<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The OSINT Newsletter]]></title><description><![CDATA[OSINT news, tools, tactics, and techniques]]></description><link>https://osintnewsletter.com</link><image><url>https://substackcdn.com/image/fetch/$s_!yF4I!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png</url><title>The OSINT Newsletter</title><link>https://osintnewsletter.com</link></image><generator>Substack</generator><lastBuildDate>Mon, 08 Jun 2026 05:32:03 GMT</lastBuildDate><atom:link href="https://osintnewsletter.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Jake Creps]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[contact@osint.news]]></webMaster><itunes:owner><itunes:email><![CDATA[contact@osint.news]]></itunes:email><itunes:name><![CDATA[The OSINT Newsletter]]></itunes:name></itunes:owner><itunes:author><![CDATA[The OSINT Newsletter]]></itunes:author><googleplay:owner><![CDATA[contact@osint.news]]></googleplay:owner><googleplay:email><![CDATA[contact@osint.news]]></googleplay:email><googleplay:author><![CDATA[The OSINT Newsletter]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The OSINT Newsletter - Issue #109]]></title><description><![CDATA[Why Boring is Better: OSINT on Public Records & Government Databases]]></description><link>https://osintnewsletter.com/p/109</link><guid isPermaLink="false">https://osintnewsletter.com/p/109</guid><pubDate>Thu, 04 Jun 2026 15:02:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/91acae06-8f20-4ef1-b172-1020a6393645_1900x1000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; <strong>Welcome to the 109th issue of The OSINT Newsletter.</strong> This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. Here&#8217;s an overview of what&#8217;s in this issue:</p><ul><li><p>Which data is easiest to find this way</p></li><li><p>Why jurisdictions matter if you want to stay on track</p></li><li><p>How the right workflow can make any OSINT fun</p></li><li><p>&#8230;and why real life isn&#8217;t the X-Files.</p></li></ul><div><hr></div><p>&#129667; If you missed the last newsletter, here&#8217;s a link to catch up.</p><p>&#9889; <strong>Codifying Open Source Intelligence Methodology with AI</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;6f7c8be6-57e7-4f8e-a79f-aa7d7f3f8c45&quot;,&quot;caption&quot;:&quot;&#128075; Welcome to the 108th issue of The OSINT Newsletter. This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. My goal with this newsletter is to help promote the OSINT industry, develop better investigators, and raise awareness of ethical use cases for open source intelligence.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The OSINT Newsletter - Issue #108&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-05-28T13:03:23.639Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/380854b4-a964-4f43-9e8b-c7948f757c1d_1900x1000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/108&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:198847688,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:19,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>&#127897;&#65039; <strong>If you prefer to listen, here&#8217;s a link to the podcast instead.</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;41b29cdc-494a-4f60-813e-6cc5a49a6d03&quot;,&quot;caption&quot;:&quot;Description&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Episode 19: Codifying OSINT and Calling the Numbers&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-05-29T15:00:39.533Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9e7f914e-77f3-440b-beee-573be45728bb_1200x630.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/episode-19-codifying-osint-and-calling&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:199307100,&quot;type&quot;:&quot;podcast&quot;,&quot;reaction_count&quot;:7,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Let&#8217;s get started. &#11015;&#65039;</p><div><hr></div><h1>Why Boring is Better: OSINT on Public Records &amp; Government Databases</h1><p>Public records have a reputation problem. Namely, they&#8217;re boring.</p><p>A government database doesn&#8217;t have the fast-moving, high-noise chaos factor of social media. No avatars, hot takes, or late night posting sprees <a href="https://www.huffingtonpost.co.uk/entry/donald-trump-stephen-colbert-finale_n_6a0ff353e4b0bb04cec5d72e">about that jerk Stephen Colbert</a>. Instead, you&#8217;re working with PDFs, registries and forms that look like they were last accessed in 2002. It&#8217;s enough to bore an investigator <a href="https://www.sciencedirect.com/science/article/pii/S0165176520303554">to sleep</a>.</p><p>Sure, this isn&#8217;t OSINT that screams &#8220;start here&#8221; - but that&#8217;s precisely the point. Public records are unchanging and largely unnoticed, and that makes them some of the most reliable anchors out there. You can spend hours chasing a username that leads nowhere, or watch an account or post vanish mid-investigation when OP <a href="https://www.vox.com/explain-it-to-me/477210/social-media-posts-regret-what-to-do-explained">decides it&#8217;s too cringe</a> to bear. But once a public record&#8217;s recorded, it sticks, and it won&#8217;t have moved in years - no matter how toe-curling.</p><p>Sometimes, with OSINT, boring is better.</p><p>This issue will cover:</p><ul><li><p>What you can get from public records and government databases</p></li><li><p>Where to start without getting lost in endless registries</p></li><li><p>A fun, repeatable OSINT workflow for even the dullest investigations</p></li><li><p>&#8230;and why <a href="https://rollcall.com/factbase/topic/twitter?platform=all&amp;sort=date&amp;sort_order=desc&amp;page=1">Trump&#8217;s tweets</a> are actually relevant here.</p></li></ul><p>Just resting your eyes, right? Let&#8217;s get started.</p><h2>What Counts as a Public Record?</h2><p>Think less X-Files, more just&#8230; Files.</p><p>Put simply: public records are any documents created, filed, or maintained by government bodies as part of official processes. They&#8217;re usually verifiable, real-world data that maps activity in the real world, such as:</p><h3>Property Records</h3><p>The least exciting documents that answer the most useful question: where someone actually lives (or lived). Property records show the ownership of a house, land or business, alongside purchase history, co-owners, and addresses.</p><h3>Court Records</h3><p>If something serious went down, it probably ended up here. Court records cover disputes, and charges, adding the context, timelines, and connections you definitely won&#8217;t find on someone&#8217;s carefully curated online presence. In Florida, for example, arrests are a matter of public record under specific rules - blessing the world with <a href="https://floridaman.com/">Florida Man</a>.</p><h3>Business Registrations</h3><p>Follow the companies, find the employees (or bosses). Business records list directors, shareholders, and addresses for premises. They&#8217;re perfect for mapping who&#8217;s connected to what - especially for financial investigations, or if you&#8217;re looking to verify the wild claims on a subject&#8217;s LinkedIn.</p><h3>Licensing Databases</h3><p>Speaking of verification, these can prove if someone is (or isn&#8217;t) what they claim to be. Licensing records cut through inflated bios with something much less exciting: the truth.</p><p>Depending on the jurisdiction, they can confirm occupations, qualifications, certifications, and sometimes disciplinary actions in sectors like healthcare, law, construction, or transport.</p><h2>Beginner Tools for Digging Government Dirt</h2><p>Don&#8217;t try to play <a href="https://screenrant.com/the-x-files-lone-gunmen-spinoff-failure-fast-cancellation-explained/">The Lone Gunmen</a> straight off the bat. Start simple, with official sources.</p><p>The beginner-friendly following will get you direct access to structured, government-held data for OSINT investigations that get results. No Mulder and Scully shenanigans required.</p><h3>Government Open-Data Portals</h3><p><strong>Pros: </strong>Great for quick wins without advanced tooling.</p><p><strong>Cons:</strong> Easy to get lost.</p><p>The official hubs of &#8220;we&#8217;ll just leave this here&#8221;. Governments publish datasets on everything. Property, crime, spending, infrastructure - they all get dumped here in searchable, downloadable, and surprisingly underused form.</p><h3>County/State Record Search Tools</h3><p><strong>Pros: </strong>Solid and often the fastest way to anchor an investigation in reality.</p><p><strong>Cons:</strong> Interfaces from hell.</p><p>If this type of OSINT could get any less glamorous, it just did. On a local level, registries for property, courts, or business filings usually let you search by name, address, or company. Interfaces can be clunky (and ugly as sin), but the data can be beautiful.</p><h2>A Boredom-Busting Investigation Workflow</h2><p>Let&#8217;s demonstrate why OSINT looks good in beige. Follow these steps for a high hit-rate:</p><ol><li><p><strong>Identify the Jurisdiction</strong></p><p>Start by figuring out where the records you need live. Rules governing database  access can vary quite randomly by country, state, or even county. Get the jurisdiction wrong and you&#8217;ll either get locked out, or waste time combing through the wrong (potentially frustrating) system. Get it right and your search becomes far faster, and far less painful.</p></li><li><p><strong>Search</strong></p><p>Once you&#8217;ve got the jurisdiction, search. Search names, companies, or addresses directly in official databases. Search, search, search. Don&#8217;t overthink it. It&#8217;s that easy.</p></li><li><p><strong>Cross-Reference</strong></p><p>One record is a clue, but four that match is a jackpot. Always cross-check names, addresses, dates, and associates across different databases to validate what you&#8217;re seeing; this is important, real-world data, so mistakes can cost you big.</p></li></ol><p>That&#8217;s it. You should have found what you&#8217;re looking for&#8230; and you&#8217;re still awake!</p><h2>What You Can Learn From Public Record OSINT</h2><p>Public records can help you find the following:</p><h3>Ownership Ties</h3><p>If you find out who owns what, and who they own it with, you can identify a subject&#8217;s partners in both business and life. It&#8217;s common to discover hidden relationships like family ties that aren&#8217;t visible elsewhere online through ownership records.</p><h3>Business Relationships</h3><p>Company filings can help trace networks of influence. Look for repeat partnerships, for example, or the same names in operation across multiple businesses. Structures are the thing to look for here.</p><h3>Legal History</h3><p>If there&#8217;s disputes, criminal charges, civil cases, financial issues&#8230; These can act as great behavioural context, showing patterns over time that help to strengthen your overall investigation.</p><h2>Key Takeaways</h2><p>See? Public records and government databases aren&#8217;t that painful. Sure, it&#8217;s all very static. This OSINT just sits still, being true. While everything else moves (and generates the excitement that comes with it), records don&#8217;t - but that&#8217;s exactly why they&#8217;re priceless.</p><p>You should now know:</p><ul><li><p>Which data is easiest to find this way</p></li><li><p>Why jurisdictions matter if you want to stay on track</p></li><li><p>How the right workflow can make any OSINT fun</p></li><li><p>&#8230;and why real life isn&#8217;t the X-Files.</p></li></ul><p>Still wondering why Trump&#8217;s tweets were relevant in this article? The answer: they&#8217;re a matter of <a href="https://theconversation.com/despite-being-permanently-banned-trumps-prolific-twitter-record-lives-on-152969">public record</a>. The US <a href="https://www.trumplibrary.gov/research/archived-social-media">National Archives</a> has all of them on a database, free to browse. Yes, all of them. Even <a href="https://media-cdn.factba.se/realdonaldtrump-twitter/869766994899468288.jpg">covfefe</a>. What OSINT value one could gain from an <a href="https://x.com/realDonaldTrump/status/1963609005844017347?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1963609005844017347%7Ctwgr%5E2ffef4678ab447eab9bdb9775d624b6908d9a638%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fwww.al.com%2Flife%2F2025%2F09%2Fdonald-trump-posts-ai-of-himself-dancing-with-cracker-barrels-uncle-herschel-to-ymca.html">AI President dancing with the Cracker Barrel Man</a> is unclear, but it&#8217;s there.</p><p>Maybe we need Mulder and Scully on it after all.</p><div><hr></div><p>&#127937; <strong>New CTF Challenge Live - Secret Meeting</strong></p><p>A new CTF challenge has been posted on our CTF website. This week&#8217;s challenge involves geolocating an image that has been intercepted by a counter intelligence agency.</p><p><a href="https://ctf.osintnewsletter.com/">Start competing in our Capture the Flag (CTF)</a></p><p>&#129667; If you missed the last CTF, <a href="https://ctf.osintnewsletter.com/challenges#The%20Scammer-32">here&#8217;s a link to catch up.</a></p><p>Last week&#8217;s CTF challenge featured a challenge titled &#8220;The Scammer&#8221; where participants were tasked with conducting an investigation on a phone number linked to a suspected scammer, in order to find the country and the phone operator associated to it.</p><p>Searching for the country code +91, we can see that it belongs to India.<br>Using <a href="https://www.emobiletracker.com/trace-process.php">https://www.emobiletracker.com/trace-process.php</a>, we can see that the operator is Reliance Jio.</p><div><hr></div><p>&#9989; That&#8217;s it for the free version of The OSINT Newsletter. Consider upgrading to a paid subscription to support this publication and independent research.</p><p>By upgrading to paid, you&#8217;ll get access to the following:</p><p>&#128064; All paid posts in the archive. <a href="https://osintnewsletter.com/">Go back and see what you&#8217;ve missed</a>!</p><p>&#128640; If you don&#8217;t have a paid subscription already, don&#8217;t worry. There&#8217;s a 7-day free trial. If you like what you&#8217;re reading, upgrade your subscription. If you can&#8217;t, I totally understand. Be on the lookout for promotions throughout the year.</p><p>&#128680; The OSINT Newsletter offers a free premium subscription to all members of law enforcement. To upgrade your subscription, please reach out to LEA@osint.news from your official law enforcement email address. </p>]]></content:encoded></item><item><title><![CDATA[Episode 19: Codifying OSINT and Calling the Numbers]]></title><description><![CDATA[Listen now | Tools, tactics, and fresh investigations expanding the open-source intelligence toolkit.]]></description><link>https://osintnewsletter.com/p/episode-19-codifying-osint-and-calling</link><guid isPermaLink="false">https://osintnewsletter.com/p/episode-19-codifying-osint-and-calling</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Fri, 29 May 2026 15:00:39 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/199307100/d54c17247a2a503413d76de81188579a.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h3>Description</h3><p><em>Tools, tactics, and fresh investigations expanding the open-source intelligence toolkit.</em></p><p>Some of the best OSINT pivots start with the things people forget about. A phone number that has quietly followed someone across a decade of accounts. A methodology buried in a blog post that could be running in the background of every future investigation.</p><p>This episode covers Issues 107 and 108 of The OSINT Newsletter and explores two sides of how modern investigators get more out of what they already have: squeezing real intelligence out of the most overlooked data point in the toolkit, and turning the methodology in your head (and other people&#8217;s heads) into something an AI agent can run on your behalf.</p><p>In Episode 19 of The OSINT Podcast, host Jake Creps starts with Issue 107 and one of the most underrated data points in the toolkit: the phone number. He walks through what intelligence actually comes from a number, where to check first without overcomplicating it, and a clean five-step workflow from standardising the format through to pivoting outward into the wider account network. He covers the platforms worth checking (WhatsApp, Telegram, Signal, Truecaller, Sync.ME), the carrier and HLR lookups that ground a number geographically, and the high-value pivots, usernames, social accounts, and breach data, that turn a single number into a network. He closes with how to handle disposable numbers and burner tactics, where the absence of data is itself a signal.</p><p><strong>Highlights include:</strong></p><p>&#128222; <strong>What a Phone Number Actually Tells You</strong> &#8211; geographic origin, platform presence, and identity fragments hiding in plain sight.</p><p>&#129517; <strong>The Five-Step Workflow</strong> &#8211; from standardising the format to pivoting outward, a clean methodology for running phone number OSINT without skipping steps.</p><p>&#128293; <strong>Burner Logic</strong> &#8211; why disposable numbers are not a dead end, and how patterns of behaviour and gaps in data become signals in their own right.</p><p>&#129302; <strong>Codifying Methodology</strong> &#8211; discovering methods worth codifying with a Google Dork, turning them into local markdown, and chaining skills together into a continuous discovery engine.</p><p>&#128279; <strong>A Worked Investigation</strong> &#8211; running /username through Sherlock, pivoting into /person-search on nxthacker99, and producing a full subject profile assessment with named intelligence gaps.</p><p>Whether the investigation starts with a single phone number or a methodology lifted from someone else&#8217;s blog post, Episode 19 is about getting more out of the OSINT you already have in front of you.</p><p><strong>References</strong></p><ul><li><p><a href="https://osintnewsletter.com/p/107">OSINT Newsletter &#8211; Issue 107</a></p></li><li><p><a href="https://osintnewsletter.com/p/108">OSINT Newsletter &#8211; Issue 108</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[The OSINT Newsletter - Issue #108]]></title><description><![CDATA[Codifying Open Source Intelligence Methodology with AI]]></description><link>https://osintnewsletter.com/p/108</link><guid isPermaLink="false">https://osintnewsletter.com/p/108</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Thu, 28 May 2026 13:03:23 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/380854b4-a964-4f43-9e8b-c7948f757c1d_1900x1000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; <strong>Welcome to the 108th issue of The OSINT Newsletter.</strong> This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. My goal with this newsletter is to help promote the OSINT industry, develop better investigators, and raise awareness of ethical use cases for open source intelligence.</p><div><hr></div><p>&#129667; If you missed the last newsletter, here&#8217;s a link to catch up.</p><p>&#9889; <strong>Call Data: OSINT on Phone Numbers</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;cca72d0f-310d-4c15-8b53-90d5b886dbad&quot;,&quot;caption&quot;:&quot;&#128075; Welcome to the 107th issue of The OSINT Newsletter. This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. Here&#8217;s an overview of what&#8217;s in this issue:&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The OSINT Newsletter - Issue #107&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-05-21T13:03:25.549Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4f34bee8-36dd-4e4c-a6b7-14442d53c9f8_1900x1000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/107&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:195889149,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:22,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Let&#8217;s get started. &#11015;&#65039;</p><div><hr></div><h1>OSINT News</h1><p>&#128240; <strong>How To Investigate A Person Of Interest In 2026</strong></p><p>An advanced guide on person search built for the year 2026. It includes tools, tactics, and techniques using available methodology. You can use this guide to build a Claude skill and augment it with your own methods.</p><p><a href="https://preciousvincentct.medium.com/how-to-investigate-a-person-of-interest-in-2026-77dfaadbe7e7">Read on Medium&#8230;</a></p><p>&#127913; H/T: Precious Vincent</p><p>&#128240; <strong>Inside Modern OSINT: Detecting Disinformation, Tools of the Trade, and the Ethics That Shape It</strong></p><p>An OSINT guide on tracking coordinated disinformation through timing patterns, account behavior, and cross-platform signals, using verification tools like image search, geolocation, and archives, while considering privacy risks and ethical challenges in open-source investigation.</p><p><a href="https://www.impactgrid.org/post/inside-modern-osint-detecting-disinformation-tools-of-the-trade-and-the-ethics-that-shape-it">Read on Impact Grid&#8230;</a></p><p>&#127913; H/T: Zoya Baig</p><p>&#128240; <strong>Signals in the Noise: Open Source Intelligence (OSINT) for AI Loss of Control Detection</strong></p><p>An advanced OSINT/CTI framework for detecting AI loss of control. It maps threat models, observable traces like user transcripts and inference choke points, plus monitoring techniques using available methodology.</p><p><a href="https://download.ssrn.com/2026/5/8/6735558.pdf?response-content-disposition=inline&amp;X-Amz-Security-Token=IQoJb3JpZ2luX2VjEFUaCXVzLWVhc3QtMSJGMEQCIFQP3qGk%2Br7buNt%2FzMHvBf2uQlsWdpFnJU0VLRwiO1zcAiBUd8bKYumELnaKphMXVS%2BoVaVLOJ51ry0oEdqSE4HQISq9BQgeEAQaDDMwODQ3NTMwMTI1NyIMSaGymItTvDwO8XYEKpoFAHcpMScojeOS7zO4wZ6kA%2Bc2a3z%2Bj4MwVNKDz579V04L2jB6I6GGp4uTTViGeVjjPWp0t6Jfx%2B9oDxRlkfT2AWhJnm4BslUjlfBpYIPfv%2FRGCpykZTydD6bqOTJAA9u8iGiOPnC%2FliywRRCftc%2F01M90MBp5TyyZfQtE7rrUGMeolIUA8DZ501pthjMD0S7BdV74hLGGohfHGWjOHYkFrbnciy703Jyf6M0VDeGaO8Sz70nDQ93NwsBBAwjA7Ln3G7%2Bp%2FZSVBVLWZRAOnrjeDSMNY1o2pirLL%2F3WpIzOOcMxc1FDV5M13kjwxEKyL6DKdiBXgnpuQwps7WD3GMCe1e5HvJKUphSWR6AAncTGatEedi916lFKRTtSXcNrKjoyV%2B4Fb5rny2%2FwM9NzYDjIQL%2B79QgA3PpZLcohA8Waxgg7OSwpWbeimNa%2BqnIuIRPt%2Ff8QMOIZ0VOKVBZmRM0i%2FECK4x23pLS1NPboi0d8Vr6gqYl2frCxtke%2Fdlu%2B1P4hPoLV1NraHtu2V7jHWEZWrdTCMdkPrsb0%2B118deuazJhsZNPoFDfzH%2Fwq2JYPZ8CELhPdBoyhu%2FENNr1aHUhby6Dscs1A3%2FWdF3RSoMWQtPHedogmCGAC5eNTuD95brxjwfdKrQeizjaR1mpEKY0buZ2H4ABsyTzUJ5MjtEiAjqwa2JOnmVEDC2y%2BGIooHnNAZr92w%2B6d1k5DgZQwSQ%2FMsKoSVLzR6U50MygkPQn0tad%2BKlGvbGrEG9PCDgxi9o4jx%2BMaSYTgRisXx1OwSvim1uPeplXgq77T4N0XLcynofDQJTdeDW6Bz3yAaZbpVqXeHE9A0GzNOuywN6F4Pv1OKDANWjJj%2FfSBjF6aOXccg6ckVMC1q8sHoHFXMKaowdAGOrIBsXnkpiXVqfi4JbQdz0kN%2BOsP26didTHXAHtACiq3SGGnzTJn86pyiKENw1s6pwTWgcCXacb7ha%2BMxC2wN%2BY1kdZziOo6zGuAAxRTeM8wTgNUifGkL1%2FGxvd8SUOA%2BUWY7%2FpexIzhhhlT6ZUv7jFXtTqgYNu8kzgZug8SqAcRpbzV6EcvMjqRpqZDGWfqpWZIAhk%2FT9wICistCgsKF19Gv0OCMAs4KCEj8XqqOBSIgS0nZg%3D%3D&amp;X-Amz-Algorithm=AWS4-HMAC-SHA256&amp;X-Amz-Date=20260522T141145Z&amp;X-Amz-SignedHeaders=host&amp;X-Amz-Expires=300&amp;X-Amz-Credential=ASIAUPUUPRWE2U3TUVDW%2F20260522%2Fus-east-1%2Fs3%2Faws4_request&amp;X-Amz-Signature=2dfc69d6aeb779ecda9a6e970df23949b8538181b92dce3826c94273be885eb3&amp;abstractId=6735558">Read the paper&#8230;</a></p><div><hr></div><h1>OSINT Tools</h1><p>&#128270; <strong>OpenOSINT</strong></p><p>OpenOSINT is an open-source OSINT framework for collecting, organizing, and analyzing publicly available data to support investigations, combining automation tools and modular workflows for reconnaissance, data gathering, and information analysis.</p><p><a href="https://github.com/OpenOSINT/OpenOSINT">GitHub</a></p><p>&#127913; H/T: Tommaso Bertocchi</p><p>&#128270; <strong>Open Graph Intel (OGI)</strong></p><p>OGI is an OSINT-focused tool for visualizing and analyzing connections in data, helping map relationships between entities, sources, and signals to support investigative workflows and structured analysis of information networks.</p><p><a href="https://ogi.khas.app/">Web App</a></p><p>&#127913; H/T: khashashin</p><p>&#128270; <strong>Anthropic Courses</strong></p><p>Anthropic&#8217;s learning hub is a training platform providing structured courses on using Claude, AI workflows, and developer topics, with lessons, quizzes, progress tracking, and certificates for completion.</p><p><a href="https://anthropic.skilljar.com/">Anthropic Academy</a></p><div><hr></div><p>&#127937; New CTF Challenge Live - The Scammer</p><p>A new CTF challenge has been posted on our CTF website. This week&#8217;s challenge involves </p><p>conducting an investigation on a phone number linked to a suspected scammer.</p><p><a href="https://ctf.osintnewsletter.com/">Start competing in our Capture the Flag (CTF) </a></p><p>&#129667; If you missed the last CTF, <a href="https://ctf.osintnewsletter.com/challenges#Last%20Order-31">here&#8217;s a link to catch up</a>. </p><p>Last week&#8217;s CTF challenge featured a challenge titled &#8220;Last Order&#8221; where participants were tasked with finding a restaurant&#8217;s location, and the dish that a suspect had ordered.</p><p>Challenge Solution WU : </p><p>Using a reverse image search on the provided cctv image, we find a match showing a restaurant called Amor Gastronomia in London on TheFork.</p><p>By checking the restaurant&#8217;s official website, the address is listed in the footer as Halloway Road 139.</p><p>Finally, reviewing the restaurant&#8217;s London menu, the most expensive signature pasta dish appears to be TAGLIOLINI AL TARTUFO.</p><div><hr></div><p>&#9989; That&#8217;s it for the free version of The OSINT Newsletter. Consider upgrading to a paid subscription to support this publication and independent research.</p><p>By upgrading to paid, you&#8217;ll get access to the following:</p><p>&#9889; <strong>Codifying Open Source Intelligence Methodology with AI</strong></p><ul><li><p>There are dozens if not hundreds of methods for open source intelligence collection, analysis, and dissemination. Everyone has a different process, too. In this issue, I&#8217;m going to show you how you can create a repository of methodology that you can use to instruct your AI of choice to automate. </p></li></ul><p>&#128064; All paid posts in the archive. <a href="https://osintnewsletter.com/">Go back and see what you&#8217;ve missed</a>!</p><p>&#128640; If you don&#8217;t have a paid subscription already, don&#8217;t worry there&#8217;s a 7-day free trial. If you like what you&#8217;re reading, upgrade your subscription. If you can&#8217;t, I totally understand. Be on the lookout for promotions throughout the year. I&#8217;ll start with <strong>How To Investigate A Person Of Interest In 2026 </strong>from the OSINT news section.</p><p>&#128680; The OSINT Newsletter offers a free premium subscription to all members of law enforcement. To upgrade your subscription, please reach out to LEA@osint.news from your official law enforcement email address. </p>
      <p>
          <a href="https://osintnewsletter.com/p/108">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The OSINT Newsletter - Issue #107]]></title><description><![CDATA[Call Data: OSINT on Phone Numbers]]></description><link>https://osintnewsletter.com/p/107</link><guid isPermaLink="false">https://osintnewsletter.com/p/107</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Thu, 21 May 2026 13:03:25 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4f34bee8-36dd-4e4c-a6b7-14442d53c9f8_1900x1000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; <strong>Welcome to the 107th issue of The OSINT Newsletter.</strong> This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. Here&#8217;s an overview of what&#8217;s in this issue:</p><ul><li><p>What intelligence comes from a phone number</p></li><li><p>Where to check first (without overcomplicating it)</p></li><li><p>A clean workflow for investigations</p></li><li><p>&#8230;and why it&#8217;s not worth changing your name to Spiderman.</p></li></ul><div><hr></div><p>&#129667; If you missed the last newsletter, here&#8217;s a link to catch up.</p><p>&#9889; <strong>Creating Claude Skills for Open Source Intelligence</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;3dc8a87d-7534-43d1-b62c-eaf65c8b1c61&quot;,&quot;caption&quot;:&quot;&#128075; Welcome to the 106th issue of The OSINT Newsletter. This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. My goal with this newsletter is to help promote the OSINT industry, develop better investigators, and raise awareness of ethical use cases for open source intelligence&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The OSINT Newsletter - Issue #106&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-05-14T13:02:44.570Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2f311190-b9ba-425f-99fd-ce9f98592713_1729x910.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/106&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196968569,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:19,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>&#127897;&#65039; <strong>If you prefer to listen, here&#8217;s a link to the podcast instead.</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;d988d096-7872-4d37-9866-6e3390272fd8&quot;,&quot;caption&quot;:&quot;Some intelligence is buried deep in the shadows of the internet - and some of it is built by you, for you, with a few lines of plain English.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Episode 18: Episode 18: Dark Web Spelunking and Skilling Up Claude&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-05-15T13:03:08.822Z&quot;,&quot;cover_image&quot;:&quot;https://substack-video.s3.amazonaws.com/video_upload/post/197525105/2bb95886-371e-4706-b38b-5f9081994258/transcoded-1778689332.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/episode-18-episode-18-dark-web-spelunking&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:197525105,&quot;type&quot;:&quot;podcast&quot;,&quot;reaction_count&quot;:16,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Let&#8217;s get started. &#11015;&#65039;</p><div><hr></div><h1>Call Data: OSINT on Phone Numbers</h1><p>Phone numbers sit in a strange place in OSINT. They&#8217;re near-ubiquitous and tied to everything, but as a result very easy to overlook. Unlike usernames (which can change) or email addresses (easy to create), numbers tend to stick. They follow people across platforms, accounts, years of activity, and even States. <a href="https://www.pewresearch.org/methods/2016/08/01/moving-without-changing-your-cellphone-number-a-predicament-for-pollsters/#:~:text=At%20the%20state%20level%2C%20the%20geographic%20accuracy%20rate%20tends%20to,regardless%20of%20landline%20telephone%20ownership.">Surprisingly few people</a> want the hassle of learning a new number, even when they get a new phone.</p><p>You might create a new Gmail, and change your username (or legal name) to<a href="https://www.mirror.co.uk/news/weird-news/meet-the-people-whove-given-themselves-88857"> Baron Venom Balrog Sabretooth Vader Megatron Vegeta Robotnik Magneto Bison Sephiroth Lex Luthor Skeletor Joker Grind</a>, but your phone number is mostly static. This persistence makes phone numbers one of the most reliable anchors you can work with for OSINT.</p><p>Sometimes OSINT is just a number. This issue will teach you:</p><ul><li><p>What intelligence comes from a phone number</p></li><li><p>Where to check first (without overcomplicating it)</p></li><li><p>A clean workflow for investigations</p></li><li><p>&#8230;and why it&#8217;s not worth changing your name to Spiderman.</p></li></ul><p>Calling Baron Grind&#8230;</p><h2>What Can Phone Number OSINT Uncover?</h2><p>The infrastructure of phone numbers is key to what you can get out of them through OSINT. Every number is tied to a telecom system, to a region, and only then to a web of online accounts. That means even before you get into deeper online OSINT, there are three immediate layers of value:</p><h3>Geographic Origin</h3><p>Country codes (+1, +44, +91, etc.) are <a href="https://countrycode.org/">GeoINT in themselves</a>. These one or two nifty numbers instantly place a phone&#8217;s owner at a national level. If you can find out carrier data, you can narrow a rough operating region even further. At the very least, you can find out if your target&#8217;s in the US or Uzbekistan.</p><h3>Platform Presence</h3><p>Many platforms use phone numbers as their backbone identifier. If a number is registered on apps like <a href="https://blog.pagefreezer.com/whatsapp-osint-investigation-guide">WhatsApp</a> or Telegram, you may be able to view profile photos, usernames, or activity signals just by knowing the right digits.</p><h3>Identity Fragments</h3><p>Even before the real OSINT starts, people litter the world with identity fragments - by reusing their static phone number. Old listings, forgotten profiles, or scraped datasets can quietly connect multiple pieces together.</p><h2>Some Phone OSINT Tools That Actually Work</h2><p>You don&#8217;t need a complex stack to begin phone OSINT. That&#8217;s what makes phone numbers such a universally popular data point. In fact, the most effective tools and methods are often at your fingertips.</p><h3>Caller ID Platforms</h3><p><strong>Sync.ME</strong>, <strong>NumLookup</strong>, and <strong>That&#8217;s Them</strong> scan public records and user-contributed data, drawing on that to see if a number&#8217;s been identified before. Results can be inconsistent, so treat them as leads not gospel. If multiple sources align, then they&#8217;re worth your attention.</p><h3>Checking the Apps</h3><p>Here&#8217;s an old OSINT trick. Save the number as a contact, then check <strong>WhatsApp</strong>, <strong>Telegram</strong>, or <strong>Signal</strong>. Adding a contact will reveal a profile photo and status - Telegram will even expose a username.</p><h3>Caller ID Platforms</h3><p><strong>Truecaller</strong>, <strong>Hiya</strong>, and <strong>CallApp</strong> use crowdsourced data, so again, cross-reference. Patterns across multiple platforms mean something.</p><h3>Finding Carrier Data</h3><p>If you know nothing about the carrier, services like <strong>Numverify</strong>, <strong>Twilio Lookup</strong>, or other free HLR lookup tools can help identify the telecom provider and line type (mobile, VoIP, or landline). Cross-check as always.</p><h2>Getting Started: A Clean Workflow (Don&#8217;t Skip Steps)</h2><p>Investigating a number&#8230; That&#8217;s easy, right? Think you can improvise? Don&#8217;t. A structured approach will always get better results.</p><p>Give this workflow a try:</p><p><strong>1. Standardize the Format</strong></p><p>Always convert to international format. Tools and platforms require international format numbers and inconsistencies will cost you results. What&#8217;s more, country codes aren&#8217;t data you want to ignore.</p><p><strong>2. Location, Location, Location</strong></p><p>Use that country code. Combine with any carrier info to ground your investigation geographically; when you&#8217;re stratifying your findings later, you&#8217;ll be glad you did.</p><p><strong>3. Check for Live Accounts</strong></p><p>Run the number through message platforms. You&#8217;re looking for anything visible on Telegram or WhatsApp: images, usernames, timestamps etc.</p><p><strong>4. Look for Repetition</strong></p><p>Search the number directly. Then try variations, like with or without spaces. Reuse is what you&#8217;re hunting for.</p><p><strong>5. Pivot and Expand</strong></p><p>Got a hit? Pivot outward. Search that identifier (a username, profile, email or listing). Start building out the wider account network.</p><p>&#8230;And just like that, you&#8217;re doing phone number OSINT.</p><h3>What Counts As a High-Value Pivot?</h3><p>You might be wondering which leads are strong enough to take that fifth step. The real value comes from the following data points:</p><p><strong>&#8594; Usernames<br></strong>If you see the same username twice, that&#8217;s your bridge into wider platform analysis; especially if the username is conspicuously unusual or unique. There&#8217;s unlikely to be two people choosing Baron_V_B_S_V_M_V_R_M_B&#8230; (You get the picture).</p><p><strong>&#8594; Social Accounts<br></strong>If a number was required to sign up, some platforms expose profiles directly. Others reveal connections indirectly. Either way, a linked social account is OSINT gold.</p><p><strong>&#8594; Breach Data<br></strong>If the number appears in leaked datasets or on <a href="https://haveibeenpwned.com/">HaveIBeenPwned</a>, it can link to emails, credentials, and historic activity. As always, be careful working with data that comes from an inherently sketchy source.</p><h2>Feel the Burn: Disposable Numbers &amp; Evasion Tactics</h2><p>OSINT investigators chasing fraud, spam networks, or illicit activity face up to a unique challenge. Phone number stability is usually the USP here. What if the number you&#8217;re looking for is temporary by design?</p><p><a href="https://www.techtarget.com/whatis/definition/burner-phone">Burner phone</a> numbers get spun up quickly, used briefly, and abandoned just as fast. The aim is to get a phone number, get what you need from it, and <a href="https://www.youtube.com/watch?v=gAYL5H46QnQ">THROW IT ON THE GROUND</a>. The point of virtual numbers, VoIP services, and burner SIMs is to create numbers and accounts without tying them to a long-term, real identity - the very thing that makes phone number OSINT so easy.</p><p>So, change of tactics. Look for <strong>patterns of behaviour</strong>, not long-term reuse. VoIP numbers, for example, might cluster around specific services or regions, or repeatedly appear attached to similar types of accounts or listings. That would signal the same person, exhibiting the same behavior over and over again.</p><p>Gaps are a biggie too: no reverse lookup data, no caller ID history, and limited presence across platforms are absences that constitute a signal in themselves.</p><p>If a number looks &#8220;empty&#8221;, don&#8217;t assume it&#8217;s useless. It may just be designed that way.</p><h2>Key Takeaways</h2><p>Phone number OSINT works because numbers are mostly static and stable things. You can change your email, your socials, or even your name, but most people are lazy with their phones. And unlike physical addresses or Social Security numbers, people <a href="https://www.wcpo.com/money/consumer/dont-waste-your-money/can-i-have-your-phone-number-why-to-think-twice-before-saying-yes">hand out their phone numbers</a> like candy.</p><p>You should know:</p><ul><li><p>One number won&#8217;t tell you everything, but it might tell you where to look next</p></li><li><p>Use simple methods before complex ones</p></li><li><p>Follow number reuse and patterns</p></li><li><p>Build outward: number &#8594; account &#8594; network</p></li></ul><p>&#8230;and when you change your name to <a href="https://www.bbc.co.uk/news/uk-england-nottinghamshire-16319610">Emperor Spiderman Gandalf Wolverine Skywalker Optimus Prime Goku Sonic Xavier Ryu Cloud Superman HeMan Batman Thrash</a> in witness protection, maybe change your number.</p><p><strong>Until next time, investigators!</strong></p><div><hr></div><p>&#127937; <strong>New CTF Challenge Live - Last Order</strong></p><p>A new CTF challenge has been posted on our CTF website. This week&#8217;s challenge involves analyzing surveillance footage from a blurred traffic camera frame to identify a suspect&#8217;s location. Investigators believe the suspect entered a highly rated restaurant, ordered its most expensive signature pasta dish, and left in a hurry. Your task is to determine the restaurant, its exact address, and the specific pasta dish ordered.</p><p><a href="https://ctf.osintnewsletter.com/">Start competing in our Capture the Flag (CTF) </a></p><p>&#129667; If you missed the last CTF, <a href="https://ctf.osintnewsletter.com/challenges?#The%20Dark%20Web%20Hacker-30">here&#8217;s a link to catch up</a>. </p><p>Last week&#8217;s CTF challenge featured a challenge titled &#8220;The Dark Web Hacker&#8221; where participants were tasked with finding a hacker&#8217;s specific email address linked to a specific hacking forum.</p><p>Challenge Solution WU : </p><p>Knowing that the username had been reused across multiple forums and appeared in several data breaches, we searched for the username &#8220;sarkstic&#8221; on breach.vip. This led us to a World of Warcraft forum account on OwnedCore, along with the email address associated with it: dreadfuleyes@yahoo.com</p><div><hr></div><p>&#9989; That&#8217;s it for the free version of The OSINT Newsletter. Consider upgrading to a paid subscription to support this publication and independent research.</p><p>By upgrading to paid, you&#8217;ll get access to the following:</p><p>&#128064; All paid posts in the archive. <a href="https://osintnewsletter.com/">Go back and see what you&#8217;ve missed</a>!</p><p>&#128640; If you don&#8217;t have a paid subscription already, don&#8217;t worry. There&#8217;s a 7-day free trial. If you like what you&#8217;re reading, upgrade your subscription. If you can&#8217;t, I totally understand. Be on the lookout for promotions throughout the year.</p><p>&#128680; The OSINT Newsletter offers a free premium subscription to all members of law enforcement. To upgrade your subscription, please reach out to LEA@osint.news from your official law enforcement email address. </p>]]></content:encoded></item><item><title><![CDATA[Episode 18: Dark Web Spelunking and Skilling Up Claude]]></title><description><![CDATA[Listen now (39 mins) | Tools, tactics, and fresh investigations expanding the open-source intelligence toolkit.]]></description><link>https://osintnewsletter.com/p/episode-18-episode-18-dark-web-spelunking</link><guid isPermaLink="false">https://osintnewsletter.com/p/episode-18-episode-18-dark-web-spelunking</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Fri, 15 May 2026 13:03:08 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/197525105/3625989197a4eafcaf030f3d243a17d3.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Some intelligence is buried deep in the shadows of the internet - and some of it is built by you, for you, with a few lines of plain English.</p><p>This episode covers Issues 105 and 106 of The OSINT Newsletter and explores two very different sides of modern investigations: going deeper into the Dark Web for intelligence, and using AI to automate the repeatable parts of your workflow.</p><p>In Episode 18 of The OSINT Podcast, host Jake Creps picks up where Part One left off and takes investigators further into Dark Web intelligence - or DARKINT. He recaps the layered structure of the surface, deep, and dark web, then digs into the beginner toolkit: onion browsers, hidden services, public leak indexes, and onion search engines. Jake walks through a practical methodology for tracing identifiers - emails, usernames, and phone numbers - from breach data on the Dark Web back up to the surface, and explains how to correlate and validate findings without falling for false positives.</p><p>He also pulls no punches on the limitations. DARKINT is an adversarial, high-risk environment full of manipulated datasets, unverifiable attribution, and content that can stay with an investigator long after the browser is closed. The episode covers the compliance considerations of handling breached data and the psychological risks of working in this space - and why both deserve serious thought before diving in.</p><p>From there, the episode shifts to something brand new: building Claude Skills for OSINT. Jake explains what Claude Skills are - reusable, plain-language instruction sets that turn AI into a reliable part of your investigative workflow - and walks step-by-step through creating one for username search. No code required. He covers picking the right workflow to automate, writing the skill itself, testing it inside Claude Code with Sherlock, and refining it with simple natural-language tweaks.</p><p>The episode closes with a look at how to supercharge an OSINT skill: instructing Claude to pivot on its own findings, find new tools when collection hits a wall, and fall back to manual methods when scripts fail. It is a glimpse of what investigative automation actually looks like when AI stops being a novelty and starts doing real work alongside the analyst.</p><p><strong>Highlights include:</strong></p><p>&#129477; <strong>DARKINT Toolkit</strong> &#8211; onion browsers, hidden services, leak indexes, and onion search engines explained for beginners curious about web spelunking.</p><p>&#128279; <strong>Surface-Bound Pivots</strong> &#8211; a step-by-step methodology for tracing emails, usernames, and phone numbers from breach data back to the surface web.</p><p>&#9888;&#65039; <strong>The Monsters Under The Bed</strong> &#8211; the real limitations of DARKINT, from manipulated datasets and unverifiable attribution to the psychological toll of the work.</p><p>&#129302; <strong>Building Claude Skills</strong> &#8211; how to turn a repeatable OSINT workflow into a reusable Claude Skill, with a full walkthrough of automating a username search using Sherlock.</p><p>&#128640; <strong>Supercharging Automation</strong> &#8211; instructing Claude to pivot on its findings, hunt for new tools, and fall back to manual methods when scripts come up short.</p><p>Whether the data is hiding in the dark or waiting to be unlocked by the right set of instructions, Episode 18 shows how modern investigators are reaching both.</p><p><strong>References</strong></p><ul><li><p><a href="https://osintnewsletter.com/p/105">OSINT Newsletter &#8211; Issue 105</a></p></li><li><p><a href="https://osintnewsletter.com/p/106">OSINT Newsletter &#8211; Issue 106</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[The OSINT Newsletter - Issue #106]]></title><description><![CDATA[Creating Claude Skills for Open Source Intelligence]]></description><link>https://osintnewsletter.com/p/106</link><guid isPermaLink="false">https://osintnewsletter.com/p/106</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Thu, 14 May 2026 13:02:44 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/2f311190-b9ba-425f-99fd-ce9f98592713_1729x910.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; <strong>Welcome to the 106th issue of The OSINT Newsletter.</strong> This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. My goal with this newsletter is to help promote the OSINT industry, develop better investigators, and raise awareness of ethical use cases for open source intelligence</p><div><hr></div><p>&#129667; If you missed the last newsletter, here&#8217;s a link to catch up.</p><p>&#9889; <strong>OSINT and the Dark Web: Part Two</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;fc8427d5-d32d-4666-a0a0-bd27bf2afb7f&quot;,&quot;caption&quot;:&quot;&#128075; Welcome to the 105th issue of The OSINT Newsletter. This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. Here&#8217;s an overview of what&#8217;s in this issue:&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The OSINT Newsletter - Issue #105&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-05-07T13:02:37.991Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ea01acf7-49d5-481b-9fc9-fb830dbe64c6_1900x1000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/105&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:195371625,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:20,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Let&#8217;s get started. &#11015;&#65039;</p><div><hr></div><h1>OSINT News</h1><p>&#128240;  <strong>What happens when agentic AI meets intelligence analysis?</strong></p><p>Agentic AI, Maltego MCP servers, conflict monitoring, and self-hosted intel platforms are opening up new possibilities for OSINT, but the tools only matter if the analyst knows how to turn information into intelligence.</p><p>&#127913; H/T: Aaron Roberts</p><p><a href="https://www.linkedin.com/posts/aaroncti_osint-tools-thursday-30042026-ugcPost-7455325870900117504-KCHD/?utm_source=share&amp;utm_medium=member_ios&amp;rcm=ACoAABq6F0oBbmG93OZu2jSa-VZL4TF8Qv14q1Y">Read on LinkedIn&#8230;</a></p><p>&#128240; <strong>Vibe Coding Is Becoming an OSINT Risk</strong></p><p>AI is making it easier to build and adopt OSINT tools, but the real risk starts when investigators trust software they do not fully understand to shape analysis, workflows, and operational decisions.</p><p><a href="https://www.dutchosintguy.com/post/vibe-coding-is-becoming-an-osint-risk">Read on DutchOSINTGuy&#8230;</a></p><p>&#127913; H/T: Niko Dekens</p><p>&#128240; <strong>Turn Off ChatGPT&#8217;s New Ad Tracking</strong></p><p>ChatGPT&#8217;s free tier is now opt-in to ad tracking and data sharing by default, linking user activity to marketing systems unless you actively turn it off in settings.</p><p><a href="https://onlinesafety.substack.com/p/turn-off-chatgpts-new-ad-tracking">Read on Tate&#8217;s Online Safety Community&#8230;</a></p><p>&#127913; H/T: Tate Jarrow</p><div><hr></div><h1>OSINT Tools</h1><p>&#128270; <strong>BamQam</strong></p><p>A new OSINT-style dashboard that aggregates live geopolitical and military data into a map-based intelligence feed, with unclear provenance and trust level.</p><p><a href="https://bamqam.com/">Web App</a></p><p>&#128270; <strong>DrishX</strong></p><p>A satellite-powered freight intelligence tool that uses open-source orbital imagery to detect and analyze logistics movement patterns like vehicle flow for OSINT-style monitoring and trend analysis.</p><p><a href="https://github.com/sparkyniner/DRISH-X-Satellite-powered-freight-intelligence-?utm_source=">GitHub</a></p><p>&#127913; H/T: Sairaj Balaji</p><p>&#128270; <strong>claude-osint</strong></p><p>An OSINT automation framework built on Claude that structures investigative workflows for research and intelligence tasks.</p><p><a href="https://github.com/elementalsouls/Claude-OSINT">GitHub</a></p><p>&#127913; H/T: Sachin Sharma</p><div><hr></div><div><hr></div><p>&#9989; That&#8217;s it for the free version of The OSINT Newsletter. Consider upgrading to a paid subscription to support this publication and independent research.</p><p>By upgrading to paid, you&#8217;ll get access to the following:</p><p>&#9889; <strong>Creating Claude Skills for Open Source Intelligence</strong></p><ul><li><p>Claude Skills allow you to automate a significant portion of your workflow using very specific instructions. In this issue, I&#8217;m going to show you how you can fully automate a username search, including pivoting to additional methods based on findings, all with a single request from Claude.</p></li></ul><p>&#128064; All paid posts in the archive. <a href="https://osintnewsletter.com/">Go back and see what you&#8217;ve missed</a>!</p><p>&#128640; If you don&#8217;t have a paid subscription already, don&#8217;t worry there&#8217;s a 7-day free trial. If you like what you&#8217;re reading, upgrade your subscription. If you can&#8217;t, I totally understand. Be on the lookout for promotions throughout the year.</p><p>&#128680; The OSINT Newsletter offers a free premium subscription to all members of law enforcement. To upgrade your subscription, please reach out to LEA@osint.news from your official law enforcement email address. </p>
      <p>
          <a href="https://osintnewsletter.com/p/106">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The OSINT Newsletter - Issue #105]]></title><description><![CDATA[OSINT and the Dark Web: Part Two]]></description><link>https://osintnewsletter.com/p/105</link><guid isPermaLink="false">https://osintnewsletter.com/p/105</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Thu, 07 May 2026 13:02:37 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/ea01acf7-49d5-481b-9fc9-fb830dbe64c6_1900x1000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; <strong>Welcome to the 105th issue of The OSINT Newsletter.</strong> This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. Here&#8217;s an overview of what&#8217;s in this issue:</p><ul><li><p>The tools you need to know</p></li><li><p>Strategies and limitations</p></li><li><p>Following data to the surface</p></li><li><p>&#8230;and how to fight the monsters under the Internet&#8217;s bed.</p></li></ul><div><hr></div><p>&#129667; If you missed the last newsletter, here&#8217;s a link to catch up.</p><p>&#9889; <strong>Gathering OSINT from Live Traffic: Datasets and Cameras</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;947d033c-f84b-4794-b7a6-3bc3099039cd&quot;,&quot;caption&quot;:&quot;&#128075; Welcome to the 104th issue of The OSINT Newsletter. This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. My goal with this newsletter is to help promote the OSINT industry, develop better investigators, and raise awareness of ethical use cases for open source intelligence.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The OSINT Newsletter - Issue #104&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-04-30T13:01:43.501Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/38c3eb70-e542-42d7-8ea1-87deef95e5e8_1900x1000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/104&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:182551367,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:20,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>&#127897;&#65039; <strong>If you prefer to listen, here&#8217;s a link to the podcast instead.</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;f46ecd7b-bdeb-43e4-a6a9-9f77e8210b35&quot;,&quot;caption&quot;:&quot;Not all intelligence lives on the surface. Some of the most valuable data is deliberately hidden - and some of it is hiding in plain sight, flowing through the roads around you.&quot;,&quot;cta&quot;:&quot;Listen now&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Episode 17: Dark Web Intelligence and Gathering OSINT from Live Traffic&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-05-01T13:02:56.423Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0d3a3e61-c166-4bb8-8a87-d3e5407515e1_1200x630.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/episode-17-dark-web-intelligence&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:195728208,&quot;type&quot;:&quot;podcast&quot;,&quot;reaction_count&quot;:9,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Let&#8217;s get started. &#11015;&#65039;</p><div><hr></div><h1>OSINT and the Dark Web: Part Two</h1><p>Welcome (back) to the dark side. <a href="https://knowyourmeme.com/memes/come-to-the-dark-side">We have OSINT</a>.</p><p>Although it looks dangerous, DARKInt it&#8217;s perfectly safe if you know how - and if you read last week&#8217;s issue, you probably do. Without further introduction, let&#8217;s go even deeper into Dark Web OSINT.</p><p>In Part Two, we&#8217;ll cover:</p><ul><li><p>The tools you need to know</p></li><li><p>Strategies and limitations</p></li><li><p>Following data to the surface</p></li><li><p>&#8230;and how to fight the monsters under the Internet&#8217;s bed.</p></li></ul><p>Don&#8217;t forget your flashlight.</p><h2>Recap: What is the Dark Web?</h2><p>If the internet is an iceberg, it has three layers: the surface, deep, and dark web.</p><ul><li><p><strong>Surface Web: </strong>The normie &#8221;internet&#8221;. Indexed by search engines like Google and Bing.</p></li><li><p><strong>Deep Web: </strong>The &#8220;invisible&#8221; <a href="https://www.osint.industries/post/osint-on-the-deep-web-a-comprehensive-guide-to-deep-web-and-dark-web-osint">90% of the web</a> you don&#8217;t need a specific tool to access. Online banking, private networks, and corporate systems live here.</p></li><li><p><strong>Dark Web:</strong> The unindexed 1-6% of the web, only accessible via specialised tools. Always anonymised, always encrypted.</p></li></ul><p>What you find in this dark bottom layer - open-source or not - is dark web intelligence. So, think of Dark Web intelligence (or DARKINT) as OSINT&#8217;s emo little brother. Got it? Good.</p><h2>A Beginner&#8217;s Guide to DARKInt Tools</h2><p>To access the Dark Web, specific tools are required. Here&#8217;s a conceptual run-down of the best tools for beginners curious about traversing the depths. Of course, this overview is intended for educational purposes only, rather than encouraging active exploration as soon as possible - it&#8217;s best to think before you leap.</p><h3>Browsers Are Like Onions</h3><p>TOR is the most (in)famous of the bunch. Short for <a href="https://www.avg.com/en/signal/what-is-tor-browser-and-is-it-safe">The Onion Router</a>, TOR is too complex to unpack fully here. What&#8217;s more, we already did that last week.</p><p>Basically, onion browsers work by routing your connection through multiple encrypted layers - a bit like an onion - so no single point can trace your activity. The Dark Web&#8217;s sites then use .onion domains; &#8220;hidden services,&#8221; where both user and host are obscured. Instead of connecting directly, both sides layer up encrypted links via a shared rendezvous point on the TOR network, so nobody knows anybody else&#8217;s true IP This creates the built-in anonymity which makes the Dark Web so popular, keeping everything&#8230; under wraps (sorry).</p><h3>Where&#8217;s The Leak?</h3><p>We know one of the most common forms of DARKInt comes in the form of the humble data breach. Public leak indexes are one of the most beginner-friendly entry points into <a href="https://hackread.com/best-dark-web-intelligence-platforms/">DARKInt</a>, as they point users to large collections of said breached data.</p><p>Unlike raw breach dumps (a.k.a. the actual compromised data) leak indexes are designed for search and discovery, and act as directories or lookup tools, rather than hosting any data directly. They&#8217;re finding where data exists, and how it connects across leaks. Although datasets are traded, reused or repackaged across multiple Dark Web platforms, indexes can often find specific data whether it&#8217;s circulating across the Dark Web or in the wider web bloodstream beyond.</p><p>The usual caveats about breached data apply. There&#8217;s always a <a href="https://www.linkedin.com/pulse/ethical-dilemma-using-data-breach-information-osint-paul-wright-jmmaf">compliance problem</a> when handling potentially stolen data, so treat any data you find as if it were your own.</p><h3>Search Engines Are Like Onions Too.</h3><p>These aren&#8217;t the Dark Web Google. If TOR is your vehicle into the Dark Web, <a href="https://www.breachsense.com/blog/dark-web-search-engines/">onion search engines</a> are more like a slightly unreliable sat-nav; this Garmin won&#8217;t get you there, but it might point you in the right direction. These tools don&#8217;t provide access to anything. Instead, they index and surface .onion sites, helping users discover hidden services they might not know about. Onion search engines:</p><ul><li><p>Index .onion domains and hidden services</p></li><li><p>Enable keyword-based discovery (once you&#8217;re already using TOR)</p></li></ul><p>Unlike TOR browsers (which actually connect you to sites) <a href="https://www.makeuseof.com/how-to-search-dark-web/">onion search engines</a> sit a layer above like the onion&#8217;s outer skin, acting as discovery tools rather than access tools. And because the Dark Web is so transient (sites appear, disappear, or hide deliberately), these engines are best thought of as more treasure hunt than Google search. The coverage on the aforementioned Garmin is patchy, unstable, and often outdated. Still, it works when it doesn&#8217;t drive you into a lake - or an active volcano.</p><h3>Tracing An Account Back to the Surface, Step-By-Step.</h3><ol><li><p><strong>Use the tools above (indexes, search engines) to identify breaches.</strong></p></li><li><p><strong>Extract identifiers (email, username, phone number) from DARKINT sources.</strong></p><ul><li><p>You&#8217;ll need a Tor browser to access them.</p></li></ul></li><li><p><strong>Pivot using emails.</strong></p></li></ol><ul><li><p>Identify email accounts, recovery emails, and profiles just as you would as normal.</p></li></ul><ol start="4"><li><p><strong>Look for usernames.</strong></p></li></ol><ul><li><p>Do the same for usernames - especially look for reuse across social media, forums, or gaming sites.</p></li><li><p>Look for variations, and cross-reference matches as in light-mode OSINT.</p></li></ul><ol start="5"><li><p><strong>Pivot using phone numbers.</strong></p></li></ol><ul><li><p>Investigate links to messaging apps, listings, or leaked records that use breached phone numbers.</p></li></ul><ol start="6"><li><p><strong>Correlate findings.</strong></p></li></ol><ul><li><p>Always combine multiple data points to strengthen attribution.</p></li></ul><p>Lastly&#8230; <strong>Validate carefully.</strong></p><ul><li><p>Watch out for false positives, outdated, or manipulated data - on the Dark Web, these are all over the place</p></li></ul><h2>Key Limitations on DARKInt</h2><p>If these two guides have made the dark, dirty web sound all sunshine and rainbows, now is the time to crush your dreams. There&#8217;s no unicorns skipping around down there. DARKInt has limitations, and plenty of them. Let&#8217;s meet the monsters under the Internet&#8217;s bed.</p><h3>A High Risk Environment</h3><p>Imagine a world where everybody hates each other. That&#8217;s kinda the Dark Web. DARKInt operates within an anonymised, adversarial ecosystem built to keep its infrastructure volatile, and access inconsistent. Elevated operational security risks are baked-in. Hidden services frequently appear and disappear, and interacting with them can expose investigators to threat just by virtue (or vice) of a click. Tread carefully.</p><h3>False-Data Scam-O-Rama</h3><p>Data quality is &#8216;highly unreliable&#8217; to be polite. Breach dumps are often annoyingly duplicated, hopelessly outdated, trickily manipulated, or deliberately seeded with false facts. Financially motivated actors frequently distribute misleading datasets. At worst, you might end up involved in a particularly <a href="https://ktla.com/news/california/hospice-fraud-scheme-267-million/">icky scam</a>. At best, the overall signal-to-noise ratio can reach a hair-tearing level. Be patient.</p><h3>Not Everything is Verifiable</h3><p>So you have that &#8216;highly unreliable&#8217; data. It might never become reliable. Attribution and validation are inherently limited on the Dark Web, where anonymisation layers and restricted visibility are the whole point. So much activity occurs behind closed doors -  in closed networks or private exchanges - that datasets can&#8217;t always be corroborated or independently verified (outside of our dreams). Manage your expectations.</p><h3>Seeing Things You Can&#8217;t Unsee</h3><p>If you work recklessly in DARKInt, you&#8217;re playing psychological Russian roulette. You may encounter material that is disturbing, illegal, or just deeply distressing; content that <a href="https://www.psychiatry.org/news-room/apa-blogs/the-impact-of-trauma-%E2%80%93-even-from-a-distance">stays with you</a> long after you&#8217;ve closed TOR. When people are anonymous, they showcase the worst things humanity can do to each other. Even if you do everything right, you can end up seeing something deeply wrong. Have caution.</p><h2>Key Takeaways</h2><p>Our journey through the Web&#8217;s dark side is coming to an end. You should now know:</p><ul><li><p>All DARKINT is OSINT, but not all OSINT is DARKINT</p></li><li><p>The tools beginners need to go web spelunking</p></li><li><p>How to bring dark data into the light</p></li><li><p>&#8230; and why the Dark Web isn&#8217;t where the unicorns live.</p></li></ul><p>See you next issue, investigators!</p><div><hr></div><p>&#127937; New CTF Challenge Live - Covert Communication<br><br>A new CTF challenge has been posted on our CTF website. This week&#8217;s challenge involves analyzing a covert communications channel used by a suspected intelligence operative and finding the name of the location.<br><br><a href="https://ctf.osintnewsletter.com/">Start competing in our Capture the Flag (CTF)</a> </p><p>&#129667; If you missed the last CTF, <a href="https://ctf.osintnewsletter.com/challenges#The%20Dark%20Web%20DB-28">here&#8217;s a link to catch up</a>. <br><br>Last week&#8217;s CTF challenge featured a challenge titled &#8220;The Dark Web DB&#8221; required participants to investigate a suspected data breach involving Quick, where a threat actor allegedly published a customer database on the dark web and uncover key details about the publication.</p><p>To solve the challenge, we need: </p><ol><li><p>Copy &amp; paste the onion link into Wayback Machine.</p></li><li><p>Then we filter the results by date and select 06 March of 2026. We get a result for 06 March 2026 at 08:01:04. </p></li><li><p>We click on it, looking at the forum, on the right corner, we can see a post regarding a french and Belgian database. </p></li><li><p>It says that it was published 10 mins ago, we can also see the username of the threat actor who published it, which is: <strong>sarkstic</strong>. </p></li><li><p>Knowing that the forum was crawled at 08:01:04 and that the post says 10 mins ago, the post was made at 07:51:04.</p></li></ol><div><hr></div><p>&#9989; That&#8217;s it for the free version of The OSINT Newsletter. Consider upgrading to a paid subscription to support this publication and independent research.</p><p>By upgrading to paid, you&#8217;ll get access to the following:</p><p>&#128064; All paid posts in the archive. <a href="https://osintnewsletter.com/">Go back and see what you&#8217;ve missed</a>!</p><p>&#128640; If you don&#8217;t have a paid subscription already, don&#8217;t worry. There&#8217;s a 7-day free trial. If you like what you&#8217;re reading, upgrade your subscription. If you can&#8217;t, I totally understand. Be on the lookout for promotions throughout the year.</p><p>&#128680; The OSINT Newsletter offers a free premium subscription to all members of law enforcement. To upgrade your subscription, please reach out to LEA@osint.news from your official law enforcement email address. </p>]]></content:encoded></item><item><title><![CDATA[Episode 17: Dark Web Intelligence and Gathering OSINT from Live Traffic]]></title><description><![CDATA[Listen now | Tools, tactics, and fresh investigations expanding the open-source intelligence toolkit.]]></description><link>https://osintnewsletter.com/p/episode-17-dark-web-intelligence</link><guid isPermaLink="false">https://osintnewsletter.com/p/episode-17-dark-web-intelligence</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Fri, 01 May 2026 13:02:56 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/195728208/f63869b7bbed8df0640356ff9b9ab736.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Not all intelligence lives on the surface. Some of the most valuable data is deliberately hidden - and some of it is hiding in plain sight, flowing through the roads around you.</p><p>This episode covers Issues 103 and 104 of The OSINT Newsletter and focuses on two distinct but complementary areas: understanding the Dark Web as an intelligence source, and using live traffic data and cameras to build real-time situational awareness.</p><p>In Episode 17 of The OSINT Podcast, host Jake Creps opens with a foundational primer on Dark Web intelligence - or DARKINT. He breaks down the difference between the surface, deep, and dark web, explains how onion browsers and hidden services work, and outlines what investigators are likely to encounter when they go looking: breach dumps, criminal forums, paste sites, and shared credentials.</p><p>Jake covers the key distinction between OSINT and DARKINT - all DARKINT is OSINT, but not all OSINT is DARKINT - and explains why investigators combine both to build a complete picture of a target. He also addresses the compliance considerations that come with handling data sourced from the shadowy side of the net.</p><p>The episode then shifts to something more grounded - literally. Jake walks through how live traffic data can be used to gain situational awareness around a specific location or event. Starting with familiar tools like Google Maps and Waze, he explains how investigators can layer incident data, traffic flow, and police sightings before moving into more technical territory: the MapQuest Traffic API, the unofficial Waze API, and how to fuse multiple data sources into a single, custom solution.</p><p>From there, Jake covers live traffic camera feeds - manual methods via Department of Transportation sites, and API-based options like Road511 and Vizzion that allow investigators to build scalable, multi-location monitoring pipelines. The episode closes with a look at an unexpected bonus data source: rideshare apps, and the real-time vehicle location data sitting inside their public-facing interfaces.</p><p><strong>Highlights include:</strong></p><p>&#129477; <strong>Dark Web 101</strong> &#8211; surface, deep, and dark web explained, how onion browsers and hidden services work, and why Dark Web users are like ogres.</p><p>&#128373;&#65039; <strong>DARKINT Data Types</strong> &#8211; breach dumps, criminal forums, paste sites, and what each means for an OSINT investigation.</p><p>&#128678; <strong>Live Traffic Intelligence</strong> &#8211; using Google Maps, Waze, MapQuest API, and the unofficial Waze API to monitor incidents, road closures, and traffic flow in areas of interest.</p><p>&#128249; <strong>Traffic Camera Feeds</strong> &#8211; how to aggregate live camera feeds manually and at scale using Road511, Vizzion, and scraping methods.</p><p>The best investigators know how to follow the data wherever it leads - even into the dark, or down the road. Episode 17 shows you how to do both.</p><p><strong>References</strong></p><ul><li><p><a href="https://osintnewsletter.com/p/103">OSINT Newsletter &#8211; Issue 103</a></p></li><li><p><a href="https://osintnewsletter.com/p/104">OSINT Newsletter &#8211; Issue 104</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[The OSINT Newsletter - Issue #104]]></title><description><![CDATA[Gathering OSINT from Live Traffic: Datasets and Cameras]]></description><link>https://osintnewsletter.com/p/104</link><guid isPermaLink="false">https://osintnewsletter.com/p/104</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Thu, 30 Apr 2026 13:01:43 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/38c3eb70-e542-42d7-8ea1-87deef95e5e8_1900x1000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; <strong>Welcome to the 104th issue of The OSINT Newsletter.</strong> This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. My goal with this newsletter is to help promote the OSINT industry, develop better investigators, and raise awareness of ethical use cases for open source intelligence.</p><div><hr></div><p>&#129667; If you missed the last newsletter, here&#8217;s a link to catch up.</p><p>&#9889; <strong>OSINT and the Dark Web: Part One</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;e61aa437-dd5c-4814-9238-afe545c7d1a4&quot;,&quot;caption&quot;:&quot;&#128075; Welcome to the 103rd issue of The OSINT Newsletter. This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. Here&#8217;s an overview of what&#8217;s in this issue:&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The OSINT Newsletter - Issue #103&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-04-23T13:01:47.658Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/974a0cf9-a400-490a-8626-b8ed972f93a1_1900x1000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/103&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194548480,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:22,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Let&#8217;s get started. &#11015;&#65039;</p><div><hr></div><h1>OSINT News</h1><p>&#128240;  <strong>3 Basic but Overlooked Intelligence Analysis Techniques</strong></p><p>Plot it on a map, lay it out over time, or group it by theme. Simple moves that surface patterns, gaps, and what matters without collecting anything new.</p><p><a href="https://www.linkedin.com/posts/paul-prouse-741283245_intelligenceleadership-intelligenceanalysis-activity-7444956756809736192-4TyV/?utm_source=share&amp;utm_medium=member_ios&amp;rcm=ACoAABq6F0oBbmG93OZu2jSa-VZL4TF8Qv14q1Y">Read on LinkedIn&#8230;</a></p><p>&#127913; H/T: Paul Prouse</p><p><strong>&#128240;  Mining China&#8217;s &#8216;Little Red Book&#8217; for Open Source Gold</strong> </p><p>A breakdown of how Xiaohongshu can be used for investigations, from diaspora activity to censorship patterns, plus practical tips for search, language, and preserving content before it disappears.</p><p><a href="https://www.bellingcat.com/resources/2026/04/20/xiaohongshu-rednote-open-source-guide/?utm_source=linkedin">Read on Bellingcat&#8230;</a></p><p>&#127913; H/T: Chu Yang</p><p>&#128240; <strong>Hundreds of Fake Pro-Trump Avatars Emerge on Social Media</strong></p><p>An investigation finds networks of AI-generated avatars posting pro-Trump content across major platforms, blending spam, engagement farming, and political messaging at scale.</p><p><a href="https://www.nytimes.com/2026/04/17/business/media/artificial-intelligence-trump-social-media.html">Read on The New York Times&#8230;</a> | <a href="https://archive.is/20260420233500/https://www.nytimes.com/2026/04/17/business/media/artificial-intelligence-trump-social-media.html">No Paywall</a></p><p>&#127913; H/T: Tiffany Hsu</p><div><hr></div><h1>OSINT Tools</h1><p>&#128270; <strong>CoJournalist</strong></p><p>coJournalist lets reporters deploy AI &#8220;scouts&#8221; to track pages, social accounts, and public records, then distills updates into structured, cite-ready leads.</p><p><a href="https://www.cojournalist.ai/login">Web App</a></p><p>&#127913; H/T: Tom Vaillan</p><p>&#128270; <strong>Snapchat Bitmoji History</strong></p><p>A simple tool that pulls past Bitmoji versions from a Snap profile and displays them in one place, building on earlier research and tooling.</p><p><a href="https://tools.myosint.training/#bm-snapchat-bitmoji-history">Bookmarklet</a></p><p>&#127913; H/T: Micah Hoffman</p><p>&#128270; <strong>ImageWhisperer</strong></p><p>ImageWhisperer analyzes uploaded media for AI generation and manipulation signals, producing a single verdict with evidence across multiple detection models.</p><p><a href="https://imagewhisperer.org/">Web App</a></p><p>&#127913; H/T: Henk Van Ess</p><div><hr></div><p>&#127937; New CTF Challenge Live - The Dark Web DB</p><p>A new CTF challenge has been posted on our CTF website. This week&#8217;s challenge involves identifying a threat actor who published a database allegedly belonging to a French and Belgian fast-food chain &#8220;Quick&#8221; on the Dark Web. Your objective is to find the actor&#8217;s username and determine the exact timestamp of the original publication.</p><p><a href="https://ctf.osintnewsletter.com/">Start competing in our Capture the Flag (CTF) </a></p><p>&#129667; If you missed the last CTF, <a href="https://ctf.osintnewsletter.com/challenges#Crowd%20Control-27">here&#8217;s a link to catch up.</a> </p><p>Last week&#8217;s CTF challenge featured a challenge titled &#8220;Crowd Control&#8221; where participants needed to estimate the number of people present in an auditorium by using a specific AI tool available publicly.</p><div><hr></div><p>&#9989; That&#8217;s it for the free version of The OSINT Newsletter. Consider upgrading to a paid subscription to support this publication and independent research.</p><p>By upgrading to paid, you&#8217;ll get access to the following:</p><p><strong>&#9889; Gathering OSINT from Live Traffic: Datasets and Cameras</strong></p><ul><li><p>Traffic datasets and live cameras give you situational awareness into areas of interest for an investigation. Whether it&#8217;s business continuity, executive protection, global travel, or something niche, this issue breaks down the options available to you in an actionable plan. </p></li></ul><p>&#128064; All paid posts in the archive. <a href="https://osintnewsletter.com/">Go back and see what you&#8217;ve missed</a>!</p><p>&#128640; If you don&#8217;t have a paid subscription already, don&#8217;t worry there&#8217;s a 7-day free trial. If you like what you&#8217;re reading, upgrade your subscription. If you can&#8217;t, I totally understand. Be on the lookout for promotions throughout the year.</p><p>&#128680; The OSINT Newsletter offers a free premium subscription to all members of law enforcement. To upgrade your subscription, please reach out to LEA@osint.news from your official law enforcement email address. </p>
      <p>
          <a href="https://osintnewsletter.com/p/104">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The OSINT Newsletter - Issue #103]]></title><description><![CDATA[OSINT and the Dark Web: Part One]]></description><link>https://osintnewsletter.com/p/103</link><guid isPermaLink="false">https://osintnewsletter.com/p/103</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Thu, 23 Apr 2026 13:01:47 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/974a0cf9-a400-490a-8626-b8ed972f93a1_1900x1000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; <strong>Welcome to the 103rd issue of The OSINT Newsletter.</strong> This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. Here&#8217;s an overview of what&#8217;s in this issue:</p><ul><li><p>What the Dark Web is</p></li><li><p>The difference between surface, deep and dark web</p></li><li><p>The kinds of data you&#8217;ll find</p></li><li><p>OSINT vs. DARKINT</p></li><li><p>&#8230;and why Dark Web users are like onions.</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://osintnewsletter.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">This publication is reader-supported. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p>&#129667; If you missed the last newsletter, here&#8217;s a link to catch up.</p><p>&#9889; <strong>OSINT Methods for Archiving and Searching Video by Keyword</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;2a843aac-d3d9-4336-a32e-2dbf2acfb538&quot;,&quot;caption&quot;:&quot;&#128075; Welcome to the 102nd issue of The OSINT Newsletter. This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. My goal with this newsletter is to help promote the OSINT industry, develop better investigators, and raise awareness of ethical use cases for open source intelligence.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The OSINT Newsletter - Issue #102&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-04-09T13:03:01.842Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/afd3af24-7892-4ad0-8969-63d699f733e0_1900x1000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/102&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:182551198,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:20,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>&#127897;&#65039; <strong>If you prefer to listen, here&#8217;s a link to the podcast instead.</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;744f25d1-3d6c-4ee2-9e0a-d04c26801cf7&quot;,&quot;caption&quot;:&quot;Every investigation starts somewhere. For many, it starts with a username. And increasingly, the evidence lives inside a video you don&#8217;t have time to watch.&quot;,&quot;cta&quot;:&quot;Listen now&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Episode 16: Investigating Digital Footprints and Archiving Video at Scale&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-04-10T15:00:43.335Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2d562b3-17e6-407a-a622-f48627195d02_1200x630.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/episode-16-investigating-digital&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193669127,&quot;type&quot;:&quot;podcast&quot;,&quot;reaction_count&quot;:18,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Let&#8217;s get started. &#11015;&#65039;</p><div><hr></div><p>While OSINT operates out in the open - it is <em>open source</em> intelligence, after all - some of the most significant data lurks in the dark corners of the internet. So this time, we&#8217;re getting shady with it. Dark Web intelligence (or DARKINT) is the hidden side of OSINT. It sounds dangerous; but it&#8217;s perfectly safe to step into the gloom if you know how. Let&#8217;s begin our two-issue trip into the shadows with an overview of Dark Web OSINT. In Part One, we&#8217;ll cover:</p><ul><li><p>What the Dark Web is</p></li><li><p>The difference between surface, deep and dark web</p></li><li><p>The kinds of data you&#8217;ll find</p></li><li><p>OSINT vs. DARKINT</p></li><li><p>&#8230;and why Dark Web users are like onions.</p></li></ul><p>Let&#8217;s go dark.</p><h2>What is the Dark Web?</h2><p>The internet looks a little like an iceberg. It&#8217;s divided into multiple layers: the surface web at the top, the dark web at the bottom, and the deep web in the middle.</p><ul><li><p><strong>Surface Web:</strong> The normie &#8221;internet&#8221;. The stuff you use every day, that is indexed by conventional search engines (Google, Bing etc.), and easily searchable.</p></li><li><p><strong>Deep Web:</strong> Also known as the &#8220;invisible web&#8221; or &#8220;hidden web&#8217;. Unindexed and not easily searchable, but still accessible without a specialised browser. Content on the deep web includes online banking services, private networks and corporate systems. It makes up around <a href="https://www.trendmicro.com/en/what-is/dark-web/deep-web-vs-dark-web.html">90% of the internet.</a></p></li><li><p><strong>Dark Web:</strong> Unindexed, encrypted, and only accessible with specialised tools like onion browsers. The Dark Web makes up somewhere between <a href="https://www.iso.org/information-security/dark-web">1%</a> and <a href="https://www.childrenssociety.org.uk/information/professionals/resources/what-is-the-dark-web">6% of the internet</a>; and unlike its deep cousin, it&#8217;s always anonymised. Data found on this layer is known as dark web intelligence (<a href="https://section.dk/darknet-intelligence.html">DARKINT</a>).</p></li></ul><p>The important thing to remember about the Dark Web is that it&#8217;s not a single place; it&#8217;s a collection of anonymous websites hosted on encrypted networks. Some of these networks play host to <a href="https://www.group-ib.com/blog/dark-web-fraud/">financial fraudsters</a>, <a href="https://www.un.org/counterterrorism/en/media/3928">terrorist cells</a>, <a href="https://rainn.org/get-the-facts-about-csam-child-sexual-abuse-material/how-does-csam-get-distributed/">CSAM</a>, <a href="https://newsinteractives.cbc.ca/longform/the-new-frontier-of-the-drug-trade/">drug dealing</a> and <a href="https://www.rand.org/randeurope/research/projects/2017/international-arms-trade-on-the-hidden-web.html">weapons sales</a>.</p><p>But - despite the scare stories - not everything on the dark web is dodgy. Although many criminals do ply their wares on the internet&#8217;s dark side, it also has legitimate privacy-driven and anti-censorship use cases. For example, even <a href="https://www.bbc.co.uk/news/technology-50150981">major news outlets mirror their sites on the Dark Web</a>, to give citizens secret access under harsh state censorship.</p><h2>Onion Browsers and Hidden Services</h2><p>To access the Dark Web, you&#8217;ll need special tools. Enter TOR: short for <a href="https://www.avg.com/en/signal/what-is-tor-browser-and-is-it-safe">The Onion Router</a>. Onion browsers like TOR are too complicated to explain in detail here; but they basically work by encrypting your connections through multiple layers - like the skin of an onion. Each layer only knows part of the journey, making it extremely difficult to trace your activities. What makes the Dark Web a-peel-ing (sorry) to its users is anonymity; and onion browsers have this built-in.</p><p>Meanwhile, websites on the Dark Web use .onion domains, too, meaning both the user and the host are completely obscured. These sites are officially called <a href="https://www.icann.org/en/blogs/details/the-dark-web-the-land-of-hidden-services-27-6-2017-en">&#8216;hidden services&#8217; </a>- and without them, there&#8217;s no Dark Web.</p><p>Hosted within the TOR network, hidden services work similarly; both user and host build encrypted connections instead of linking up directly. Each hidden service will send out a descriptor on the TOR network, that&#8217;s discoverable to all users that know the .onion address. When users gain access to the site, they <em>actually</em> go to this rendezvous point - so neither side knows each other&#8217;s<em> real</em> IP. This process means mutual anonymity for everybody involved.</p><p>So in Shrek terms, Dark Web users are the <a href="https://www.youtube.com/watch?v=-FtCTW2rVFM&amp;t=21">ogres of the internet. </a>They&#8217;ve got layers.</p><h2>DARKINT: What Will You Find on the Dark Web?</h2><p>From an OSINT perspective, the most important part of the Dark Web will <a href="https://knowyourmeme.com/memes/maybe-the-real-treasure-was-the-friends-we-made-along-the-way">always be the data we meet along the way. </a>But what data types can you expect to find on the shadowy side of the net? Here&#8217;s what&#8217;s usually lurking down there.</p><h3>Data Leaks and Breach Dumps</h3><p>One of the most valuable (and most common) forms of DARKINT is the good old breach dump. Compromised data - leaked logins, for example - proliferates all over the Dark Web. You can find:</p><ul><li><p>Email and password combinations</p></li><li><p>Usernames and aliases</p></li><li><p>Phone and mobile numbers</p></li></ul><p>The boon with breach dumps is they often &#8220;package&#8221; multiple data points together; terrible for the subjects&#8217; anonymity, but perfect for OSINT pros piecing together an identity profile. These datasets can even be traded, reused or repackaged across multiple Dark Web platforms. However, it&#8217;s important to bear in mind the <a href="https://www.linkedin.com/pulse/ethical-dilemma-using-data-breach-information-osint-paul-wright-jmmaf">compliance problem</a> when handling potentially dirty data.</p><h3>Forums and Marketplaces</h3><p>Remember the fraud, drugs and guns we discussed earlier? Those Dark Web forums and marketplaces are central to the hidden net&#8217;s ecosystem; although they&#8217;re <a href="https://www.eccu.edu/blog/the-dark-web-and-its-dangers/">dangerous and damaging for the offline world, </a>they allow OSINT investigators to catch bad guys in the act. Cybercriminal activity can include:</p><ul><li><p>Discussion of terrorist activities</p></li><li><p>Organising financial fraud</p></li><li><p>Buying and selling personal data</p></li><li><p>&#8220;Service&#8221; marketplaces (drugs, guns, porn etc)</p></li></ul><p>Even though the Dark Web is anonymised, it can still provide data that unmasks serious criminals. Many investigations <a href="https://www.osint.industries/project/know-your-enemy-how-osint-collaboration-can-profile-a-predator">have been cracked with DARKINT</a> - exposing heinous offenders including child sexual abusers.</p><h3>Paste Sites and Shared Credential</h3><p>Paste sites - like <a href="https://www.authentic8.com/blog/what-is-pastebin-cyberthreat-intelligence">Pastebin</a> - are social media platforms that allow their users to dump large quantities of plain-text data online. They were created as innocent spaces for coders to share snippets of work, but have become increasingly popular with threat actors as a staging ground for dangerous activity.</p><p>These are often used to <a href="https://par.nsf.gov/servlets/purl/10336827">share sensitive information</a> from stolen credit card details, to malware, to exploit code. Although they aren&#8217;t often persistent, they can still be full of data that gets widely distributed - data that can also be crucial for OSINT.</p><h2>OSINT vs DARKINT</h2><p>All DARKINT is OSINT, but not all OSINT is DARKINT. OSINT includes the publicly accessible, indexed or easily reachable by the normie-net data. Meanwhile, DARKINT is just the hidden, encrypted data that only specialised Dark Web tools can dig up.</p><p>The question remains, however: why risk digging into DARKINT at all? Surely - unless you&#8217;re fighting cybercrime - the Dark Web is more risk than reward? Well, whilst OSINT tells you what&#8217;s going on out in public, DARKINT exposes what netizens intentionally work to hide. In practice, most investigators will combine OSINT and DARKINT to find all the data they need.</p><h2>Key Takeaways</h2><p>So, now you&#8217;ve taken your first steps into the shadowy side of the internet known as the Dark Web. You should now know:</p><ul><li><p>The Internet is like an iceberg - 90% is below the surface</p></li><li><p>The Dark Web isn&#8217;t all dodgy; it does have legitimate uses</p></li><li><p>All DARKINT is OSINT, but not all OSINT is DARKINT</p></li><li><p>&#8230; and DARKINT investigators are like onions - they have layers.</p></li></ul><p>See you next issue, investigators!</p><div><hr></div><p>&#11088; <strong>Sponsor: SockPuppet.io</strong></p><p>SockPuppet delivers secure, isolated environments with persistent virtual desktops and phones, real carrier-based SMS for OTPs, and residential IP connectivity&#8212;selectable from hundreds of locations. All accessible through a simple web interface that scales as your investigations grow.</p><p>Visit <a href="https://hubs.la/Q03DbZN00">SockPuppet.io</a> to empower your investigations with technology trusted by intelligence professionals.</p><div><hr></div><p>&#127937; <strong>New CTF Challenge Live - Crowd Control</strong></p><p>A new CTF challenge has been posted on our CTF website. This week&#8217;s challenge involves estimating the number of people in a photograph from the 2024 NATO Summit using a specific tool.</p><p>Start competing in our <a href="https://ctf.osintnewsletter.com/">Capture the Flag (CTF)</a></p><p>&#129667; If you missed the last CTF, <a href="https://ctf.osintnewsletter.com/challenges#Digital Footprints-26">here&#8217;s a link to catch up</a>. </p><p>Last week&#8217;s CTF challenge featured a challenge titled &#8220;Digital Footprints&#8221; where participants needed to identify the domains linked to a specific email address using only OSINT techniques.</p><div><hr></div><p>&#9989; That&#8217;s it for the free version of The OSINT Newsletter. Consider upgrading to a paid subscription to support this publication and independent research.</p><p>By upgrading to paid, you&#8217;ll get access to the following:</p><p>&#128064; All paid posts in the archive. <a href="https://osintnewsletter.com/">Go back and see what you&#8217;ve missed</a>!</p><p>&#128640; If you don&#8217;t have a paid subscription already, don&#8217;t worry. There&#8217;s a 7-day free trial. If you like what you&#8217;re reading, upgrade your subscription. If you can&#8217;t, I totally understand. Be on the lookout for promotions throughout the year.</p><p>&#128680; The OSINT Newsletter offers a free premium subscription to all members of law enforcement. To upgrade your subscription, please reach out to LEA@osint.news from your official law enforcement email address. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://osintnewsletter.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">This publication is reader-supported. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Episode 16: Investigating Digital Footprints and Archiving Video at Scale]]></title><description><![CDATA[Listen now | Tools, tactics, and fresh investigations expanding the open-source intelligence toolkit.]]></description><link>https://osintnewsletter.com/p/episode-16-investigating-digital</link><guid isPermaLink="false">https://osintnewsletter.com/p/episode-16-investigating-digital</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Fri, 10 Apr 2026 15:00:43 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/193669127/e085405cbe4dc9b4744dd5c9586b112d.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Every investigation starts somewhere. For many, it starts with a username. And increasingly, the evidence lives inside a video you don&#8217;t have time to watch.</p><p>This episode covers Issues 101 and 102 of The OSINT Newsletter and focuses on two practical areas of modern OSINT: mapping a target&#8217;s digital footprint using a comprehensive open-source framework, and extracting intelligence from video content at scale.</p><p>In Episode 16 of The OSINT Podcast, host Jake Creps opens with a deep dive into TheBigBrother, a GitHub-based OSINT framework that consolidates username enumeration, reverse image searching, network scanning, dark web lookups, EXIF extraction, crypto tracing, and more into a single tool. Jake walks through setup, core modules, and the real investigative value it offers - from identity correlation and social media pivoting to red teaming and privacy audits.</p><p>He then moves into one of the more underrated challenges in OSINT: working with video. Jake breaks down how to extract transcripts from YouTube and TikTok using tools like YouTube Transcript API and TokScript, and explains how to scale that process across dozens or hundreds of videos using open-source libraries and lightweight custom tooling.</p><p>Once video content is converted to text, the episode shows how to make it searchable - combining local search methods, Obsidian vaults, and LLMs to analyse transcripts at scale and produce actionable intelligence outputs.</p><p>Along the way, the episode reinforces a core principle: tools support collection, but intelligence requires analysis. Knowing how to build the pipeline is only half the work - knowing what to do with the output is what separates a collection exercise from actual OSINT.</p><p><strong>Highlights include:</strong></p><p>&#128269; <strong>TheBigBrother Deep Dive</strong> &#8211; a full walkthrough of the framework&#8217;s modules including Profiler, Footprint, Net Scan, Dark Web, EXIF, Dorks, and Sky Radar, with practical use cases for each.</p><p>&#127909; <strong>Video Transcript Extraction</strong> &#8211; how to pull transcripts from YouTube and TikTok one at a time and at scale using YouTube Transcript API, TokScript, and the Summarize library.</p><p>&#128194; <strong>Searching at Scale</strong> &#8211; combining transcribed video content with local search tools, Obsidian, and LLMs to surface patterns and produce intelligence reports.</p><p>Whether you&#8217;re tracing a username across the internet or digging through hours of video evidence, Episode 16 gives you the tools and workflow to do it efficiently.</p><p><strong>References</strong></p><ul><li><p><a href="https://osintnewsletter.com/p/101">OSINT Newsletter &#8211; Issue 101</a></p></li><li><p><a href="https://osintnewsletter.com/p/102">OSINT Newsletter &#8211; Issue 102</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[The OSINT Newsletter - Issue #102]]></title><description><![CDATA[OSINT Methods for Archiving and Searching Video by Keyword]]></description><link>https://osintnewsletter.com/p/102</link><guid isPermaLink="false">https://osintnewsletter.com/p/102</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Thu, 09 Apr 2026 13:03:01 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/afd3af24-7892-4ad0-8969-63d699f733e0_1900x1000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; <strong>Welcome to the 102nd issue of The OSINT Newsletter.</strong> This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. My goal with this newsletter is to help promote the OSINT industry, develop better investigators, and raise awareness of ethical use cases for open source intelligence.</p><div><hr></div><p>&#129667; If you missed the last newsletter, here&#8217;s a link to catch up.</p><p>&#9889; <strong>A deep dive into TheBigBrother, a comprehensive OSINT framework</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;8b405474-3739-4ec9-a3a1-14cd14aca3df&quot;,&quot;caption&quot;:&quot;&#128075; Welcome to the 101st issue of The OSINT Newsletter. This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The OSINT Newsletter - Issue #101&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-04-02T14:31:05.102Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5d6243dc-fd06-4fde-aaad-350bd452487f_1900x1000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/101&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:192960741,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:17,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Let&#8217;s get started. &#11015;&#65039;</p><div><hr></div><h1>OSINT News</h1><p>&#128240;  <strong>Geolocating Taliban in the Afghan Desert</strong></p><p>Ben walks you through a recent investigation he did in the Afghan desert. He steps through how he identified a base, tracked a flight, located a soldier drop off point, finding a dune strike location, and more.</p><p><a href="https://www.linkedin.com/posts/bendobrown_i-geolocated-taliban-special-forces-drills-share-7436737465677361152-WLV0?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAABq6F0oBbmG93OZu2jSa-VZL4TF8Qv14q1Y">Read on LinkedIn&#8230;</a> | <a href="https://www.youtube.com/watch?v=7t9gXDuWyKg">YouTube</a></p><p>&#127913; H/T: Benjamin Strick</p><p>&#128240; <strong>How OSINT Verifies Viral Claims During Wartime Chaos</strong></p><p>This video shows how to analyze a viral Reddit claim that Iran bombed its own girls&#8217; school by identifying manipulation signals, evaluating online actors and naming patterns, comparing search results, and verifying wartime claims using government sources, fact-checkers, verification outlets, and cross-model AI.</p><p><a href="https://www.youtube.com/watch?v=Q7mVKCyBLek">Watch on YouTube&#8230;</a></p><p>&#127913; H/T: Kirby Plessas</p><p>&#128240;  <strong>How Wildlife Traffickers Are Using Coded Language to Sell Protected Animals On Facebook</strong> </p><p>Foeke walks through how to identify coded language on Facebook Marketplace that indicates the sale of protected animals, including screenshots and other evidence collected.</p><p><a href="https://www.bellingcat.com/news/2026/03/19/how-wildlife-traffickers-are-using-coded-language-to-sell-protected-animals-on-facebook/">Read on Bellingcat&#8230;</a></p><p>&#127913; H/T: Foeke Postma</p><div><hr></div><h1>OSINT Tools</h1><p>&#128270; <strong>OSINT Rack</strong></p><p>OSINT Rack is a collection of OSINT tools categorized by use case, blog posts, courses, books, events, and more.</p><p><a href="https://osintrack.com/">Web App</a></p><p>&#127913; H/T: Mario Santella</p><p>&#128270; <strong>Tor Node Archive</strong></p><p>Tod Node Archive gives you insight into the world of Tor Nodes with a search engine, downloadable dataset, and a changelog.</p><p><a href="https://tor-archive.github.io/">Web App/Dataset</a></p><p>&#127913; H/T: </p><p>&#128270; <strong>CrowdCounter</strong></p><p>CrowdCounter estimates how many people are in a photo, saving you the time it takes to count manually. Too bad it doesn&#8217;t have an API, Henk!</p><p><a href="https://digitaldigging.org/crowdchecker/">Web App</a></p><p>&#127913; H/T: Henk Van Ess</p><div><hr></div><p>&#127937; <strong>New CTF Challenge Live - Digital Footprints</strong></p><p>A new CTF challenge has been posted on our CTF website. This week&#8217;s challenge involves identifying multiple domains linked to a well-known threat actor using only its email address.</p><p>Start competing in our <a href="https://ctf.osintnewsletter.com/">Capture the Flag (CTF)</a></p><p>&#129667; If you missed the last CTF, <a href="https://ctf.osintnewsletter.com/challenges#Tracing the Source-25">here&#8217;s a link to catch up</a>. </p><p>Last week&#8217;s CTF challenge featured a challenge titled &#8220;Tracing the Source&#8221; where participants needed to identify the username of the Telegram channel that published a promotional message and the name of the telegram channel that was promoted in that message, using only OSINT techniques.</p><p>Solution WU :</p><p>To solve this challenge, we need to use https://deaddrop.theosintconsultants.com/ to locate the original Telegram message.</p><p>By enclosing the message in quotation marks for an exact search (e.g., (&#8221;&#1606;&#1575;&#1578; &#1575;&#1576;&#1593;&#1579;&#1608;&#1604;&#1610; &#1575;&#1604;&#1582;&#1575;&#1589;...&#8221;) and applying a date filter corresponding to the timestamp (From: 2026-04-01 To: 2026-04-01), we were able to pinpoint a search result that displayed:</p><ul><li><p>The username of the channel that posted the message</p></li><li><p>The content of the message</p></li><li><p>The username of the promoted channel</p></li></ul><p>This method allowed us to identify the Telegram channel solely using the message content and the timestamp, as required by the challenge.</p><div><hr></div><p>&#9989; That&#8217;s it for the free version of The OSINT Newsletter. Consider upgrading to a paid subscription to support this publication and independent research.</p><p>By upgrading to paid, you&#8217;ll get access to the following:</p><p><strong>&#9889; OSINT Methods for Archiving and Searching Video by Keyword</strong></p><ul><li><p>Learn tools, tactics, and techniques for processing information from videos in a way that&#8217;s searchable at scale.</p></li></ul><p>&#128064; All paid posts in the archive. <a href="https://osintnewsletter.com/">Go back and see what you&#8217;ve missed</a>!</p><p>&#128640; If you don&#8217;t have a paid subscription already, don&#8217;t worry there&#8217;s a 7-day free trial. If you like what you&#8217;re reading, upgrade your subscription. If you can&#8217;t, I totally understand. Be on the lookout for promotions throughout the year.</p><p>&#128680; The OSINT Newsletter offers a free premium subscription to all members of law enforcement. To upgrade your subscription, please reach out to LEA@osint.news from your official law enforcement email address. </p>
      <p>
          <a href="https://osintnewsletter.com/p/102">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The OSINT Newsletter - 50% Off Easter Sale]]></title><description><![CDATA[Improve your OSINT skill set for less]]></description><link>https://osintnewsletter.com/p/the-osint-newsletter-50-off-easter-1df</link><guid isPermaLink="false">https://osintnewsletter.com/p/the-osint-newsletter-50-off-easter-1df</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Sun, 05 Apr 2026 13:03:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yF4I!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#127881; Hey, everyone. I&#8217;m excited to announce that The OSINT Newsletter is having an Easter sale!</p><p>&#127873; It&#8217;s been a while since a paid subscription of The OSINT Newsletter went on sale. Recently, the newsletter crossed the 32,000 subscriber mark. To celebrate, here&#8217;s a 50% off discount.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://osintnewsletter.com/a0cb54dc&quot;,&quot;text&quot;:&quot;50% Off&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://osintnewsletter.com/a0cb54dc"><span>50% Off</span></a></p><p>Here&#8217;s what you&#8217;ll get access to by upgrading now:</p><ul><li><p>Access to the entire newsletter archive of paid content with over 100 issues of tools, tactics, and techniques.</p></li><li><p>Continuously improve your skill set with the latest OSINT methods to discover more, be more efficient, and bring more value to your organization or mission.</p></li></ul><p>Thanks for your support. </p><p><strong>Click here to get 50% off The OSINT Newsletter</strong>&#128071;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://osintnewsletter.com/a0cb54dc&quot;,&quot;text&quot;:&quot;Get Better at OSINT for $40&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://osintnewsletter.com/a0cb54dc"><span>Get Better at OSINT for $40</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[The OSINT Newsletter - Issue #101]]></title><description><![CDATA[A deep dive into TheBigBrother, a comprehensive OSINT framework]]></description><link>https://osintnewsletter.com/p/101</link><guid isPermaLink="false">https://osintnewsletter.com/p/101</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Thu, 02 Apr 2026 14:31:05 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/5d6243dc-fd06-4fde-aaad-350bd452487f_1900x1000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; <strong>Welcome to the 101st issue of The OSINT Newsletter.</strong> This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator.</p><p>&#128680; This is the first post in the return of OSINT Tool Tuesday, an ongoing series of tool review deep dives aimed at helping investigators improve their tool kit. I understand it&#8217;s Thursday&#8230; we will be publishing these on Tuesdays moving forward!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://osintnewsletter.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">This Substack is reader-supported. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1><strong>TheBigBrother</strong></h1><p><strong><a href="https://github.com/chadi0x/TheBigBrother">TheBigBrother</a></strong> is a GitHub project that offers a comprehensive OSINT framework designed to investigate an individual&#8217;s digital footprint across the internet, enabling users to gather information such as associated usernames, social media profiles, metadata, and other publicly available intelligence. Essentially, it&#8217;s a username tool on steroids.</p><p>&#127913; H/T: Chadi0x</p><p>TheBigBrother allows you to search primarily by username, while also supporting a range of modules including email lookups, domain intelligence, metadata extraction (EXIF), and cryptocurrency tracing.</p><p>It brings together multiple OSINT techniques into a single toolkit, making it a valuable resource for investigations across law enforcement, cyber security, corporate intelligence, executive protection, and online threat analysis.</p><p><strong>In this guide, I&#8217;ll walk you through how to set up The Big Brother, how to use the tool, practical use cases you can apply it to, and key pivot points you can leverage from the information it uncovers.</strong></p><p>Let&#8217;s get started. &#11015;&#65039;</p><div><hr></div><h3><strong>Setup</strong></h3><p><strong>Recommended = Docker Method</strong></p><p>The easiest way to get The Big Brother up and running is by using Docker, which handles all dependencies and environment configuration for you.</p><h3><strong>Prerequisites</strong></h3><p>Before you begin, make sure you have installed:</p><ul><li><p>Docker</p></li><li><p>Docker Compose</p></li></ul><p>You can verify installation with by typing these commands into your terminal:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;c698a27e-2136-4d84-8b18-7538a6004061&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">docker --version

docker-compose --version</code></pre></div><h3><strong>Step 1: Clone the Repository</strong></h3><p>On your terminal, run:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;f097ab73-ef42-4a60-85d0-c24ca497e482&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">git clone https://github.com/chadi0x/TheBigBrother.git

cd the-big-brother</code></pre></div><h3><strong>Step 2: Launch TheBigBrother</strong></h3><p>Run the following command to build and start the tool:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;378cf9b7-a2c1-4e47-86a1-08e198e45933&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">docker-compose up --build</code></pre></div><p>This will:</p><ul><li><p>Build the Docker image</p></li><li><p>Install all required dependencies</p></li><li><p>Launch The Big Brother environment</p></li></ul><p><strong>MANUAL SETUP</strong></p><p>If you prefer not to use Docker, you can install and run The Big Brother locally using Python.</p><h3><strong>Prerequisites</strong></h3><p>Make sure the following are installed:</p><ul><li><p><strong>Python 3.8+</strong></p></li><li><p><strong>Git</strong></p></li><li><p><strong>pip</strong></p></li></ul><p>You can verify with:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;facd0f59-9d84-4f88-8302-a6af57f6dd07&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">python3 --version

git --version

pip3 --version</code></pre></div><h3><strong>Linux/MacOS Setup</strong></h3><ol><li><p><strong>Create a virtual environment</strong></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;9448af71-3bde-4479-802f-ee13c428ca72&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">python3 -m venv venv

source venv/bin/activate</code></pre></div><ol start="2"><li><p><strong>Install Dependencies</strong></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;2040d477-fbd2-44e9-a8fe-43fc2f103dae&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">pip install -r requirements.txt

playwright install chromium</code></pre></div><ol start="3"><li><p><strong>Launch the Application</strong></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;410ca6fa-cce9-4c00-8ad2-729efdb26c81&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">python -m uvicorn the_big_brother.gui.main:app --port 8000</code></pre></div><h3><strong>Windows Setup</strong></h3><ol><li><p><strong>Install Dependencies</strong></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;5755fb09-f3d5-4e7c-b342-063fa3c6a04d&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">pip install -r requirements.txt

playwright install chromium</code></pre></div><ol start="2"><li><p><strong>Launch the Application</strong></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;4406ac3b-6679-4e60-a066-731bf2cc01cd&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">python -m uvicorn the_big_brother.gui.main:app --port 8000</code></pre></div><p><strong>Next Steps:</strong></p><p>Once running, open your browser and go to:</p><p>http://localhost:8000</p><p>You&#8217;ll see the <strong>The Big Brother web interface</strong>, where you can:</p><ul><li><p>Enter usernames</p></li><li><p>Run modules</p></li><li><p>View results visually</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hy9g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d4665b0-bece-4592-b733-c1faa06ccbc7_1600x844.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hy9g!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d4665b0-bece-4592-b733-c1faa06ccbc7_1600x844.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hy9g!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d4665b0-bece-4592-b733-c1faa06ccbc7_1600x844.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hy9g!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d4665b0-bece-4592-b733-c1faa06ccbc7_1600x844.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hy9g!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d4665b0-bece-4592-b733-c1faa06ccbc7_1600x844.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hy9g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d4665b0-bece-4592-b733-c1faa06ccbc7_1600x844.jpeg" width="1456" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d4665b0-bece-4592-b733-c1faa06ccbc7_1600x844.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hy9g!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d4665b0-bece-4592-b733-c1faa06ccbc7_1600x844.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hy9g!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d4665b0-bece-4592-b733-c1faa06ccbc7_1600x844.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hy9g!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d4665b0-bece-4592-b733-c1faa06ccbc7_1600x844.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hy9g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d4665b0-bece-4592-b733-c1faa06ccbc7_1600x844.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Now, let&#8217;s dive into TheBigBrother usage and use cases.</strong></p><div><hr></div><h3><strong>Usage</strong></h3><p>Now that we&#8217;ve covered the basics, let&#8217;s dive into some of the core modules within The Big Brother and how you can use them in OSINT investigations.</p><h2><strong>Profiler</strong></h2><p>The Profiler module is designed to build a high-level overview of a target by aggregating information from multiple sources into a single profile.</p><p>This can include:</p><ul><li><p>Usernames</p></li><li><p>Social media accounts</p></li><li><p>General online presence</p></li></ul><p>Example:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;44d50c66-0905-4670-9012-abc9845b19a8&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">python3 thebigbrother.py --profiler testusername</code></pre></div><p>This will produce a consolidated view of the target, helping you quickly understand who you&#8217;re dealing with.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xr0h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1da6dcc7-0c70-45cb-9237-1802ea068bc3_1600x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xr0h!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1da6dcc7-0c70-45cb-9237-1802ea068bc3_1600x834.png 424w, https://substackcdn.com/image/fetch/$s_!xr0h!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1da6dcc7-0c70-45cb-9237-1802ea068bc3_1600x834.png 848w, https://substackcdn.com/image/fetch/$s_!xr0h!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1da6dcc7-0c70-45cb-9237-1802ea068bc3_1600x834.png 1272w, https://substackcdn.com/image/fetch/$s_!xr0h!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1da6dcc7-0c70-45cb-9237-1802ea068bc3_1600x834.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xr0h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1da6dcc7-0c70-45cb-9237-1802ea068bc3_1600x834.png" width="1456" height="759" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1da6dcc7-0c70-45cb-9237-1802ea068bc3_1600x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:759,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xr0h!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1da6dcc7-0c70-45cb-9237-1802ea068bc3_1600x834.png 424w, https://substackcdn.com/image/fetch/$s_!xr0h!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1da6dcc7-0c70-45cb-9237-1802ea068bc3_1600x834.png 848w, https://substackcdn.com/image/fetch/$s_!xr0h!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1da6dcc7-0c70-45cb-9237-1802ea068bc3_1600x834.png 1272w, https://substackcdn.com/image/fetch/$s_!xr0h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1da6dcc7-0c70-45cb-9237-1802ea068bc3_1600x834.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On the web interface, you can enter a target identifier (username, email address, phone number). Associated profile  images will appear in the blank space above.</p><p>&#128466;&#65039; This is a great starting point before diving deeper into specific modules.</p><h2><strong>Footprint</strong></h2><p>The Footprint module focuses on identifying where a username exists across the internet.</p><p>Example:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;92ba5709-197f-4403-bfd8-9f0015c1ce7a&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">python3 thebigbrother.py --footprint testusername</code></pre></div><p>This will:</p><ul><li><p>Enumerate accounts across platforms</p></li><li><p>Highlight reused usernames</p></li><li><p>Map out digital presence</p></li></ul><p>As you can see, our test on the web interface brought up 7 platforms linked to our email address.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!blcv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ba5b76-3150-49d2-b223-4f4f36b21d57_1600x490.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!blcv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ba5b76-3150-49d2-b223-4f4f36b21d57_1600x490.png 424w, https://substackcdn.com/image/fetch/$s_!blcv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ba5b76-3150-49d2-b223-4f4f36b21d57_1600x490.png 848w, https://substackcdn.com/image/fetch/$s_!blcv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ba5b76-3150-49d2-b223-4f4f36b21d57_1600x490.png 1272w, https://substackcdn.com/image/fetch/$s_!blcv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ba5b76-3150-49d2-b223-4f4f36b21d57_1600x490.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!blcv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ba5b76-3150-49d2-b223-4f4f36b21d57_1600x490.png" width="1456" height="446" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/64ba5b76-3150-49d2-b223-4f4f36b21d57_1600x490.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:446,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!blcv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ba5b76-3150-49d2-b223-4f4f36b21d57_1600x490.png 424w, https://substackcdn.com/image/fetch/$s_!blcv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ba5b76-3150-49d2-b223-4f4f36b21d57_1600x490.png 848w, https://substackcdn.com/image/fetch/$s_!blcv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ba5b76-3150-49d2-b223-4f4f36b21d57_1600x490.png 1272w, https://substackcdn.com/image/fetch/$s_!blcv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ba5b76-3150-49d2-b223-4f4f36b21d57_1600x490.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>&#128466;&#65039; Use this to identify pivot points into other tools or manual investigation.</p><h2><strong>Net Scan</strong></h2><p>The Net Scan module is used for gathering network-level intelligence.</p><p>Example:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;9688b0ed-0a8a-44d3-bdc3-cdb209f22ae1&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">python3 thebigbrother.py --netscan example.com</code></pre></div><p>This may return:</p><ul><li><p>IP addresses</p></li><li><p>Open ports</p></li><li><p>Hosting/provider information</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YZjX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b483cba-f095-4813-bc52-d8f56f25787b_1600x466.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YZjX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b483cba-f095-4813-bc52-d8f56f25787b_1600x466.png 424w, https://substackcdn.com/image/fetch/$s_!YZjX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b483cba-f095-4813-bc52-d8f56f25787b_1600x466.png 848w, https://substackcdn.com/image/fetch/$s_!YZjX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b483cba-f095-4813-bc52-d8f56f25787b_1600x466.png 1272w, https://substackcdn.com/image/fetch/$s_!YZjX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b483cba-f095-4813-bc52-d8f56f25787b_1600x466.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YZjX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b483cba-f095-4813-bc52-d8f56f25787b_1600x466.png" width="1456" height="424" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9b483cba-f095-4813-bc52-d8f56f25787b_1600x466.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:424,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YZjX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b483cba-f095-4813-bc52-d8f56f25787b_1600x466.png 424w, https://substackcdn.com/image/fetch/$s_!YZjX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b483cba-f095-4813-bc52-d8f56f25787b_1600x466.png 848w, https://substackcdn.com/image/fetch/$s_!YZjX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b483cba-f095-4813-bc52-d8f56f25787b_1600x466.png 1272w, https://substackcdn.com/image/fetch/$s_!YZjX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b483cba-f095-4813-bc52-d8f56f25787b_1600x466.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Our YouTube example on the web interface brought up the below network information:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vHhO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8987ad6-ed0e-4f95-a42a-ee84ab4668e0_1600x842.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vHhO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8987ad6-ed0e-4f95-a42a-ee84ab4668e0_1600x842.png 424w, https://substackcdn.com/image/fetch/$s_!vHhO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8987ad6-ed0e-4f95-a42a-ee84ab4668e0_1600x842.png 848w, https://substackcdn.com/image/fetch/$s_!vHhO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8987ad6-ed0e-4f95-a42a-ee84ab4668e0_1600x842.png 1272w, https://substackcdn.com/image/fetch/$s_!vHhO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8987ad6-ed0e-4f95-a42a-ee84ab4668e0_1600x842.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vHhO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8987ad6-ed0e-4f95-a42a-ee84ab4668e0_1600x842.png" width="1456" height="766" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d8987ad6-ed0e-4f95-a42a-ee84ab4668e0_1600x842.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:766,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vHhO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8987ad6-ed0e-4f95-a42a-ee84ab4668e0_1600x842.png 424w, https://substackcdn.com/image/fetch/$s_!vHhO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8987ad6-ed0e-4f95-a42a-ee84ab4668e0_1600x842.png 848w, https://substackcdn.com/image/fetch/$s_!vHhO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8987ad6-ed0e-4f95-a42a-ee84ab4668e0_1600x842.png 1272w, https://substackcdn.com/image/fetch/$s_!vHhO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8987ad6-ed0e-4f95-a42a-ee84ab4668e0_1600x842.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>&#128466;&#65039; Useful for infrastructure mapping and identifying related assets.</p><h2><strong>Dark Web</strong></h2><p>The <strong>Dark Web</strong> module attempts to identify whether a target appears in:</p><ul><li><p>Data breaches</p></li><li><p>Leaked databases</p></li><li><p>Dark web mentions</p></li></ul><p>Example:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;3521f1ab-54fa-4cd4-8b67-bd0555b25e3b&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">python3 thebigbrother.py --darkweb test@email.com</code></pre></div><p>This can help uncover:</p><ul><li><p>Compromised credentials</p></li><li><p>Exposure risks</p></li><li><p>Historical leaks</p></li></ul><p>You can enter a keyword e.g. a leak or database into the web interface search bar as below:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!L68N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f191dff-0e00-4010-9a6b-fd0dbb402cf0_1600x534.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!L68N!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f191dff-0e00-4010-9a6b-fd0dbb402cf0_1600x534.png 424w, https://substackcdn.com/image/fetch/$s_!L68N!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f191dff-0e00-4010-9a6b-fd0dbb402cf0_1600x534.png 848w, https://substackcdn.com/image/fetch/$s_!L68N!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f191dff-0e00-4010-9a6b-fd0dbb402cf0_1600x534.png 1272w, https://substackcdn.com/image/fetch/$s_!L68N!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f191dff-0e00-4010-9a6b-fd0dbb402cf0_1600x534.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!L68N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f191dff-0e00-4010-9a6b-fd0dbb402cf0_1600x534.png" width="1456" height="486" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1f191dff-0e00-4010-9a6b-fd0dbb402cf0_1600x534.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:486,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!L68N!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f191dff-0e00-4010-9a6b-fd0dbb402cf0_1600x534.png 424w, https://substackcdn.com/image/fetch/$s_!L68N!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f191dff-0e00-4010-9a6b-fd0dbb402cf0_1600x534.png 848w, https://substackcdn.com/image/fetch/$s_!L68N!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f191dff-0e00-4010-9a6b-fd0dbb402cf0_1600x534.png 1272w, https://substackcdn.com/image/fetch/$s_!L68N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f191dff-0e00-4010-9a6b-fd0dbb402cf0_1600x534.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Crypto</strong></h2><p>The Crypto module is used to analyse cryptocurrency wallets and transactions.</p><p>Example:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;e0fabe35-06a5-4d17-9c12-59e2dba1aaa3&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">python3 thebigbrother.py --crypto &lt;wallet_address&gt;</code></pre></div><p>This may reveal:</p><ul><li><p>Transaction history</p></li><li><p>Wallet activity</p></li><li><p>Links to other wallets</p></li></ul><p>On the web interface, simply enter the wallet address in question into the search bar below (bitcoin or ethereum).</p><p>&#128466;&#65039; Particularly useful in fraud, ransomware, or financial investigations.</p><h2><strong>SSL</strong></h2><p>The SSL module gathers intelligence from SSL certificates.</p><p>Example:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;dfa8edd3-f0a0-445d-aa1c-6ecb9e598c4a&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">python3 thebigbrother.py --ssl example.com</code></pre></div><p>This can uncover:</p><ul><li><p>Associated domains</p></li><li><p>Certificate details</p></li><li><p>Infrastructure links</p></li></ul><p>&#128466;&#65039; Great for finding hidden or related domains tied to a target.</p><h2><strong>EXIF</strong></h2><p>The EXIF module extracts metadata from images.</p><p>Example:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;5165aaff-9418-4c8a-a658-b683d202c79e&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">python3 thebigbrother.py --exif image.jpg</code></pre></div><p>This may include:</p><ul><li><p>GPS coordinates</p></li><li><p>Device information</p></li><li><p>Date/time data</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Cop7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c104def-d465-4ce7-a6f3-ea837235f754_1600x790.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Cop7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c104def-d465-4ce7-a6f3-ea837235f754_1600x790.png 424w, https://substackcdn.com/image/fetch/$s_!Cop7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c104def-d465-4ce7-a6f3-ea837235f754_1600x790.png 848w, https://substackcdn.com/image/fetch/$s_!Cop7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c104def-d465-4ce7-a6f3-ea837235f754_1600x790.png 1272w, https://substackcdn.com/image/fetch/$s_!Cop7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c104def-d465-4ce7-a6f3-ea837235f754_1600x790.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Cop7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c104def-d465-4ce7-a6f3-ea837235f754_1600x790.png" width="1456" height="719" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6c104def-d465-4ce7-a6f3-ea837235f754_1600x790.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:719,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Cop7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c104def-d465-4ce7-a6f3-ea837235f754_1600x790.png 424w, https://substackcdn.com/image/fetch/$s_!Cop7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c104def-d465-4ce7-a6f3-ea837235f754_1600x790.png 848w, https://substackcdn.com/image/fetch/$s_!Cop7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c104def-d465-4ce7-a6f3-ea837235f754_1600x790.png 1272w, https://substackcdn.com/image/fetch/$s_!Cop7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c104def-d465-4ce7-a6f3-ea837235f754_1600x790.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As in our web interface example, you won&#8217;t always get detailed information.</p><p>&#128466;&#65039; Extremely useful when analysing images from social media or leaks.</p><h2><strong>Dorks</strong></h2><p>The Dorks module leverages advanced search queries (Google Dorking) to find indexed information about a target.</p><p>Example:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;1f6f9f25-87cb-4ed8-8275-8e06864c90fb&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">python3 thebigbrother.py --dorks testusername</code></pre></div><p>This will generate queries to uncover:</p><ul><li><p>Public documents</p></li><li><p>Exposed data</p></li><li><p>Indexed profiles</p></li></ul><p>&#128466;&#65039; Helps surface information that isn&#8217;t easily found through direct searches.</p><h2><strong>GEOINT</strong></h2><p>The GEOINT module focuses on geographic intelligence.</p><p>Example:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;0e6e4604-c804-4e85-aebc-a84a987ff2b0&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">python3 thebigbrother.py --geoint &lt;location_or_image&gt;</code></pre></div><p>This may help:</p><ul><li><p>Identify locations from images</p></li><li><p>Analyse geographic patterns</p></li><li><p>Support situational awareness</p></li></ul><p>Our web interface search produced various location insights from various different sources, ideal for corroboration.</p><p>&#128466;&#65039; Useful for uncovering location-based insights from images, videos, and geographic data.</p><h2><strong>Sky Radar</strong></h2><p>The Sky Radar module is used for aviation-related intelligence.</p><p>Example:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;d91e4094-fa36-4ce4-8057-ee3372ebfd30&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">python3 thebigbrother.py --skyradar &lt;flight_or_aircraft&gt;</code></pre></div><p>This can provide:</p><ul><li><p>Flight tracking data</p></li><li><p>Aircraft information</p></li><li><p>Movement patterns</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9hO4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa88e25c-f31b-4fe2-8ed7-20af0f5f1ef1_1600x705.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9hO4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa88e25c-f31b-4fe2-8ed7-20af0f5f1ef1_1600x705.png 424w, https://substackcdn.com/image/fetch/$s_!9hO4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa88e25c-f31b-4fe2-8ed7-20af0f5f1ef1_1600x705.png 848w, https://substackcdn.com/image/fetch/$s_!9hO4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa88e25c-f31b-4fe2-8ed7-20af0f5f1ef1_1600x705.png 1272w, https://substackcdn.com/image/fetch/$s_!9hO4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa88e25c-f31b-4fe2-8ed7-20af0f5f1ef1_1600x705.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9hO4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa88e25c-f31b-4fe2-8ed7-20af0f5f1ef1_1600x705.png" width="1456" height="642" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fa88e25c-f31b-4fe2-8ed7-20af0f5f1ef1_1600x705.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:642,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9hO4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa88e25c-f31b-4fe2-8ed7-20af0f5f1ef1_1600x705.png 424w, https://substackcdn.com/image/fetch/$s_!9hO4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa88e25c-f31b-4fe2-8ed7-20af0f5f1ef1_1600x705.png 848w, https://substackcdn.com/image/fetch/$s_!9hO4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa88e25c-f31b-4fe2-8ed7-20af0f5f1ef1_1600x705.png 1272w, https://substackcdn.com/image/fetch/$s_!9hO4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa88e25c-f31b-4fe2-8ed7-20af0f5f1ef1_1600x705.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>&#128466;&#65039; Useful in niche investigations involving travel, logistics, or tracking assets.</p><h3><strong>Use Cases</strong></h3><p>TheBigBrother is essentially a username intelligence + image correlation tool that:</p><ul><li><p>scans hundreds of platforms (~400+) for usernames</p></li><li><p>pulls profile images</p></li><li><p>runs automated reverse image searches across multiple engines</p></li></ul><p>That combination is best for identity linking, username pivoting, and avatar-based correlation.</p><p><strong>The bottom line?</strong> It shines in early-stage investigations, when you&#8217;re trying to answer: &#8220;Where else does this person exist online?&#8221;</p><p><strong>Where this tool is actually useful in OSINT:</strong></p><p><strong>Identity Correlation/linking accounts</strong></p><p>If you start with a username or even just a profile image, you can find matching usernames across platforms, confirm links using reused profile pictures, and cluster accounts belonging to the same person.</p><p><strong>Social Media Investigations</strong></p><p>The tool accelerates what analysts normally do manually i.e. searching usernames across platforms, comparing profile photos and running reverse image searches separately. With this automated, you can quickly find forgotten/old accounts, identify niche platforms, and uncover behaviour patterns across platforms. </p><p><strong>Reverse Image Pivoting</strong></p><p>This is, in our opinion, an underrated use of the tool. Essentially, because it auto-runs reverse image searches, you can detect reused avatars across multiple accounts, spot fake personas using stock/AI images, and find the original source of a profile image. This is useful for catfish investigations, scammer tracking, or simply verifying whether a persona is real.</p><p><strong>Threat Intelligence / Cyber Investigations</strong></p><p>In cyber threat intel, attackers often reuse usernames, avatars, and branding. TheBigBrother helps pivot from a known handle to a broader footprint, and can identify presence on GitHub, forums, marketplaces, and social platforms.</p><p><strong>Red Teaming / Privacy Audits</strong></p><p>Security teams can use this tool to understand what an attacker could discover publicly via simulating how easily identities can be correlated and identifying OPSEC failures such as username and avatar reuse.</p><div><hr></div><p>&#127937; <strong>New CTF Challenge Live - The Insider</strong></p><p>A new CTF challenge has been posted on our CTF website. This week&#8217;s challenge focuses on Local search methods. Your task is to identify the username of an insider who plans to target a company with ransomware and also determine the targeted company name.</p><p>Start competing in our Capture the Flag (CTF)</p><p>&#129667; If you missed the last CTF, here&#8217;s a link to catch up.</p><p>Last week&#8217;s CTF challenge featured a challenge titled &#8220;The Hacktivist&#8221;.</p><p>Solution WU :</p><p>Using <a href="https://twitterwebviewer.com/">Twitter Viewer - View Twitter Without Account</a> and typing the username of the X account &#8220;RepresaliaNet&#8221; we could browse the posts made by the threat actor without having an account.</p><p>While browsing the posts, we could notice that one of the posts published on Nov 28, 2024 contains the username : YourZer321-PVC</p><p>Scrolling further, we could see that the first post date was : 25/09/2024</p><p>To find the country we needed to have an account (Sock Puppet). By clicking on &#8220;about this account&#8221;, we could see that the account was based in : Uzbekistan</p><div><hr></div><p>&#9989; That&#8217;s all for this issue of The OSINT Newsletter. Thanks for reading and supporting this publication with a paid subscription.</p><p>&#128161; Remember OSINT != tools. Tools help you plan and collect data but the result of that tool is not OSINT. You must analyze, verify, receive feedback, refine, and produce a final, actionable product of value before it can be called intelligence.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://osintnewsletter.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">This Substack is reader-supported. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Episode 15: Offline OSINT and Building Ethical Investigative Skill Sets]]></title><description><![CDATA[Listen now | Tools, tactics, and fresh investigations expanding the open-source intelligence toolkit.]]></description><link>https://osintnewsletter.com/p/episode-15-offline-osint-and-building</link><guid isPermaLink="false">https://osintnewsletter.com/p/episode-15-offline-osint-and-building</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Fri, 27 Mar 2026 16:00:56 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/192080768/027f02f16e763cf37328d1099f7b254b.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Not all intelligence lives online. Some of the most valuable data is already sitting on your machine. And every investigator eventually runs into the same problem: how do you actually work with it at scale?</p><p>This episode covers Issues 99 and 100 of The OSINT Newsletter and focuses on two essential aspects of modern OSINT: processing large datasets locally using efficient tools, and developing your investigative skill set through consistent, ethical practice.</p><p>In Episode 15 of The OSINT Podcast, host Jake Creps explores offline OSINT from first principles, breaking down why traditional tools fail when dealing with investigative scale data. The episode explains how local search tools operate without loading entire datasets into memory, allowing investigators to extract key information from massive files quickly and efficiently.</p><p>Jake walks through core command line techniques used in local analysis, including grep for pattern matching, csvkit for structured data filtering, and tools like awk and jq for processing and transforming datasets. By combining these tools, investigators can build lightweight pipelines that turn raw data into usable intelligence.</p><p>The episode then shifts from tools to mindset, focusing on how investigators actually develop their skill set over time. Rather than relying on theory alone, Jake outlines practical, repeatable methods for improving as an OSINT practitioner.</p><p>He explores how collecting and sharing tools builds familiarity with the ecosystem, why writing and teaching methods reinforces understanding, and how small scale investigations such as analysing spam emails can provide valuable repetitions without ethical risk.</p><p>Jake also discusses the importance of applying OSINT for real world impact, highlighting opportunities to support non profit investigations and contribute to meaningful causes. Alongside this, the episode covers personal OPSEC, showing how investigators can use their own techniques to audit and reduce their digital footprint.</p><p>Along the way, Jake reinforces a core principle of OSINT: tools enable collection, but intelligence comes from analysis. Mastery comes from repetition, not novelty.</p><p><strong>Highlights include:</strong></p><p><strong>&#128194; Offline OSINT</strong> &#8211; Working with Local Data &#8211; how to search and analyse massive datasets using tools like grep, csvkit, awk, and jq without overwhelming your system.</p><p><strong>&#129504; Building Your OSINT Skill Set</strong> &#8211; practical methods for improving as an investigator through repetition, teaching, tool discovery, and low risk investigations.</p><p><strong>&#128736; Tools in Focus</strong> &#8211; grep for fast pattern matching, csvkit for structured data handling, and command line workflows for scalable data processing.</p><p>Throughout the episode, the focus stays on practical investigative thinking. Data reveals patterns. Practice builds intuition. And the best investigators know how to combine both.</p><p>If you want to improve how you handle large datasets and develop your OSINT skill set in a structured, ethical way, Episode 15 is for you.</p><p><strong>References</strong></p><ul><li><p><a href="https://osintnewsletter.com/p/99">OSINT Newsletter &#8211; Issue 99</a></p></li><li><p><a href="https://osintnewsletter.com/p/100">OSINT Newsletter &#8211; Issue 100</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[The OSINT Newsletter - Issue #100]]></title><description><![CDATA[5 Ethical Ways to Develop Your OSINT Skill Set]]></description><link>https://osintnewsletter.com/p/100</link><guid isPermaLink="false">https://osintnewsletter.com/p/100</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Thu, 26 Mar 2026 13:03:02 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/56a2ee35-dfbc-463f-91b3-13d47813f172_1900x1000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; <strong>Welcome to the 100th issue of The OSINT Newsletter.</strong> This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. My goal with this newsletter is to help promote the OSINT industry, develop better investigators, and raise awareness of ethical use cases for open source intelligence.</p><div><hr></div><p>&#129667; If you missed the last newsletter, here&#8217;s a link to catch up.</p><p>&#9889; <strong>Offline OSINT: Local Search Tools and Methods</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;911ec222-8bbd-49ea-ad3c-13e61f9dcee5&quot;,&quot;caption&quot;:&quot;&#128075; Welcome to the 99th issue of The OSINT Newsletter. This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. Here&#8217;s an overview of what&#8217;s in this issue:&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The OSINT Newsletter - Issue #99&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-03-19T13:03:15.544Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f02b7f8f-9831-4415-a9bb-861951daa88a_1900x1000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/99&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:190731034,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:12,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Let&#8217;s get started. &#11015;&#65039;</p><div><hr></div><h1>OSINT News</h1><p>&#128240; <strong>Public GitHub Repositories from News Organizations</strong></p><p>Open Journalism delivers a biweekly update of open source projects published by news organizations. Sometimes tools, datasets, or other useful bits of information, make sure show your support for this great project.</p><p><a href="https://openjournalism.news/">Read on Open Journalism&#8230;</a></p><p>&#127913; H/T: Scott Klein</p><p>&#128240; <strong>Changes in Google Programmable Search Engines</strong></p><p>There are changes coming to custom search engines in Google. They will no longer have the option to do a full web. Many OSINT tools are built on the back of custom search engines. If you use any, it might be time to diversify.</p><p><a href="https://www.linkedin.com/posts/henribeek_osint-cti-programmablesearchengine-share-7437029043822137344-R5Eu?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAABq6F0oBbmG93OZu2jSa-VZL4TF8Qv14q1Y">Read on LinkedIn&#8230;</a></p><p>&#127913; H/T: Henri Beek</p><p>&#128240; <strong>Open-source intelligence shuts down</strong></p><p>This article highlights something I&#8217;ve mentioned often, becoming too reliant on datasets being available and eventually being disrupted by changes. Satellite images of the area affected in the ongoing war in Iran have been blocked or removed. Many research projects rely on regular access to these images for humanitarian purposes or otherwise.</p><p><a href="https://www.economist.com/middle-east-and-africa/2026/03/15/open-source-intelligence-shuts-down">Read on The Economist&#8230;</a> | <a href="https://archive.is/20260318191138/https://www.economist.com/middle-east-and-africa/2026/03/15/open-source-intelligence-shuts-down">No Paywall</a></p><div><hr></div><h1>OSINT Tools</h1><p>&#128270; <strong>WireTapper</strong></p><p>This is a niche tool. It may even be somewhat of a grey tool. Using the Wigle, WPA Sec, OpenCellID, and Shodan API keys, WireTapper provides insight into location-based technical data from passive sources.</p><p><a href="https://github.com/h9zdev/WireTapper">GitHub</a></p><p>&#127913; H/T: h9zdev</p><p>&#128270; <strong>Deaddrop</strong></p><p>Another Telegram search engine. Always build redundancy. Search for content within a scraped Telegram archive and find information that isn&#8217;t indexed by search engines.</p><p><a href="https://deaddrop.theosintconsultants.com/">Web App</a> | <a href="https://www.linkedin.com/posts/osint-telegram-threatintelligence-share-7437538632992964608-u5i5?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAABq6F0oBbmG93OZu2jSa-VZL4TF8Qv14q1Y">LinkedIn</a></p><p>&#127913; H/T: The OSINT Consultants</p><p>&#128270; <strong>LootBin</strong></p><p>Termbin is like Pastebin but through the command line. LootBin helps you gather information from Termbin, another source not indexed by search engines.</p><p><a href="https://github.com/gustqvo432/LootBin">GitHub</a></p><p>&#127913; H/T: gustqvo432</p><p><strong>Note:</strong> There seems to be some suspicious code in the Windows version of this tool. Do not install it. Instead, understand the concept educationally.</p><p>&#11088; <strong>Sponsor: SockPuppet.io</strong></p><p>SockPuppet delivers secure, isolated environments with persistent virtual desktops and phones, real carrier-based SMS for OTPs, and residential IP connectivity&#8212;selectable from hundreds of locations. All accessible through a simple web interface that scales as your investigations grow.</p><p>Visit <a href="https://hubs.la/Q03DbZN00">SockPuppet.io</a> to empower your investigations with technology trusted by intelligence professionals.</p><div><hr></div><p>&#9989; That&#8217;s it for the free version of The OSINT Newsletter. Consider upgrading to a paid subscription to support this publication and independent research.</p><p>By upgrading to paid, you&#8217;ll get access to the following:</p><p><strong>&#9889;5 Ethical Ways to Develop Your OSINT Skill Set</strong></p><ul><li><p>Developing an OSINT skill set is valuable for a variety of roles. I&#8217;ve seen OSINT used everywhere from recruiting for HR departments to tracking Elon Musk&#8217;s airplane. If you&#8217;re looking for ways to build your skill set ethically, you&#8217;ve come to the right place. If you practice all 5 methods even once, you&#8217;ll be noticeably better.</p></li></ul><p>&#128064; All paid posts in the archive. <a href="https://osintnewsletter.com/">Go back and see what you&#8217;ve missed</a>!</p><p>&#128640; If you don&#8217;t have a paid subscription already, don&#8217;t worry there&#8217;s a 7-day free trial. If you like what you&#8217;re reading, upgrade your subscription. If you can&#8217;t, I totally understand. Be on the lookout for promotions throughout the year.</p><p>&#128680; The OSINT Newsletter offers a free premium subscription to all members of law enforcement. To upgrade your subscription, please reach out to LEA@osint.news from your official law enforcement email address. </p><div><hr></div>
      <p>
          <a href="https://osintnewsletter.com/p/100">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The OSINT Newsletter - Issue #99]]></title><description><![CDATA[Offline OSINT: Local Search Tools and Methods]]></description><link>https://osintnewsletter.com/p/99</link><guid isPermaLink="false">https://osintnewsletter.com/p/99</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Thu, 19 Mar 2026 13:03:15 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/f02b7f8f-9831-4415-a9bb-861951daa88a_1900x1000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; <strong>Welcome to the 99th issue of The OSINT Newsletter.</strong> This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. Here&#8217;s an overview of what&#8217;s in this issue:</p><ul><li><p>How to search large datasets locally</p></li><li><p>Command-line search methods</p></li><li><p>Pro tools for processing structured data</p></li><li><p>&#8230;and everything you need to know about analysing large files.</p></li></ul><div><hr></div><p>&#129667; If you missed the last newsletter, here&#8217;s a link to catch up.</p><p>&#9889; <strong>Collecting Information from Local Sources in an OSINT Investigation</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;ed396eed-3ecc-4f56-ad22-fbe64b7218d1&quot;,&quot;caption&quot;:&quot;&#128075; Welcome to the 98th issue of The OSINT Newsletter. This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. My goal with this newsletter is to help promote the OSINT industry, develop better investigators, and raise awareness of ethical use cases for open source intelligence.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The OSINT Newsletter - Issue #98&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-03-12T13:03:21.724Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a6a19e21-818b-44cb-9cdb-30a570a22e33_1900x1000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/98&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:182551142,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:17,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>&#127897;&#65039; <strong>If you prefer to listen, here&#8217;s a link to the podcast instead.</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;f8fbbec8-8756-4783-8d71-c41c9357aece&quot;,&quot;caption&quot;:&quot;Every packet travels somewhere. Every connection leaves a trace. And every investigator eventually has to answer the same question: where did this activity actually come from?&quot;,&quot;cta&quot;:&quot;Listen now&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Episode 14: IP Address Investigations and Local OSINT&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-03-13T14:03:03.039Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f4b9fb1c-cf61-4d63-9bba-4b88225f31d6_1200x630.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/episode-14-ip-address-investigations&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:190501977,&quot;type&quot;:&quot;podcast&quot;,&quot;reaction_count&quot;:7,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Let&#8217;s get started. &#11015;&#65039;</p><div><hr></div><h1>Offline OSINT: Local Search Tools and Methods</h1><p>Not all OSINT happens on the internet. Sometimes the most valuable insights come from something you&#8217;ve already got downloaded; and every OSINT investigator has heaps of exported spreadsheets and datasets on file to work with. But when you&#8217;re archiving everything, it&#8217;s easy for your collection of documents - or even the size of the datasets themselves - to get huge.</p><p>But processing data with the wrong tools can be a real drag. If you&#8217;ve ever tried to open a 3GB CSV file in Excel, you already know the pain. Standard office tools simply weren&#8217;t built for investigative-scale datasets - and that&#8217;s where local device search tools come in.</p><p>Let&#8217;s get into local search.</p><h2>What is Local Search?</h2><p>OSINT investigators often end up working with big datasets. Breach dumps, scrapes, exports and archives can mount up, with a single file easily containing millions of rows. A rookie investigator will usually try to open these with traditional spreadsheet software (think Microsoft Excel); only to find it crashes instantly or slows to a stop. In turn, searching through a dataset is even more of a struggle. It&#8217;s possible, but <a href="https://support.microsoft.com/en-us/office/what-to-do-if-a-data-set-is-too-large-for-the-excel-grid-976e6a34-9756-48f4-828c-ca80b3d0e15c">it&#8217;s extremely painful.</a></p><p>Local device search tools are made to solve this problem. They scan the files directly, without loading everything into memory and making themselves sluggish. Instead of manually scrolling through data, you can extract exactly what you need in seconds - like pulling from a digital library catalog, rather than searching shelf-by-shelf.</p><h2>Searching vs. Processing: How to Handle Large Files</h2><p>The tools we&#8217;re about to talk about are all naturals at searching big files. But what if you want to do more than just search? Then you need processing power. If you want to:</p><ul><li><p>Extract all email domains from a breach file</p></li><li><p>Identify the most common usernames in a dataset</p></li><li><p>Count how many times a specific organisation appears</p></li><li><p>Separate valid data from corrupted rows</p></li></ul><p>Then clearly, just search won&#8217;t cut it. Luckily, <a href="https://warwick.ac.uk/research/rtp/sc/rse/training/linuxdesktop/basiccommandline/">command-line</a> processing tools excel at these tasks because they&#8217;re designed for automation and scale. Many investigators will even combine the tools we&#8217;re about to discuss together; mixing and matching methods and modules lets you build data- processing pipelines that perfectly fit your needs.</p><p>For example, you might search up a keyword with grep, then use awk to count the matches. If it sounds like we&#8217;re talking nonsense&#8230; let&#8217;s learn what the grep we&#8217;re on about.</p><h2>grep: The Text Search Tool</h2><p><a href="https://www.youtube.com/watch?v=EK-A--VaTYo">grep</a> (short for global regular expression print) is one of the most popular local device search tools in the OSINT community. It&#8217;s a Unix command-based search, localised to your device; grep scans text files for matching patterns, and returns every line containing your query.</p><p>It&#8217;s fast, simple, and extremely powerful when working with large text-based datasets. The perfect way to surface those pesky data points when they&#8217;re swamped. Use grep to search files for:</p><ul><li><p>Email addresses</p></li><li><p>Phone numbers</p></li><li><p>Domain names</p></li><li><p>Usernames</p></li><li><p>Keywords related to your investigation</p></li></ul><p>For example, if you wanted to search a breach file for a particular email address, grep could scan millions of rows for it almost instantly.</p><p>On top of this, grep can also do <a href="https://www.ibm.com/docs/ar/i/7.4.0?topic=data-grep">pattern matching. </a>This means you can search for entire categories of data, too, as well as exact words; any email address ending in a particular domain, for instance. Because it reads line-by-line rather than loading files fully, grep can comfortably handle big datasets that would blow up normal apps.</p><h2>csvkit: Making Sense of Spreadsheets</h2><p>Most OSINT datasets are stored as <a href="https://flatfile.com/blog/what-is-a-csv-file-guide-to-uses-and-benefits/">CSV files</a>. CSV stands for &#8220;comma separated values,&#8221; and it&#8217;s one of the most common formats for structured data exports. Breach databases, scraped content, and research datasets are frequently distributed this way. Usually, CSV means spreadsheets; but even programs that don&#8217;t seem like spreadsheet apps will often offer CSV as an output file type.</p><p>But CSV files grow big, fast. To deal with this, you need a tool specially designed to deal with CSVs - without opening them and overloading your machine. <a href="https://csvkit.readthedocs.io/en/latest/">csvkit is such a tool</a>; it works from the command line to search, filter, and analyse spreadsheets without opening. Instead of scrolling through millions of rows, you can:</p><ul><li><p>View column headers instantly</p></li><li><p>Filter rows based on conditions</p></li><li><p>Extract specific columns</p></li><li><p>Convert files into other (more manageable) formats</p></li></ul><p>For example, if a sheet has three columns full of usernames, IPs, and emails, csvkit allows you to isolate just the column you need and ignore the rest. Makes it much easier to focus on each different data point methodically without getting distracted.</p><h2>More Tools for Local Data</h2><p>Beyond grep and csvkit, several other lower-case-named tools are popular in pro OSINT workflows. They might have a disregard for grammar rules, but they&#8217;re great at handling big datasets - searching, processing, analysing, and more.</p><ul><li><p><a href="https://github.com/BurntSushi/ripgrep">ripgrep</a>: ripgrep is designed to make grep commands even quicker and easier with little changes; automatically ignoring irrelevant files, like binary data for example. If you have a whole folder of datasets, ripgrep will whip through that entire directory structure - stat.</p></li><li><p><a href="https://www.ibm.com/docs/en/aix/7.1.0?topic=awk-command">awk</a>: like grep and <a href="https://www.ibm.com/docs/en/aix/7.2.0?topic=s-sed-command">sed</a>, awk is a command-line filter. More general than grep, it&#8217;s often used for processing structured data - and can handle different commands and modifications than its cousins.</p></li><li><p><a href="https://jqlang.org"> jq</a>: described as &#8220;sed for JSON data&#8221;. Sometimes, datasets are stored in JSON format rather than CSV, making them much more difficult to read manually. jq can search and pull out specific fields from JSON data turning messy machine-readable files into human-readable intel.</p></li><li><p><a href="https://sqlite.org">SQLite</a>: When a dataset gets super big, it&#8217;s sometimes easier to import it into a lightweight database than leave it standalone. SQLite lets you do this. Plus, it&#8217;s already the most used database engine in the world.</p></li></ul><h2>Example: Local Search in Action</h2><p>this time, imagine you are a professional osint analyst, working with a dataset containing millions of logins. but something seems wrong. immediately, you realise - all the data appears in lowercase.</p><p>somebody has stolen all the capital letters, and the issue is spreading. you need to find out when, and how.</p><h3>step one: search</h3><p>first you need to confirm that the capitals have gone. using grep, you scan the dataset for a username you<em> know </em>should be capitalised. Here, every instance appears in lowercase - confirming the capitals aren&#8217;t where they should be.</p><h3>step two: process</h3><p>next, you process the data for evidence. you use awk to analyse patterns across the dataset - counting the examples of that de-capitalised username, and identifying other entries that should have been capitalised. you begin to question the thief&#8217;s motives.</p><h3>step three: structured analysis</h3><p>you isolate each column with cvskit, and work through each methodically: usernames, email addresses, dates, checking each for formatting issues. the loss has occurred consistently across all fields. seeing the scale of the crime disturbs you.</p><h3>step four: check other formats</h3><p>Finally, you run jq on an older version of your dataset. these files still contain capital letters - meaning the dataset was just corrupted during the csv export.</p><p>as for the issue spreading&#8230; you need a new keyboard.</p><h3>Key Takeaways</h3><p>So, now you know the basics of local search. By now you should be able to:</p><ul><li><p><strong>Search:</strong> Use commands to find specific data points</p></li><li><p><strong>Process:</strong> Execute more complex commands to make your life easier</p></li><li><p><strong>Analyse:</strong> Work with tools to identify patterns and pivot</p></li><li><p><strong>type: </strong>ignore automatic capitalisation and write in lower case</p></li></ul><p>See you next time, investigators!</p><div><hr></div><p>&#127937; New CTF Challenge Live - The Hacktivist (2 Parts)</p><p>A new CTF challenge has been posted on our CTF website. This week&#8217;s challenge focuses on identifying the hacker username of a threat actor, the date of their first post announcing the start of a cyberattack and the country in which the account is actually operated, using only open source intelligence techniques.</p><p><a href="https://ctf.osintnewsletter.com/login?next=%2Fchallenges%3F">Start competing in our Capture the Flag (CTF)</a></p><p>&#129667; If you missed the last CTF, here&#8217;s a <a href="https://ctf.osintnewsletter.com/challenges?#Trace%20The%20IP-21">link to catch up</a>.</p><p>Last week&#8217;s CTF challenge featured a challenge titled &#8220;Trace The IP&#8221;. Here is the solution:</p><p>Using <a href="https://www.iplocation.net/ip-lookup">IP Lookup | Find Your Public IP Address Location</a> and searching for 151.202.95.130 we could see that the IP was linked to several cities : Tuckahoe, Bronxville, New York, Eastchester, Yonkers. Formatting them in alphabetical order gave us : Bronxville, Eastchester, New York, Tuckahoe, Yonkers. </p><p>Looking at the ISP we could see that it was Verizon Business.</p><div><hr></div><p>&#9989; That&#8217;s it for the free version of The OSINT Newsletter. Consider upgrading to a paid subscription to support this publication and independent research.</p><p>By upgrading to paid, you&#8217;ll get access to the following:</p><p>&#128064; All paid posts in the archive. <a href="https://osintnewsletter.com/">Go back and see what you&#8217;ve missed</a>!</p><p>&#128640; If you don&#8217;t have a paid subscription already, don&#8217;t worry. There&#8217;s a 7-day free trial. If you like what you&#8217;re reading, upgrade your subscription. If you can&#8217;t, I totally understand. Be on the lookout for promotions throughout the year.</p><p>&#128680; The OSINT Newsletter offers a free premium subscription to all members of law enforcement. To upgrade your subscription, please reach out to LEA@osint.news from your official law enforcement email address. </p>]]></content:encoded></item><item><title><![CDATA[Episode 14: IP Address Investigations and Local OSINT]]></title><description><![CDATA[Listen now | Tools, tactics, and fresh investigations expanding the open-source intelligence toolkit.]]></description><link>https://osintnewsletter.com/p/episode-14-ip-address-investigations</link><guid isPermaLink="false">https://osintnewsletter.com/p/episode-14-ip-address-investigations</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Fri, 13 Mar 2026 14:03:03 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/190501977/dce9c42a740b9875f40d291af7a23165.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Every packet travels somewhere. Every connection leaves a trace. And every investigator eventually has to answer the same question: where did this activity actually come from?</p><p>This episode covers Issues 97 and 98 of The OSINT Newsletter and focuses on two critical aspects of modern OSINT: understanding how IP addresses reveal the movement of data across the internet, and how investigators can gather intelligence from a specific location even when they are nowhere near it.</p><p>In Episode 14 of The OSINT Podcast, host Jake Creps explores IP address OSINT from first principles, explaining how IPs function as the routing system of the internet. The episode walks through the difference between user IPs and server infrastructure, why dynamic IP addresses constantly change hands, and how static infrastructure can reveal patterns behind suspicious activity.</p><p>Jake then breaks down several investigative techniques used in IP analysis, including reverse IP lookups, passive DNS research, IP geolocation, and identifying traffic routed through VPNs and Tor nodes. When combined with timestamps and behavioural patterns, these signals allow investigators to reconstruct the path digital activity has taken across networks.</p><p>The episode then shifts to a different but equally important challenge: local OSINT investigations. Some investigations require extremely targeted intelligence from a specific city or region. In those cases, investigators must replicate the local internet environment in order to see the same results a local user would.</p><p>Jake explores how investigators can use VPNs and browser location manipulation to appear local, allowing search engines, advertisements, and recommendation systems to reveal location specific information. From there, he discusses how to build local intelligence feeds by aggregating small regional publications, government websites, and community sources into a single stream using RSS readers and alerting tools.</p><p>The episode also looks at analysing activity around physical locations using Google Maps &#8220;Popular Times&#8221; data, showing how investigators can detect patterns and unusual activity around businesses or venues without ever being physically present.</p><p>Along the way, Jake highlights several useful OSINT tools and resources including Dark Light Viewer, Twitter Viewer, and GeoSentinel, while also touching on developments in AI driven investigations and evolving OPSEC considerations.</p><p>As always, the emphasis remains on method over novelty. Infrastructure reveals behaviour. Location reveals context. And the best investigators know how to follow both.</p><p>Highlights include:</p><p><strong>&#128230; IP Address OSINT</strong> &#8211; Following the Packets &#8211; how IP addresses function as the routing system of the internet, why dynamic IPs complicate attribution, and how reverse IP lookups and passive DNS can reveal hidden infrastructure.</p><p><strong>&#127757; Local OSINT Investigations</strong> &#8211; techniques for collecting intelligence from a specific place remotely using VPNs, browser configuration, local news aggregation, and location specific data sources.</p><p><strong>&#128736; Tools in Focus</strong> &#8211; Dark Light Viewer for satellite light comparison, Twitter Viewer for footprint free browsing of X profiles, and GeoSentinel for tracking global movement across maritime and aviation data.</p><p>Throughout the episode, the focus stays on practical investigative thinking. Infrastructure creates patterns. Location creates context. And when both are understood together, digital activity becomes much easier to trace.</p><p>If you want to strengthen your understanding of IP address investigations and location based intelligence gathering, Episode 14 is for you.</p><p><strong>References</strong></p><p><a href="https://osintnewsletter.com/p/97">OSINT Newsletter &#8211; Issue 97</a></p><p><a href="https://osintnewsletter.com/p/98">OSINT Newsletter &#8211; Issue 98</a></p>]]></content:encoded></item><item><title><![CDATA[The OSINT Newsletter - Issue #98]]></title><description><![CDATA[Collecting Information from Local Sources in an OSINT Investigation]]></description><link>https://osintnewsletter.com/p/98</link><guid isPermaLink="false">https://osintnewsletter.com/p/98</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Thu, 12 Mar 2026 13:03:21 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/a6a19e21-818b-44cb-9cdb-30a570a22e33_1900x1000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; <strong>Welcome to the 98th issue of The OSINT Newsletter.</strong> This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. My goal with this newsletter is to help promote the OSINT industry, develop better investigators, and raise awareness of ethical use cases for open source intelligence.</p><div><hr></div><p>&#129667; If you missed the last newsletter, here&#8217;s a link to catch up.</p><p>&#9889; <strong>Return to Sender: OSINT With IP Addresses</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;62165ff4-18d1-4ff8-8056-b24b1c7fc202&quot;,&quot;caption&quot;:&quot;&#128075; Welcome to the 97th issue of The OSINT Newsletter. This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. Here&#8217;s an overview of what&#8217;s in this issue:&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The OSINT Newsletter - Issue #97&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:369150506,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!E93h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fa1de3e-2f30-4b94-b240-6df2a26b84bc_400x400.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-03-05T14:02:17.854Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d01d42f1-c1da-42ae-9bec-16eddef9fb5c_1900x1000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/97&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:189795808,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:18,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Let&#8217;s get started. &#11015;&#65039;</p><div><hr></div><h1>OSINT News</h1><p>&#128240;  <strong>Exploring a Secret Underground OSINT Marketplace</strong></p><p>This issue of The OSINT Insider is a treasure trove of useful information for OSINT practitioners covering topics from new OSINT tools and datasets.</p><p><a href="https://osintinsider.com/p/osint-insider-issue-8-exploring-a">Read on OSINT Insider&#8230;</a></p><p>&#127913; H/T: <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;The OSINT Insider&quot;,&quot;id&quot;:301308524,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/25c5eeb2-9c4c-49e8-b7a5-f8623b69600a_500x500.png&quot;,&quot;uuid&quot;:&quot;117a7169-f2dd-4932-ac4f-a8d76f682b2a&quot;}" data-component-name="MentionToDOM"></span> </p><p>&#128240; <strong>I Built an OSINT Agent Skill to Expose Your Digital Tattoo</strong></p><p>OPSEC isn&#8217;t just about what you post online, it&#8217;s about what happens to the content after you post. This issue of The Secure Circuit covers an OSINT tool that helps you cover your tracks and also find the tracks of others.</p><p><a href="https://littlehakr.substack.com/p/osint-agent-skill">Read on The Secure Circuit&#8230;</a></p><p>&#127913; H/T: <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;David Kyazze&quot;,&quot;id&quot;:335422791,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!g9VH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e2d9708-1726-4b5f-8ef9-29eca65a24b7_1286x1287.jpeg&quot;,&quot;uuid&quot;:&quot;78fc983e-8ba3-4837-8e22-0039a2f950d7&quot;}" data-component-name="MentionToDOM"></span> </p><p>&#128240; <strong>AI for OSINT Investigations: Turning Data Chaos into Intelligence</strong></p><p>It&#8217;s 2026, AI is here and you&#8217;re going to use it whether you want to or not. Generic AI tools like GPT and Gemini may not be great for OSINT; however, AI within OSINT tools is a different story.</p><p><a href="https://projectosint.substack.com/p/ai-for-osint-investigations-turning">Read on Project OSINT&#8230;</a></p><p>&#127913; H/T: <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Project OSINT&quot;,&quot;id&quot;:334944396,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/29d5fac8-300e-46fb-af06-154b1dab7a0f_1024x1024.png&quot;,&quot;uuid&quot;:&quot;71d2c3b6-25b2-42bb-91a2-acce442a65e8&quot;}" data-component-name="MentionToDOM"></span> </p><div><hr></div><h1>OSINT Tools</h1><p>&#128270; <strong>Dark Light Viewer</strong></p><p>Compare nighttime light levels across any location on Earth, across any period from one month to ten years.</p><p><a href="https://github.com/bendobrown/Dark-Light-Viewer">GitHub</a></p><p>&#127913; H/T: Benjamin Strick</p><p>&#128270; <strong>Twitter Viewer</strong></p><p>View a Twitter (X) profile without having to log in. See posts and media without leaving a footprint.</p><p><a href="https://twitterwebviewer.com/">Web App</a></p><p>&#128270; <strong>GeoSentinel</strong></p><p>Track global movement in real team; from maritime to aviation. Review in geospatial tooling.</p><p><a href="https://github.com/h9zdev/GeoSentinel/">GitHub</a></p><p>&#127913; H/T: H9</p><div><hr></div><h3>Description</h3><h2>Scenario</h2><p>A potential IP address associated with a French threat actor has been identified. Further investigation is required to determine the ISP name and the cities linked to this IP address in order to support attribution and ongoing analysis.</p><div><hr></div><h2>Challenge Objective</h2><p>Your task as an OSINT analyst is to find :</p><ul><li><p>The cities linked to this IP (in alphabetical order).</p></li><li><p>The ISP name.</p></li></ul><div><hr></div><p>&#127937; <strong>New CTF Challenge Live - Trace The IP</strong></p><p>A new CTF challenge has been posted on our CTF website. This week&#8217;s challenge focuses on identifying the ISP name and the cities associated with a specific IP address using only open source intelligence techniques.</p><p>Start competing in our Capture the Flag (CTF)</p><p>&#129667; If you missed the last CTF, here&#8217;s a <a href="https://ctf.osintnewsletter.com/challenges#The%20Wi-Fi%20Password-19">link</a> to catch up.</p><p>Last week&#8217;s CTF challenge featured a challenge titled &#8220;The Wi-Fi Password&#8221;. Participants needed to identify the the password of a suspicious Wi-Fi using only open source intelligence tools and techniques.</p><p>Solution:</p><ul><li><p>Searching for : epstein property Florida on google brings us to the wikipedia page where the address is displayed</p></li><li><p>Looking at the address we notice that it&#8217;s in Palm Beach</p></li><li><p>Using &#128270; p3Wifi <a href="https://3wifi.dev/map.html">Free WiFi map - p3wifi</a> and searching for the Palm Beach area we notice a weird Wi-Fi named SteinStein with the password visible in clear, located in front of a store named LaMuse which is exactly 0.7 miles and 3 minutes away from Epstein&#8217;s property when checking it on google maps with itinerary search.</p></li></ul><div><hr></div><p>&#9989; That&#8217;s it for the free version of The OSINT Newsletter. Consider upgrading to a paid subscription to support this publication and independent research.</p><p>By upgrading to paid, you&#8217;ll get access to the following:</p><p><strong>&#9889; Collecting Information from Local Sources in an OSINT Investigation</strong></p><ul><li><p>The internet reacts to where you are in the world. You can trick the internet into thinking you&#8217;re somewhere else. Once you do that, your entire browsing experience changes. I discuss this, local news aggregation, and mining &#8220;Popular times&#8221; from Google Maps in this issue of The OSINT Newsletter.</p></li></ul><p>&#128064; All paid posts in the archive. <a href="https://osintnewsletter.com/">Go back and see what you&#8217;ve missed</a>!</p><p>&#128640; If you don&#8217;t have a paid subscription already, don&#8217;t worry there&#8217;s a 7-day free trial. If you like what you&#8217;re reading, upgrade your subscription. If you can&#8217;t, I totally understand. Be on the lookout for promotions throughout the year.</p><p>&#128680; The OSINT Newsletter offers a free premium subscription to all members of law enforcement. To upgrade your subscription, please reach out to LEA@osint.news from your official law enforcement email address. </p>
      <p>
          <a href="https://osintnewsletter.com/p/98">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The OSINT Newsletter - Issue #97]]></title><description><![CDATA[Return to Sender: OSINT With IP Addresses]]></description><link>https://osintnewsletter.com/p/97</link><guid isPermaLink="false">https://osintnewsletter.com/p/97</guid><dc:creator><![CDATA[The OSINT Newsletter]]></dc:creator><pubDate>Thu, 05 Mar 2026 14:02:17 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/d01d42f1-c1da-42ae-9bec-16eddef9fb5c_1900x1000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; <strong>Welcome to the 97th issue of The OSINT Newsletter.</strong> This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. Here&#8217;s an overview of what&#8217;s in this issue:</p><ul><li><p>Introduction to IP addresses.</p></li><li><p>How to investigate an IP address.</p></li><li><p>A step-by-step process for IP investigation.</p></li></ul><div><hr></div><p>&#129667; If you missed the last newsletter, here&#8217;s a link to catch up.</p><p>&#9889; <strong>Organizing Information and Avoiding Duplication of Effort</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;c97dfc1c-0d72-442d-b18a-2077418f60d1&quot;,&quot;caption&quot;:&quot;&#128075; Welcome to the 96th issue of The OSINT Newsletter. This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. My goal with this newsletter is to help promote the OSINT industry, develop better investigators, and raise awareness of ethical use cases for open source intelligence.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The OSINT Newsletter - Issue #96&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-02-26T14:02:52.196Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/275f5ed9-5ebb-41c5-8f20-c7d656e1b54b_1900x1000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/96&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:182551062,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:18,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>&#127897;&#65039; <strong>If you prefer to listen, here&#8217;s a link to the podcast instead.</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;6dc6549a-2559-416d-8619-0c4e775d9e0f&quot;,&quot;caption&quot;:&quot;Every image was taken somewhere. Every investigation starts somewhere. And every wasted click costs you time.&quot;,&quot;cta&quot;:&quot;Listen now&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Episode 13 - Geolocation Mastery and Organizing \nYour Investigations&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:130747684,&quot;name&quot;:&quot;The OSINT Newsletter&quot;,&quot;bio&quot;:&quot;Fighting the machines to write S tier content. OSINT tools, tactics, and techniques.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f911711c-3bbd-421e-9d55-d9dcaffb23c5_240x240.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-02-28T16:01:10.228Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c718f65a-7fe7-4380-a7ee-f6cc779adf5f_1200x630.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://osintnewsletter.com/p/episode-13-geolocation-mastery-and&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:189003588,&quot;type&quot;:&quot;podcast&quot;,&quot;reaction_count&quot;:13,&quot;comment_count&quot;:1,&quot;publication_id&quot;:1442182,&quot;publication_name&quot;:&quot;The OSINT Newsletter&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yF4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5993aebc-3fc0-409c-bfc1-a8765534c7ab_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Let&#8217;s get started. &#11015;&#65039;</p><div><hr></div><p>The internet is like a big mail service. Every time somebody logs into their account, clicks on to a link or loads up a site, the data for that action gets parcelled up and shipped across the web. If domains are street names, IP addresses are the house numbers that actually direct the parcels to the right home. And like regular mail, the whole process leaves a trace behind.</p><p>Of course, stealing people&#8217;s mail is a felony <a href="https://www.youtube.com/watch?v=I64hCfX9Uyo">(and a great punk track)</a> - but that doesn&#8217;t mean you can&#8217;t get valuable OSINT from tracking its journey. If you know how to read IP addresses, they can tell you where traffic travelled, what infrastructure handled it, and whether someone tried to hide the sender.</p><p>In this issue, we&#8217;re following the packets. We&#8217;ll cover:</p><ul><li><p>The basics of IP addresses</p></li><li><p>How IPs can change (and why that matters)</p></li><li><p>Reverse IP lookups</p></li><li><p>Geolocation with IPs</p></li><li><p>..plus all about VPNs and Tor traffic.</p></li></ul><p>Now, let&#8217;s check the labels.</p><h2>What Is an IP Address?</h2><p>An <a href="https://www.fortinet.com/uk/resources/cyberglossary/what-is-ip-address">IP address (short for Internet Protocol address)</a>, is a numerical identifier assigned to each device or server connected to a network. Think of it like a shipment number. It can either look like:</p><ul><li><p><strong>IPv4: </strong>The old faithful. Appears as four blocks of numbers separated by dots, e.g. 192.168.1.1.</p></li><li><p><strong>IPv6: </strong>The longer, newer format, becoming increasingly common as the <a href="https://www.arin.net/resources/guide/ipv6/">internet runs out of IPv4 space.</a> Appears as eight blocks of numbers separated by colons, e.g. 2001:0db8:85a3:0000:0000:8a2e:0370:7334</p></li></ul><p>In OSINT terms, you can divide all kinds of IPs into two categories: <strong>User IPs</strong>, and <strong>Server IPs.</strong> A user IP belongs to a device connecting to a service. Meanwhile, a server IP belongs to infrastructure hosting websites, apps, or mail networks. Confusing the two is like mistaking a sender&#8217;s return address for a warehouse location.</p><p>IP addresses aren&#8217;t as stable an identifier as email addresses, for instance. But that&#8217;s OK; IP address OSINT is less about identifying individuals, and more about mapping the movement of data back to its source. Follow enough parcels, and you&#8217;ll find the depot.</p><h2>Package Redirected: Why IPs Change, and What They Tell You</h2><p>One of the biggest misconceptions in IP OSINT is assuming that IP addresses are permanent identifiers. Just because IPs are unique, doesn&#8217;t mean they can&#8217;t move from place to place. So why do IPs change, why does it matter&#8230; and once an IP changes, can you trace where it&#8217;s been?</p><h3>Dynamic IP Addresses</h3><p>Most average-Joe residential IP users are<a href="https://www.fortinet.com/uk/resources/cyberglossary/static-vs-dynamic-ip"> assigned dynamic IPs by their ISP</a> (Internet Service Provider). These can change for a ton of reasons: after a router gets rebooted, for example, when a lease gets refreshed, or just over time. The most important thing to remember is that dynamic IPs get passed around between users. An IP that belonged to one person last month might belong to somebody else now.</p><h3>Static IP Addresses</h3><p>Businesses and hosting providers, however, usually use static IPs. These are longer-term allocations, tied to servers and infrastructure semi-permanently (emphasis on <em>semi</em>). However, when you see the same static IP appearing repeatedly, you can be reasonably confident you&#8217;re looking at a fixed point.</p><h3>What IP Addresses Can Tell You</h3><p>When Google alerts you that some stranger in France is suddenly using your login on an iPhone 12, they&#8217;ve gained this intelligence by checking the new French login IP address against the <a href="https://support.google.com/mail/answer/45938?hl=en">last 10 IPs you logged in from.</a> Clearly, although an IP can&#8217;t tell you <em>who</em> did something online, it can tell you <em>where</em>, and with what device.</p><p>Overall, what IPs show you is the circumstances at the time an online activity took place. Was a login coming from a residential ISP? A data centre? A VPN provider? Or did multiple compromised accounts route through the same infrastructure - then suddenly switch to a totally different address? When paired with timestamps, old IPs help reconstruct movement patterns, and build up a theoretical narrative; like reading old postmarks to imagine a package&#8217;s journey.</p><h2>Delivery Instructions: How to Investigate an IP</h2><p>So, now you know why it&#8217;s worth investigating IPs, we can get to work on <em>how</em>. Some involve pro OSINT tools, but others are significantly more lo-fi. Let&#8217;s get into our favourite tips, tricks and techniques for investigating IP addresses.</p><h3>Reverse IP Lookups</h3><p>Reverse IP lookup - like reverse image search - flips the direction. Instead of asking &#8216;what IP does this domain use?&#8217;, you ask &#8216;what other domains are hosted on this IP?&#8217;. This is super useful when investigating scam networks and phishing campaigns.</p><p>To do it, plug the target IP into a<a href="https://dnschecker.org/reverse-dns.php"> passive DNS database</a>, or an OSINT platform that supports reverse lookup (like <a href="https://www.maltego.com">Maltego</a>). The results will bring up any domains associated with that address.</p><h3>Hosting and Registration</h3><p>Next, look for suspicious infrastructure. This could look like:</p><ul><li><p>Multiple domains sharing the same hosting</p></li><li><p>Sudden bursts of activity (registering lots of domains at once, then none at all)</p></li><li><p>Thematic similarities (crypto, &#8220;investment&#8221;, fake law firms etc.)</p></li></ul><p>For example, if a single server IP hosts ten nearly identical &#8220;investment opportunity&#8221; websites registered within weeks of each other - especially on the same cheap VPS - then that&#8217;s a strong sign of unsavoury activity. Look up hosting and registration details with <a href="https://who.is">WhoIs </a>searching.</p><p>That said, context still rules. Large hosting providers often place hundreds of legitimate websites on the same shared IP. In those cases, you&#8217;re looking at shared warehouse space, not necessarily shared ownership.</p><h3>Geolocation</h3><p>We covered <a href="https://www.iplocation.net">IP geolocation</a> a little in the last issue; it&#8217;s a way of identifying the country and often the city an IP is hosted in. It&#8217;s often inaccurate, and can&#8217;t pinpoint a specific address. So, think of it as narrowing delivery to the right city - not the exact doorstep.</p><p>However, it can still be useful - particularly for spotting inconsistencies. If a company claims to operate exclusively in one country but consistently routes traffic through infrastructure in another, for instance. Also look for repeated logins from the same location, and check if that matches with the IP geolocation result.</p><h3>VPNs (Virtual Private Networks)</h3><p>VPNs are a blessing and a curse for IP OSINT. When someone uses a VPN, the IP address you see belongs to the VPN provider&#8217;s infrastructure - not the user&#8217;s original connection. These VPN IPs often resolve to big data centres, too, making it tricky to tie down the user&#8217;s actual details.</p><p>There are ways to track if somebody&#8217;s using a VPN; rapid shifts between locations, for example. This is extremely useful if you need proof that a target is intentionally rerouting their traffic to avoid being detected.</p><h3>Tor Nodes</h3><p>Tor also adds another layer of complexity. The IP you see with <a href="https://www.csoonline.com/article/565798/what-is-the-tor-browser-how-it-works-and-how-it-can-help-you-protect-your-identity-online.html">a Tor browser </a>is the target&#8217;s exit node, not the actual origin. Tor exit nodes are also completely public and rotate between users globally; so if you detect one, all it tells you is that the target didn&#8217;t want to be tracked. It doesn&#8217;t imply malicious intent, but it does tell you the package was deliberately relabelled before delivery.</p><h2>Example: IP Address OSINT in Action</h2><p>This time, imagine somebody has been making repeated attempts to log into your Strava account. If successful, they could hopelessly distort your PBs. All you know is that the logins originate from the same IP address. Let&#8217;s find out who&#8217;s running things.</p><p><strong>Step 1: Identify the Owner</strong></p><p>A Whois search shows that the login IP is registered to a regional consumer IP; a specific subscriber, on residential broadband. But where, and who?</p><p><strong>Step 2: Analyse the Behavior</strong></p><p>The IP is fairly consistent - with no jumping locations or ties to known exit nodes. That means the user isn&#8217;t attempting to hide their identity. The login attempts are also spaced irregularly, with pauses that resemble manual interaction rather than botting. So this is a real person.</p><p><strong>Step 3: Geolocate</strong></p><p>Cross-referencing multiple IP geolocation services places the IP consistently in western Ohio, near a cluster of rural towns. You&#8217;ve never been to Ohio. And you definitely haven&#8217;t been logging into Strava from there. An interesting detail: the region is known for its expansive cornfields.</p><p><strong>Step 4: Reverse IP &amp; Domain Check</strong></p><p>A reverse IP lookup reveals two domains hosted to that same IP.</p><p>The first is a personal blog documenting endurance training experiments; one man pushing himself to run further and further in concentric circles without becoming dizzy.</p><p>The second, humanccohio.com, shows groups of runners arranged in geometric formations across harvested fields - what the author calls &#8220;human crop circles.&#8221; Metadata from the site aligns with the same western Ohio geolocation as the IP.</p><p><strong>Step 5: Behavioral Context</strong></p><p>The timestamps of the login attempts coincide with posts on the blog discussing &#8220;mapping local athlete data&#8221; and &#8220;identifying high-mileage runners nearby.&#8221;</p><p>Mystery solved: this is one guy in western Ohio, checking out Strava profiles in an attempt to recruit (or map) local athletes without their knowledge for his &#8216;human crop circle&#8217; project. Weird.</p><h2>Key Takeaways</h2><p>Message delivered - now you know how to do OSINT with IP addresses. You should know:</p><ul><li><p><strong>How delivery works: </strong>An IP is like a house number, it directs the data</p></li><li><p><strong>IPs change: </strong>Just because an IP is there now, doesn&#8217;t mean it&#8217;ll stick around</p></li><li><p><strong>Check the return address: </strong>reverse IP search is your most powerful tool</p></li><li><p><strong>Cross-reference everything:</strong> corroborate with behaviour to get the full story</p></li></ul><p>See you next week, investigators!</p><div><hr></div><p>&#127937; <strong>New CTF Challenge Live - The Wi-Fi Password</strong></p><p>A new CTF challenge has been posted on our CTF website. This week&#8217;s CTF challenge focuses on finding the password of a weird Wi-Fi using only open source intelligence techniques.</p><p><a href="https://ctf.osintnewsletter.com/challenges">Start competing in our Capture the Flag (CTF)</a></p><p>&#129667; If you missed the last CTF, <a href="https://ctf.osintnewsletter.com/challenges#The%20Unknown%20Bridge-17">here&#8217;s a link to catch up</a>.</p><p>Last week&#8217;s CTF challenge featured a GEOINT challenge titled &#8220;The Unknown Bridge&#8221;.</p><p>Looking at the UAV in the image, we could see its number which is 166509.<br>Using bing browser and searching for &#8220;166509 flight&#8221; we could find a flight of this UAV on : <a href="https://www.flightaware.com/live/flight/166509">flightaware.com/live/flight/166509</a><br>Looking at the tracking, we could see that it was last seen near Patuxent River MD, we could also notice the same airport as in the image which is Patuxent River (NHK)<br>On the left side of the airport we could see the same bridge as in the image which is named: <em>Thomas Johnson.</em><br>By searching on Google : Patuxent River Bridge, we could see that the full name of the bridge was : <em>Governor Thomas Johnson.</em></p><div><hr></div><p>&#9989; That&#8217;s it for the free version of The OSINT Newsletter. Consider upgrading to a paid subscription to support this publication and independent research.</p><p>By upgrading to paid, you&#8217;ll get access to the following:</p><p>&#128064; All paid posts in the archive. <a href="https://osintnewsletter.com/">Go back and see what you&#8217;ve missed</a>!</p><p>&#128640; If you don&#8217;t have a paid subscription already, don&#8217;t worry. There&#8217;s a 7-day free trial. If you like what you&#8217;re reading, upgrade your subscription. If you can&#8217;t, I totally understand. Be on the lookout for promotions throughout the year.</p><p>&#128680; The OSINT Newsletter offers a free premium subscription to all members of law enforcement. To upgrade your subscription, please reach out to LEA@osint.news from your official law enforcement email address. </p>]]></content:encoded></item></channel></rss>