/hq/general.htm
  • Domestic security service: Federal'naya Sluzhba Bezopasnosti (FSB) โ€” https://www.fsb.ru
  • OSINT unit / tradecraft: Russian intelligence services use OSINT as part of their active measures and disinformation campaigns. The GRU's Unit 26165 (Fancy Bear / APT28) has been documented using OSINT to identify targets for spear-phishing and influence operations (Mueller Report, 2019; Bellingcat investigations).
  • Publicly verifiable tradecraft points:
  • What is NOT verified (myth-busting):
    • "Every Russian troll is GRU" โ€” many influence operations are conducted by private actors (IRA, Prigozhin's networks) with loose state coordination.
    • "Russian intelligence has perfect access to all Russian data" โ€” Russian investigators also use grey-market probiv bots, suggesting they don't have direct access to all databases.

Government Sources (Verified URLs)

SourceURLFunctionStatus
ะคะะก (Federal Tax Service)https://www.nalog.gov.ruFederal Tax Serviceโœ… 200
ะ•ะ“ะ ะฎะ› (Unified State Register of Legal Entities)https://egrul.nalog.ruRussian business registryโš ๏ธ 307 redirect
Pravo.gov.ruhttps://publication.pravo.gov.ruOfficial legal portalโš ๏ธ Timeout
Rosstathttps://www.rosstat.gov.ruFederal statisticsโœ… 200
Kremlinhttps://en.kremlin.ruPresidential administrationโœ… 200

Local Sources & Press

Country-Specific OSINT Tools

  • RuPEP (Russian Political Exposed Persons) โ€” https://rupep.ru โš ๏ธ Timeout โ€” database of Russian elites and PEPs.
  • Meduza โ€” independent Russian-language news.
  • Agentstvo โ€” investigative journalism.
  • InformNapalm โ€” OSINT community documenting Russian military actions.
  • Peacekeeper (Mirotvorets) โ€” Ukrainian-run database of pro-Russian actors (controversial).
  • Russian Telegram channels โ€” main source for real-time OSINT on Russian military, political events.
  • "Fake news" law (March 2022): Criminalises publication of "false information" about the Russian military, punishable by up to 15 years imprisonment. This affects any OSINT investigator publishing about Russian military actions.
  • Foreign agent law: Individuals and organizations receiving foreign support must register as "foreign agents".
  • VPN legality: VPNs are technically legal but providers must block sites on the Russian government's blacklist. Many VPN providers have left the Russian market.
  • OPSEC: Investigators publishing about Russia from outside should use sock puppets, never real identities. Russian intelligence has a documented history of targeting diaspora investigators.

Notable Cases

๐Ÿ‡บ๐Ÿ‡ฆ Ukraine (added for completeness) โ€” Click to expand

Digital Landscape

Internet penetration ~80% (early 2024). Google dominates search. Telegram is the dominant messaging app (used by both military and civilians during the war). X, Facebook, Instagram, TikTok, YouTube are the main social platforms. Ukraine has developed a sophisticated OSINT ecosystem since 2014.

Intelligence Agency & OSINT Tradecraft

  • External intelligence agency: Sluzhba Zovnishn'oyi Rozvidky (SZRU) โ€” https://szru.gov.ua
  • Military intelligence: HUR (Holovne Upravlinnya Rozvidky) โ€” https://www.gur.gov.ua
  • OSINT unit / tradecraft: Ukraine has the most sophisticated open-source OSINT ecosystem of any country at war, centred on:
    • InformNapalm โ€” volunteer OSINT community documenting Russian military equipment and personnel.
    • Cyber Resistance โ€” Ukrainian hacktivist collective.
    • Molfar โ€” Ukrainian OSINT agency (https://molfar.com).
    • State Emergency Service uses OSINT for damage assessment.
  • Publicly verifiable tradecraft points:

Government Sources (Verified URLs)

SourceURLFunction
YouControlhttps://youcontrol.com.uaComprehensive business registry aggregator
EDR (Unified State Register)https://usr.minjust.gov.uaMinistry of Justice registry
Prozorrohttps://prozorro.gov.uaPublic procurement (gold standard transparency)
data.gov.uahttps://data.gov.uaOpen data portal
Verkhovna Radahttps://www.rada.gov.uaParliamentary records

Local Sources & Press

  • Quality press: Ukrainska Pravda, Kyiv Independent, Suspilne, Babel, Levyi Bereg.
  • Investigative NGOs: Bihus.Info (https://bihus.info), Nashi Groshi, Slidstvo.Info.

Country-Specific OSINT Tools

  • YouControl โ€” business registry aggregator (free for basic lookups).
  • Prozorro โ€” public procurement transparency (gold standard).
  • EDR โ€” Ministry of Justice registry.
  • War Sanctions (war-sanctions.gur.gov.ua) โ€” OSINT-based list of companies supporting Russian war.
  • Martial law (ongoing since February 2022) โ€” restricts access to certain geographic and military information.
  • Data protection: Ukrainian Law on Personal Data Protection (2010, modified 2020).
  • OPSEC: Investigators operating in or on Ukraine during wartime should follow Ukrainian government OSINT guidelines to avoid compromising military operations.

Notable Cases

46.4 Asia

๐Ÿ‡จ๐Ÿ‡ณ China โ€” Click to expand

Digital Landscape

Internet penetration ~73% (1.05 billion users, CNNIC 2024). The Great Firewall blocks Google, Facebook, X, WhatsApp, YouTube, Telegram and most Western platforms. Baidu is the dominant search engine (~70% market share). WeChat (Weixin) is the universal super-app; Weibo is the main microblog; Douyin (Chinese TikTok) dominates short video; Xiaohongshu (RED) is the lifestyle social platform; Bilibili is the youth video platform.

Intelligence Agency & OSINT Tradecraft

Government Sources (Verified URLs)

SourceURLFunctionStatus
National Enterprise Credit Info (gsxt)http://www.gsxt.gov.cnNational business registryโš ๏ธ 521 โ€” slow, may require China-based access
creditchina.gov.cnhttp://www.creditchina.gov.cnCredit information portalโš ๏ธ 412
gov.cnhttps://www.gov.cnCentral government portalโœ… 200
Shanghai Stock Exchangehttps://www.sse.com.cnStock exchange filingsโš ๏ธ Timeout
Shenzhen Stock Exchangehttps://www.szse.cnStock exchange filingsโš ๏ธ Timeout
China Courthttps://www.chinacourt.orgCourt judgments (limited)โš ๏ธ Timeout

Note: Most Chinese government portals are slow or block foreign IPs. Use China-based VPN (legality varies) or third-party commercial aggregators like Sayari, Sayari Graph, or ChinะฐFAQs.

Local Sources & Press

Country-Specific OSINT Tools

  • National Enterprise Credit Information Publicity System (gsxt.gov.cn) โ€” official business registry (requires China-based access).
  • ASPI Xinjiang Data Project โ€” https://xjdp.aspi.org.au โ€” database of detention camps.
  • ChinaFile Documentary Center โ€” https://www.chinafile.com/documentary-center โ€” leaked documents and reports.
  • China Digital Times โ€” https://chinadigitaltimes.net โ€” censored content archive.
  • Sayari Graph (commercial) โ€” corporate network analysis with strong China coverage.
  • Shahit.biz (Xinjiang Victims Database) โ€” https://shahit.biz/eng/ โœ… โ€” database of detained Uyghurs and other minorities.
  • Cybersecurity Law (2017) and Data Security Law (2021) โ€” strict regulations on data handling, cross-border data transfer.
  • Personal Information Protection Law (PIPL, 2021) โ€” China's GDPR-equivalent.
  • National Intelligence Law (2017) โ€” requires Chinese organisations and citizens to "support, assist and cooperate with national intelligence efforts" โ€” applies extraterritorially to Chinese nationals abroad.
  • VPN legality: Personal VPN use is technically illegal but widely tolerated. Commercial VPN providers must register with the government; many Western VPNs are blocked.
  • OPSEC for investigators: Do not investigate Chinese targets from within China. Use a non-Chinese VPN. Do not contact sources via WeChat (monitored). Use Signal or ProtonMail.

Notable Cases

  • ASPI Xinjiang Data Project (2020). Mapped 380+ detention camps in Xinjiang using satellite imagery, government procurement documents, and leaked construction bids. URL: https://xjdp.aspi.org.au
  • Pegasus Project (2021). Forbidden Stories and Amnesty International investigation documented use of Pegasus spyware against Uyghur activists.
๐Ÿ‡ฐ๐Ÿ‡ฟ๐Ÿ‡ฐ๐Ÿ‡ท Korea (North & South) โ€” Click to expand

North Korea (DPRK)

Digital Landscape

Internet penetration <1% of the population. The country uses Kwangmyong, a closed intranet, instead of the global internet. Mobile phones (~6 million subscribers on Koryolink) are restricted to domestic calls and Kwangmyong. Foreign diplomats and elites have limited internet access.

Intelligence Agency & OSINT Tradecraft
Government Sources (Verified URLs)

North Korea has no publicly accessible government databases. All OSINT on DPRK uses external sources:

SourceURLFunctionStatus
38 Northhttps://www.38north.orgUS-Korea Institute analysisโš ๏ธ 403, live in browser
NK Newshttps://www.nknews.orgDPRK-focused news and analysisโœ… 200
NK Prohttps://www.nknews.org/proPremium DPRK analysis (paid)โœ… 200
NKEconWatchhttps://www.nkeconwatch.comDPRK economy watchโš ๏ธ 403, live in browser
OpenSanctions DPRKhttps://www.opensanctions.org/datasets/UN sanctionsโœ… 200
Local Sources & Press
Country-Specific OSINT Tools
  • 38 North โ€” satellite imagery analysis of DPRK facilities.
  • NK News โ€” comprehensive news aggregator.
  • Daily NK โ€” sources inside DPRK.
  • CSIS Beyond Parallel โ€” satellite imagery and analysis.
  • OpenSanctions DPRK datasets โ€” UN sanctions list.
  • Sanctions: North Korea is under comprehensive UN, US, EU sanctions. Any interaction with DPRK entities may violate sanctions.
  • OPSEC: DPRK intelligence actively targets researchers, defectors, and journalists investigating the regime. Avoid contact with DPRK-affiliated entities.
Notable Cases

South Korea (ROK)

Digital Landscape

Internet penetration ~98% (KISA 2024). Naver (~70% market share) and Daum/Kakao dominate search over Google. KakaoTalk is the universal messaging app (~95% of smartphone users). X, Instagram, YouTube, Facebook are the main social platforms. South Korea has one of the world's most advanced OSINT ecosystems.

Intelligence Agency & OSINT Tradecraft
Government Sources (Verified URLs)
SourceURLFunctionStatus
Hometaxhttps://www.hometax.go.krTax authority, business registrationโš ๏ธ Timeout
data.go.krhttps://www.data.go.krOpen data portalโš ๏ธ Timeout
NICE (business credit)https://www.nice.co.krBusiness credit informationโš ๏ธ Timeout
DART (financial disclosures)https://dart.fss.or.krFinancial Supervisory Service disclosuresโš ๏ธ Timeout
Koreabizwirehttps://www.koreabizwire.comBusiness news (English)โœ… 200
Local Sources & Press
  • Quality press: Hankyoreh, Chosun Ilbo, JoongAng Ilbo, Dong-a Ilbo, Korea Herald, Yonhap (news agency), Korea Joongang Daily (English).
  • Investigative NGOs: Newstapa (https://www.newstapa.com), News Cokeba, SisaIN.
  • OSINT community: OSINT Korea community, Lukio blog (https://osintteam.blog).
Country-Specific OSINT Tools
  • Hometax โ€” tax authority business registration lookup.
  • NICE โ€” business credit information.
  • DART โ€” financial supervisory disclosures.
  • YouthBoBo (์œ ์Šค๋ณด๋ณด) โ€” people search engine.
  • KakaoTalk account lookup โ€” phone number to KakaoTalk account matching (grey-market).
  • Personal Information Protection Act (PIPA, 2011) โ€” strict data protection law, stronger than GDPR in some aspects.
  • Access to information: Official Information Disclosure Act (1998).
  • National Security Law (1948) โ€” restricts content promoting North Korea; criminalises praise of DPRK.
  • SLAPP risk: Criminal defamation suits are common against journalists.
Notable Cases
๐Ÿ‡ฏ๐Ÿ‡ต Japan โ€” Click to expand

Digital Landscape

Internet penetration ~93% (MIC 2024). Google (~75%) and Yahoo! Japan (~25%) dominate search. LINE is the dominant messaging app (~85 million users). X (Twitter) is unusually popular in Japan (~60 million users); Facebook, Instagram, TikTok are major platforms. Japan has a strong cybersecurity community and is building up its intelligence apparatus.

Intelligence Agency & OSINT Tradecraft

Government Sources (Verified URLs)

SourceURLFunctionStatus
National Tax Agencyhttps://www.nta.go.jp/englishTax authorityโš ๏ธ 403, live in browser
corporate.no.jphttps://houmu-bunshou.comCorporate registry (commercial)โš ๏ธ Timeout
e-Gov Japanhttps://www.e-gov.go.jpLegal portalโœ… 200
e-Stathttps://www.e-stat.go.jpStatistics portalโœ… 200
Japan Patent Officehttps://www.jpo.go.jpPatent registryโœ… 200

Note: Japan's corporate registry (ๆณ•ๅ‹™ๅฑ€, Hลmukyoku) is not freely accessible online โ€” it requires physical visit or proxy request. Commercial aggregators like Teikoku Databank, TDB, and Tokyo Shoko Research (TSR) provide business information for a fee.

Local Sources & Press

  • Quality press: Yomiuri Shimbun, Asahi Shimbun, Mainichi Shimbun, Nihon Keizai Shimbun (Nikkei), NHK (public broadcaster), Japan Times (English), Kyodo News (news agency).
  • Investigative NGOs: FactCheck Center (https://factcheckcenter.jp), FactCheck Initiative Japan (FIJ).
  • OSINT community: Japan OSINT community (Twitter/X, Discord), Japan Cybersecurity Conference.

Country-Specific OSINT Tools

  • Teikoku Databank โ€” commercial corporate information database.
  • Tokyo Shoko Research (TSR) โ€” commercial business information.
  • JPO (Japan Patent Office) โ€” patent search.
  • e-Stat โ€” official government statistics portal.
  • LINE account lookup โ€” phone number to LINE account matching (grey-market, similar to Kakao).
  • FactCheck Center โ€” Japanese fact-checking organisation.
  • Act on the Protection of Personal Information (APPI, 2003, amended 2022) โ€” Japan's data protection law. Regulated by Personal Information Protection Commission (PPC).
  • Access to information: Act on Access to Information Held by Administrative Organs (1999).
  • Specially Designated Secrets Act (2013) โ€” criminalises leaking of national security secrets, including by journalists who report on them.
  • SLAPP risk: Low. Defamation cases typically result in monetary damages.
  • Note on corporate registries: Japan's corporate registry is notably less accessible than Western equivalents; physical presence or paid proxy is required for full access.

Notable Cases

  • AUM Shinrikyo sarin attack (1995). Investigation used OSINT on the cult's publications to build understanding of the attack.
  • 2024-2026 Japan intelligence reform โ€” creation of new centralised agency is in response to changing regional security environment.

46.5 Middle East

๐Ÿ‡ฎ๐Ÿ‡ฑ Israel โ€” Click to expand

Digital Landscape

Internet penetration ~90% (Central Bureau of Statistics 2024). Google dominates search. WhatsApp is the dominant messaging app (~80% of smartphone users); Telegram has significant penetration. X, LinkedIn, Facebook, Instagram are the main social platforms. Israel has one of the world's most advanced cybersecurity and OSINT ecosystems (Check Point, NSO Group, Cellebrite, Cobwebs, Toka).

Intelligence Agency & OSINT Tradecraft

  • External intelligence agency: The Mossad (HaMossad leModi'in uleTafkidim Meyuchadim) โ€” https://www.mossad.gov.il/eng โœ….
  • Internal security service: Shabak / Israel Security Agency (ISA) โ€” https://www.shabak.gov.il.
  • Signals intelligence: Unit 8200 (military intelligence unit under IDF).
  • OSINT unit / tradecraft: Israel does not publicly detail OSINT directorates. Unit 8200 is widely understood to have sophisticated OSINT capabilities alongside SIGINT, but specific tradecraft is classified.
  • Publicly verifiable tradecraft points:
    • Israel's intelligence community is the subject of extensive academic and journalistic coverage (Ronen Bergman's Rise and Kill First, 2018 โ€” public source).
    • Bellingcat Israel/Palestine investigations โ€” https://www.bellingcat.com/category/regions/mena/israel-palestine/ โ€” demonstrate OSINT methodology applied to the region.
  • What is NOT verified (myth-busting):
    • "Mossad taught the CIA everything" โ€” this is myth; both agencies developed independently with periods of cooperation and competition.
    • "Unit 8200 produces all cybersecurity CEOs" โ€” many Israeli cybersecurity founders are Unit 8200 alumni, but this is correlation not causation; many non-alumni are also successful.
    • Specific Mossad operations depicted in films (Munich, Operation Finale) are dramatised versions of real events; do not treat dramatisations as accurate tradecraft.

Government Sources (Verified URLs)

SourceURLFunctionStatus
Israel Companies Registrarhttps://ica.justice.gov.ilCorporate registryโœ… 200
Nevo (legal database)https://www.nevo.co.ilCourt decisions, official publicationsโœ… 200
data.gov.ilhttps://data.gov.ilGovernment open dataโœ… 200
Israel Land Authorityhttps://mmi.gov.ilLand registryโš ๏ธ Timeout
Bank of Israelhttps://www.boi.org.ilCentral bankโœ… 200
Knessethttps://main.knesset.gov.ilParliamentary recordsโš ๏ธ Timeout

Local Sources & Press

Country-Specific OSINT Tools

  • Israel Companies Registrar (ica.justice.gov.il) โ€” corporate registry.
  • Nevo โ€” comprehensive legal database.
  • data.gov.il โ€” government open data.
  • FakeReporter โ€” disinformation tracking.
  • B'Tselem โ€” human rights documentation.
  • +972 Magazine โ€” independent journalism.
  • Privacy Protection Law (1981, amended 2017) โ€” Israel's data protection law. Regulated by the Privacy Protection Authority (PPA).
  • Freedom of Information Law (1998) โ€” Israeli FOIA.
  • Military censorship: Israel has a military censor with authority to review certain publications related to national security. Investigators should be aware of this if publishing on military affairs.
  • Defamation: Strong defamation laws; criminal defamation is theoretically possible but rare.
  • OPSEC: Israel is an active conflict zone; investigators should follow government safety guidelines.

Notable Cases

๐Ÿ‡ฎ๐Ÿ‡ท Iran โ€” Click to expand

Digital Landscape

Internet penetration ~84% (StatCounter 2024), but the internet is heavily filtered and slowed. Google, WhatsApp, Instagram and Telegram are the main platforms but are subject to frequent throttling and blocking. Telegram is the primary source of news for many Iranians (~50 million users pre-2022 blocking; many now use VPN). Domestic platforms include Eitaa, Bale, and Soroush (state-promoted alternatives). The 2022 Mahsa Amini protests saw near-total internet blackouts.

Intelligence Agency & OSINT Tradecraft

Government Sources (Verified URLs)

SourceURLFunctionStatus
Iranian Companies Registrationhttp://www.irsherkat.ssc.irCorporate registryโš ๏ธ Timeout
Official Gazettehttp://www.rrk.irOfficial gazetteโš ๏ธ Timeout
Iran Open Datahttps://iranopendata.orgOpen data portalโœ… 200
Central Bank of Iranhttps://www.cbi.irCentral bankโš ๏ธ Timeout

Note: Iranian government portals are intermittently accessible from outside Iran. Use Iranian diaspora sources for verification.

Local Sources & Press

Country-Specific OSINT Tools

  • Iran International โ€” exile news with OSINT investigations.
  • IranWire โ€” exile journalism.
  • Iran Open Data โ€” https://iranopendata.org โ€” open data portal.
  • Center for Human Rights in Iran โ€” human rights documentation.
  • Telegram channels โ€” primary source for real-time OSINT on Iranian events.
  • HackerTen โ€” Iranian hacker community tracker.
  • Computer Crimes Law (2009) โ€” criminalises "spreading lies" online, posting content against the state.
  • Press Law (1986) โ€” restricts journalism; licenses required.
  • No GDPR-equivalent: Iran has limited personal data protection.
  • OPSEC: Iranian intelligence actively targets diaspora investigators and journalists. Documented cases of kidnapping and assassination plots. Use sock puppets, VPN, encrypted communications. Do not contact sources via Iranian platforms (monitored).
  • Sanctions: Iran is under comprehensive US, EU sanctions. Any interaction with Iranian entities may violate sanctions.

Notable Cases

  • Mahsa Amini protests (2022). Extensive OSINT documentation of protests and repression, despite internet blackouts. NGOs like HRANA and Iran Human Rights compiled casualty lists using OSINT.
  • Charming Kitten exposure (2024). Iran International exposed the IRGC surveillance unit behind targeting of dissidents.
๐Ÿ‡ธ๐Ÿ‡ฆ Saudi Arabia โ€” Click to expand

Digital Landscape

Internet penetration ~99% (CITC 2024, one of the highest in the world). Google dominates search. WhatsApp is the dominant messaging app; Snapchat is unusually popular (~20 million users). X (Twitter) is the main platform for political discourse. The Saudi government has invested heavily in Vision 2030 digital transformation.

Intelligence Agency & OSINT Tradecraft

  • Main intelligence agency: General Intelligence Presidency (GIP, Ri'asat al-Istikhbarat al-'Amma) โ€” no public English website. URL: https://www.gip.gov.sa (intermittent).
  • State Security: Presidency of State Security (PSS) โ€” established 2017 to oversee counter-terrorism and domestic intelligence.
  • Cyber operations: Saudi Arabia has built up cyber capabilities; the National Cybersecurity Authority (NCA) regulates and oversees cyber defence.
  • OSINT unit / tradecraft: GIP uses OSINT for monitoring domestic and regional opposition. Specific tradecraft is classified.
  • Publicly verifiable tradecraft points:
  • What is NOT verified: Specific GIP tradecraft details are not publicly available.

Government Sources (Verified URLs)

SourceURLFunctionStatus
Ministry of Commercehttps://mc.gov.saBusiness registryโš ๏ธ Timeout
Umm Al-Qura (official gazette)https://www.ummulqura.org.saOfficial gazetteโœ… 200
SDAIA Open Datahttps://www.sdaia.gov.sa/enOpen data portalโš ๏ธ Timeout
Saudi Open Data Portalhttps://data.gov.saOpen data portalโš ๏ธ Timeout
Saudi Stock Exchange (Tadawul)https://www.saudiexchange.saStock exchangeโš ๏ธ Timeout

Local Sources & Press

  • Quality press: Arab News, Asharq Al-Awsat, Al Arabiya, Al Hadath, Saudi Gazette.
  • Investigative NGOs: ALQST (https://alqst.org, human rights), Democracy for the Arab World Now (DAWN, https://dawnmena.org).
  • OSINT community: Limited due to political restrictions; most Saudi OSINT analysis is done by exile organisations.

Country-Specific OSINT Tools

  • Ministry of Commerce business registry โ€” corporate lookup.
  • Umm Al-Qura โ€” official gazette.
  • Saudi Open Data Portal โ€” government data.
  • ALQST โ€” human rights documentation.
  • DAWN โ€” advocacy and documentation.
  • Anti-Cyber Crime Law (2007) โ€” broad provisions criminalising "production, preparation, transmission, or storage of material impinging on public order, religious values, public morals, and privacy".
  • Personal Data Protection Law (PDPL, 2021, amended 2023) โ€” Saudi Arabia's data protection law. Regulated by SDAIA.
  • Counter-Terrorism Law (2017) โ€” broad provisions used against dissidents and investigators.
  • OPSEC: Saudi Arabia has documented history of targeting dissidents abroad (Khashoggi case). Investigators should use sock puppets, VPN, encrypted communications. Avoid travel to Saudi Arabia if investigating sensitive topics.
  • Defamation: Criminal defamation with prison sentences; blasphemy punishable by death.

Notable Cases

๐Ÿ‡น๐Ÿ‡ท Turkey โ€” Click to expand

Digital Landscape

Internet penetration ~83% (BTK 2024). Google dominates search; Yandex has ~20% market share. WhatsApp is the dominant messaging app (~75% of smartphone users); Telegram is widely used. X (Twitter) is the primary political discourse platform (~16 million users); YouTube, Instagram, Facebook, TikTok are major platforms. Turkey has a vibrant but heavily pressured media ecosystem.

Intelligence Agency & OSINT Tradecraft

  • Main intelligence agency: Millรฎ ฤฐstihbarat TeลŸkilatฤฑ (MIT, National Intelligence Organization) โ€” https://www.mit.gov.tr โš ๏ธ Timeout.
  • Military intelligence: Intelligence Department of General Staff (now under Ministry of National Defence).
  • OSINT unit / tradecraft: MIT has an OSINT branch. Turkish intelligence has been documented using OSINT to identify coup plotters, Kurdish activists, and Gรผlen movement members.
  • Publicly verifiable tradecraft points:
    • MIT's legal basis is Law No. 2937 on the State Intelligence Services and the National Intelligence Organization (https://www.mevzuat.gov.tr/mevzuatmetin/1.5.2937.pdf).
    • Turkey has been documented using Pegasus spyware (Citizen Lab reports).
    • MIT informant leaks (2020-2022) โ€” Nordic Monitor (https://nordicmonitor.com) published leaked MIT documents revealing OSINT-based targeting of dissidents abroad.

Government Sources (Verified URLs)

SourceURLFunctionStatus
MERSฤฐS (Central Registry System)https://www.mersis.gov.trBusiness registryโš ๏ธ Timeout
e-Devlet (e-Government)https://www.turkiye.gov.trGovernment services portalโœ… 200
Trade Registry Gazettehttps://tobb.org.trChamber of commerceโœ… 200
Resmi Gazetehttps://www.resmigazete.gov.trOfficial gazetteโœ… 200
TUฤฐKhttps://www.tuik.gov.trStatistics instituteโœ… 200

Local Sources & Press

  • Quality press (pro-government): Sabah, Daily Sabah (English), Yeni ลžafak, Anadolu Agency (state news).
  • Quality press (independent/opposition): Sรถzcรผ, Cumhuriyet, BirGรผn, Diken, T24, Artฤฑ Gerรงek (https://artigercek.com).
  • Investigative NGOs: P24 (Platform for Independent Journalism, https://p24.com.tr), Stockholm Center for Freedom (https://stockholmcf.org, exile), Nordic Monitor (https://nordicmonitor.com, exile).
  • OSINT community: Limited due to political pressure; exile OSINT communities like SCF and Nordic Monitor fill the gap.

Country-Specific OSINT Tools

  • MERSฤฐS โ€” Central Registry System for business lookup.
  • e-Devlet โ€” government services portal (requires Turkish ID).
  • Trade Registry Gazette โ€” official commercial announcements.
  • Resmi Gazete โ€” official gazette.
  • Nordic Monitor โ€” leaked MIT documents.
  • Stockholm Center for Freedom โ€” exile human rights documentation.
  • Personal Data Protection Law (KVKK, 2018) โ€” Turkey's data protection law. Regulated by KVKK Authority.
  • Law on the Right to Information (2003) โ€” Turkish FOIA.
  • Anti-Terror Law (1991) โ€” broad provisions used against journalists and investigators.
  • Disinformation law (October 2022) โ€” criminalises "disinformation" with up to 3 years imprisonment.
  • OPSEC: Turkey has documented history of targeting dissidents abroad (kidnappings of Gรผlenists). Investigators should use sock puppets, VPN, encrypted communications.
  • SLAPP risk: High. Turkey is one of the world's largest jailers of journalists.

Notable Cases

  • 2016 coup attempt investigation โ€” MIT used OSINT to identify coup plotters; thousands were arrested based on this analysis.
  • Nordic Monitor MIT leaks (2020-2022) โ€” exposed MIT informant network and targeting of dissidents abroad. URL: https://nordicmonitor.com.

46.6 Oceania

๐Ÿ‡ฆ๐Ÿ‡บ Australia โ€” Click to expand

Digital Landscape

Internet penetration ~91% (ABS 2024). Google dominates search. WhatsApp, iMessage, Messenger dominate messaging. X, LinkedIn, Facebook, Instagram, Reddit are the main social platforms. Australia has a strong OSINT and intelligence studies community (ASPI, Australian National University, ANU National Security College).

Intelligence Agency & OSINT Tradecraft

Government Sources (Verified URLs)

SourceURLFunctionStatus
ABN Lookuphttps://abr.business.gov.auAustralian Business Registerโœ… 200
ASIC Connecthttps://connectonline.asic.gov.auBusiness registryโœ… 200
data.gov.auhttps://data.gov.auGovernment open dataโœ… 200
Federal Register of Legislationhttps://www.legislation.gov.auLegislation databaseโœ… 200
Australian Business Registerhttps://abr.business.gov.auABN lookupโœ… 200

Local Sources & Press

  • Quality press: ABC (Australian Broadcasting Corporation, https://www.abc.net.au โœ…), The Guardian Australia (https://www.theguardian.com/au), Sydney Morning Herald (https://www.smh.com.au), The Age, The Australian.
  • Investigative NGOs: Australian Strategic Policy Institute (ASPI, https://www.aspi.org.au), International Consortium of Investigative Journalists (ICIJ, Australian involvement).
  • OSINT community: ASPI, Australian National University National Security College, OSINT Australia community.

Country-Specific OSINT Tools

  • Privacy Act 1988 โ€” Australia's federal data protection law. Regulated by Office of the Australian Information Commissioner (OAIC).
  • Freedom of Information Act 1982 โ€” federal FOIA.
  • Defamation law (reformed 2021) โ€” added "serious harm" threshold; anti-SLAPP provisions in some states.
  • OPSEC: Generally safe environment for investigators.

Notable Cases

  • ASPI Xinjiang Data Project (2020). Mapped 380+ detention camps in Xinjiang using satellite imagery, government procurement documents, and leaked construction bids. URL: https://xjdp.aspi.org.au
  • Australian SIGNT/OSINT investigation into MH17 โ€” ASD contributed OSINT to the joint investigation.

47. Corporate OSINT Tradecraft

Public methodology of leading OSINT / threat intelligence companies. Each section below distils the publicly documented methodology from vendor blogs, reports and academic case studies. Marketing claims are flagged explicitly. Workflows are descriptive of what the company publishes โ€” they are not leaks of internal SOPs.

47.1 Tier 1 Vendors

Bellingcat (Investigative Journalism NGO)

Briefing: Independent, Netherlands-based investigative journalism NGO founded 2014 by Eliot Higgins. Uses open-source and social-media content (photos, videos, satellite imagery, leaked databases, flight records, court filings) to investigate armed conflicts, human-rights abuses, state-sponsored assassinations and environmental crimes. Operates a small staff plus a global network of volunteer researchers; publishes its tools and methods openly. Combines geolocation, chronolocation, content verification and structured cross-referencing of leaked or paid-data sources.

Landmark public cases (with verifiable URLs):

  1. MH17 downing (2014-2017) โ€” linked the Buk missile launcher to the Russian 53rd Anti-Aircraft Missile Brigade.
  2. Skripal poisoning (2018) โ€” identified Salisbury suspects as GRU officers Chepiga and Mishkin.
  3. Navalny poisoning (2020) โ€” identified the FSB chemical-weapons team.
  4. Bucha/Ukraine monitoring (2022-) โ€” real-time verification of civilian casualties.

Reproducible 12-step methodology (as published):

  1. Define the question and the verifiable hypothesis.
  2. Collect primary open sources โ€” Telegram, VK, X, passenger manifests, leaked phone-call metadata, satellite imagery, court records. Bellingcat explicitly relies on the Russian "probiv" data market (Telegram bots returning passport/phone/vehicle records).
  3. Cross-reference every single data point against a second source.
  4. Use leaked databases as anchor sources โ€” they are immutable snapshots that cannot be retroactively edited.
  5. Pivot on travel records โ€” examine passenger manifests of parallel flights (one day earlier/later).
  6. Pivot on phone records โ€” list every number called; reverse-lookup each (GetContact, Telegram bots).
  7. Use address and vehicle registration to identify employer โ€” when an FSB/GRU officer registers a vehicle at a government facility, enumerate every other vehicle at that address (Bellingcat found 191).
  8. Use parking-payment databases for geolocation.
  9. Reverse-engineer alias-generation patterns โ€” FSB/GRU algorithm: same first name, same day/month of birth (year shifted ยฑ1), last name = wife's/girlfriend's maiden name.
  10. Geolocate imagery when needed โ€” Yandex Images, Google Lens, SunCalc, Google Earth, Mapillary.
  11. Cluster suspects by repeated co-travel and communication โ€” graph of who communicated with whom, who flew with whom, who shared addresses.
  12. Publish the full evidence chain โ€” methodology, screenshots, redacted raw data, names โ€” alongside partner outlets (The Insider, CNN, Der Spiegel) for auditability.

Tools Bellingcat publicly mentions:

  • Bellingcat Online Investigation Toolkit (https://bellingcat.gitbook.io/toolkit)
  • Telegram probiv bots (paid, grey-market)
  • GetContact, Yandex Maps/Images, Google Earth Pro, Sentinel Hub, Copernicus EMS, NASA FIRMS, SunCalc, FlightRadar24, ADS-B Exchange, OpenSky Network, OpenCorporates, Wayback Machine, archive.today, Hunchly, InVID-WeVerify, FotoForensics, Forensically, Maltego, Spiderfoot, theHarvester.

Limitations & ethics:

  • Reliance on Russian grey-market data. Bellingcat explicitly acknowledges the privacy and ethics concerns of buying leaked phone records and passport files; the practice would be illegal in most Western jurisdictions (GDPR).
  • Geographic bias. Strongest cases involve Russia, Syria, Ukraine โ€” regions with porous data protection and active conflicts. China, North Korea and Iran are far harder.
  • NGO, not forensic lab. Their findings are journalistic conclusions, not chain-of-custody evidence admissible in court without corroboration.
  • Volunteer model means variable quality control; the editorial team applies the same 12-step cross-referencing standard before publication.

Mandiant (Google Cloud)

Briefing: Mandiant was acquired by Google in September 2022 for $5.4B and is now part of Google Threat Intelligence (GTI). Its methodology is incident-response-led threat-actor clustering using the UNC (UNCategorized) taxonomy. Novel malicious activity is grouped into a temporary UNC#### cluster; when enough TTP, infrastructure and code overlap accumulates, the cluster is merged into an existing named group (APT## for state-sponsored, FIN## for financially motivated).

Landmark public cases (with verifiable URLs):

  1. SolarWinds / UNC2452 โ†’ APT29 (2020-2021). https://cloud.google.com/blog/topics/threat-intelligence/unc2452-merged-into-apt29
  2. M-Trends 2025 annual report โ€” Mandiant tracked 302 different threat groups in 2024. PDF: https://services.google.com/fh/files/misc/m-trends-2025-en.pdf
  3. APT groups catalogue: https://cloud.google.com/security/resources/insights/apt-groups
  4. Trade-Offs of Cyber Attribution (methodology paper): https://cloud.google.com/blog/topics/threat-intelligence/trade-offs-attribution

Public 12-step workflow (reconstructed from public blog posts):

  1. Triage an incident / sample submission. A new artefact enters via Mandiant Consulting IR engagements, the VirusTotal corpus, or Google telemetry. Compute hashes, extract strings, run YARA rules.
  2. Pivot through VirusTotal Graph. Walk from the artefact to related files, URLs, contact domains and IPs that share behaviour, submission timing or first-seen dates.
  3. Cluster the activity into a UNC. If the TTPs do not match an existing named group, a new UNC#### designator is created.
  4. Accumulate evidence over time. Overlap dimensions: code sharing, infrastructure reuse (registrant info, SSL certs, ASN patterns), victimology, attack lifecycle, timing.
  5. Apply the Suspected/Possible confidence scale. Analysts score overlaps as Possible Association (weak) or Suspected Association (strong). https://gtidocs.virustotal.com/docs/suspected-attribution
  6. Test the merge hypothesis. Compare the UNC against every named APT## / FIN## in the catalogue.
  7. Peer-review within Mandiant Intelligence. Other analysts challenge the merge โ€” looking for counter-evidence (tool sharing between unrelated groups, false-flag indicators).
  8. Publish attribution with confidence label. Mandiant reports use "assessed with high/moderate/low confidence" language aligned with ICD-203.
  9. Public merge announcement. When attribution is final, Mandiant publishes a blog post announcing the merge.
  10. Update YARA rules and detection content. IOCs, YARA, STIX/TAXII feeds updated.
  11. Brief IR consultants and customers.
  12. Re-evaluate periodically. If new evidence contradicts the merge, Mandiant can split the cluster again.

Tools Mandiant publicly mentions:

  • VirusTotal (public + Enterprise), VirusTotal Graph, Mandiant Advantage, Google Chronicle / Google Security Operations, YARA, FLARE-VM, capa, Google telemetry (Gmail, Chrome Safe Browsing, Android Play Protect).

Limitations:

  • Product-vs-research blur. Public reports mix commercial positioning with actual methodology.
  • Confidence is explicitly graded. Mandiant does not claim 100% attribution.
  • VirusTotal dataset bias. VT submissions skew Western; actors who avoid AV and submission to VT are under-represented.
  • Acquisition friction. Pre-2022 Mandiant publications (Equation Group, APT1, FIN7) were produced when Mandiant was independent; post-acquisition work is integrated with Google telemetry.

CrowdStrike

Briefing: Endpoint protection + threat intelligence company famous for the adversary naming convention where every tracked actor gets a name composed of an animal + a weather/event term: BEAR (Russia), PANDA (China), SPIDER (eCrime), KITTEN (Iran), CHOLLIMA (North Korea), HAWK (India). CrowdStrike's methodology is centred on Falcon endpoint telemetry + analyst cells.

Landmark public cases:

  1. DNC hack (2016). CrowdStrike attributed the breach to FANCY BEAR (APT28) and COZY BEAR (APT29).
  2. Fancy Bear Ukrainian artillery (2016). https://www.crowdstrike.com/blog/bears-midst-intrusion-disclosure/
  3. Global Threat Report (annual). https://www.crowdstrike.com/en-us/global-threat-report/

Public 10-step attribution methodology:

  1. Falcon telemetry ingestion โ€” endpoint sensors collect process, network, file, registry events.
  2. ML + analyst cells triage โ€” machine learning flags suspicious patterns; human analysts review.
  3. Activity clustering โ€” group observed activity into clusters based on shared TTPs.
  4. Geopolitical overlay โ€” apply country attribution based on victimology, language indicators, working hours.
  5. Adversary naming โ€” assign a new name (BEAR/PANDA/SPIDER/KITTEN/CHOLLIMA/HAWK + suffix).
  6. Peer review โ€” other analysts challenge the attribution.
  7. Independent verification policy โ€” CrowdStrike publishes enough detail for independent verification.
  8. Publish adversary profile โ€” full TTPs, IOCs, MITRE ATT&CK mapping.
  9. Update detection content โ€” Falcon platform updated to detect the new adversary.
  10. Adversary Universe โ€” public web page documenting all tracked adversaries. https://www.crowdstrike.com/en-us/adversaries/

Limitations:

  • Endpoint bias โ€” CrowdStrike's visibility is endpoint-centric; network-only attacks may be missed.
  • Marketing of "Adversary Universe" โ€” branding on real process; the methodology is real but the public site is partly marketing.
  • Naming complexity โ€” same actor = FANCY BEAR / APT28 / Forest Blizzard / Strontium / Sofacy / Pawn Storm / Sednit. The 2025 Microsoft-CrowdStrike shared glossary (https://www.crowdstrike.com/blog/crowdstrike-microsoft-naming-glossary/) is an attempt to harmonise.

Recorded Future

Briefing: Threat intelligence platform using NLP + machine learning over OSINT masivo. The Insikt Group is the research arm. Markets the "centaur model" (human + AI) and the "Intelligence Graphยฎ" (trademarked marketing terms wrapping real methodology).

Landmark public cases:

  1. Insikt Group research portal โ€” https://www.recordedfuture.com/research
  2. Iran AI report โ€” Recorded Future's research on Iranian AI capabilities.
  3. CopyCop disinformation โ€” analysis of an AI-generated disinformation network.

Public 4-pillar methodology (per Insikt Group's published description):

  1. Infrastructure detection and pivoting โ€” auto-detection of malicious infrastructure, pivot to related domains/IPs.
  2. Victim identification โ€” automatic identification of victims from breach reports, dark web posts.
  3. Network traffic analysis โ€” analyse C2 traffic patterns.
  4. Multi-source validation โ€” the centaur model: AI proposes, human analyst verifies.

Output formats: 7 standard formats โ€” Intelligence Brief, Full Report, Flash Report, Special Report, Cyber Daily newsletter, Weekly Cyber Exploits, Monthly Threat Forecast.

Limitations:

  • Enterprise pricing ($$$) โ€” Recorded Future platform is enterprise-priced. Recommend the free Community Edition only as a teaser, not a working tool.
  • "Centaur model" and "Intelligence Graphยฎ" are trademarked marketing terms wrapping real methodology.
  • AI bias โ€” NLP models can amplify biased sources if training data skews Western.

47.2 Tier 2 Vendors

Google Threat Intelligence (GTI / ex-Mandiant + VirusTotal)

Briefing: Unified commercial brand launched April 2024 after folding together Chronicle (cloud-native SIEM, 2018), VirusTotal (acquired by Google in 2012, >2 billion analysed files/URLs/domains/IPs) and Mandiant (acquired September 2022). GTI's research methodology is essentially Mandiant's methodology โ€” IR-led threat-actor clustering using the UNC taxonomy.

Public emblematic cases:

  1. SolarWinds / UNC2452 โ†’ APT29 โ€” https://cloud.google.com/blog/topics/threat-intelligence/unc2452-merged-into-apt29
  2. M-Trends 2025 โ€” https://services.google.com/fh/files/misc/m-trends-2025-en.pdf
  3. APT groups catalogue โ€” https://cloud.google.com/security/resources/insights/apt-groups
  4. Suspected Attribution API โ€” https://gtidocs.virustotal.com/docs/suspected-attribution

Methodology: Same as Mandiant (see above) + Google's corpus (VT + Gmail + Chrome + Android telemetry) as the corroborating evidence base.

Useful public resources:

ResourceURL
Google Cloud TI bloghttps://cloud.google.com/blog/topics/threat-intelligence
M-Trends 2025 PDFhttps://services.google.com/fh/files/misc/m-trends-2025-en.pdf
APT groups cataloguehttps://cloud.google.com/security/resources/insights/apt-groups
GTI documentation portalhttps://gtidocs.virustotal.com/
VirusTotal (free)https://www.virustotal.com/
Mandiant GitHub (open-source tools)https://github.com/mandiant

Microsoft Threat Intelligence (MSTIC)

Briefing: In-house research team that tracks nation-state and criminal actors across Microsoft's vast telemetry surface โ€” Windows, Office 365 email, Azure, Microsoft Defender for Endpoint, LinkedIn, Bing and Xbox. According to the 2024 Microsoft Digital Defense Report, MSTIC observes ~600 million cyberattacks per day.

Adversary naming convention (2 eras):

  • 2015-April 2023: Chemical elements (typosquatted) โ€” Strontium (APT28), Nobelium (APT29), Zinc, Chromium, Thallium, Hafnium, Phosphorus, Bismuth. Microsoft deliberately misspelled real chemical element names so they could register matching domains/handles without impersonating the real-element websites.
  • April 2023-present: Weather taxonomy โ€” Russian actors = * Blizzard, Chinese = * Typhoon, Iranian = * Sandstorm, Lebanese = * Rain, North Korean = * Sleet, Indian = * Hawk. Replaced the element scheme for clarity.

Public emblematic cases:

  1. SolarWinds / NOBELIUM / APT29 (2020-2021) โ€” MSTIC was the first to publicly name the actor.
  2. Volt Typhoon (2023) โ€” Chinese critical-infrastructure targeting disclosure.
  3. Forest Blizzard / APT28 (2024) โ€” Russian military intelligence.
  4. Microsoft Digital Defense Report 2024 โ€” https://www.microsoft.com/en-us/security/business/microsoft-digital-defense-report-2024
  5. MS-CrowdStrike shared naming glossary (2025) โ€” https://www.crowdstrike.com/blog/crowdstrike-microsoft-naming-glossary/

Public 12-step workflow (reconstructed from MSTIC blog posts):

  1. Telemetry ingestion from Windows, O365, Azure, Defender, LinkedIn, Bing, Xbox.
  2. ML + analyst triage โ€” anomaly detection, then human review.
  3. MITRE ATT&CK mapping โ€” map observed TTPs to ATT&CK techniques.
  4. Country assessment โ€” based on victimology, language, working hours, infrastructure.
  5. Weather naming โ€” assign a name based on country of origin + weather phenomenon.
  6. Government coordination โ€” MSTIC frequently discloses nation-state activity in coordination with US government (CISA, FBI).
  7. Publish technical blog post with IOCs, YARA, detection queries.
  8. Update Defender detections โ€” push detection content to Defender for Endpoint customers.
  9. Brief government partners โ€” CISA, NSA, FBI.
  10. Publish Digital Defense Report โ€” annual public summary.
  11. Update threat actor encyclopedia โ€” https://learn.microsoft.com/en-us/defender/threat-intelligence/.
  12. Re-evaluate periodically โ€” splits/merges as evidence accumulates.

Limitations:

  • Naming churn โ€” chemicalโ†’weather (April 2023) caused industry confusion.
  • US-gov alignment appearance โ€” MSTIC's nation-state disclosures often align with US foreign policy; this is correlation (shared goals) but critics see it as politicisation.
  • Marketing vs research blur โ€” Digital Defense Report mixes commercial positioning with actual research.

Useful public resources:

ResourceURL
Microsoft Security bloghttps://www.microsoft.com/en-us/security/blog
Digital Defense Report 2024https://www.microsoft.com/en-us/security/business/microsoft-digital-defense-report-2024
MSTIC threat actor encyclopediahttps://learn.microsoft.com/en-us/defender/threat-intelligence/
MSRC (Microsoft Security Response Center)https://msrc.microsoft.com/

Cisco Talos

Briefing: Cisco's threat intelligence team. Specialises in malware analysis, threat hunting, and network intelligence. Publishes daily blog posts and an annual Year in Review.

Public emblematic cases:

  1. Cisco Talos 2025 Year in Review โ€” https://blog.talosintelligence.com/
  2. Threat Hunting programme โ€” public methodology posts.
  3. GhIDA โ€” Ghidra + IDA Pro integration tool (open source).
  4. LLM-as-RE-sidekick โ€” research on using LLMs in reverse engineering.
  5. Cisco Live BRKSEC-2884 โ€” public threat-hunting training.

Public 12-step workflow (reconstructed from Talos blog posts):

  1. Sample intake โ€” from Cisco Secure endpoints, customer IR engagements, VirusTotal, spam traps.
  2. Static triage โ€” hash check, strings, imports, sections.
  3. Sandbox detonation โ€” ThreatGrid (Cisco's sandbox) analysis.
  4. Umbrella network pivot โ€” use Cisco Umbrella DNS data to find related domains/IPs.
  5. IDA Pro + Ghidra RE โ€” deep reverse engineering with GhIDA integration.
  6. Behavioural analysis โ€” dynamic analysis in VM, API call tracing.
  7. Snort/ClamAV signature creation โ€” write detection rules.
  8. Threat brief publication โ€” blog post at blog.talosintelligence.com.
  9. Year in Review โ€” annual summary report.
  10. Customer push โ€” push detections to Cisco Secure customers.
  11. Open-source tool release โ€” tools like GhIDA published to GitHub.
  12. Re-evaluate periodically โ€” track malware family evolution.

Limitations:

  • Network-edge bias โ€” Talos visibility is network-centric (Cisco routers, firewalls); endpoint-only attacks may be under-represented.
  • Commercial tie-ins โ€” Talos reports often reference Cisco Secure products.

Useful public resources:

ResourceURL
Talos bloghttps://blog.talosintelligence.com/
Talos Year in Reviewhttps://blog.talosintelligence.com/year-in-review/
Talos GitHubhttps://github.com/Cisco-Talos

Kaspersky GReAT (Global Research & Analysis Team)

Briefing: Kaspersky's elite research team responsible for tracking the most sophisticated APTs (Stuxnet, Flame, Equation Group). Publishes on Securelist (https://securelist.com).

Public emblematic cases:

  1. Stuxnet (2010) โ€” analysis of the first cyber-physical weapon. https://securelist.com/stuxnet-zero-victims/67483/
  2. Flame (2012) โ€” discovery of a sophisticated espionage toolkit. https://securelist.com/the-flame-questions-and-answers/34344/
  3. Gauss (2012) โ€” discovery of nation-state banking malware. https://securelist.com/gauss-nation-state-cyber-espionage-banking-trojan/36620/
  4. Equation Group (2015) โ€” Q&A PDF documenting the most sophisticated APT group yet discovered. https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07205555/Equation_group_questions_and_answers.pdf
  5. Securelist RE workshop โ€” public training materials.

Public 12-step workflow (reconstructed from Securelist publications):

  1. KSN (Kaspersky Security Network) telemetry โ€” telemetry from Kaspersky endpoint products worldwide.
  2. Victimology analysis โ€” identify targeted victims, geographic and sectoral patterns.
  3. Static analysis โ€” hash, strings, imports, sections.
  4. Unpacking โ€” multi-stage unpacking for packed malware.
  5. Behavioural analysis โ€” dynamic analysis in sandbox.
  6. IDA Pro / Binary Ninja / Ghidra RE โ€” deep reverse engineering.
  7. Decompilation โ€” high-level reconstruction of malware logic.
  8. C2 protocol analysis โ€” reverse-engineer command-and-control protocol.
  9. Capability analysis โ€” identify exploit payloads, lateral movement tools, persistence mechanisms.
  10. Clustering โ€” group malware samples into families based on code/infrastructure overlap.
  11. Cautious attribution โ€” Kaspersky is more conservative than US vendors in naming specific countries; uses "actor X" or "the malware's authors" rather than direct nation-state attribution.
  12. Securelist publication โ€” detailed technical blog post with IOCs, YARA, source code samples.

Limitations & controversies:

Useful public resources:

ResourceURL
Securelist (Kaspersky blog)https://securelist.com
Kaspersky threat intelligencehttps://www.kaspersky.com/enterprise-security/threat-intelligence
Kaspersky GTIhttps://gti.kaspersky.com
Kaspersky GitHub (open-source tools)https://github.com/kaspersky

47.3 Cross-Vendor Comparison

DimensionBellingcatMandiant/GTICrowdStrikeRecorded FutureMSTICTalosKaspersky
Primary disciplineVisual GEOINTIR-led threat intelEndpoint telemetryNLP on OSINTTelemetryNetwork + malwareRE + malware
Attribution methodPublic cross-refUNC clusteringAdversary namingCentaur modelWeather namingSample clusteringCautious, country-agnostic
Naming systemNoneAPT##/FIN##/UNC##BEAR/PANDA/SPIDERNone (uses others')Weather (was chemical)NoneNone (uses others')
ReproducibilityHigh (workflow published)Low (needs platform)Low (needs Falcon)Low (needs platform)Low (needs telemetry)MediumMedium
Geographic biasRussia/Syria/Ukraine strong; China/NK/Iran weakStrong WesternStrong WesternStrong WesternStrong WesternStrong WesternStrong Russia/Asia
Free tierAll toolkit freeVirusTotal freeAdversary Hub freeCommunity Edition (limited)Threat encyclopedia freeBlog freeSecurelist free
Government alignmentNone (NGO)US-aligned (post-acquisition)US-alignedUS-alignedUS-alignedUS-alignedRussian (controversial)

Appendix B. Structured Analytic Techniques (SATs)

Structured Analytic Techniques are mental tools to reduce analytical biases and produce more defensible conclusions. Popularised by Richards Heuer Jr. (Psychology of Intelligence Analysis, 1999) and by Heuer & Pherson (Structured Analytic Techniques for Intelligence Analysis, 3rd ed. 2020, CQ Press). These techniques are in the public domain of professional analytical literature โ€” they are not attributed to specific agencies.

B.1 ACH (Analysis of Competing Hypotheses)

What it is: Systematic method to evaluate multiple explanatory hypotheses against the same set of evidence, instead of seeking evidence for the preferred hypothesis. Combats confirmation bias.

When to use: When analysis has high consequences (strategic decisions, judicial conclusions, public conclusions that damage reputations) and multiple plausible hypotheses compete.

The 8 steps:

  1. List all plausible hypotheses (3-7) without premature discard. Force inclusion of 1-2 "unlikely" ones to avoid tunnel vision.
  2. List all significant evidence (facts, not inferences) + arguments.
  3. Build a hypothesis ร— evidence matrix. Rows = evidence. Columns = hypotheses.
  4. For each cell, evaluate consistency: + consistent ยท โˆ’ inconsistent ยท ? indeterminate. Crucial: evaluate whether the evidence is INCONSISTENT with the hypothesis, not whether it supports it. This inversion breaks confirmation bias.
  5. Refine the matrix: remove evidence that does not discriminate between hypotheses.
  6. Compute the "inconsistency score" per hypothesis. The hypothesis with FEWER inconsistencies is the most robust (NOT the most consistent).
  7. Analyse sensitivity: "What evidence, if false, would change the conclusion?"
  8. Report with uncertainty: do not eliminate alternative hypotheses, report them with their relative probabilities.

Minimum ACH template:

              | H1: fraud   | H2: error     | H3: external
              | intentional | accounting    | malicious
--------------|-------------|---------------|------------
E1: balancing |    โˆ’        |     +         |    ?
E2: timing    |    +        |     โˆ’         |    +
E3: motive    |    +        |     ?         |    +
E4: auditor   |    +        |     +         |    โˆ’
E5: access    |    +        |     +         |    โˆ’
--------------|-------------|---------------|------------
# Inconsistencies | 1       |     2         |    2
Conclusion:   | H1 most robust (fewest inconsistencies);
              | H3 plausible if E4 (auditor) breaks

B.2 Key Assumptions Check

What it is: Explicit identification of the unverified assumptions on which an analysis rests. Combats anchoring bias.

When to use: At the start of any non-trivial analysis. Prerequisite for ACH and Devil's Advocacy.

#AssumptionWhy I assumed itSource/EvidenceIf false, impact on conclusionAction to verify
1"Entity X is still active"Listed in registry 6 months agoLast queryChange of main hypothesisRe-query today
2"Identified UBO is correct"Listing in PSC RegisterCompanies HouseLower confidence overallCross-check ICIJ + adverse media
3"Applicable sanctions are EU"Client in EUContractRe-evaluate with OFAC/UKConfirm with client

Rules: minimum 5-8 assumptions per analysis ยท assign confidence High/Medium/Low ยท if โ‰ฅ2 assumptions are "Low", the overall conclusion cannot be "High Confidence" ยท review at the end of the analysis.

B.3 Devil's Advocacy

What it is: Designating a person (or role) to systematically criticise the dominant conclusion. Combats groupthink and premature closure.

How to implement individually:

  1. Assume the role explicitly. Write "Devil's Advocacy exercise" in the document.
  2. Identify 3-5 weak points in your own argument. Questions: What evidence do I NOT have? What alternative conclusion would explain the same data? What fails if my main source lied?
  3. Build the best possible counter-argument. Not a strawman โ€” a strong argument that an intelligent critic would build. If you cannot build it, you do not understand the case well enough.
  4. Honestly evaluate whether the counter-argument has merit. Modify conclusion or confidence if it does.
  5. Document in the deliverable: "Devil's Advocacy applied; alternative hypothesis X considered and rejected for Y / accepted partially, adjusting confidence from High to Moderate".

Traps: If it NEVER changes the conclusion, you are doing it wrong ยท Do not just aim at minor flaws, aim at the pillars.

B.4 Indicators & Warnings (I&W)

What it is: Monitoring system that defines in advance what observable signals would indicate a scenario is materialising. Enables early detection.

When to use: Continuous surveillance of scenarios (sanctions, internal fraud, geopolitical conflict, competitor reputational crisis).

SCENARIO MONITORED: "Entity X is sanctioned by OFAC within next 6 months"
INITIAL CONFIDENCE: Low (no active indicators)
MONITORING OWNER: [analyst]
REVIEW FREQUENCY: weekly

INDICATORS (in increasing specificity order):

Level 1 โ€” Background indicators (long duration, low specificity):
  [ ] Entity X appears in quality adverse media โ‰ฅ3 times in 30 days
  [ ] Entity X's main jurisdiction added to FATF grey list
  [ ] Close commercial partner of Entity X designated by OFAC

Level 2 โ€” Tactical indicators (medium specificity, weeks):
  [ ] Entity X changes auditor or correspondent bank without public reason
  [ ] Entity X transfers assets to risk jurisdiction (RUS, IRN, PRK)
  [ ] Civil litigation filed against Entity X in extraterritorial jurisdiction

Level 3 โ€” Strategic indicators (high specificity, days):
  [ ] US State Department issues statement mentioning Entity X
  [ ] OFAC publishes sector-specific guidance
  [ ] US Congress introduces legislation naming Entity X

ACTIVATION MATRIX:
  - 1 Level 1 indicator โ†’ re-evaluate Lowโ†’Moderate, daily monitoring
  - 2+ Level 1 or 1 Level 2 โ†’ Moderateโ†’High, deep DD
  - 1 Level 3 โ†’ High confidence of imminent designation; activate contingency plan

Principles: Indicators must be observable ยท Activation matrix defined BEFORE any indicator occurs ยท System has value only if reviewed at the committed frequency.


๐Ÿค Contribute

  1. Fork โžœ 2. Branch new-tool โžœ 3. PR with tested URL (screenshot mandatory)
    Read CONTRIBUTING.md before.

๐Ÿ“„ License

GPL-3 โ€“ Educational and research use. Don't be naughty.


ยซInformation wants to be free, but privacy wants to be respected.ยป
โ€” unknown