The OSINT Newsletter - Issue #51
The latest and greatest in OSINT news, tools, tactics, and techniques
👋 Welcome to the 51st issue of The OSINT Newsletter. This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. My goal with this newsletter is to help promote the OSINT industry, develop better investigators, and raise awareness of ethical use cases for open source intelligence.
🚨 For the last year, I’ve received countless emails and direct messages asking me questions about the OSINT tradecraft. This has inspired me to launch a weekly Ask Me Anything (AMA) thread. Starting this Thursday, paid subscribers will be able to ask questions, get answers, and collaborate with other paid subscribers. Every week, right here on Substack.
To help launch this, here’s a discount on a paid subscription.
🪃 If you missed the last newsletter, here’s a link to catch up.
⚡ How to use Zehef for OSINT Investigations
⚡ The OSINT Newsletter - Issue #50
Let’s get started. ⬇️
OSINT News
📰 Tools and tips round up: Email investigations, digging into payment gateways, and more
Craig Silverman did an excellent roundup of tools, tactics, techniques, and news in digital investigations over the last 30+ days. I’m grateful he included The OSINT Newsletter in some of these references.
🎩 H/T:
📰 CIA's Burns Spurs Spy Agencies to Embrace Book Learning, Data Extraction
There’s an ongoing shift in the intelligence community to taking open source intelligence seriously. Led by CIA chief William Burns, the CIA has issued a 2-year plan for ramping up OSINT in the agency. SpyTalk discusses this at length.
🎩 H/T:
📰 How to Get Started: Investigating Payment Gateways Online
If you’re doing financial investigations, one common trail to follow is to understand how an organization processes payments. This can lead to several insights depending on the information available. From cryptocurrencies to Stripe integrations, Bellingcat discusses this in depth.
🎩 H/T: Kolina Koltai
OSINT Tools
🌟 Sponsor: Authentic8
Free access for journalists, academics, and non-profits
Authentic8 is offering high-risk communities free access to its digital investigations platform, Silo for Research. The Silo Shield program, in collaboration with CISA, will elevate awareness of cyber threats experienced by journalists, academics, humanitarian aid groups, and non-profits — and provide helpful resources.
Learn more and apply here.
🔎 Geoguessr GPT
If you’ve used tools like GeoSpy, you understand how powerful AI can be in determining the approximate location of an image. I discovered a publicly-available GPT that’s been specifically tuned for Geoguessr, a geolocation game. This can be used for realistic geolocation cases as well.
🎩 H/T: Fireintel
🔎 Not Evil MTX
Dark web search engines are hard to come by. Tools like Ahmia give almost always zero relevant results. If you’re looking for a dark web search engine that actually returns results, give Not Evil MTX a try.
⚠️ The Tor Link below is a .onion URL. Make sure you have a Tor browser configured correctly before clicking on it.
notevilmtxf25uw7tskqxj6njlpebyrmlrerfv5hc4tuq7c7hilbyiqd[.]onion
🎩 H/T: Dark Web Informer
🔎 Excavator
Similar to Not Evil MTX, Excavator is another dark web search engine hosted on an onion URL. If you’re looking for dark web search results or are investigating known actors on the dark web, give this search engine a try.
⚠️ The Tor Link below is a .onion URL. Make sure you have a Tor browser configured correctly before clicking on it.
2fd6cemt4gmccflhm6imvdfvli3nf7zn6rfrwpsy7uhxrgbypvwf5fad[.]onion
🎩 H/T: Dark Web Informer
🥸 Bad OPSEC
On the note of Tor and onion URLs, make sure to keep good OPSEC. If you’re not sure what good OPSEC is, here’s a list of examples of bad OPSEC.
🎩 H/T: jermanuts
✅ That’s it for the free version of The OSINT Newsletter. Consider upgrading to a paid subscription to support this publication and independent research.
By upgrading to paid, you’ll get access to the following:
No email header ads
OSINT tool tutorials
Ask Me Anything OSINT thread
👀 All paid posts in the archive. Go back and see what you’ve missed!
🚀 If you don’t have a paid subscription already, don’t worry there’s a 7-day free trial. If you like what you’re reading, upgrade your subscription. If you can’t, I totally understand. Be on the lookout for promotions throughout the year.
How do I unsubscribe to this newsletter?
Regarding OPSEC examples, here is an IG account that I follow that post real world OPSEC failures (https://www.instagram.com/opsec_fail/)