Compilation, procedures, tools and ethics for open source research
Command-line utilities · Link audit details
This repository is dedicated to the responsible and ethical practice of Open-Source Intelligence (OSINT). All information, tools, and methodologies provided herein are intended solely for educational, research, and lawful investigative purposes. Users are strongly encouraged to adhere to ethical guidelines, respect privacy rights, comply with applicable laws and regulations, and obtain necessary permissions before conducting any investigations. Misuse of this information for illegal activities, harassment, or violation of privacy is strictly prohibited and may result in legal consequences. By accessing this repository, you agree to use the content responsibly and ethically.
1. Fundamentals | 2. 4-Step Methodology | 3. Tools Mind Map | 11. Legal Considerations | 28. Professional Methodologies
4. Internet Search | 5. Social Networks | 6. GEOINT & Images | 7. Domain / IP / DNS | 15. Email/Phone Investigation | 17. Blockchain/Crypto | 18. Transport OSINT | 19. WiFi/Wardriving | 20. Content Verification | 21. Username Enumeration | 22. Web Scraping | 23. Metadata Extraction | 24. Network Scanning | 29. Advanced Google Dorks | 31. People Investigations | 32. Company Research
8. Deep & Dark Web | 16. Data Breaches | 25. Dark Web | 30. Learning Resources | 12. Extra Resources
9. Automation (Python) | 10. Report Templates | 13. AI Intelligence | 14. Facial Recognition | 26. All-in-One Frameworks | 27. Advanced Maltego
33. Threat Intelligence Feeds | 34. ICS/OT & Critical-Infrastructure OSINT | 35. AI Agent Skills & MCP
36. Financial OSINT | 37. Investigator OPSEC & Sock Puppets | 38. Cloud Storage OSINT | 39. Mobile App OSINT | 40. Decentralized Social OSINT | 41. Counter-OSINT Self-Audit | 42. Discord & Telegram OSINT 2026 | 43. Satellite OSINT 2026 | 44. C2PA + SynthID + Deepfake Detection 2026 | 45. Professional Templates & Deliverables | 46. Regional OSINT | 47. Corporate OSINT Tradecraft | Appendix B. Structured Analytic Techniques
Tip
Extend OSINT-BIBLE with the companion tools that fit your workflow:
- Operationalize its methodologies with osint-agent-skills.
- Investigate privately with Abster-Intelligence.
- Automate auditable workflows with agentic-harness.
| Concept | Quick Definition |
|---|---|
| OSINT | Intelligence obtained from public sources without violating logical or physical access |
| OPSEC | Minimize footprint: VPN → VM → alias → metadata strip |
| Intelligence Cycle | Direction → Collection → Processing → Analysis → Dissemination |
| PII | Information that identifies: email, phone, RFC, CURP, IP, IMEI, MAC |
| Primary Source | Original publication (tweet, official PDF, photo EXIF) |
| Secondary Source | Article citing the primary (validate) |
- Define question → What do I want to know?
- Identify sources → Table below |
- Collect → Manual + automations |
- Validate and document → Screenshots, hash, date, URL, archive.org |
| Data Type | Usual Location | Star Tool |
|---|---|---|
| Name | LinkedIn, Facebook | Maigret |
| Data breaches, newsletters | HIBP | |
| Phone | WhatsApp Business, TrueCaller | Infobel |
| Username | Forums, gaming, GitHub | Snoop |
| Photo | Geolocation, EXIF | Exiftool |
| Domain | WHOIS, certificates | Amass |
| IP | Scanning, Shodan | Shodan |
| Crypto wallet | Blockchain explorers | BlockCypher |
graph TD
A[OSINT] --> B(Search)
A --> C(Social Networks)
A --> D(Geo)
A --> E(Domain/IP)
A --> F(DeepDark)
A --> G(Automate)
B --> B1(Google Dorks)
B --> B2(Useful Dorks)
C --> C1(Twint-fork)
C --> C2(Maigret)
C --> C3(Instaloader)
D --> D1(Overpass-turbo)
D --> D2(Satellites.pro)
D --> D3(ExifTool)
E --> E1(Amass)
E --> E2(CRT.sh)
E --> E3(DNSDumpster)
F --> F1(Onionscan)
F --> F2(Ahmia)
G --> G1(Recon-ng)
G --> G2(SpiderFoot)
| Objective | Dork | Example |
|---|---|---|
| Government PDFs | site:gov filetype:pdf "contract" |
Mexico |
| Exposure | intitle:"index of" passwords.txt |
— |
| IP Cameras | inurl:viewer/live/index.html |
— |
| Emails | site:linkedin.com "@company.com" |
— |
| Subdomains | site:*.target.com -www |
— |
- DuckDuckGo "bangs" →
!archive - Yandex → best results CIS
- Baidu → Asia
- Startpage → no logs
- Shodan → IoT, ICS, SCADA
- Censys → cert + banner
- FOFA → China, free API
- BinaryEdge → global scanning
- Hunter.io → corporate emails
- PublicWWW → search in source code
- SearchCode → search in 75B lines of code
- SimilarSites → similar sites
- Netlas → internet intelligence
- CriminalIP → search in connected internet
- NerdyData → website technologies
- GreyNoise → internet noise
- Intezer Analyze → malware analysis
- Kaspersky OpenTIP → threat scanning
- VirusTotal → file/URL analysis
- AlienVault OTX → threat exchange
- ExploitDB → exploit database
- MalwareBazaar → malware samples
- Malware Domain List → malicious domains
- PhishTank → phishing URLs
- URLhaus → malware URLs
- YARAify → YARA rules
- PulseDive → IOC search
- ThreatFox → malware IOCs
- Breach Directory → breach searches
- Have I Been Pwned → breach verification
- DNSViz → DNSSEC visualization
- DNSdumpster → DNS enumeration
- SpyOnWeb → related sites
- Yark → archive YouTube
- CovertAction → investigative journalism
- Trellix Research → threat research
- CP Research → Checkpoint research
- Wikistrat → collaborative analysis
- PolySwarm → threat scanning
- HackerOne Hacktivity → public vulnerabilities
- WikiLeaks → leaked documents
- Talos Reports → vulnerability reports
- MalAPI → malware APIs
- UserSearch → user search
- SecureList → Kaspersky blog
- SPLC Hate Map → hate map
- ICSR → radicalization studies
- Militant Wire → militancy analysis
- START Publications → terrorism publications
- SPLC Resources → SPLC resources
- Tracking Terrorism → terrorism tracking
- Mapping Militants → mapping militants
- Naval Institute → naval news
- Institute of International Relations → international relations
- Janes → defense intelligence
- TASS News → Russian news
- Sputnik News → Sputnik news
- PIPS → Pakistan peace studies
- PICSS → Pakistan conflict studies
- Reuters → news agency
- RT → Russia Today
- InternetActivism → humanitarian tools
- IISS → international studies institute
- CFR → council on foreign relations
- SciHub → access to scientific papers
- ResearchHub → research discussion
- IDCrawl → people search
- Osint Industries → email/phone search
- ESPY → phone search
- SUNDERS → surveillance cameras
- Deepinfo → internet intelligence
- Session → private messaging
- Consortium News → independent journalism
- Tutanota → encrypted email
- Committee to Protect Journalists → journalist protection
- SecurityWeek → security news
- NCRI → network contagion research
- Geopolitical Economy Report → geopolitical reports
- The Grayzone → independent journalism
- FlightAware → flight tracking
- FlightRadar24 → flight radar
- MarineTraffic → maritime traffic
- VesselFinder → ship search
- NewspaperArchive → newspaper archives
- The Indian Express → Indian news
- Daily Excelsior → Jammu Kashmir news
- DNA India → Indian news
- Greater Kashmir → Kashmir news
- Nagaland Post → Nagaland news
- RFE/RL → Radio Free Europe
- Akto → API security
- Generated Photos → AI photos
- HDRobots → AI tools directory
- Channel 4 News → British news
- ThreatMon Reports → threat reports
- Israel Datasets → Israeli datasets
- AI Dubbing → AI dubbing
- Budget Key → Israel budget
- Ship Spotting → ship photos
- Broadcastify → police audio
- OpenCelliD → cell tower database
- AviationStack → aviation API
- DocumentCloud → document management
- IDRW → Indian defense
- XFE → X-Force exchange
- Scumware → malware research
- Ukraine Live Cams → Ukraine cameras
- TWN → webcam network
- Opentopia → public webcams
- Transparency → anti-corruption
- Maigret → user search
- OCCRP → organized crime
- Qdorks → dork generator
- Radio Garden → world radios
- LolArchiver OSINT → OSINT search
- BreachBase → breach base
- WorldCam → world webcams
- Webcam Galore → webcams
- WiFi Map → WiFi hotspots
- OpenTrafficCamMap → traffic cameras
- Skyline Webcams → skyline webcams
- Pictimo → world webcams
- Instances.social → Mastodon recommender
- CamHacker → public webcams
- Labs TIB Geoestimation → geographic estimation
- Picarta → photo location prediction
- Tiny Scan → URL scanning
- ZeroDay → zero-day vulnerabilities
- Predicta Search → digital search
- Ventusky → weather maps
- OSV → open source vulnerabilities
- Coalition ESS → exploit scoring
- Validin → attack surface mapping
- CIRCL PDNS → passive DNS
- InTheWild → exploits in wild
- 360 Quake → cyberspace mapping
- Cloudflare Radar → internet trends
- Crisis24 → security risk management
- arXiv → scientific papers
| Resource | Stars | Last push | What it adds |
|---|---|---|---|
| awesome-censys-queries | 1,244 | 2026-07 | Curated set of non-obvious Censys queries for asset discovery |
- Wayback Machine
- CachedView (Google + Archive.is)
- URLScan → capture + DOM + requests
- Ubikron → AI-powered evidence collection & entity extraction
- Screenshot Guru → screen test
- Stored Website → cached pages
- YARAify → YARA rules
- PulseDive → IOC search
- ThreatFox → malware IOCs
- Breach Directory → breaches
- Have I Been Pwned → breach verification
- DNSViz → DNSSEC
- DNSdumpster → DNS enumeration
- SpyOnWeb → related sites
- Yark → archive YouTube
- Facebook Recover Lookup - Link: Facebook Recover Lookup (requires a logged-in session) - Description: Used to check if a given email or phone number is associated with any Facebook account or not.
- Social Searcher - Link: Social Searcher - Description: Allows you to monitor all public social mentions in social networks and the web.
- Lookup-id.com - Link: Lookup-id.com - Description: Helps you find the Facebook ID of anyone's profile or a Group.
- Who posted this - Link: Who posted this - Description: Facebook keyword search for people who work in the public interest. It allows you to search keywords on specific dates.
- Facebook Search - Link: Facebook Search - Description: Allows you to search on Facebook for posts, people, photos, etc., using some filters.
- Facebook Graph Searcher - Link: Facebook Graph Searcher - Description: To search someone on Facebook.
- Facebook People Search - Link: Facebook People Search (HTTP 400 from automated link checks; confirm availability in a browser) - Description: Search on Facebook by victim's name.
- DumpItBlue - Link: DumpItBlue+ - Description: helps to dump Facebook stuff for analysis or reporting purposes.
- Export Comments - Link: Export Comments - Description: Easily exports all comments from your social media posts to Excel file.
- Facebook Applications - Link: Facebook Applications - Description: A collection of online tools that automate and facilitate Facebook.
- Social Analyzer - Link: SocialAnalyzer - Social Sentiment & Analysis - Description: a free tool of social media monitoring and analysis.
- AnalyzeID - Link: AnalyzeID - Description: Just looking for sites that supposedly may have the same owner. Including a FaceBook App ID match.
- SOWsearch - Link: sowsearch - Description: a simple interface to show how the current Facebook search function works.
- Facebook Matrix - Link: FacebookMatrix - Description: Formulas for Searching Facebook.
- Who posted what - Link: Who Posted What - Description: A non public Facebook keyword search for people who work in the public interest. It allows you to search keywords on specific dates.
- StalkFace - Link: StalkFace - Description: Toolkit to stalk someone on Facebook.
- Search is Back - Link: Search is Back - Description: ind people and events on Facebook Search by location, relationships, and more!.
- FB-Search - Link: FB-Search - Description: busca por teléfono o correo.
- FB-Posts-scraper - Link: FB-Posts-scraper - Description: (Python).
- FB-Video-downloader - Link: FB-Video-downloader - Description: .
- IFTTT Integrations - Link: IFTTT Instagram integrations - Description: Popular Instagram workflows & automations.
- IMGinn.io - Link: IMGinn.io - Description: view and download all the content on the social network Instagram all at one place.
- Instaloader - Link: Instaloader - Description: Download pictures (or videos) along with their captions and other metadata from Instagram.
- SolG - Link: SolG - Description: The Instagram OSINT Tool gets a range of information from an Instagram account that you normally wouldn't be able to get from just looking at their profile.
- Osintgram - Link: Osintgram - Description: Osintgram is an OSINT tool on Instagram to collect, analyze, and run reconnaissance.
- Toutatis - Link: toutatis - Description: It is a tool written to retrieve private information such as Phone Number, Mail Address, ID on Instagram accounts via API.
- instalooter - Link: instalooter - Description: InstaLooter is a program that can download any picture or video associated from an Instagram profile, without any API access.
- Exportgram - Link: Exportgram - Description: A web application made for people who want to export instagram comments into excel, csv and json formats.
- Profile Analyzer - Link: Profile Analyzer - Description: Analyze any public profile on Instagram – the tool is free, unlimited, and secure. Enter a username to take advantage of precise statistics.
- Find Instagram User Id - Link: Find Instagram User Id - Description: This tool called "Find Instagram User ID" provides an easy way for developers and designers to get Instagram account numeric ID by username.
- Instahunt - Link: Instahunt - Description: Easily find social media posts surrounding a location.
- Musicaldown - Link: Musicaldown - Description: web.
- RecruitEm - Link: RecruitEm - Description: Allows you to search social media profiles. It helps recruiters to create a Google boolean string that searches all public profiles.
- RocketReach - Link: RocketReach - Description: Allows you to programmatically search and lookup contact info over 700 million professionals and 35 million companies.
- Phantom Buster - Link: Phantom Buster - Description: Automation tool suite that includes data extraction capabilities.
- linkedprospect - Link: LinkedIn Boolean Search - Description: Build a targeted list of LinkedIn people using boolean search.
- ReverseContact - Link: Reverse Email Lookup - Description: Find Linked Profiles associated with any email.
- LinkedIn Search Engine - Link: Programmable Search Engine - Description: Programmable Search Engine for LinkedIn profiles.
- Free People Search Tool - Link: Free People Search Tool - Description: Find people easily online.
- IntelligenceX Linkedin - Link: IntelligenceX Linkedin - Description: A webbased tool for searching someone on Linkedin.
- Linkedin Search Tool - Link: Linkedin Search Tool - Description: Provides you a interface with various tools for Linkedin Osint.
- LinkedInt - Link: LinkedInt - Description: Providing you with Linkedin Intelligence.
- InSpy - Link: InSpy - Description: InSpy is a python based LinkedIn enumeration tool.
- CrossLinked - Link: CrossLinked - Description: CrossLinked is a LinkedIn enumeration tool that uses search engine scraping to collect valid employee names from an organization.
- Hunter.io - Link: Hunter.io - Description: Find and verify corporate email patterns. 25 free searches per month.
- TweetDeck - Link: TweetDeck - Description: Offers a more convenient Twitter experience by allowing you to view multiple timelines in one easy interface.
- FollowerWonk - Link: FollowerWonk - Description: Helps you find Twitter accounts using bio and provides many other useful features.
- Twitter Advanced Search - Retired endpoint; use the native search tools at X and verify availability in a browser.
- memory.lol - Link: memory.lol - Description: a tiny web service that provides historical information about twitter users.
- SocialData API - Link: SocialData API - Description: an unofficial Twitter API alternative that allows scraping historical tweets, user profiles, lists and Twitter spaces without using Twitter's API.
- Social Bearing - Link: Social Bearing - Description: Insights & analytics for tweets & timelines.
- Tinfoleak - Link: Tinfoleak - Description: Search for Twitter users leaks.
- Network Tool - Link: Network Tool - Description: Explore how information spreads across Twitter with an interactive network using OSoMe data.
- Foller - Link: Foller - Description: Looking for someone in the United States? Our free people search engine finds social media profiles, public records, and more!
- SimpleScraper OSINT - Link: SimpleScraper OSINT - Description: This Airtable automatically scrapes OSINT-related twitter accounts ever 3 minutes and saves tweets that contain coordinates.
- Deleted Tweet Finder - Link: Deleted Tweet Finder - Description: Search for deleted tweets across multiple archival services.
- Twitter Search Tool - Link: Twitter search tool - Description: On this page you can create advanced search queries within Twitter.
- Twitter Video Downloader - Link: Twitter Video Downloader - Description: Download Twitter videos & GIFs from tweets.
- Download Twitter Data - Link: Download Twitter Data - Description: Download Twitter data in csv format by entering any Twitter handle, keyword, hashtag, List ID or Space ID.
- Twitonomy - Link: Twitonomy - Description: Twitter #analytics and much more.
- tweeterid - Link: tweeterid - Description: Type in any Twitter ID or @handle below, and it will be converted into the respective ID or username.
- BirdHunt - Link: BirdHunt - Description: Easily find social media posts surrounding a location.
- Twint-docker - Link: Twint-docker - Description: Download all tweets from a user without API access.
- Sentiment140 - Link: Sentiment140 - Description: Bulk sentiment analysis for tweets via CSV.
- Xquik - Link: Xquik - Description: 122 API endpoints for search, user, post and monitor. API key, USD 0.00015/read.
- TwiFlux - Link: TwiFlux - A collection of browser-based tools for Twitter/X, including video, image, tweet and thread downloaders, format converters, search tools, and other utilities.
- DownAlbum - Link: DownAlbum - Description: Google Chrome extension for downloading albums of photos from various websites, including Pinterest.
- Experts PHP: Pinterest Photo Downloader - Link: Pinterest Photo Downloader - Description: Website providing a tool to download photos from Pinterest.
- Pingroupie - Link: Pingroupie - Description: A Meta Search Engine for Pinterest that lets you discover Collaborative Boards, Influencers, Pins, and new Keywords.
- Tailwind - Link: Tailwind - Description: Social media scheduling and management tool that supports Pinterest.
- Pinterest Guest - Link: Pinterest Guest - Description: Mozilla Firefox add-on for browsing Pinterest without logging in or creating an account.
- F5BOT - Link: F5BOT - Description: Receive notifications for new Reddit posts matching specific keywords.
- Mostly Harmless - Link: Mostly Harmless - Description: A suite of tools for Reddit, including user analysis, subreddit comparison, and more.
- OSINT Combine: Reddit Post Analyzer - Link: OSINT Combine: Reddit Post Analyzer - Description: Analyze and gather information from Reddit posts for OSINT purposes.
- Phantom Buster - Link: Phantom Buster - Description: Automation tool suite that includes Reddit data extraction capabilities.
- rdddeck - Link: rdddeck - Description: Real-time dashboard for monitoring multiple Reddit communities.
- Readr for Reddit - Link: Readr for Reddit - Description: Google Chrome extension for an improved reading experience on Reddit.
- Reddit Comment Search - Link: Reddit Comment Search - Description: Search for specific comments and conversations on Reddit.
- Redditery - Link: Redditery - Description: Explore Reddit posts and comments based on various criteria.
- Reddit Hacks - Link: Reddit Hacks - Description: Collection of Reddit hacks and tricks for advanced users.
- Reddit List - Link: Reddit List - Description: Directory of popular subreddits organized by various categories.
- reddtip - Link: reddtip - Description: Show appreciation to Reddit users by sending them tips in cryptocurrencies.
- Reddit Search - Link: Reddit Search (realsrikar) - Description: Various tools and websites for searching and discovering content on Reddit.
- Reddit Stream - Link: Reddit Stream - Description: Live-streaming of Reddit comments for real-time discussions.
- Reddit Suite - Link: Reddit Enhancement Suite (Chrome Extension) - Description: Browser extension that enhances the Reddit browsing experience with additional features.
- Reddit User Analyser - Link: Reddit User Analyser - Description: Analyze and visualize the activity and behavior of Reddit users.
- Reditr - Link: Reditr - Description: Desktop Reddit client with a clean and intuitive interface.
- Reeddit - Link: Reeddit - Description: Simplified and clean Reddit web interface for a distraction-free browsing experience.
- smat - Link: smat - Description: Social media analytics tool that includes Reddit for tracking trends and engagement.
- socid_extractor - Link: socid_extractor - Description: Extract user information from Reddit and other social media platforms.
- Suggest me a subreddit - Link: Suggest me a subreddit - Description: Get recommendations for new subreddits to explore based on your preferences.
- Subreddits - Link: Subreddits - Description: Directory of active subreddits organized by various categories.
- uforio - Link: uforio - Description: Generate word clouds from Reddit comment threads.
- Universal Reddit Scraper (URS) - Link: Universal Reddit Scraper (URS) - Description: Python-based tool for scraping Reddit data for analysis.
- Vizit - Link: Vizit - Description: Visualize and analyze relationships between Reddit users and subreddits.
- Wisdom of Reddit - Link: Wisdom of Reddit - Description: Curated collection of insightful quotes and comments from Reddit.
- Awesome Lists - Link: Awesome Lists - Description: A curated list of awesome lists for various programming languages, frameworks, and tools.
- CoderStats - Link: CoderStats - Description: A platform for developers to track and showcase their coding activity and statistics from GitHub.
- Digital Privacy - Link: Digital Privacy - Description: A collection of resources and tools for enhancing digital privacy and security.
- Find Github User ID - Link: Find Github User ID - Description: A web tool for finding the unique identifier (ID) of a GitHub user.
- GH Archive - Link: GH Archive - Description: A project that provides a public dataset of GitHub activity, including events and metadata.
- Github Dorks - Link: Github Dorks - Description: A collection of GitHub dorks, which are search queries to find sensitive information in repositories.
- Github Stars - Link: Github Stars - Description: A website that showcases GitHub repositories with the most stars and popularity.
- Github Trending RSS - Link: Github Trending RSS - Description: An RSS feed generator for trending repositories on GitHub.
- Github Username Search Engine - Link: Github Username Search Engine - Description: A search engine to find GitHub usernames based on various filters and criteria.
- Github Username Search Engine - Link: Github Username Search Engine - Description: Another search engine to find GitHub usernames with advanced filtering options.
- GitHut - Link: GitHut - Description: A website that provides statistics and visualizations of programming languages on GitHub.
| Tool | URL | Function |
|---|---|---|
| GitGot | https://github.com/BishopFox/GitGot | GitHub repo audit |
| gitGraber | https://github.com/hisxo/gitGraber | GitHub secrets search |
| GitHound | https://github.com/tillson/git-hound | Sensitive info search |
| TruffleHog | https://github.com/trufflesecurity/trufflehog | Credential detection with verification |
| Gitleaks | https://github.com/gitleaks/gitleaks | Fast secrets detection |
1. ORGNAME filename:.env AWS_SECRET_ACCESS_KEY
2. ORGNAME filename:.env MAIL_PASSWORD
3. ORGNAME filename:.npmrc _auth
4. ORGNAME filename:.dockercfg
5. ORGNAME filename:config.rb password
6. ORGNAME filename:id_rsa BEGIN OPENSSH PRIVATE KEY
7. ORGNAME filename:id_dsa BEGIN DSA PRIVATE KEY
8. ORGNAME extension:pem PRIVATE KEY
9. ORGNAME filename:.git-credentials
10. ORGNAME filename:settings.py SECRET_KEY
11. ORGNAME filename:wp-config.php DB_PASSWORD
12. ORGNAME filename:database.yml password
13. ORGNAME "api.openai.com" Authorization:Bearer
14. ORGNAME extension:sh AWS_ACCESS_KEY_ID
15. ORGNAME filename:terraform.tfvars
Variations: fork:true to include forks · archived:true for archived repos · pushed:>2026-01-01 for recent.
TruffleHog (active credential verification):
# Install
go install github.com/trufflesecurity/trufflehog/v3@latest
# Scan repo with full history:
trufflehog git <REPOSITORY_URL> --only-verified
# Scan organisation:
trufflehog github --org=ORGNAME --only-verified
# JSON output:
trufflehog git <REPOSITORY_URL> --json --only-verified > findings.jsonThe --only-verified flag filters only secrets confirmed active. Reduces false positives.
gitGraber (continuous monitoring in cron):
git clone https://github.com/hisxo/gitGraber.git
cd gitGraber
# Configure config.py with GITHUB_TOKENS, WORDLIST, SLACK_WEBHOOK
# First run:
python3 gitGraber.py --wordlist wordlists/your_wordlist.txt --output
# Cron every 6h:
# 0 */6 * * * cd /opt/gitGraber && python3 gitGraber.py --wordlist ...GitGot (interactive audit):
pip install gitgot
python3 gitgot.py -q "ORGNAME"
# Interactive session: [i]gnore, [s]ave, [r]eview, [q]uit- Accessing a public repo is legitimate. GitHub public is public.
- NOT legitimate: using a found secret to escalate access. The difference between defensive OSINT and attack is use, not access.
- Responsible disclosure: discovering a leak obliges you to notify the repo owner. 90 days before public disclosure (Project Zero standard).
- Do not include the full secret in the client report. Format
ghp_••••••[last4]. - GitHub Security Advisory for leaks in third-party repos.
- addmeContacts - Link: addmeContacts - Description: A platform to find and connect with new contacts on various social media platforms.
- ChatToday - Link: ChatToday - Description: An online chat platform for connecting and chatting with people from around the world.
- Gebruikersnamen: Snapchat - Link: Gebruikersnamen: Snapchat - Description: A website for finding Snapchat usernames.
- OSINT Combine: Snapchat MultiViewer - Link: OSINT Combine: Snapchat MultiViewer - Description: A tool for viewing multiple Snapchat accounts simultaneously.
- Snapchat-mapscraper - Link: Snapchat-mapscraper - Description: A tool for scraping public Snapchat Stories from the Snap Map.
- Snap Political Ads Library - Link: Snap Political Ads Library - Description: Snapchat's library of political ads displayed on the platform.
- Social Finder - Link: Social Finder - Description: A platform to search and discover social media profiles on various platforms.
- SnapIntel - Link: SnapIntel - Description: a python tool providing you information about Snapchat users.
- AddMeS - Link: AddMeS - Description: The 'Add Me' directory of Snapchat users on web.
- checkwa - Link: checkwa - Description: An online tool to check the status and availability of WhatsApp numbers.
- WhatsApp Fake Chat - Link: WhatsApp Fake Chat - Description: An online tool to generate fake WhatsApp conversations for fun or pranks.
- whatsfoto - Link: whatsfoto - Description: A Python script to download profile pictures from WhatsApp contacts.
- CheckLeaked WhatsApp - Link: CheckLeaked WhatsApp - Description: An online tool to look up WhatsApp numbers — download the current and historical profile pictures, read the About/bio text, and detect Business/Enterprise accounts. Free web interface with an optional API.
- addmeContacts - Link: addmeContacts - Description: A platform to find and connect with new contacts on various social media platforms.
- ChatToday - Link: ChatToday - Description: An online chat platform for connecting and chatting with people from around the world.
- Skypli - Link: Skypli - Description: A website for discovering and connecting with new Skype contacts.
- ChatBottle: Telegram - Link: ChatBottle: Telegram - Description: A directory of Telegram bots for various purposes.
- ChatToday - Link: ChatToday - Description: An online chat platform for connecting and chatting with people from around the world.
- informer - Link: informer - Description: A Python library for retrieving information about Telegram channels, groups, and users.
- _IntelligenceX: Telegram - Link: _IntelligenceX: Telegram - Description: IntelligenceX's Telegram tool for searching and analyzing Telegram data.
- Lyzem.com - Link: Lyzem.com - Description: A website to search and find Telegram groups and channels.
- Telegram Channels - Link: Telegram Channels - Description: A directory of Telegram channels covering various topics.
- Telegram Channels - Link: Telegram Channels - Description: A platform to discover and browse Telegram channels.
- Telegram Channels Search - Link: Telegram Channels Search - Description: A search engine to find Telegram channels by keywords.
- Telegram Directory - Link: Telegram Directory - Description: A comprehensive directory of Telegram channels, groups, and bots.
- Telegram Group - Link: Telegram Group - Description: A website to search and join Telegram groups.
- telegram-history-dump - Link: telegram-history-dump - Description: A Python script to dump the history of a Telegram chat into a SQLite database.
- Telegram-osint-lib - Link: Telegram-osint-lib - Description: A Python library for performing open-source intelligence (OSINT) on Telegram.
- Telegram Scraper - Link: Telegram Scraper - Description: A powerful Telegram scraping tool for extracting user information and media.
- Tgram.io - Link: Tgram.io - Description: A platform to explore and search for Telegram channels, groups, and bots.
- Tgstat.com - Link: Tgstat.com - Description: A comprehensive platform for analyzing and tracking Telegram channels and groups.
- Tgstat RU - Link: Tgstat RU - Description: A Russian platform for analyzing and monitoring Telegram channels and groups.
- DiscordOSINT - Link: DiscordOSINT - Description: This Repository Will contain useful resources to conduct research on Discord.
- Discord.name - Link: Discord.name - Description: Discord profile lookup using user ID.
- Discord History Tracker - Link: Discord History Tracker - Description: Discord History Tracker lets you save chat history in your servers, groups, and private conversations, and view it offline.
- Top.gg - Link: Top.gg - Description: Explore millions of Discord Bots.
- Unofficial Discord Lookup - Link: Unofficial Discord Lookup - Description: Search for discord profile using id.
- Disboard - Link: Disboard - Description: DISBOARD is the place where you can list/find Discord servers.
- OnlyFans Finder - Link: The Favourite OnlyFans search - Description: The tools allow easy searching via advanced filtering capabilities and sorting functionality, making it easy to access desired material.
- OnlyFam - Link: OnlyFam - Description: OnlyFans Search & Model Finder - Find Creators in the World's Largest OnlyFans Database
- OnlyFinder - Link: OnlyFinder - Description: OnlyFans Search Engine - OnlyFans Account Finder.
- OnlySearch - Link: OnlySearch - Description: Find OnlyFans profiles by searching for key words.
- Sotugas - Link: SóTugas - Description: Encontra Contas do OnlyFans Portugal 🇵🇹.
- Fansmetrics - Link: Fansmetrics - Description: Use this OnlyFans Finder to search in 3,000,000 OnlyFans Accounts.
- Findr.fans - Link: Findr.fans - Description: Only Fans Search Tool.
- Hubite - Link: Hubite - Description: Advanced OnlyFans Search Engine.
- Similarfans - Link: Similarfans - Description: Blog for OnlyFans content creators.
- Fansearch - Link: Fansearch - Description: Fansearch is the best OnlyFans Finder to search in 3,000,000 OnlyFans Accounts.
- Mavekite - Link: Mavekite - Description: Search the profile using username.
- TikTok hashtag analysis toolset - Link: TikTok hashtag analysis toolset - Description: The tool helps to download posts and videos from TikTok for a given set of hashtags over a period of time.
- TikTok Video Downloader - Link: TikTok Video Downloader - Description: ssstiktok is a free TikTok video downloader without watermark tool that helps you download TikTok videos without watermark (Musically) online.
- Exolyt - Link: exolyt - Description: The best tool for TikTok analytics & insights.
exiftool -a -u foto.jpg | grep -i "gps\|date\|camera"
# strip before publishing
exiftool -all= foto_sanitizada.jpg- Google Earth Pro → temporal displacement
- Suncalc → shadow = time
- Overpass-turbo → POI within radius
- FlightAware → flight tracking
- FlightRadar24 → flight radar
- MarineTraffic → maritime traffic
- VesselFinder → ships
- WiGLE → geolocated WiFi database
- OpenCelliD → cell towers
- Broadcastify → police audio
- AviationStack → aviation API
- Labs TIB Geoestimation → geographic estimation
- Picarta → photo location prediction
- Ventusky → weather maps
- Ukraine Live Cams → Ukraine cameras
- TWN → webcam network
- Opentopia → public webcams
- WorldCam → world webcams
- Webcam Galore → webcams
- OpenTrafficCamMap → traffic cameras
- Skyline Webcams → skyline webcams
- Pictimo → world webcams
- CamHacker → public webcams
| Tool | Stars | Language | Last push | What it adds |
|---|---|---|---|---|
| GeoWiFi | 1,510 | Python | 2026-09 | Geolocates a BSSID or SSID against public Wi-Fi geolocation databases |
- Copernicus Browser → Sentinel-1/2/3/5P, free browser
- NASA-FIRMS → real-time fires
- Zoom Earth → METAR overlay
- FlightRadar24 → flight radar
- ADS-B Exchange → no military filters
- FlightAware → flight history
- PiAware (Raspberry Pi) → own ADS-B receiver
- MarineTraffic → global AIS tracking
- VesselFinder → free alternative
- ShipSpotting → ship photo database
Video as a specific OSINT source plus chronolocation (determining when material was recorded). Does not duplicate 6.1-6.3 (metadata, geolocation, satellite).
| # | Step | Tool |
|---|---|---|
| 1 | Identify the geolocation objective (humanitarian/journalistic/military) | — |
| 2 | Extract keyframes with FFmpeg: ffmpeg -i video.mp4 -vf "fps=1/10" frame_%04d.png |
FFmpeg |
| 3 | Extract EXIF metadata: exiftool video.mp4 |
ExifTool |
| 4 | Analyse audio: language, accent, calls to prayer (adhan = time + orientation to Mecca) | — |
| 5 | Identify visual anchors: signs, licence plates, architecture, vegetation | — |
| 6 | Geolocate anchors individually with Google Lens / Yandex Images + Overpass Turbo | — |
| 7 | Trace sight lines from each anchor | Google Earth Pro |
| 8 | Validate with Street View | Google Street View |
| 9 | Validate with historical satellite imagery | Google Earth Pro + Copernicus Browser |
| 10 | Determine camera cardinal orientation with SunCalc | SunCalc |
| 11 | Triangulate date (chronolocation) | See 6.4.2 |
| 12 | Document with BLUF + evidence package (each anchor with frame + screenshot + URL + hash) | — |
- Geolocate first (6.4.1). Without lat/long, solar position cannot be calculated.
- Identify vertical object with a sharp projected shadow. Pole, column, standing person.
- Measure cardinal direction of the shadow (azimuth in degrees from Google Earth Pro).
- Measure relative length: ratio
shadow/object_height. Solar elevation =arctan(h/l). - Compute solar position with SunCalc.org (move slider until azimuth+elevation match).
- Resolve symmetric date ambiguity with contextual clues (vegetation, snow, datable events).
- Validate with historical weather. Visual Crossing Weather History (free tier).
- Document margin of error. Typically ±30-90 min of time, ±2-7 days of date. Report with confidence level.
| Tool | URL | Function |
|---|---|---|
| FFmpeg | https://ffmpeg.org | Video analysis and processing |
| FotoForensics | https://fotoforensics.com | ELA image analysis |
| Forensically | https://29a.ch/photo-forensics | Visual analysis suite |
| ExifTool | https://exiftool.org | Metadata |
| SunCalc | https://www.suncalc.org | Solar position |
| Google Earth Pro | https://earth.google.com/web/ | Historical satellite |
| Sentinel Hub | https://www.sentinel-hub.com | Sentinel-2 imagery |
| yt-dlp | https://github.com/yt-dlp/yt-dlp | Video download |
| GeoConfirmed | https://geoconfirmed.org | Collaborative geolocation |
Following the withdrawal of Russian troops from Bucha (Ukraine) in March 2022, images of civilian bodies in Yablunska Street appeared. Russia denied responsibility. Bellingcat and The New York Times published on 4 April 2022 an analysis demonstrating that the bodies were already present during the Russian occupation, using Maxar satellite imagery from 19 March.
Methodology:
- Geolocation of each frame with a visible body in Yablunska Street.
- Acquisition of Maxar imagery from 19 March (during Russian occupation).
- Frame-by-frame comparison: dark objects on the street in the same locations where the 2 April video showed bodies. One-to-one correspondence.
- Validation with second satellite (Planet Labs, 21 March).
- Conclusion: bodies were already on the street on 19 March (Russian control). High confidence (cross-corroboration of satellite + video + testimonies).
Sources:
| Objective | Tool | Quick Command |
|---|---|---|
| Subdomains | Amass | amass enum -d target.com -o subs.txt |
| Certificates | CRT.sh | curl https://crt.sh/?q=%25.target.com&output=json |
| Historical DNS | SecurityTrails | Free API 50/month |
| Tech stack | StackScan | 399M+ sites, reverse lookup by technology |
| Neighbor IPs | BGP.he | CIDR |
| Reputation | VirusTotal | vt ip_info <ip> |
| Quick scan | Nmap-online | no VPN |
| Subdomains | Subdomain Center | https://www.subdomain.center |
| Subdomains | SubdomainRadar | https://www.subdomainradar.io |
| Historical DNS | DNS History | http://dnshistory.org |
| Reputation | Talos | https://www.talosintelligence.com/ |
| Scan | Binary Defense | https://www.binarydefense.com/banlist.txt |
| BGP Ranking | CIRCL BGP | https://bgpranking.circl.lu |
| Botnet Tracker | MalwareTech | https://intel.malwaretech.com/ |
| BOTVRIJ.EU | BOTVRIJ | http://www.botvrij.eu/ |
| C&C Tracker | Bambenek | https://osint.bambenekconsulting.com/feeds/c2-ipmasterlist.txt |
| CertStream | CertStream | https://certstream.calidog.io/ |
| CCSS Forum | CCSS Forum | http://www.ccssforum.org/malware-certificates.php |
| CI Army List | CINS Score | http://cinsscore.com/#list |
| Cisco Umbrella | Cisco Umbrella | http://s3-us-west-1.amazonaws.com/umbrella-static/index.html |
| Cloudmersive | Cloudmersive | https://cloudmersive.com/virus-api |
| Critical Stack | Critical Stack | https://intelstack.com/ |
| CrowdSec | CrowdSec | https://app.crowdsec.net/ |
| Cyber Cure | Cyber Cure | https://www.cybercure.ai/ |
| DataPlane | DataPlane | https://dataplane.org/ |
| Focsec | Focsec | https://focsec.com |
| Disposable Domains | Disposable Domains | https://github.com/disposable-email-domains/disposable-email-domains |
| Emerging Threats | Emerging Threats | http://rules.emergingthreats.net/fwrules/ |
| ExoneraTor | ExoneraTor | https://exonerator.torproject.org/ |
| Exploitalert | Exploitalert | http://www.exploitalert.com/ |
| FastIntercept | FastIntercept | https://intercept.sh/threatlists/ |
| Feodo Tracker | Feodo Tracker | https://feodotracker.abuse.ch/ |
| FireHOL | FireHOL | https://iplists.firehol.org/ |
| FraudGuard | FraudGuard | https://fraudguard.io/ |
| Grey Noise | Grey Noise | http://greynoise.io/ |
| HoneyDB | HoneyDB | https://riskdiscovery.com/honeydb/ |
| Icewater | Icewater | https://github.com/SupportIntelligence/Icewater |
| InQuest Labs | InQuest Labs | https://labs.inquest.net |
| I-Blocklist | I-Blocklist | https://www.iblocklist.com/lists |
| IPsum | IPsum | https://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt |
| James Brine | James Brine | https://jamesbrine.com.au |
| Kaspersky Feeds | Kaspersky | https://support.kaspersky.com/datafeeds |
| Malpedia | Malpedia | https://malpedia.caad.fkie.fraunhofer.de/ |
| MalShare | MalShare | http://www.malshare.com/ |
| Maltiverse | Maltiverse | https://www.maltiverse.com/ |
| MalwareBazaar | MalwareBazaar | https://bazaar.abuse.ch/ |
| Malware Domain List | Malware Domain List | https://www.malwarepatrol.net/ |
| MetaDefender | MetaDefender | https://www.opswat.com/developers/threat-intelligence-feed |
| Netlab OpenData | Netlab | https://data.netlab.360.com/ |
| NoThink! | NoThink! | http://www.nothink.org |
| Obstracts | Obstracts | https://www.obstracts.com/ |
| OpenPhish | OpenPhish | https://openphish.com/phishing_feeds.html |
| 0xSI_f33d | 0xSI_f33d | https://feed.seguranca-informatica.pt/index.php |
| PhishTank | PhishTank | https://www.phishtank.com/developer_info.php |
| PickupSTIX | PickupSTIX | https://www.celerium.com/pickupstix |
| RST Cloud | RST Cloud | https://rstcloud.net/ |
| SecurityScorecard | SecurityScorecard | https://github.com/securityscorecard/SSC-Threat-Intel-IoCs |
| Stixify | Stixify | https://www.stixify.com/ |
| signature-base | signature-base | https://github.com/Neo23x0/signature-base |
| Spamhaus | Spamhaus | https://www.spamhaus.org/ |
| Spur | Spur | https://spur.us |
| SSL Blacklist | SSL Blacklist | https://sslbl.abuse.ch/ |
| Statvoo | Statvoo | https://statvoo.com/dl/top-1million-sites.csv.zip |
| Strongarm | Strongarm | https://strongarm.io |
| SIEM Rules | SIEM Rules | https://www.siemrules.com |
| Talos | Talos | https://www.talosintelligence.com/ |
| threatfeeds.io | threatfeeds.io | https://threatfeeds.io |
| threatfox | threatfox | https://threatfox.abuse.ch/ |
| Technical Blogs (Dataminr) | Technical Blogs | https://www.dataminr.com/blog/ |
| ThreatExchange | ThreatExchange | https://developers.facebook.com/docs/threat-exchange/ (HTTP 400 from automated link checks; confirm availability in a browser) |
| TypeDB CTI | TypeDB CTI | https://github.com/typedb-osi/typedb-cti |
| XFE | XFE | https://exchange.xforce.ibmcloud.com/ |
| Yeti | Yeti | https://yeti-platform.io/ |
| 1st Dual Stack | 1st Dual Stack | https://IOCFeed.mrlooquer.com/ |
| Yara-Rules | Yara-Rules | https://github.com/Yara-Rules/rules |
| VirusShare | VirusShare | https://virusshare.com/ |
| CIRCL PDNS | CIRCL PDNS | https://www.circl.lu/services/passive-dns |
| InTheWild | InTheWild | https://github.com/gmatuz/inthewilddb |
| 360 Quake | 360 Quake | https://quake.360.net |
| Cloudflare Radar | Cloudflare Radar | https://radar.cloudflare.com/traffic |
| Validin | Validin | https://app.validin.com |
| OSV | OSV | https://osv.dev |
| Coalition ESS | Coalition ESS | https://ess.coalitioninc.com |
| WHOIS & Domain History | WhoisFreaks | https://whoisfreaks.com |
| IP Geolocation & Threat Intel | ipgeolocation.io | https://ipgeolocation.io |
site:*.target.com filetype:pdf
site:*.target.com intitle:"dashboard"
site:*.target.com intext:"confidential"
| Need | Solution | URL |
|---|---|---|
| Search .onion | Ahmia | clean index |
| Check if data leaked | HaveIBeenPwned | API |
| Markets | DarkOwl (paid) | — |
| Credentials | DeHashed (freemium) | — |
| Search .onion | TOR Link | https://tor.link |
| Scanner services | OnionScan | https://github.com/s-rah/onionscan |
| Verified directory | Dark.fail | https://dark.fail |
| Old searcher | Torch | (only .onion) |
| Scraper onion | DarkDump | https://github.com/josh0xA/darkdump |
| Tor Project | Tor Project | https://torproject.org |
| Public webcams | TWN | http://www.the-webcam-network.com |
| Public webcams | Opentopia | https://www.opentopia.com/ |
| World webcams | WorldCam | https://worldcam.eu |
| Webcams | Webcam Galore | https://www.webcamgalore.com |
| Traffic cameras | OpenTrafficCamMap | https://otc.armchairresearch.org/map |
| Skyline webcams | Skyline Webcams | https://www.skylinewebcams.com/en/webcam |
| World webcams | Pictimo | https://www.pictimo.com |
| Public webcams | CamHacker | https://www.camhacker.com |
| Surveillance cameras | SUNDERS | https://sunders.uber.space |
| Ukraine cameras | Ukraine Live Cams | https://nagix.github.io/ukraine-livecams |
OPSEC for .onion
- TailsOS → USB → bridge-Tor → NO extra proxies
- Disable scripts Noscript → max
- Never maximize window (fingerprint)
- Never use VPN + Tor (traffic correlation)
- Use bridges if Tor is blocked
- NoScript to max
- No window resizing
- No downloading to persistent disk
python -m venv osint-env
source osint-env/bin/activate
pip install twint-fork recon-ng selenium requests beautifulsoup4 shodan#!/usr/bin/env python3
# mini_osint.py
import shodan, requests, json, sys
from bs4 import BeautifulSoup
API_KEY = 'YOUR_SHODAN_API'
s = shodan.Shodan(API_KEY)
domain = sys.argv[1]
# 1. Subdomains via CRT.sh
crt = requests.get(f'https://crt.sh/?q=%25.{domain}&output=json').json()
subs = sorted(set([r['name_value'] for r in crt]))
print('[+] Found subdomains:', len(subs))
# 2. IPs from resolution
ips = set()
for sub in subs[:20]: # demo limit
try:
ips.add(socket.gethostbyname(sub))
except:
pass
# 3. Shodan quick look
for ip in ips:
try:
info = s.host(ip)
print(ip, info['org'], info.get('vulns', 'N/A'))
except:
passrecon-ng
> marketplace install all
> workspaces add target
> use domains-domains/brute_force
> set SOURCE target.com
> run
> use hosts-hosts/resolve
> run
> use reporting/csv
> runFolder /templates/ in your repo. Mandatory YAML front-matter:
---
investigator: your-alias
date: 2025-12-16
objective: "Target Name"
scope: domain + RRSS
status: draft # draft | reviewed | delivered
---
# Executive Summary
(5 lines)
# Primary Sources
- URL | date | capture hash
# Chronology
- 2024-10-01: Domain registration
- 2025-01-15: First leak
# Annexes
- Screenshots folder `/annexes/`
- CSV extracts| Country | Framework | Key |
|---|---|---|
| Mexico | PDP Law 2018 | Explicit consent for PII |
| Spain | LOPD-GDPR | Art. 6.1-f: legitimate interest (research) |
| USA | CFAA | No bypass to authentication |
| Europe | GDPR | DPIA if >1000 people |
| — | OSINT-Code-Ethics | No doxxing, no stalking, no data selling |
Ethical checklist ☐ Is the source 100% public? ☐ Is the data sensitive PII? → minimize ☐ Is there verifiable public interest? ☐ Can it be de-identified?
- Open Source Intelligence Techniques — Michael Bazzell — Official site with book updates, podcast & tools (current edition available on Amazon)
- Bellingcat Resources — Free guides, case studies & methodology articles
- Bellingcat Online Investigation Toolkit — Live, searchable toolkit maintained by Bellingcat
- SANS Reading Room — OSINT — Peer-reviewed whitepapers (free with registration)
- SANS Reading Room — Forensics — DFIR whitepapers, free
- SANS SEC497 OSINT Course — Course outline, free sample content
- NIST SP 800-150 — Guide to Cyber Threat Information Sharing — Official US gov PDF, free
- ENISA Threat Landscape 2024 — Full EU report, free PDF
- UK NCSC Threat Reports — UK government cyber threat reports
- INTERPOL Cybercrime Reports — Official INTERPOL publications hub
- Citizen Lab Publications — Academic research on digital threats, free PDFs
- RAND Open Source Intelligence Research — Peer-reviewed RAND papers
- CSIS Strategic Technologies Program — Think-tank reports on tech & security
- arXiv Cryptography & Security — Academic preprints, fully free
- FIRST.org Best Practices Guides — CSIRT best-practice guides
- MITRE ATT&CK Resources — Framework docs, FAQs, training
- Trace Labs Resources — Missing persons OSINT CTF methodology
- OSINT Dojo — Free daily challenges & training paths
- OSINT Framework — Live searchable tree of OSINT tools
- Awesome OSINT (jivoi) — Curated mega-list, GitHub
- OSINT Collection (Ph055a) — Curated free & actionable resources
- INCIBE-CERT Blog — Spanish cybersecurity articles (free)
- The DFIR Report — Real-world intrusion case studies, free
- Krebs on Security — Investigative cybersecurity journalism
- Cisco Talos Blog — Daily threat intel blog
- EFF Surveillance Self-Defense — Free multilingual guides on privacy & OPSEC
- Pwn.college — Free ASU-hosted security course platform
- SEINT (SANS 487)
- OSINT-Do-jo – daily challenges
AI-powered tools for OSINT 2025:
| Tool | Function | URL | Note |
|---|---|---|---|
| anonchatgpt | Anonymous ChatGPT client | https://anonchatgpt.com | No account needed |
| ai-toolkit | Essential AI toolkit for journalists | https://huggingface.co/spaces/JournalistsonHF/ai-toolkit | Free and open-source |
| ChatPDF | Ask questions to PDFs | https://www.chatpdf.com/ | Simple and free |
| Monica | ChatGPT copilot in Chrome | https://monica.im/ | Summarize, translate |
| BabelX | Multilingual OSINT platform | https://www.babelstreet.com | 200+ languages |
| Fivecast | Predictive analysis with ML | https://www.fivecast.com | Real-time threat detection |
| HyperVerge | Deepfake detection | https://hyperverge.co | AI biometric verification |
| ShadowDragon | Social Darkint with AI | https://shadowdragon.io | Behavior analysis |
| Jev Social | AI-guided social-media research | https://github.com/socai-io/jev-social | Local Chrome; open source |
| Talkwalker | Media monitoring with AI | https://www.talkwalker.com | Sentiment analysis |
| DorkGPT | AI dork generator | https://www.dorkgpt.com | Auto-creates Google dorks |
| SearchDorks | Dorks for multiple engines | https://kriztalz.sh/search-dorks | FOFA, Shodan, Censys |
| Sensity AI | Deepfake detection | https://sensity.ai | Professional |
| Full Fact | AI fact-checking (UK) | https://fullfact.org | Free |
| Logically | AI disinfo detection | https://logically.com | Free tier |
| Directory | Coverage | URL |
|---|---|---|
| Artificial-Intelligence-Universe | 800+ AI tools | https://github.com/frangelbarrera/Artificial-Intelligence-Universe |
| awesome-ai-agents | 132 AI agents, 22 categories | https://github.com/frangelbarrera/awesome-ai-agents |
| Awesome-Hacking-with-AI | AI-powered offensive security | https://github.com/frangelbarrera/Awesome-Hacking-with-AI |
| osint-agent-skills | MCP server for OSINT agents | https://github.com/frangelbarrera/osint-agent-skills |
Beyond basic searches:
| Tool | Capability | URL | Cost |
|---|---|---|---|
| PimEyes | Facial search on internet | https://pimeyes.com/en | Freemium |
| OSINT by PimEyes | Pro version for professionals | https://osint.pimeyes.com | Paid |
| FaceCheck.ID | Search in social networks | https://facecheck.id | Freemium |
| Clearview AI | Police facial recognition | (Requires authorization) | Professional |
Usage methodology:
- Capture high-quality image
- Use FaceCheck.ID for social networks
- PimEyes for broad web search
- Validate results by crossing platforms
| Tool | Function | URL |
|---|---|---|
| Holehe | Find associated accounts to email | https://github.com/megadose/holehe |
| GHunt | Investigate Google accounts | https://github.com/mxrch/GHunt |
| Epieos | Email + phone reverse lookup | https://epieos.com |
| h8mail | Search in data breaches | https://github.com/khast3x/h8mail |
| EmailHippo | Email verification | https://tools.emailhippo.com |
| Hunter.io | Find corporate emails | https://hunter.io |
| Tool | Function | URL |
|---|---|---|
| Phoneinfoga | Investigation framework | https://github.com/sundowndev/phoneinfoga |
| Truecaller | Call identifier | https://www.truecaller.com |
| Infobel | International search | https://www.infobel.com |
| Numverify | Validation API | https://numverify.com |
Automation script (Python):
# email_osint_checker.py
import holehe
import requests
def check_email_accounts(email):
"""Checks in 120+ platforms"""
modules = holehe.import_submodules('holehe.modules')
for module in modules:
# Execute verification
passAlternatives and complements to HIBP:
| Platform | Database | URL | Access |
|---|---|---|---|
| DeHashed | 17+ billion records | https://dehashed.com | Freemium |
| Snusbase | Recent breaches | https://snusbase.com | Paid |
| LeakCheck | Real-time search | https://leakcheck.io | Freemium |
| Intelligence X | Dark web + breaches | https://intelx.io | Freemium |
| h8mail | Local breach search | GitHub | Free |
| Hudson Rock | Infostealer intelligence | https://www.hudsonrock.com/threat-intelligence-cybercrime-tools | Free |
| LeakRadar | 290B+ stealer logs & breaches | https://leakradar.io | Freemium |
| CheckLeaked | Real-time email/username/phone/password search | https://checkleaked.cc | Freemium |
Quick command:
# h8mail - mass search
h8mail -t targets.txt -bc local_breach_folder/ --power-allSpecialized tools:
| Tool | Blockchain | URL | Function |
|---|---|---|---|
| Chainalysis Reactor | Multi-chain | https://www.chainalysis.com | Forensic analysis professional |
| Elliptic | Bitcoin, Ethereum | https://www.elliptic.co | Money laundering detection |
| Arkham Intelligence | Multi-chain | https://info.arkm.com/ | Entity mapping with AI |
| Glassnode | On-chain analytics | https://glassnode.com | Advanced metrics |
| Etherscan | Ethereum | https://etherscan.io | Main explorer |
| Blockchain.info | Bitcoin | https://www.blockchain.com/explorer | Classic explorer |
| BlockCypher | Multi-chain API | https://www.blockcypher.com | Free API |
| Wallet Explorer | Bitcoin | https://www.walletexplorer.com | Wallet analysis |
Investigation methodology:
1. Identify wallet address
2. Search in Arkham Intelligence (known labels)
3. Analyze transactions in Etherscan/Blockchain.info
4. Trace fund flow with BlockCypher
5. Check in Chainalysis if available
| Tool | Function | URL |
|---|---|---|
| OpenALPR | License plate recognition | https://github.com/openalpr/openalpr |
| Carfax | Vehicle history (US) | https://www.carfax.com |
| Tool | Function | URL |
|---|---|---|
| FlightRadar24 | Live tracking | https://www.flightradar24.com |
| ADS-B Exchange | No military filters | https://globe.adsbexchange.com |
| FlightAware | Flight history | https://flightaware.com |
| Phantom Tide | Restricted airspace, maritime, and incident map | https://phantom.labs.jamessawyer.co.uk |
| PiAware (Raspberry Pi) | Own ADS-B receiver | https://flightaware.com/adsb/piaware |
Setup of homemade ADS-B receiver:
# Configure PiAware on Raspberry Pi
sudo apt-get install piaware
sudo piaware-config <options>
sudo systemctl restart piaware| Tool | Function | URL |
|---|---|---|
| MarineTraffic | Global AIS tracking | https://www.marinetraffic.com |
| VesselFinder | Free alternative | https://www.vesselfinder.com |
| ShipSpotting | Photo database | https://www.shipspotting.com/ |
| Tool | Function | URL/Installation |
|---|---|---|
| WiGLE | Global WiFi database | https://wigle.net |
| WiGLE WiFi Wardriving (Android) | Mapping app | Google Play |
| Kismet | WiFi/Bluetooth detector | https://www.kismetwireless.net |
| Aircrack-ng | WiFi audit suite | https://www.aircrack-ng.org |
OSINT use case:
1. Search unique SSID in WiGLE
2. Find approximate router location
3. Correlate with other geolocation data
4. Identify movements/locations of target
Fact-checking tools:
| Tool | Function | URL | Type |
|---|---|---|---|
| InVID & WeVerify | Video verification plugin | https://weverify.eu/verification-plugin | Extension |
| FotoForensics | ELA image analysis | https://fotoforensics.com | Web |
| Forensically | Visual analysis suite | https://29a.ch/photo-forensics | Web |
| HyperVerge Deepfake Detector | AI detection | https://hyperverge.co | API |
| Sensity AI | Deepfakes detection | https://sensity.ai | Professional |
| Content Authenticity Initiative | Origin verification | https://contentauthenticity.org | Standard |
Verification process:
1. Extract metadata with ExifTool
2. Analyze with FotoForensics (ELA)
3. Check consistencies with Forensically
4. For video: use InVID for keyframes
5. Reverse image search in TinEye/Google
| Tool | Stars | Language | Last push | What it adds |
|---|---|---|---|---|
| SingleFile | 22,484 | JavaScript | 2026-09 | Saves a faithful, self-contained copy of a full web page for archival and verification |
Beyond Maigret and Sherlock:
| Tool | Platforms | URL | Highlight |
|---|---|---|---|
| Sherlock | 400+ platforms | https://github.com/sherlock-project/sherlock | Faster |
| Maigret | 500+ platforms | https://github.com/soxoj/maigret | More precise |
| WhatsMyName | 600+ platforms | https://github.com/WebBreacher/WhatsMyName | Most complete |
| Snoop | 320+ (RU/CIS emphasis) | https://github.com/snooppr/snoop | Russian/CIS |
| Blackbird | 200+ with PDF report | https://github.com/antoniaci/blackbird | Export |
| UserSearch | 600+ platforms | https://usersearch.org | Largest Reverse User Search Online |
Speed comparison:
# Benchmark (10 usernames)
sherlock: ~45 seconds
maigret: ~90 seconds (more precise)
blackbird: ~60 seconds (with report)| Tool | Function | URL | Level |
|---|---|---|---|
| Photon | Ultra-fast crawler | https://github.com/s0md3v/Photon | Intermediate |
| Scrapy | Complete framework | https://scrapy.org | Advanced |
| Playwright | Browser automation | https://playwright.dev | Advanced |
| Selenium | Classic automation | https://www.selenium.dev | Intermediate |
| Beautiful Soup | HTML/XML parser | https://www.crummy.com/software/BeautifulSoup | Basic |
Basic Photon script:
python photon.py -u https://target.com \
--export=json \
--dns \
--keys \
--threads 10Complete suite:
| Tool | File Type | URL | Platform |
|---|---|---|---|
| ExifTool | Images, PDF, Office | https://exiftool.org | CLI |
| FOCA | Office, PDF (GUI) | https://github.com/ElevenPaths/FOCA | Windows |
| Metagoofil | Public documents | https://github.com/laramies/metagoofil | CLI |
| MAT2 | Metadata cleaner | https://0xacab.org/jvoisin/mat2 | CLI |
Metadata workflow:
# 1. Extract metadata
exiftool -a -u -g1 document.pdf > metadata.txt
# 2. Search sensitive info
grep -i "author\|creator\|email\|gps" metadata.txt
# 3. Clean before publishing
mat2 --inplace clean_document.pdfAdvanced tools:
| Tool | Speed | URL | Ideal Use |
|---|---|---|---|
| Nmap | Medium | https://nmap.org | Complete scan |
| Masscan | Very fast | https://github.com/robertdavidgraham/masscan | Internet-scale |
| RustScan | Very fast | https://github.com/bee-san/RustScan | Modern port |
| Nuclei | Templates | https://github.com/projectdiscovery/nuclei | Vulnerabilities |
Speed comparison:
# Scan 65k ports on 1 IP
nmap: ~5 minutes
rustscan: ~10 seconds → then nmap
masscan: ~5 seconds (less detail)| Tool | Stars | Language | Last push | What it adds |
|---|---|---|---|---|
| bbot | 10,623 | Python | 2026-09 | Recursive internet scanner with module chaining |
| reNgine | 8,860 | HTML | 2026-09 | Web recon framework with a database-driven UI and configurable scan engines |
| reconFTW | 8,145 | Shell | 2026-09 | Automated recon pipeline that chains best-in-class tools per phase |
| Osmedeus | 6,579 | Go | 2026-09 | Workflow engine for offensive security and recon orchestration |
| IVRE | 4,154 | Python | 2026-09 | Self-hosted network reconnaissance framework for scans you own |
Specialized tools:
| Tool | Function | URL | Requirement |
|---|---|---|---|
| Ahmia | .onion searcher | https://ahmia.fi | Web browser |
| OnionScan | Service scanner | https://github.com/s-rah/onionscan | Tor installed |
| Dark.fail | Verified directory | https://dark.fail | Tor Browser |
| Torch | Old searcher | (only .onion) | Tor Browser |
| DarkDump | Onion scraper | https://github.com/josh0xA/darkdump | Python + Tor |
Dark Web OPSEC:
1. Operating system: Tails OS (amnesic)
2. Never use VPN + Tor (traffic correlation)
3. Use bridges if Tor is blocked
4. NoScript to max
5. No window resizing
6. No downloading to persistent disk
All-in-one platforms:
| Framework | Language | URL | Strength |
|---|---|---|---|
| Abster Intelligence | TypeScript / Next.js | https://github.com/frangelbarrera/Abster-Intelligence | Local-first, graph engine, BYOK-LLM, privacy-first |
| Ubikron | Browser Ext | https://ubikron.com | AI-powered case management & entity extraction |
| SpiderFoot | Python | https://github.com/smicallef/spiderfoot | Total automation |
| Recon-ng | Python | https://github.com/lanmaster53/recon-ng | Modular |
| theHarvester | Python | https://github.com/laramies/theHarvester | Email/subdomain |
| Maltego | Java | https://www.maltego.com | Visualization |
SpiderFoot setup:
git clone https://github.com/smicallef/spiderfoot.git
cd spiderfoot
pip3 install -r requirements.txt
python3 sf.py -l 127.0.0.1:5001| Tool | Stars | Language | Last push | What it adds |
|---|---|---|---|---|
| web-check | 34,921 | TypeScript | 2026-09 | All-in-one OSINT dashboard for any website: DNS, headers, TLS, technology stack and threat intel |
| social-analyzer | 24,113 | JavaScript | 2026-01 | Detects a person's profile across 1,000+ social sites, with API, CLI and web app |
| flowsint | 8,933 | TypeScript | 2026-09 | Graph-based investigation platform: entities, relationships and visual analysis |
| osint_stuff_tool_collection | 8,874 | HTML | 2026-05 | Several hundred online OSINT tools, catalogued by task |
| OpenOSINT | 1,645 | Python | 2026-09 | OSINT agent with REPL, MCP server and CLI; 20 tools, works with local models |
Essential plugins:
| Transform Hub | Function | Note |
|---|---|---|
| Standard Transforms | 150+ official transforms | Free |
| Shodan Transform | Shodan integration | Requires API |
| VirusTotal | Malware/URL analysis | Requires API |
| Netlas Transform | Similar to Shodan | https://netlas.io |
| Hunter.io | Email search | Requires account |
| Builtwith | Site technologies | Requires API |
Create custom transform:
# my_transform.py
from maltego_trx.entities import Person, EmailAddress
from maltego_trx.transform import DiscoverableTransform
class PersonToEmail(DiscoverableTransform):
@classmethod
def create_entities(cls, request, response):
person_name = request.Value
# Your logic here
response.addEntity(EmailAddress, f"{person_name}@example.com")
return response1. Identification: What are we investigating?
2. Preservation: Archive EVERYTHING (archive.is, wayback)
3. Verification: Triangulate with 3+ sources
4. Contextualization: Complete chronology
5. Documentation: Screenshots + hash + timestamp
6. Validation: Peer review before publishing
PHASE 1: DIRECTION
├── Define questions (RFI)
├── Establish legal limits
└── Approve scope
PHASE 2: COLLECTION
├── Passive sources
├── Semi-passive sources
└── Save evidence
PHASE 3: PROCESSING
├── Normalize data
├── Translate languages
└── Structure information
PHASE 4: ANALYSIS
├── Link analysis (Maltego)
├── Timeline creation
├── Pattern recognition
└── Cross validation
PHASE 5: DISSEMINATION
├── Executive report
├── Technical report
├── Visual presentation
└── Evidence archive
2025 Dorks (specific):
# Sensitive information leaks
site:pastebin.com "password" "@company.com"
site:github.com "api_key" OR "api_secret" "company"
site:trello.com intext:"password" OR intext:"passwd"
# Exposed corporate documents
site:*.s3.amazonaws.com ext:xls | ext:xlsx "confidential"
filetype:pdf intext:"internal use only" site:gov
# IP cameras and IoT devices
inurl:/view/view.shtml
intitle:"webcamXP 5"
# Exposed admin panels
intitle:"index of" "admin"
intitle:"Dashboard" inurl:login
inurl:wp-admin intitle:"Dashboard"
# Exposed databases
intitle:"phpMyAdmin" "Welcome to phpMyAdmin"
inurl:"/phpmyadmin/index.php"
"#mysql dump" filetype:sql
# Employee information
site:linkedin.com "company name" "CEO" | "CTO" | "CISO"
site:*.linkedin.com "@companymail.com"
# Subdomains (combine with crt.sh)
site:*.target.com -www
site:*.*.target.com
📺 YouTube Channels (Spanish):
- Ethical Hacking - Pablo González
- CyberSecurityJobs
- DragonJAR
- José Luis García
- Security Hacklabs
📚 Recommended Books:
- "Open Source Intelligence Techniques" - Michael Bazzell (8th ed., 2024)
- "OSINT for Threat Intelligence" - Scott J Roberts
- "The OSINT Handbook" - i-intelligence
🎓 Certifications:
- GOSI (GIAC Open Source Intelligence) - SANS
- CSCTP (Certified Social Media Intelligence Expert) - McAfee Institute
- OSINT Professional Certification - OSINT Combine
🔗 Communities:
- Reddit: r/OSINT, r/OpenSourceIntelligence
- Discord: IntelTechniques Server, OSINT-FR
- Telegram: OSINT Latam, OSINT Dojo
- Twitter/X: #OSINT, #OSINTfor Good
Tools for investigating individuals:
| Tool | Function | URL |
|---|---|---|
| Pipl | People search engine | https://pipl.com |
| Spokeo | Background checks | https://www.spokeo.com |
| BeenVerified | Public records search | https://www.beenverified.com |
| Intelius | People finder | https://www.intelius.com |
| Whitepages | Phone and address lookup | https://www.whitepages.com |
| ZabaSearch | Free people search | https://www.zabasearch.com |
| PeopleFinder | Comprehensive search | https://www.peoplefinder.com |
| Instant Checkmate | Background reports | https://www.instantcheckmate.com |
| TruthFinder | Public records | https://www.truthfinder.com |
| US Search | People search | https://www.ussearch.com |
Tools for investigating companies:
| Tool | Function | URL |
|---|---|---|
| Crunchbase | Company database | https://crunchbase.com |
| WellFound (formerly AngelList) | Startup database | https://wellfound.com |
| PitchBook | Private company data | https://pitchbook.com |
| ZoomInfo | Business contacts | https://www.zoominfo.com |
| D&B Hoovers | Company profiles | https://app.dnbhoovers.com |
| Dun & Bradstreet | Business credit reports | https://www.dnb.com/en-us/ |
| EDGAR | SEC filings | https://www.sec.gov/edgar |
| OpenCorporates | Global company registry | https://opencorporates.com |
| Company House | UK company registry | https://find-and-update.company-information.service.gov.uk |
| Bloomberg | Financial data | https://www.bloomberg.com |
Consolidated IoC feeds for threat intelligence :
| Feed | Type | URL |
|---|---|---|
| MalwareBazaar | Malware samples | https://bazaar.abuse.ch |
| ThreatFox | IoC aggregator | https://threatfox.abuse.ch |
| Feodo Tracker | C2 IPs | https://feodotracker.abuse.ch |
| SSL Blacklist | Malicious SSL certs | https://sslbl.abuse.ch |
| URLhaus | Malware URLs | https://urlhaus.abuse.ch |
| MalShare | Malware repository | http://www.malshare.com |
| VirusShare | Sample sharing | https://virusshare.com |
| Malware Domain List | Malicious domains | https://www.malwarepatrol.net |
| AlienVault OTX | Community threat intel | https://otx.alienvault.com |
| IBM X-Force | Threat exchange | https://exchange.xforce.ibmcloud.com |
| Recorded Future | Commercial feed (free blog) | https://www.recordedfuture.com |
| Microsoft Threat Intelligence | MS-curated | https://www.microsoft.com/en-us/wdsi |
| CISA Known Exploited Vulnerabilities | KEV catalog | https://www.cisa.gov/known-exploited-vulnerabilities-catalog |
| Vulnrichment | CISA enriched CVEs | https://github.com/cisagov/vulnrichment |
| Feed | Type | URL |
|---|---|---|
| PhishTank | Phishing URLs | https://www.phishtank.com |
| OpenPhish | Phishing URLs | https://openphish.com |
| FraudGuard | Fraud intelligence | https://fraudguard.io |
| HaveIBeenPwned | Breach notification | https://haveibeenpwned.com |
| DeHashed | Breach search | https://dehashed.com |
| IntelligenceX | Dark web + leaks | https://intelx.io |
| LeakCheck | Real-time breach | https://leakcheck.io |
| Snusbase | Recent breaches | https://snusbase.com |
| Hudson Rock | Infostealer intel | https://www.hudsonrock.com |
| Feed | Type | URL |
|---|---|---|
| Spamhaus | IP/domain reputation | https://www.spamhaus.org |
| FireHOL | IP blocklists | https://iplists.firehol.org/ |
| AbuseIPDB | IP abuse reports | https://www.abuseipdb.com |
| GreyNoise | Internet scanner noise | https://www.greynoise.io |
| CINS Score | Botnet IPs | http://cinsscore.com/#list |
| Binary Defense | Banlist | https://www.binarydefense.com/banlist.txt |
| IPsum | Curated IPs | https://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt |
| Platform | Type | URL |
|---|---|---|
| MISP | Open-source CTI platform | https://www.misp-project.org |
| OpenCTI | Open-source CTI platform | https://filigran.io/products/opencti |
| Yeti | IoC platform | https://yeti-platform.io/ |
| aegistrace-threat-intelligence | Python CTI pipeline (author's) | https://github.com/frangelbarrera/aegistrace-threat-intelligence |
| PulseDive | IoC enrichment | https://pulsedive.com |
| AlienVault OTX | Threat exchange | https://otx.alienvault.com |
| Platform | Stars | Language | Last push | What it adds |
|---|---|---|---|---|
| IntelOwl | 4,728 | Python | 2026-09 | Scalable CTI at volume: enriches observables through dozens of analyzers and connectors |
| harpoon | 1,293 | Python | 2026-09 | CLI combining open-source intelligence and threat intelligence lookups |
OSINT for industrial control systems, SCADA, and critical infrastructure:
| Resource | Type | URL |
|---|---|---|
| ICS-Cybersecurity-Audit (author's) | 5-phase audit methodology, IEC 62443 / NIST 800-82 | https://github.com/frangelbarrera/ICS-Cybersecurity-Audit |
| MITRE ATT&CK for ICS | Tactics & techniques matrix | https://attack.mitre.org/matrices/ics |
| CISA ICS Advisories | Vulnerability advisories | https://www.cisa.gov/ics |
| NIST SP 800-82 Rev. 3 | OT security guidance | https://csrc.nist.gov/pubs/sp/800/82/r3/final |
| Tool | Function | URL |
|---|---|---|
| IndustrialScanner (author's) | Modbus/S7Comm/DNP3 PCAP analyzer | https://github.com/frangelbarrera/industrial-scanner |
| Shodan ICS filters | ICS device search | https://www.shodan.io/search?query=port%3A502 |
| Censys ICS | ICS device search | https://search.censys.io/search?resource=hosts&q=tags%3A%22ics%22 |
| Claroty | OT security (vendor) | https://claroty.com |
| Nozomi Networks | OT security (vendor) | https://www.nozominetworks.com |
| Year | Incident | Target | Lesson |
|---|---|---|---|
| 2010 | Stuxnet | Natanz uranium enrichment (IR) | First digital weapon, S7 PLC reprogramming |
| 2015 | BlackEnergy | Ukraine power grid | First confirmed cyber-physical blackout |
| 2016 | Industroyer/CrashOverride | Ukraine power grid | Automated ICS protocol abuse |
| 2017 | TRITON/TRISIS | Saudi Petrochemical (SIS) | First attack on Safety Instrumented Systems |
| 2021 | Colonial Pipeline | US fuel pipeline (IT-side) | Ransomware OT impact without direct compromise |
| 2022 | Industroyer2 | Ukraine energy sector | Modular ICS malware evolution |
Full case studies: https://github.com/frangelbarrera/ICS-Cybersecurity-Audit/tree/main/docs/case-studies
port:502 country:DE # Modbus
port:102 country:ES # S7Comm
port:20000 # DNP3
port:47808 # BACnet
port:4840 # OPC UA
"Schneider Electric" # Quantum PLCs
"Siemens" port:102 # S7 devices
Run OSINT workflows inside Claude Code, Cursor, Ollama, or any MCP-compatible client:
| Resource | Type | URL |
|---|---|---|
| osint-agent-skills (author's) | 22 MCP tools + 295-line system prompt + 9 pivot playbooks | https://github.com/frangelbarrera/osint-agent-skills |
| PulseMCP | MCP server directory | https://www.pulsemcp.com |
| MCP Server Finder (Glama) | Directory | https://glama.ai/mcp/servers |
| awesome-mcp-servers | Curated list | https://github.com/punkpeye/awesome-mcp-servers |
| MCP Server | Wraps | URL |
|---|---|---|
| Brave Search MCP | Brave Search | https://github.com/brave/brave-search-mcp-server |
| Fetch MCP | Web fetcher | https://github.com/modelcontextprotocol/servers/blob/main/src/fetch |
| SQLite MCP | Local DB | https://github.com/modelcontextprotocol/servers-archived/tree/main/src/sqlite |
| Framework | Language | URL | Highlight |
|---|---|---|---|
| AutoGPT | Python | https://github.com/Significant-Gravitas/AutoGPT | Autonomous goal-driven agents |
| CrewAI | Python | https://github.com/crewAIInc/crewAI | Role-based multi-agent |
| LangGraph | Python | https://github.com/langchain-ai/langgraph | Stateful agent graphs |
| n8n | TypeScript | https://n8n.io | Visual workflow + AI nodes |
| Dify | Python | https://dify.ai | Open-source LLM app platform |
| secure-agent-orchestrator (author's) | Python | https://github.com/frangelbarrera/secure-agent-orchestrator | Lightweight SOAR for distributed security agents |
| Tool | Type | URL |
|---|---|---|
| Ollama | Local LLM runner | https://ollama.com |
| LM Studio | Desktop GUI | https://lmstudio.ai |
| vLLM | Production server | https://github.com/vllm-project/vllm |
| Jan | Offline assistant | https://jan.ai |
# 1. Clone the skills repo
git clone https://github.com/frangelbarrera/osint-agent-skills.git
cd osint-agent-skills
# 2. Add to .claude/settings.json
{
"mcpServers": {
"osint": {
"command": "node",
"args": ["./tools/mcp-server.js"],
"env": {
"SHODAN_KEY": "your-key",
"VT_API_KEY": "your-key",
"GITHUB_TOKEN": "your-token"
}
}
}
}
# 3. Launch Claude Code — tools will be auto-discovered| Step | Action | Tool / Source |
|---|---|---|
| 1 | Identify initial entity: legal name, jurisdiction, registration number | OpenCorporates · Companies House UK |
| 2 | Obtain incorporation document | National public registry · OCCRP Aleph |
| 3 | Identify active AND historical directors | OpenCorporates · SEC EDGAR |
| 4 | Identify declared shareholders | OpenOwnership Register · GLEIF |
| 5 | Detect nominees and trusts | ICIJ Offshore Leaks |
| 6 | Verify physical-person identities | LittleSis · national civil registries |
| 7 | Walk the chain to next level (iterate to person or 5 levels max) | Maltego · Obsidian |
| 8 | Cross-check against sanctions (incl. OFAC 50 Percent Rule) | OpenSanctions · OFAC SDN |
| 9 | Verify UBO tax-residency transparency | FATF High-Risk Jurisdictions |
| 10 | Search adverse media and litigation | OpenSanctions PEPs · CourtListener |
| 11 | Validate with blockchain/crypto if applicable | Arkham Intelligence · Etherscan |
| 12 | Document final ownership chain (nodes, edges, %, dates, hashes) | Maltego + Obsidian + SHA-256 per document |
| Tool | URL | Function |
|---|---|---|
| OpenCorporates | https://opencorporates.com | Global corporate registry (140M+ entities) |
| OpenOwnership Register | https://www.openownership.org/en/topics/open-ownership-register/ | Public UBO registers |
| OpenSanctions | https://www.opensanctions.org | Aggregated sanctions + PEPs |
| OCCRP Aleph | https://aleph.occrp.org | Cross-border asset investigation |
| ICIJ Offshore Leaks | https://offshoreleaks.icij.org | Pandora / Panama / Paradise Papers |
| LittleSis | https://littlesis.org | US people–power connections |
| FollowTheMoney | https://followthemoney.tech | OpenSanctions data model |
| FinCEN | https://www.fincen.gov | US financial records portal |
| SEC EDGAR | https://www.sec.gov/edgar | US corporate filings |
| GLEIF | https://www.gleif.org | Legal Entity Identifier registry |
| OFAC SDN List | https://ofac.treasury.gov | US Treasury sanctions |
| EU Sanctions Map | https://www.sanctionsmap.eu | Interactive EU sanctions map |
| CourtListener | https://www.courtlistener.com | US federal court records |
| OpenSecrets | https://www.opensecrets.org | US money-in-politics |
| Sayari | https://sayari.com | Commercial corporate-network intel |
| Equasis | https://www.equasis.org | Global merchant vessel registry |
| Arkham Intelligence | https://info.arkm.com/ | On-chain wallet attribution |
| Dune Analytics | https://dune.com | SQL across 100+ blockchains (free tier) |
| Nansen | https://nansen.ai | Smart-money signals ($49/mo) |
| Arbiscan | https://arbiscan.io | Arbitrum L2 explorer |
| Basescan | https://basescan.org | Base L2 explorer |
| Optimistic Etherscan | https://optimistic.etherscan.io | Optimism L2 explorer |
- Confusing director with UBO. A director signs minutes; a UBO economically controls. In offshore shells the director is usually a professional nominee with 200+ companies.
- Not handling transliterations. Mohammed / Muhammad / Mohamad / Mehmet — exact match fails. Use ISO 9 (Russian) or Hanyu Pinyin (Chinese).
- Trusting PSC Register as ground truth. The UK PSC Register is self-reported; real UBOs hide behind nominees. Always cross-check with ICIJ.
- Treating sanctions lists as binary. "Not listed" ≠ "clean". Designation takes months–years. Use adverse media + peer designations.
- Mixing accusation with conviction. A DOJ forfeiture complaint is a civil allegation, not a conviction. Cite as "the DOJ alleges in its 2016 complaint...".
- Forgetting OFAC 50 Percent Rule. An unlisted entity owned 50%+ in aggregate by sanctioned persons is legally blocked.
- Treating blockchain analytics as absolute truth. Wallet attributions (Arkham, Chainalysis) are heuristics. Always document source and confidence level.
- No chain-of-custody. A screenshot without URL, date, and hash is not admissible. For formal DD: archive.org snapshot + timestamped screenshot + SHA-256.
1Malaysia Development Berhad (1MDB) was a Malaysian sovereign wealth fund established in 2009. Between 2009 and 2015, approximately USD 4.5 billion was misappropriated according to the US Department of Justice. The DOJ filed civil forfeiture complaints in 2016, 2017 and 2019 seeking to recover more than USD 1.7 billion in assets.
Public money flow reconstructed from open sources:
- Origin: Bonds issued by 1MDB (2009-2013) under joint management with Goldman Sachs.
- First shell layer: Transfers to Good Star Limited (Seychelles), controlled by Jho Low (Low Taek Jho).
- Intermediate layer: Good Star → Wynton Trading (BVI) → Black Rock Asia (HK) → accounts linked to Malaysian PM Najib Razak. Part reached Najib's personal AmBank account (USD 681M in 2013, the "Saudi donation").
- Final destination: Real estate in NY / Beverly Hills (USD 100M+), the yacht Equanimus (USD 250M), rights to The Wolf of Wall Street, art works.
Verified public sources:
- DOJ Money Laundering and Asset Recovery Section (kleptocracy cases)
- DOJ press release July 2016
- DOJ: Over $1 Billion in Misappropriated 1MDB Funds Now Repatriated to Malaysia
- Sarawak Report — Clare Rewcastle Brown's blog that broke the scandal in 2015
- ICIJ Offshore Leaks — search "Good Star", "Wynton", "Jho Low"
- PACER US Courts — civil filings, Central District of California
| Tool | URL | Function |
|---|---|---|
| Cover Your Tracks (EFF) | https://coveryourtracks.eff.org | Browser fingerprinting test |
| CreepJS | https://github.com/AbrahamJuliot/creepjs | Advanced Trust Score analysis |
| Mullvad Browser | https://mullvad.net/en/browser | Anti-fingerprinting browser (Tor Project + Mullvad VPN) |
| LibreWolf | https://librewolf.net | Hardened Firefox for privacy |
| Whonix | https://www.whonix.org | Two-VM Tor workstation |
- Audit your current fingerprint with Cover Your Tracks + CreepJS. Document the baseline.
- Decide OPSEC level: Low (normal browser + VPN), Medium (Mullvad Browser + VPN), High (Whonix gateway + Workstation VM).
- Create an isolated research identity: dedicated email, no reuse of personal identity elements.
- For sensitive investigations: use Tails OS on a bootable USB, no persistence.
- Rotate identity periodically (every 30–90 days for long-running investigations).
- Never mix identities: each sock puppet lives in its own browser profile / VM.
- Network hygiene: trusted VPN + DNS over HTTPS. Do not use ISP DNS.
- Metadata strip: MAT2 or ExifTool before uploading any file.
- Communications: Signal or Session for source contact. Not personal WhatsApp.
- Document OPSEC decisions in the final report: what level was used, why, what was done if something failed.
Rule 1: Never use real personal identity. Create a consistent fictitious identity (age, interests, plausible location).
Rule 2: The sock puppet needs a "digital history" — it cannot be born the day of the investigation. Buy accounts with 1–2 years of age or cultivate identities in standby.
Rule 3: Human behaviour. Do not do 200 searches in an hour. Respect plausible hours. Interact with irrelevant content to mix signal.
Rule 4: Consistent device fingerprint. If the sock puppet "lives" in Madrid, the browser must have timezone Europe/Madrid, locale es-ES, no obvious extensions.
Rule 5: Do not cross the line. Sock puppets for verifying public accounts = legitimate. Sock puppets to deceive, manipulate or extract information from people = ethically problematic and legally risky in many jurisdictions.
| Resource | URL | Function |
|---|---|---|
| Mullvad VPN | https://mullvad.net | No-log VPN, anonymous cash payment |
| IVPN | https://www.ivpn.net | Audited no-log VPN |
| ProtonVPN | https://protonvpn.com | Swiss VPN, freemium |
| Tor Project | https://www.torproject.org | Network anonymity |
| Snowflake | https://snowflake.torproject.org | WebRTC pluggable transport |
| obfs4 bridges | https://bridges.torproject.org | Anti-censorship Tor bridges |
| Tool | URL | Function |
|---|---|---|
| GrayhatWarfare | https://buckets.grayhatwarfare.com | 712K+ indexed buckets (2K free, premium paid) |
| osint.sh/buckets | https://osint.sh/buckets | Keyword search across AWS+Azure buckets |
| cloud_enum | https://github.com/initstring/cloud_enum | Multi-cloud enumeration (AWS / Azure / GCP) |
| GrayhatWarfare Shorteners | https://grayhatwarfare.com | URL shortener enumeration |
- Identify candidate bucket names based on target domain (e.g.
acmecorp-backups,acme-assets,acme-public). - Search GrayhatWarfare by target keyword.
- Validate with cloud_enum (permutation brute-force of plausible names).
- If an open bucket is found, enumerate objects with
aws s3 ls --no-sign-request s3://bucket-name/ --recursive. - Document timestamp + hash before downloading evidence.
- For Azure: use Azure Storage Explorer or
az storage blob list --account-name X --container-name Y --auth-mode login. - For GCP:
gsutil ls gs://bucket-name/(without auth shows public objects). - Responsible disclosure if sensitive data is found exposed.
site:s3.amazonaws.com "target"
site:blob.core.windows.net "target"
site:storage.googleapis.com "target"
site:amazonaws.com filetype:pdf "confidential"
- Accessing a public bucket is legitimate. If the bucket is open, it is the owner's responsibility.
- Downloading sensitive data (PII, credentials) and publishing it = illegal in most jurisdictions.
- Report to the owner via responsible disclosure (security.txt of the domain).
- Do not use found credentials to escalate access. That crosses from OSINT into attack.
| Tool | URL | Function |
|---|---|---|
| MobSF | https://github.com/MobSF/Mobile-Security-Framework-MobSF | Automated static/dynamic analysis framework |
| jadx | https://github.com/skylot/jadx | Java decompiler for APKs |
| apktool | https://ibotpeaches.github.io/Apktool/ | APK resource decoder |
| dex2jar | https://github.com/pxb1988/dex2jar | .dex → .jar converter |
| APKPure | https://apkpure.com | Alternative APK source to Google Play |
| APKMirror | https://www.apkmirror.com | Historical APK archive |
- Download APK from APKPure, APKMirror or Google Play (with
apkeeporgplaycli). - Load into MobSF for an automatic report: permissions, components, hardcoded secrets, URLs in code.
- Decompile with jadx for manual inspection: search for
api_key|secret|token|password|AWS_|STRIPE_with grep. - Audit AndroidManifest.xml for excessive permissions (location + contacts + SMS in an app that doesn't need them).
- Identify third-party SDKs (analytics, ads, trackers): Facebook SDK, Google Analytics, Firebase, AppsFlyer, Adjust.
- Document findings with code captures + file names + line numbers.
- Government / banking apps: audit permissions and SDKs to see what data they collect.
- Competitor apps: identify internal APIs (hardcoded URLs) for competitive intelligence.
- Dating / social apps: find undocumented endpoints (useful for safety investigations).
- Tracking apps: verify what data from minors educational apps collect.
- Static analysis is legitimate. The APK is distributable and public.
- Dynamic analysis on your own device is legitimate.
- Publicly sharing decompiled code may violate copyright and Terms of Service.
- Do not use discovered internal APIs for mass scraping or abuse.
| Tool | URL | Function |
|---|---|---|
| Bluesky Firehose (official) | https://docs.bsky.app/docs/advanced-guides/firehose | Authenticated stream of ALL events |
| AT Protocol SDK | https://atproto.blue/en/latest/atproto_firehose/index.html | Python SDK for the firehose |
| Reaper Social | https://reaper.social | Mastodon / Fediverse search & investigation |
| DigitalStakeout Bluesky monitoring | https://www.digitalstakeout.com/blog/bluesky-firehose-integration | Commercial monitoring |
| Nostr | https://nostr.org | Protocol + NIP-05 identity verification |
- Bluesky real-time: subscribe to the firehose with a keyword/user filter. For historical data, Bluesky has no native search API — use third-party (Reaper Social).
- Mastodon: each instance has its own API. Federated search is limited. List instances relevant to the target (e.g.
infosec.exchange,mas.to). - Nostr: NIP-05 verification exposes domain-linked identity. Allows pivoting from handle to verified domain.
- Farcaster: Warpcast is the main client. Public API for feeds.
- Extremism monitoring: migration of accounts banned from X to Mastodon / Nostr.
- Geopolitical investigations: Russian / Chinese actors moving to decentralized platforms after blocks on Western ones.
- Crypto communities: many Web3 projects use Farcaster and Nostr natively.
| Tool | URL | Function |
|---|---|---|
| Have I Been Pwned | https://haveibeenpwned.com | Free personal breach check (1018+ sites) |
| DeHashed | https://dehashed.com | Deep-web scans (freemium) |
| Intelligence X | https://intelx.io | Dark web + breaches |
| JustDeleteMe | https://justdeleteme.xyz | Direct deletion links for 500+ services |
| JustGetMyData | https://justgetmydata.com | GDPR data request links |
| Hudson Rock | https://www.hudsonrock.com/threat-intelligence-cybercrime-tools | Infostealer free lookup |
- Initial self-audit: search your email, username, real name in HIBP + DeHashed + IntelX + Google (
"your name" filetype:pdf). - Identify forgotten accounts via JustDeleteMe — list of services where you ever registered.
- Request personal data download via JustGetMyData (GDPR gives right to data export in 30 days).
- Delete unnecessary accounts with priority: old social networks, abandoned forums, duplicate services.
- Rotate compromised passwords with a password manager (Bitwarden, 1Password, KeePassXC).
- Document your own footprint BEFORE starting a sensitive investigation — knowing your exposure prevents surprises.
- Google Account: Activity Controls (disable Web & App Activity, Location History, YouTube History).
- Facebook: review privacy settings, download data, disable facial recognition.
- LinkedIn: review profile visibility, hide connections if you investigate sectors where your network may be a signal.
- Telegram: use a virtual number, not your main one. Enable 2FA.
- WhatsApp: review profile photo visibility, last connection, status. For investigations: secondary account with virtual number.
| Tool | URL | Function |
|---|---|---|
| Telepathy v2.3.4 | https://github.com/prose-intelligence-ltd/Telepathy-Community | Telegram OSINT toolkit (Jordan Wildon) |
| Telegago (Google CSE) | https://cse.google.com/cse?cx=006368593537057042503:efxu7xprihg | Google CSE for Telegram (do NOT use telegago.com — hijacked) |
| TelegramDB | https://telegramdb.org | Telegram channel search engine |
| TGStat | https://tgstat.com | Telegram statistics |
| DiscordLeaks (Unicorn Riot) | https://discordleaks.unicornriot.ninja/ | Discord server leaks |
- Get API credentials at https://my.telegram.org (real, valid phone number required).
- Install Telepathy:
pip install telepathy. - Basic commands:
telepathy -c channel_name(channel info),telepathy -u username(user info),telepathy -g group_id --members(memberlist). - Mass archiving:
telepathy -c channel --export json. - Location lookup: Telegram users may expose approximate location via the "People Nearby" feature.
- Server discovery via https://disboard.org and https://discordservers.com (third-party search engines).
- Discord API v10 with correct intents:
GUILD_MESSAGESto read messages,GUILD_MEMBERSfor memberlist (requires verification if bot is in >100 servers). - Audit log analysis if you have admin in the server:
discord.com/api/v10/guilds/{guild.id}/audit-logs. - User ID lookup: https://discord.id (decodes snowflake to creation timestamp).
- OPSEC: NEVER join a target server with your personal account. Create a sock puppet with a dedicated email.
- OSINT Combine — Inside Discord: An OSINT Guide
- Bellingcat Toolkit — Telepathy entry
- OSINT Handbook — Telegram
Critical context (2026): The Economist (15 March 2026) documented "Open-source intelligence shuts down" — Planet Labs enacted an indefinite blackout over the Middle East following the Gaza war; Maxar, Planet and BlackSky restricted commercial imagery. In parallel, democratization via SkyFi ($15 per image) and Copernicus Browser (ESA, free) continues. This is the defining tension of GEOINT in 2026.
| Tool | URL | Function |
|---|---|---|
| Copernicus Browser | https://browser.dataspace.copernicus.eu | Sentinel-1/2/3/5P free, full resolution |
| SkyFi | https://skyfi.com | Multi-provider marketplace ($15/image) |
| Sentinel Hub | https://www.sentinel-hub.com | Commercial over Sentinel data |
| NASA Worldview | https://worldview.earthdata.nasa.gov | Near-real-time satellite |
| USGS Earth Explorer | https://earthexplorer.usgs.gov | USGS catalogue (Landsat, MODIS) |
| Planet Labs | https://www.planet.com | Daily commercial satellite (may be restricted) |
| Maxar | https://vantor.com/ | High resolution (may be restricted post-Gaza) |
| Umbra Space | https://www.umbra.space | High-resolution SAR |
- Start with Copernicus Browser (free, historical archive from 2015+, Sentinel-2 at 10 m resolution).
- If you need near-real-time: NASA Worldview (latency <3 hours for MODIS).
- For new tasking or sub-meter resolution: SkyFi ($15+ per selective image, multi-provider).
- Before publishing: verify the provider's EULA (Planet/Maxar may revoke publication rights).
- Document source + timestamp + cloud cover % for every image used.
- For chronolocation: combine with historical imagery from Google Earth Pro (free).
- For SAR (cloud-penetrating): Copernicus Sentinel-1 or Umbra (commercial).
- Bellingcat — How to Use Free Satellite Imagery (May 2024)
- GIJN Reporter's Tipsheet — Free Satellite Images
Industrial milestone (May–August 2026): OpenAI joined the C2PA steering committee and adopted Google DeepMind's SynthID. Google announced native C2PA + SynthID verification in Search and Chrome (Google I/O 2026). Reality Defender was named "Market Shaper" by Gartner. This is the industry's scalable response to the deepfake arms race.
| Tool | URL | Function |
|---|---|---|
| C2PA viewer | https://c2paviewer.com | Visual verifier of C2PA manifests |
| Content Credentials | https://contentcredentials.org | C2PA provenance ecosystem |
| SynthID (Google DeepMind) | https://deepmind.google/models/synthid/ | AI content watermarking |
| Reality Defender | https://www.realitydefender.com | Deepfake detection (free API 50/mo) |
| Truepic | https://truepic.com | Content credentials platform |
| Sensity AI | https://sensity.ai | Deepfake detection |
| C2PA open-source SDK | https://opensource.contentauthenticity.org | Open-source Content Credentials tooling |
| SynthID Text | https://github.com/google-deepmind/synthid-text | Text watermarking reference implementation |
- Verify C2PA Content Credentials with C2PA Viewer before any analysis.
- Check for SynthID signals if the content was produced by a supported Google model; treat the result as probabilistic, not conclusive.
- If no credentials, run Reality Defender / Sensity for forensic analysis.
- Document absence of credentials as an indicator (not proof) of manipulation.
- Cross-check with reverse image search (Google Lens, Yandex, TinEye).
- For video: extract keyframes with FFmpeg and analyse each one.
The IIR is the atomic deliverable: one question, one source, one time, one evaluation. It is not a dossier (that is the Target Package). The IIR feeds a dossier.
====================================================================
INTELLIGENCE INFORMATION REPORT (IIR)
====================================================================
--- HEADER ---
REPORT NUMBER: [ORG]-IIR-[YYYY]-[NNNN]
CLASSIFICATION: UNCLASSIFIED // FOR OFFICIAL USE ONLY
SUBJECT COUNTRY: [Country ISO 3166-1 alpha-3]
PREPARED BY: [Analyst name or team]
REPORT DATE: [ISO 8601: YYYY-MM-DDThh:mmZ]
PERIOD OF REPORT: [Start date → End date]
REQUESTING OFFICE: [Team/Department that requested the analysis]
--- SOURCE EVALUATION (NATO A-F / 1-6 system) ---
SOURCE RELIABILITY: [A/B/C/D/E/F]
A=Confirmed · B=Usually reliable · C=Fairly reliable
D=Not usually reliable · E=Unreliable · F=Cannot be judged
INFO CREDIBILITY: [1/2/3/4/5/6]
1=Confirmed by others · 2=Probably true
3=Possibly true · 4=Doubtfully true · 5=Improbable
6=Cannot be judged
SOURCE DESCRIPTION: [One line, do not expose sensitive source]
SOURCE ACCESS: [Public / Aggregated / Paid / Provided by third party]
--- CONFIDENCE LEVEL (ICD 203) ---
CONFIDENCE: [HIGH / MODERATE / LOW]
JUSTIFICATION: [2-3 lines. High = corroborated by ≥2 independent sources
with solid causal logic. Moderate = 1 reliable or 2 moderate.
Low = single or weak source]
KEY ASSUMPTIONS: [List of assumptions that, if broken, lower confidence]
--- BODY ---
BLUF (Bottom Line Up Front):
[1-3 sentences. The reader must understand the critical finding from this alone.]
KEY FINDINGS (numbered, max 5):
1. [Critical finding #1]
2. [Critical finding #2]
3. [Critical finding #3]
EVIDENCE (each finding with support):
- Finding #1:
* Sources: [URL + capture date]
* Capture: [SHA-256 of original document / screenshot]
* Archive: [archive.org snapshot URL if applicable]
ANALYSIS (interpretation, not evidence):
[What it means, what it implies, what it does not imply. Apply SATs from Appendix B]
KNOWLEDGE GAPS (what you DO NOT know):
- [Gap 1]
- [Gap 2]
RECOMMENDATIONS (prioritized next steps):
1. [Action — who, what, when]
2. [Action]
3. [Action]
--- ANNEXES ---
A. Sources list (URLs, dates, hashes)
B. Charts/maps/graphs (ownership diagram, timeline, geo)
C. Raw data (PDFs, screenshots, exports)
D. Methodology note (which SATs were applied)
E. Chain of Custody log (see 45.5)
--- DISTRIBUTION ---
TO: [Nominal list]
CC: [Nominal list]
NOFORN: [Y/N]
--- REVISION HISTORY ---
| Rev | Date | Author | Changes |
|-----|------------|---------------------|-------------------------------|
| 0.1 | 2026-07-19 | A. Senior | Initial draft |
| 1.0 | 2026-07-20 | A. Senior+Reviewer | Peer review, approval |
====================================================================
| # | Field | Typical Source |
|---|---|---|
| 1 | Full canonical name + aliases | LinkedIn, civil registry |
| 2 | Date and place of birth | Adverse media, public records |
| 3 | Nationality(ies) | Public visas, public records |
| 4 | Official identifiers (RFC/CURP/CPF/CUIT/DNI) | Public registry |
| 5 | Reference photo(s) (min. 1 frontal) | LinkedIn, press |
| 6 | Chronological professional bio | LinkedIn, OCCRP Aleph |
| 7 | Current positions | LinkedIn, corporate registry |
| 8 | Relevant historical positions (10 years) | OpenCorporates, EDGAR |
| 9 | Key personal relationships | LittleSis, adverse media |
| 10 | Corporate relationships (UBO/director) | OpenOwnership, OpenCorporates |
| 11 | PEP status + since when + level | OpenSanctions PEP |
| 12 | Sanctions status + designation date | OpenSanctions aggregator |
| 13 | Adverse media (3-5 incidents) | Google News, OCCRP, ICIJ |
| 14 | Litigation (civil/criminal/admin) | PACER, local judicial registry |
| 15 | Digital footprint (email/phone/domains) | Maigret, HIBP, WhoisXML |
| 16 | Real estate footprint | Property registry |
| 17 | Declared net worth (if PEP) | Asset declaration |
| 18 | Travel and residences (5 years) | Press, Instagram geotags |
| 19 | Identified associated risks | Output of analysis |
| 20 | Analytic confidence + gap list | — |
┌──────────────────────────────────────────────────────────────────┐
│ EXECUTIVE BRIEFING — [Topic] │
│ Classification: CONFIDENTIAL // C-Suite only Date: YYYY-MM-DD │
├──────────────────────────────────────────────────────────────────┤
│ │
│ BLUF (Bottom Line Up Front): │
│ [2-3 sentences, no jargon] │
│ │
│ Confidence: HIGH ▓▓▓ / MODERATE ▓▓░ / LOW ▓░░ │
│ │
├──────────────────────────────────────────────────────────────────┤
│ 1. CONTEXT (what was investigated and why) [3-4 lines] │
│ │
│ 2. KEY FINDING [4-6 lines] │
│ - Central fact │
│ - Source(s) │
│ - Implication for the organization │
│ │
│ 3. RISK AND IMPACT (financial/reputational/operational/legal) │
│ [2x2 table or list; A/B/C marks by severity/probability] │
│ │
│ 4. RECOMMENDATIONS (3, prioritized) │
│ 1. [Immediate action — 24-72h] │
│ 2. [30-day action] │
│ 3. [90-day action] │
│ │
│ 5. NEXT STEPS / KNOWLEDGE GAPS │
│ - What is missing and how to close it (cost/effort estimate) │
│ │
├──────────────────────────────────────────────────────────────────┤
│ Full annex: [link to full IIR / Target Package] │
│ Analyst contact: [name, email, phone] │
└──────────────────────────────────────────────────────────────────┘
FACT-CHECK REPORT
=================
1. CLAIM (the verified statement)
Literal text: "..."
Claim source: [URL + date + capture]
Who said it: [person/entity + position]
2. VERIFICATION DATE: YYYY-MM-DD
3. VERIFIER(S): [name(s)]
4. VERIFICATION STATUS:
[ ] True [ ] Mostly true
[ ] Misleading [ ] Mostly false
[ ] False [ ] Unverifiable
5. EVIDENCE COLLECTED
5.1 Source 1: [type, URL, date, hash]
5.2 Source 2: ...
5.3 Source 3: ...
6. ANALYSIS (what weighs more and why)
7. OMITTED CONTEXT (what the claim does not say)
8. CONTACT WITH ORIGINAL SOURCE
Was the claimant contacted? Yes/No · Response: [...]
9. REFERENCES [verifiable URLs]
10. POST-PUBLICATION CORRECTIONS [log]
11. LICENSE AND REUSE
Before capturing:
- 1. Synchronise the device clock with NTP (difference <1s).
- 2. Verify the browser is clean (no logged-in session that biases served content).
- 3. Log pre-capture: exact URL, date/time with explicit timezone, public IP, access method (direct/VPN/Tor).
During capture:
- 4. Capture with visible timestamp on screen.
- 5. Save original format: complete HTML ("Save Page As → Webpage, Complete") + uncropped PNG screenshot.
- 6. Generate a snapshot on archive.org / archive.today and save the returned URL.
- 7. For video: download with
yt-dlppreserving original metadata; do not re-encode.
Immediately after:
- 8. Compute SHA-256 of the original file and log: filename, hash, size, UTC capture date.
- 9. For JS-heavy captures: also save HAR file (Network → Save All as HAR) and WARC if using wpull or archiveweb.
- 10. Rename files with convention
{YYYYMMDDTHHMMZ}_{slug}.{ext}(no spaces or accents).
Storage:
- 11. Store in an append-only repository (git with tags or WORM system). Never overwrite, only version. Second offline repository recommended.
- 12. Maintain a master CSV/JSON log with columns: case_id · filename · sha256 · capture_url · capture_timestamp_utc · capture_method · analyst · notes. One master file per case.
| Tool | URL | Function |
|---|---|---|
| Obsidian | https://obsidian.md | Linked notes with graphs |
| TimelineJS | https://timeline.knightlab.com | Interactive timelines |
| Aeon Timeline | https://www.aeontimeline.com | Complex timelines |
| Draw.io / diagrams.net | https://www.drawio.com/ | Diagrams and flows |
| Zotero | https://www.zotero.org | Reference management |
| CryptPad | https://cryptpad.fr | Encrypted collaboration |
| Standard Notes | https://standardnotes.com | E2E encrypted notes |
| VeraCrypt | https://veracrypt.io/ | Container encryption |
| MAT2 | https://0xacab.org/jvoisin/mat2 | Metadata stripping |
| ExifTool | https://exiftool.org | Metadata extraction |
| OpenTimestamps | https://opentimestamps.org | Blockchain timestamping |
| Hunchly | https://hunch.ly | Web capture with OPSEC ($129/yr) |
| archive.org Wayback | https://web.archive.org | Historical web archive |
| Archive.today | https://archive.today | Wayback alternative |
| Maltego | https://www.maltego.com | Link analysis and visualization |
| Datasette | https://datasette.io | Explore CSV/SQLite |
| Gephi | https://gephi.org | Graph analysis |
| RAWGraphs | https://rawgraphs.io | Charts from CSV |
| Datawrapper | https://www.datawrapper.de | Visualization for reports |
| QGIS | https://qgis.org | Desktop GIS |
| Mapillary | https://www.mapillary.com | Crowdsourced street-view |
| Atlos | https://www.atlos.org | Collaborative investigation |
| Auto-Archiver (Bellingcat) | https://github.com/bellingcat/auto-archiver | Automatic archiving |
| 4CAT | https://github.com/digitalmethodsinitiative/4cat | Social data analysis |
| Pinpoint (Google Journalist Studio) | https://journaliststudio.google.com/pinpoint/collections | Document analysis |
- BLUF absent or buried. The executive reader has no time. If the critical finding is on page 7, it does not exist.
- Confusing fact with inference. "Company X is owned by Y" (fact) vs. "probably controlled by Y" (inference). Use markers
[FACT]vs[ANALYSIS]. - No chain of custody. A screenshot without URL, date and hash is anecdotal.
- Overloading with tools. The C-Suite does not care which tools you used, only the findings.
- Not declaring knowledge gaps. A senior declares what they do not know; a junior hides it.
- Unjustified confidence. "High Confidence" without justification = suspicious.
- Wrong format scaling. A 30-page IIR to a CFO = won't be read. A 1-page executive briefing to an auditor = useless.
- No versioning. Without revision history, no one knows if they are reading version 0.1 or 1.4.
The country research is organized as individual Markdown files in countries/. Each file uses the same seven-category structure, includes a review date and can be updated independently.
| Region | Countries | Directory |
|---|---|---|
| Americas | United States, Brazil, Mexico, Argentina, Canada | countries/ |
| Western Europe | United Kingdom, Germany, France, Spain, Italy, Poland | countries/ |
| Eastern Europe & Russia | Russia, Ukraine | countries/ |
| Asia-Pacific | China, Korea (North & South), Japan | countries/ |
| Middle East | Israel, Iran, Saudi Arabia, Turkey | countries/ |
| Oceania | Australia | countries/ |
countries/README.md— complete country index and maintenance guidance.countries/_TEMPLATE.md— single source of truth for the seven standard categories.- Country files contain public-source research and access notes; verify availability and applicable law before relying on any resource.
Country URLs were last reviewed on 2026-09-25. Availability can vary by date, network, WAF policy and geography.
Public methodology of leading OSINT / threat intelligence companies. Each section below distils the publicly documented methodology from vendor blogs, reports and academic case studies. Marketing claims are flagged explicitly. Workflows are descriptive of what the company publishes — they are not leaks of internal SOPs.
Briefing: Independent, Netherlands-based investigative journalism NGO founded 2014 by Eliot Higgins. Uses open-source and social-media content (photos, videos, satellite imagery, leaked databases, flight records, court filings) to investigate armed conflicts, human-rights abuses, state-sponsored assassinations and environmental crimes. Operates a small staff plus a global network of volunteer researchers; publishes its tools and methods openly. Combines geolocation, chronolocation, content verification and structured cross-referencing of leaked or paid-data sources.
Landmark public cases (with verifiable URLs):
- MH17 downing (2014-2017) — linked the Buk missile launcher to the Russian 53rd Anti-Aircraft Missile Brigade.
- Skripal poisoning (2018) — identified Salisbury suspects as GRU officers Chepiga and Mishkin.
- Navalny poisoning (2020) — identified the FSB chemical-weapons team.
- Bucha/Ukraine monitoring (2022-) — real-time verification of civilian casualties.
Reproducible 12-step methodology (as published):
- Define the question and the verifiable hypothesis.
- Collect primary open sources — Telegram, VK, X, passenger manifests, leaked phone-call metadata, satellite imagery, court records. Bellingcat explicitly relies on the Russian "probiv" data market (Telegram bots returning passport/phone/vehicle records).
- Cross-reference every single data point against a second source.
- Use leaked databases as anchor sources — they are immutable snapshots that cannot be retroactively edited.
- Pivot on travel records — examine passenger manifests of parallel flights (one day earlier/later).
- Pivot on phone records — list every number called; reverse-lookup each (GetContact, Telegram bots).
- Use address and vehicle registration to identify employer — when an FSB/GRU officer registers a vehicle at a government facility, enumerate every other vehicle at that address (Bellingcat found 191).
- Use parking-payment databases for geolocation.
- Reverse-engineer alias-generation patterns — FSB/GRU algorithm: same first name, same day/month of birth (year shifted ±1), last name = wife's/girlfriend's maiden name.
- Geolocate imagery when needed — Yandex Images, Google Lens, SunCalc, Google Earth, Mapillary.
- Cluster suspects by repeated co-travel and communication — graph of who communicated with whom, who flew with whom, who shared addresses.
- Publish the full evidence chain — methodology, screenshots, redacted raw data, names — alongside partner outlets (The Insider, CNN, Der Spiegel) for auditability.
Tools Bellingcat publicly mentions:
- Bellingcat Online Investigation Toolkit (https://bellingcat.gitbook.io/toolkit)
- Telegram probiv bots (paid, grey-market)
- GetContact, Yandex Maps/Images, Google Earth Pro, Sentinel Hub, Copernicus EMS, NASA FIRMS, SunCalc, FlightRadar24, ADS-B Exchange, OpenSky Network, OpenCorporates, Wayback Machine, archive.today, Hunchly, InVID-WeVerify, FotoForensics, Forensically, Maltego, Spiderfoot, theHarvester.
Limitations & ethics:
- Reliance on Russian grey-market data. Bellingcat explicitly acknowledges the privacy and ethics concerns of buying leaked phone records and passport files; the practice would be illegal in most Western jurisdictions (GDPR).
- Geographic bias. Strongest cases involve Russia, Syria, Ukraine — regions with porous data protection and active conflicts. China, North Korea and Iran are far harder.
- NGO, not forensic lab. Their findings are journalistic conclusions, not chain-of-custody evidence admissible in court without corroboration.
- Volunteer model means variable quality control; the editorial team applies the same 12-step cross-referencing standard before publication.
Briefing: Mandiant was acquired by Google in September 2022 for $5.4B and is now part of Google Threat Intelligence (GTI). Its methodology is incident-response-led threat-actor clustering using the UNC (UNCategorized) taxonomy. Novel malicious activity is grouped into a temporary UNC#### cluster; when enough TTP, infrastructure and code overlap accumulates, the cluster is merged into an existing named group (APT## for state-sponsored, FIN## for financially motivated).
Landmark public cases (with verifiable URLs):
- SolarWinds / UNC2452 → APT29 (2020-2021). https://cloud.google.com/blog/topics/threat-intelligence/unc2452-merged-into-apt29
- M-Trends 2025 annual report — Mandiant tracked 302 different threat groups in 2024. PDF: https://services.google.com/fh/files/misc/m-trends-2025-en.pdf
- APT groups catalogue: https://cloud.google.com/security/resources/insights/apt-groups
- Trade-Offs of Cyber Attribution (methodology paper): https://cloud.google.com/blog/topics/threat-intelligence/trade-offs-attribution
Public 12-step workflow (reconstructed from public blog posts):
- Triage an incident / sample submission. A new artefact enters via Mandiant Consulting IR engagements, the VirusTotal corpus, or Google telemetry. Compute hashes, extract strings, run YARA rules.
- Pivot through VirusTotal Graph. Walk from the artefact to related files, URLs, contact domains and IPs that share behaviour, submission timing or first-seen dates.
- Cluster the activity into a UNC. If the TTPs do not match an existing named group, a new
UNC####designator is created. - Accumulate evidence over time. Overlap dimensions: code sharing, infrastructure reuse (registrant info, SSL certs, ASN patterns), victimology, attack lifecycle, timing.
- Apply the Suspected/Possible confidence scale. Analysts score overlaps as
Possible Association(weak) orSuspected Association(strong). https://gtidocs.virustotal.com/docs/suspected-attribution - Test the merge hypothesis. Compare the UNC against every named
APT##/FIN##in the catalogue. - Peer-review within Mandiant Intelligence. Other analysts challenge the merge — looking for counter-evidence (tool sharing between unrelated groups, false-flag indicators).
- Publish attribution with confidence label. Mandiant reports use "assessed with high/moderate/low confidence" language aligned with ICD-203.
- Public merge announcement. When attribution is final, Mandiant publishes a blog post announcing the merge.
- Update YARA rules and detection content. IOCs, YARA, STIX/TAXII feeds updated.
- Brief IR consultants and customers.
- Re-evaluate periodically. If new evidence contradicts the merge, Mandiant can split the cluster again.
Tools Mandiant publicly mentions:
- VirusTotal (public + Enterprise), VirusTotal Graph, Mandiant Advantage, Google Chronicle / Google Security Operations, YARA, FLARE-VM, capa, Google telemetry (Gmail, Chrome Safe Browsing, Android Play Protect).
Limitations:
- Product-vs-research blur. Public reports mix commercial positioning with actual methodology.
- Confidence is explicitly graded. Mandiant does not claim 100% attribution.
- VirusTotal dataset bias. VT submissions skew Western; actors who avoid AV and submission to VT are under-represented.
- Acquisition friction. Pre-2022 Mandiant publications (Equation Group, APT1, FIN7) were produced when Mandiant was independent; post-acquisition work is integrated with Google telemetry.
Briefing: Endpoint protection + threat intelligence company famous for the adversary naming convention where every tracked actor gets a name composed of an animal + a weather/event term: BEAR (Russia), PANDA (China), SPIDER (eCrime), KITTEN (Iran), CHOLLIMA (North Korea), HAWK (India). CrowdStrike's methodology is centred on Falcon endpoint telemetry + analyst cells.
Landmark public cases:
- DNC hack (2016). CrowdStrike attributed the breach to FANCY BEAR (APT28) and COZY BEAR (APT29).
- Fancy Bear Ukrainian artillery (2016). https://en.wikipedia.org/wiki/Fancy_Bear
- Global Threat Report (annual). https://www.crowdstrike.com/en-us/global-threat-report/
Public 10-step attribution methodology:
- Falcon telemetry ingestion — endpoint sensors collect process, network, file, registry events.
- ML + analyst cells triage — machine learning flags suspicious patterns; human analysts review.
- Activity clustering — group observed activity into clusters based on shared TTPs.
- Geopolitical overlay — apply country attribution based on victimology, language indicators, working hours.
- Adversary naming — assign a new name (BEAR/PANDA/SPIDER/KITTEN/CHOLLIMA/HAWK + suffix).
- Peer review — other analysts challenge the attribution.
- Independent verification policy — CrowdStrike publishes enough detail for independent verification.
- Publish adversary profile — full TTPs, IOCs, MITRE ATT&CK mapping.
- Update detection content — Falcon platform updated to detect the new adversary.
- Adversary Universe — public web page documenting all tracked adversaries. https://www.crowdstrike.com/en-us/adversaries/
Limitations:
- Endpoint bias — CrowdStrike's visibility is endpoint-centric; network-only attacks may be missed.
- Marketing of "Adversary Universe" — branding on real process; the methodology is real but the public site is partly marketing.
- Naming complexity — same actor = FANCY BEAR / APT28 / Forest Blizzard / Strontium / Sofacy / Pawn Storm / Sednit. The 2025 Microsoft-CrowdStrike shared glossary (https://learn.microsoft.com/en-us/unified-secops/microsoft-threat-actor-naming) is an attempt to harmonise.
Briefing: Threat intelligence platform using NLP + machine learning over OSINT masivo. The Insikt Group is the research arm. Markets the "centaur model" (human + AI) and the "Intelligence Graph®" (trademarked marketing terms wrapping real methodology).
Landmark public cases:
- Insikt Group research portal — https://www.recordedfuture.com/research
- Iran AI report — Recorded Future's research on Iranian AI capabilities.
- CopyCop disinformation — analysis of an AI-generated disinformation network.
Public 4-pillar methodology (per Insikt Group's published description):
- Infrastructure detection and pivoting — auto-detection of malicious infrastructure, pivot to related domains/IPs.
- Victim identification — automatic identification of victims from breach reports, dark web posts.
- Network traffic analysis — analyse C2 traffic patterns.
- Multi-source validation — the centaur model: AI proposes, human analyst verifies.
Output formats: 7 standard formats — Intelligence Brief, Full Report, Flash Report, Special Report, Cyber Daily newsletter, Weekly Cyber Exploits, Monthly Threat Forecast.
Limitations:
- Enterprise pricing ($$$) — Recorded Future platform is enterprise-priced. Recommend the free Community Edition only as a teaser, not a working tool.
- "Centaur model" and "Intelligence Graph®" are trademarked marketing terms wrapping real methodology.
- AI bias — NLP models can amplify biased sources if training data skews Western.
Briefing: Unified commercial brand launched April 2024 after folding together Chronicle (cloud-native SIEM, 2018), VirusTotal (acquired by Google in 2012, >2 billion analysed files/URLs/domains/IPs) and Mandiant (acquired September 2022). GTI's research methodology is essentially Mandiant's methodology — IR-led threat-actor clustering using the UNC taxonomy.
Public emblematic cases:
- SolarWinds / UNC2452 → APT29 — https://cloud.google.com/blog/topics/threat-intelligence/unc2452-merged-into-apt29
- M-Trends 2025 — https://services.google.com/fh/files/misc/m-trends-2025-en.pdf
- APT groups catalogue — https://cloud.google.com/security/resources/insights/apt-groups
- Suspected Attribution API — https://gtidocs.virustotal.com/docs/suspected-attribution
Methodology: Same as Mandiant (see above) + Google's corpus (VT + Gmail + Chrome + Android telemetry) as the corroborating evidence base.
Useful public resources:
| Resource | URL |
|---|---|
| Google Cloud TI blog | https://cloud.google.com/blog/topics/threat-intelligence |
| M-Trends 2025 PDF | https://services.google.com/fh/files/misc/m-trends-2025-en.pdf |
| APT groups catalogue | https://cloud.google.com/security/resources/insights/apt-groups |
| GTI documentation portal | https://gtidocs.virustotal.com/ |
| VirusTotal (free) | https://www.virustotal.com/gui/ |
| Mandiant GitHub (open-source tools) | https://github.com/mandiant |
Briefing: In-house research team that tracks nation-state and criminal actors across Microsoft's vast telemetry surface — Windows, Office 365 email, Azure, Microsoft Defender for Endpoint, LinkedIn, Bing and Xbox. According to the 2024 Microsoft Digital Defense Report, MSTIC observes ~600 million cyberattacks per day.
Adversary naming convention (2 eras):
- 2015-April 2023: Chemical elements (typosquatted) — Strontium (APT28), Nobelium (APT29), Zinc, Chromium, Thallium, Hafnium, Phosphorus, Bismuth. Microsoft deliberately misspelled real chemical element names so they could register matching domains/handles without impersonating the real-element websites.
- April 2023-present: Weather taxonomy — Russian actors =
* Blizzard, Chinese =* Typhoon, Iranian =* Sandstorm, Lebanese =* Rain, North Korean =* Sleet, Indian =* Hawk. Replaced the element scheme for clarity.
Public emblematic cases:
- SolarWinds / NOBELIUM / APT29 (2020-2021) — MSTIC was the first to publicly name the actor.
- Volt Typhoon (2023) — Chinese critical-infrastructure targeting disclosure.
- Forest Blizzard / APT28 (2024) — Russian military intelligence.
- Microsoft Digital Defense Report 2024 — https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2024
- MS-CrowdStrike shared naming glossary (2025) — https://learn.microsoft.com/en-us/unified-secops/microsoft-threat-actor-naming
Public 12-step workflow (reconstructed from MSTIC blog posts):
- Telemetry ingestion from Windows, O365, Azure, Defender, LinkedIn, Bing, Xbox.
- ML + analyst triage — anomaly detection, then human review.
- MITRE ATT&CK mapping — map observed TTPs to ATT&CK techniques.
- Country assessment — based on victimology, language, working hours, infrastructure.
- Weather naming — assign a name based on country of origin + weather phenomenon.
- Government coordination — MSTIC frequently discloses nation-state activity in coordination with US government (CISA, FBI).
- Publish technical blog post with IOCs, YARA, detection queries.
- Update Defender detections — push detection content to Defender for Endpoint customers.
- Brief government partners — CISA, NSA, FBI.
- Publish Digital Defense Report — annual public summary.
- Update threat actor encyclopedia — https://learn.microsoft.com/en-us/unified-secops/microsoft-threat-actor-naming.
- Re-evaluate periodically — splits/merges as evidence accumulates.
Limitations:
- Naming churn — chemical→weather (April 2023) caused industry confusion.
- US-gov alignment appearance — MSTIC's nation-state disclosures often align with US foreign policy; this is correlation (shared goals) but critics see it as politicisation.
- Marketing vs research blur — Digital Defense Report mixes commercial positioning with actual research.
Useful public resources:
| Resource | URL |
|---|---|
| Microsoft Security blog | https://www.microsoft.com/en-us/security/blog |
| Digital Defense Report 2024 | https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2024 |
| MSTIC threat actor encyclopedia | https://learn.microsoft.com/en-us/unified-secops/microsoft-threat-actor-naming |
| MSRC (Microsoft Security Response Center) | https://www.microsoft.com/en-us/msrc |
Briefing: Cisco's threat intelligence team. Specialises in malware analysis, threat hunting, and network intelligence. Publishes daily blog posts and an annual Year in Review.
Public emblematic cases:
- Cisco Talos 2025 Year in Review — https://blog.talosintelligence.com/
- Threat Hunting programme — public methodology posts.
- GhIDA — Ghidra + IDA Pro integration tool (open source).
- LLM-as-RE-sidekick — research on using LLMs in reverse engineering.
- Cisco Live BRKSEC-2884 — public threat-hunting training.
Public 12-step workflow (reconstructed from Talos blog posts):
- Sample intake — from Cisco Secure endpoints, customer IR engagements, VirusTotal, spam traps.
- Static triage — hash check, strings, imports, sections.
- Sandbox detonation — ThreatGrid (Cisco's sandbox) analysis.
- Umbrella network pivot — use Cisco Umbrella DNS data to find related domains/IPs.
- IDA Pro + Ghidra RE — deep reverse engineering with GhIDA integration.
- Behavioural analysis — dynamic analysis in VM, API call tracing.
- Snort/ClamAV signature creation — write detection rules.
- Threat brief publication — blog post at blog.talosintelligence.com.
- Year in Review — annual summary report.
- Customer push — push detections to Cisco Secure customers.
- Open-source tool release — tools like GhIDA published to GitHub.
- Re-evaluate periodically — track malware family evolution.
Limitations:
- Network-edge bias — Talos visibility is network-centric (Cisco routers, firewalls); endpoint-only attacks may be under-represented.
- Commercial tie-ins — Talos reports often reference Cisco Secure products.
Useful public resources:
| Resource | URL |
|---|---|
| Talos blog | https://blog.talosintelligence.com/ |
| Talos Year in Review | https://blog.talosintelligence.com/2025-talos-year-in-review-speed-scale-and-staying-power/ |
| Talos GitHub | https://github.com/Cisco-Talos |
Briefing: Kaspersky's elite research team responsible for tracking the most sophisticated APTs (Stuxnet, Flame, Equation Group). Publishes on Securelist (https://securelist.com).
Public emblematic cases:
- Stuxnet (2010) — analysis of the first cyber-physical weapon. https://securelist.com/stuxnet-zero-victims/67483/
- Flame (2012) — discovery of a sophisticated espionage toolkit. https://securelist.com/the-flame-questions-and-answers/34344/
- Gauss (2012) — discovery of nation-state banking malware. https://securelist.com/gauss-abnormal-distribution/36620/
- Equation Group (2015) — Kaspersky technical investigation report documenting the most sophisticated APT group yet discovered. https://securelist.com/investigation-report-for-the-september-2014-equation-malware-detection-incident-in-the-us/83210/
- Securelist RE workshop — public training materials.
Public 12-step workflow (reconstructed from Securelist publications):
- KSN (Kaspersky Security Network) telemetry — telemetry from Kaspersky endpoint products worldwide.
- Victimology analysis — identify targeted victims, geographic and sectoral patterns.
- Static analysis — hash, strings, imports, sections.
- Unpacking — multi-stage unpacking for packed malware.
- Behavioural analysis — dynamic analysis in sandbox.
- IDA Pro / Binary Ninja / Ghidra RE — deep reverse engineering.
- Decompilation — high-level reconstruction of malware logic.
- C2 protocol analysis — reverse-engineer command-and-control protocol.
- Capability analysis — identify exploit payloads, lateral movement tools, persistence mechanisms.
- Clustering — group malware samples into families based on code/infrastructure overlap.
- Cautious attribution — Kaspersky is more conservative than US vendors in naming specific countries; uses "actor X" or "the malware's authors" rather than direct nation-state attribution.
- Securelist publication — detailed technical blog post with IOCs, YARA, source code samples.
Limitations & controversies:
- US bans (2017 + 2024): DHS banned Kaspersky products from US federal networks in 2017 (BND 2017-138). BIS (Bureau of Industry and Security) extended the ban to all US consumer and commercial sales in 2024. URL: https://en.wikipedia.org/wiki/Kaspersky_Lab.
- Kaspersky's denial: Company has consistently denied improper ties to Russian intelligence.
- Global Transparency Initiative (GTI): Kaspersky launched the GTI in 2018 to address trust concerns: moved data processing to Zurich (2018), opened Transparency Centers in multiple countries (https://gti.kaspersky.com/en). URL: https://www.kaspersky.com/transparency-center
- Bias check: Despite governance concerns, Kaspersky's technical research quality is widely respected. Mandiant, CrowdStrike and other Western vendors continue to cite Kaspersky research in their own publications. The technical research and the governance/jurisdiction risk are separate issues — investigators should evaluate the technical content on its merits while being aware of the geopolitical context.
Useful public resources:
| Resource | URL |
|---|---|
| Securelist (Kaspersky blog) | https://securelist.com |
| Kaspersky threat intelligence | https://www.kaspersky.com/enterprise-security/threat-intelligence |
| Kaspersky GTI | https://gti.kaspersky.com/en |
| Kaspersky GitHub (open-source tools) | https://github.com/kaspersky |
| Dimension | Bellingcat | Mandiant/GTI | CrowdStrike | Recorded Future | MSTIC | Talos | Kaspersky |
|---|---|---|---|---|---|---|---|
| Primary discipline | Visual GEOINT | IR-led threat intel | Endpoint telemetry | NLP on OSINT | Telemetry | Network + malware | RE + malware |
| Attribution method | Public cross-ref | UNC clustering | Adversary naming | Centaur model | Weather naming | Sample clustering | Cautious, country-agnostic |
| Naming system | None | APT##/FIN##/UNC## | BEAR/PANDA/SPIDER | None (uses others') | Weather (was chemical) | None | None (uses others') |
| Reproducibility | High (workflow published) | Low (needs platform) | Low (needs Falcon) | Low (needs platform) | Low (needs telemetry) | Medium | Medium |
| Geographic bias | Russia/Syria/Ukraine strong; China/NK/Iran weak | Strong Western | Strong Western | Strong Western | Strong Western | Strong Western | Strong Russia/Asia |
| Free tier | All toolkit free | VirusTotal free | Adversary Hub free | Community Edition (limited) | Threat encyclopedia free | Blog free | Securelist free |
| Government alignment | None (NGO) | US-aligned (post-acquisition) | US-aligned | US-aligned | US-aligned | US-aligned | Russian (controversial) |
Structured Analytic Techniques are mental tools to reduce analytical biases and produce more defensible conclusions. Popularised by Richards Heuer Jr. (Psychology of Intelligence Analysis, 1999) and by Heuer & Pherson (Structured Analytic Techniques for Intelligence Analysis, 3rd ed. 2020, CQ Press). These techniques are in the public domain of professional analytical literature — they are not attributed to specific agencies.
What it is: Systematic method to evaluate multiple explanatory hypotheses against the same set of evidence, instead of seeking evidence for the preferred hypothesis. Combats confirmation bias.
When to use: When analysis has high consequences (strategic decisions, judicial conclusions, public conclusions that damage reputations) and multiple plausible hypotheses compete.
The 8 steps:
- List all plausible hypotheses (3-7) without premature discard. Force inclusion of 1-2 "unlikely" ones to avoid tunnel vision.
- List all significant evidence (facts, not inferences) + arguments.
- Build a hypothesis × evidence matrix. Rows = evidence. Columns = hypotheses.
- For each cell, evaluate consistency:
+consistent ·−inconsistent ·?indeterminate. Crucial: evaluate whether the evidence is INCONSISTENT with the hypothesis, not whether it supports it. This inversion breaks confirmation bias. - Refine the matrix: remove evidence that does not discriminate between hypotheses.
- Compute the "inconsistency score" per hypothesis. The hypothesis with FEWER inconsistencies is the most robust (NOT the most consistent).
- Analyse sensitivity: "What evidence, if false, would change the conclusion?"
- Report with uncertainty: do not eliminate alternative hypotheses, report them with their relative probabilities.
Minimum ACH template:
| H1: fraud | H2: error | H3: external
| intentional | accounting | malicious
--------------|-------------|---------------|------------
E1: balancing | − | + | ?
E2: timing | + | − | +
E3: motive | + | ? | +
E4: auditor | + | + | −
E5: access | + | + | −
--------------|-------------|---------------|------------
# Inconsistencies | 1 | 2 | 2
Conclusion: | H1 most robust (fewest inconsistencies);
| H3 plausible if E4 (auditor) breaks
What it is: Explicit identification of the unverified assumptions on which an analysis rests. Combats anchoring bias.
When to use: At the start of any non-trivial analysis. Prerequisite for ACH and Devil's Advocacy.
| # | Assumption | Why I assumed it | Source/Evidence | If false, impact on conclusion | Action to verify |
|---|---|---|---|---|---|
| 1 | "Entity X is still active" | Listed in registry 6 months ago | Last query | Change of main hypothesis | Re-query today |
| 2 | "Identified UBO is correct" | Listing in PSC Register | Companies House | Lower confidence overall | Cross-check ICIJ + adverse media |
| 3 | "Applicable sanctions are EU" | Client in EU | Contract | Re-evaluate with OFAC/UK | Confirm with client |
Rules: minimum 5-8 assumptions per analysis · assign confidence High/Medium/Low · if ≥2 assumptions are "Low", the overall conclusion cannot be "High Confidence" · review at the end of the analysis.
What it is: Designating a person (or role) to systematically criticise the dominant conclusion. Combats groupthink and premature closure.
How to implement individually:
- Assume the role explicitly. Write "Devil's Advocacy exercise" in the document.
- Identify 3-5 weak points in your own argument. Questions: What evidence do I NOT have? What alternative conclusion would explain the same data? What fails if my main source lied?
- Build the best possible counter-argument. Not a strawman — a strong argument that an intelligent critic would build. If you cannot build it, you do not understand the case well enough.
- Honestly evaluate whether the counter-argument has merit. Modify conclusion or confidence if it does.
- Document in the deliverable: "Devil's Advocacy applied; alternative hypothesis X considered and rejected for Y / accepted partially, adjusting confidence from High to Moderate".
Traps: If it NEVER changes the conclusion, you are doing it wrong · Do not just aim at minor flaws, aim at the pillars.
What it is: Monitoring system that defines in advance what observable signals would indicate a scenario is materialising. Enables early detection.
When to use: Continuous surveillance of scenarios (sanctions, internal fraud, geopolitical conflict, competitor reputational crisis).
SCENARIO MONITORED: "Entity X is sanctioned by OFAC within next 6 months"
INITIAL CONFIDENCE: Low (no active indicators)
MONITORING OWNER: [analyst]
REVIEW FREQUENCY: weekly
INDICATORS (in increasing specificity order):
Level 1 — Background indicators (long duration, low specificity):
[ ] Entity X appears in quality adverse media ≥3 times in 30 days
[ ] Entity X's main jurisdiction added to FATF grey list
[ ] Close commercial partner of Entity X designated by OFAC
Level 2 — Tactical indicators (medium specificity, weeks):
[ ] Entity X changes auditor or correspondent bank without public reason
[ ] Entity X transfers assets to risk jurisdiction (RUS, IRN, PRK)
[ ] Civil litigation filed against Entity X in extraterritorial jurisdiction
Level 3 — Strategic indicators (high specificity, days):
[ ] US State Department issues statement mentioning Entity X
[ ] OFAC publishes sector-specific guidance
[ ] US Congress introduces legislation naming Entity X
ACTIVATION MATRIX:
- 1 Level 1 indicator → re-evaluate Low→Moderate, daily monitoring
- 2+ Level 1 or 1 Level 2 → Moderate→High, deep DD
- 1 Level 3 → High confidence of imminent designation; activate contingency plan
Principles: Indicators must be observable · Activation matrix defined BEFORE any indicator occurs · System has value only if reviewed at the committed frequency.
- Fork ➜ 2. Branch
new-tool➜ 3. PR with tested URL (screenshot mandatory)
Read CONTRIBUTING.md before.
GPL-3 – Educational and research use. Don't be naughty.
«Information wants to be free, but privacy wants to be respected.»
— unknown