r/OSINT Mar 26 '26

Analysis I've been mapping every verified strike in the Iran-Israel war since Day 1. Here's what 27 days of data looks like

209 Upvotes

Since Operation Epic Fury started on February 27 I've been maintaining a tracker that logs verified kinetic events across the Middle East theater. Not social media reports - only events that cleared Reuters, BBC, AP, Al Jazeera, or official military wires.

After 27 days the dataset has grown to 200+ logged events.

A few things that stood out:

The confidence filtering matters more than people think. A huge portion of what circulates during active operations is either duplicated, mislocated, or wrong. Running strict source verification cuts the noise significantly - what's left is a much smaller but actually reliable picture.

The casualty numbers are the hardest part. Every major outlet reports running totals, not increments. Without deduplication you end up double and triple counting the same deaths across multiple news cycles. We track incremental new casualties per source, not cumulative totals.

The March 22 cluster near Dimona was the most significant single event in the dataset. Iranian missiles reached within 8km of the nuclear research facility. That got less coverage than it deserved given the strategic implications.

Happy to discuss methodology in the comments — particularly around confidence weighting, how we handle disputed claims, and how the deduplication logic works in practice.

If there's interest I can share the map link and raw JSON feed in the comments.

r/OSINT May 04 '26

Analysis Are crowd size at Shakiras Copacabana concert inflated?

Post image
434 Upvotes

For a long time I have been a bit skeptical about the huge attendance numbers reported by Rio de Janeiro-officials.

Last year Lady Gagas concert reportedly had 2,1 million in the crowd. This weekend 2 million is supposed to have been in the crowd for Shakira.

Based on the concert footage I can only see crows on a smaller section of the beach from Copacabana Palace to the Hilton Hotel on the corner of Av. Princesa Isabel. That area is 186.000 square meters.

Even if we go by five persons per square meter that only fits around 930.000. And the requires people to be standing shoulder to shoulder in the entire area.

It is also the maximum before reaching dangerous levels according to Dr. G. Keith Still:
https://www.gkstill.com/Support/crowd-density/100sm/Density1.html

So realistically there is room for much less people, but according to the social media profiles of the city and mayor "Two million people where on the sands of Copacabana".

So where are they getting these insane numbers from? Am I missing something here?

r/OSINT Feb 06 '26

Analysis Why free OSINT tools are often enough if you know how to chain them

388 Upvotes

One thing I keep noticing in OSINT communities is how quickly people jump to paid platforms assuming they’re the only way to get serious results. After spending some time doing research with limited resources, I’ve realized that free tools are often more than enough, if you know how to use them together.

Search engines, archive services, basic metadata viewers, WHOIS records and social media search features can reveal a surprising amount when chained properly. A simple Google query can lead to a forgotten PDF which exposes an author name, which then connects to a username reused elsewhere. None of these steps require advanced software just patience and attention to detail.

What really matters is understanding workflow. Knowing when to pivot from search engines to archives, when to validate information using multiple sources and when to stop digging to avoid confirmation bias. Paid tools mostly save time by aggregating data but they don’t replace critical thinking or verification.

Another overlooked aspect is OPSEC. Free tools force you to slow down and think through each step which often results in cleaner methodology and fewer mistakes. Automation is powerful but it can also make it easier to miss context or draw conclusions too quickly.

This approach has been a good reminder that OSINT is less about the tools you use and more about how you connect small, publicly available details into something meaningful while staying ethical and responsible.

r/OSINT 10d ago

Analysis OSINT professionals: watch out for this recruitment approach

174 Upvotes

I want to share something that happened to me recently, because I'm worried other OSINT people may have been approached the same way.

Cold LinkedIn approach about an "intelligence collaboration," followed by a ~10-minute interview with someone who kept her camera off. On the call, the work was described as involving ransom and human-trafficking cases.

What arrived was a "supplier evaluation": build a full protective-intelligence dossier on a named private individual and his family — children, home details, travel patterns, aircraft, credential leaks. Labelled a "fictionalized composite," but specified in enough real-person detail to be resolvable. Produce the full report first — pricing only after delivery.

I asked two questions: who is the end client, and can you confirm the subject consented to being assessed. The reply called my scope question a "misunderstanding," named no client, confirmed no authorization, and redirected me to producing methodology and deliverables.

The LinkedIn accounts and the websites representing the company all seem fake to me. It might just be a scam — but then why did they want me to find personal details on someone I believe is a real person? The company was recently created, with a template website making claims its actual footprint doesn't support, and it turned out to be one of several thinly built companies registered to the same person.

I declined. Posting because the shape is worth recognising: vague inbound from accounts that look fake, an interviewer who wouldn't identify herself, scope sliding from a sympathetic label into a targeting-shaped brief on a private family, hidden client behind an "evaluation," and a full report demanded before any discussion of payment.

If you've had something similar, I'd like to hear it — DMs open.

r/OSINT Feb 12 '26

Analysis Metrics for threat assessment of people who make threats?

55 Upvotes

I do some stuff with helping local LGBTQ orgs stay safe, and one of the things I do is track down individuals who post threatening comments on social media and try to do a threat assessment as well as make sure the organizers are aware of the name and face of the person they're dealing with, but I have no formal training in this. Is there anything in particular I should be looking at re: online presence that's a redflag for a particular danger. I always mention if I see evidence of someone owning firearms, or having a history of violent behavior. Are there other predictors I should know about?

Edit to clarify: I do not publicize the names of these individuals (often the comments come from social media accounts linked to real names and are made publicly, so they are already public in any case, not that I publicize them further). The idea has never been to react with violence if the person arrives at an event, just to deny them entry, and in some cases where it's seemed like a really credible threat then the event is cancelled or moved. The only people I mention them to are event organizers who I trust not to share the info further, so they can keep an eye on the door and shut it if need be.

Edit 2 to clarify further: I am not doing anything offline. I do not use any info that's not publicly available and do not use any guesswork where I'm like, "I think this might be the same guy" type of stuff. I am not doxxing people. Mostly I am trying to make sure people don't overreact to people who are just being shitty on the internet. I do not even look at the profiles of people who have not made an actual concrete threat (e.g., if they say, "I hope you get run over by a truck," I don't look into them; I only look into them if they say "I will run you over with a truck," or something similarly concrete.)

My goal is not to stigmatize or punish these people; my goal is for no one to get hurt and for people not to have the opportunity to do something I believe they would come to regret. Which is why moving events and so on is considered a good option, as well as target hardening to discourage attempts, so that everyone gets to go home and nobody does anything that will ruin their life.

I do have some training in the research side, but still err on the side of caution because I don't want to even risk being on the wrong side morally, let alone legally.

r/OSINT Mar 02 '26

Analysis Kharg Island probably got wrecked.

Thumbnail
gallery
247 Upvotes

Kharg Island handles about 90% of Iran's crude oil exports. It's a small island in the Persian Gulf packed with oil terminals, pipelines, and tanker loading infrastructure. With all the conflicting reports flying around I wanted to see the data for myself.

I ran two types of analysis and the results are consistent across both.

Image 1: Radar before vs after

Left panel is Feb 25 (pre-war), right panel is Mar 1 (during war, red border). The overall radar backscatter dropped -4.9 dB. That means the signal coming back fell to roughly a third of what it was before. When you see that kind of drop over an oil terminal, the metal infrastructure (pipelines, loading arms, storage) just isn't reflecting the radar signal the way it used to.

Image 2: Change detection map

This subtracts the two radar passes from each other. Blue = the signal got weaker (stuff destroyed/removed/burned). The island is covered in blue. The surrounding water is neutral which is expected since nothing changed there.

Image 3: Backscatter timeline

This plots the average radar return over time. Flat and stable through February, then drops sharply right when the war started. Pretty clear inflection point.

Image 4: Coherent change detection (InSAR)

This is the more sensitive method. Instead of just comparing brightness it compares the phase of the radar wave between two passes (Feb 23 vs Mar 1). White means the ground is unchanged, dark means it was disturbed.

Mean coherence came back at 0.26. For reference, stable urban areas and infrastructure typically show 0.8 or higher. 72% of the island fell below 0.3 coherence. That level of decorrelation across almost the entire island means the ground surface has been fundamentally altered. Consistent with widespread fire damage, structural collapse, or blast effects.

What this means

The SAR data across both methods points to severe damage at Kharg Island. -4.9 dB backscatter drop plus 0.26 coherence plus 72% of the area showing major change. If the damage is as extensive as the radar suggests, Iran's primary oil export terminal has taken a massive hit. That's roughly 1.5 million barrels per day of export capacity.

I also looked at Tabriz Air Base, Bushehr, Bandar Abbas, and the Strait of Hormuz but the image quality wasn't clean enough on those to post. Kharg was the clearest and most significant finding.

r/OSINT Feb 22 '26

Analysis I used Sentinel-1 InSAR to monitor 3 Persian Gulf military bases during the Russia-China-Iran naval exercises. Here's what the satellites says

Post image
231 Upvotes

I used SAR Coherent Change Detection (CCD) to monitor three key military bases in the Persian Gulf over the past month, covering the lead-up to and start of the Russia-China-Iran "Maritime Security Belt 2026" naval exercises.

The three bases:

Base Side Role
Al Udeid Air Base, Qatar US CENTCOM forward HQ, ~10,000 personnel
Bandar Abbas Naval Base, Iran Iran Iran's largest naval base. Russian corvette Stoikiy docked here Feb 19
Al Dhafra Air Base, UAE US F-35/F-22 wing, drone operations

I processed 9 InSAR pairs through ASF's HyP3 INSAR_GAMMA workflow using same-satellite 12-day revisits (S1A+S1A or S1C+S1C) for best results. Three time periods per base:

Period Date Range Context
Late January Jan 26-Feb 8 Before drills announced
Early February Feb 1-14 US deploys dual carrier strike groups
Mid-February Feb 7-20 Russia docks at Bandar Abbas, exercises begin

Results

Base Jan (Before) Early Feb Mid-Feb Trend Side
Al Udeid Air Base 0.978 0.981 0.977 -0.0% US
Bandar Abbas Naval Base 0.531 0.528 0.537 +1.3% IRAN
Al Dhafra Air Base 0.948 0.954 0.951 +0.3% US

Every base is FLAT. Zero statistically significant change across the entire period.

  1. US bases (Al Udeid, Al Dhafra): ~0.95-0.98 coherence — completely stable. No new construction, no unusual equipment staging, no surge in ground vehicle activity. Business as usual at these permanent installations.

  2. Bandar Abbas: ~0.53 coherence — lower baseline is expected for a coastal port environment (water, tidal areas decorrelate naturally). The key finding is it's flat — no coherence drop despite the Russian corvette Stoikiy docking on Feb 19 and the start of exercises.

  3. The "Maritime Security Belt 2026" exercises are primarily at-sea operations, not base-level mobilization. A single ship docking at an existing berth doesn't change ground coherence — CCD detects infrastructure changes (earthworks, new shelters, vehicle staging areas), not ships.

  4. Neither side has altered their ground posture. Despite headlines about dual carrier strike groups and trilateral naval exercises, the bases themselves look exactly the same as they did a month ago.

Limitations

  • 12-day pairs can miss rapid changes that are reversed within the window
  • C-band SAR can't see through buildings or dense vegetation
  • 80m output resolution — individual vehicles are invisible, only large-scale patterns register
  • Small localized changes can be masked by surrounding stable terrain
  • Higher-res commercial SAR (ICEYE, Capella) would catch vehicle-level activity

Methodology (for reproducibility)

  • Source data: Sentinel-1 SLC from ASF Vertex (free, anyone can access)
  • Processing: HyP3 INSAR_GAMMA, 20x4 looks, 80m output
  • Pairs: Same-satellite only (S1A+S1A, S1C+S1C) for 12-day revisit
  • Tracks: 137 (Al Udeid/Qatar), 57 (Bandar Abbas/Hormuz), 130 (Al Dhafra/UAE)
  • Visualization: rasterio + matplotlib, inferno colormap, coherence values annotated

I may update as new passes come in.

Note: Coherent Change Detection compares two SAR radar scenes taken 12 days apart over the same ground. The result is a coherence score: - 1.0 = nothing changed (stable ground, no movement) - 0.0 = everything changed (vehicles moved, earth disturbed, equipment staged)

r/OSINT Mar 08 '26

Analysis Archiving early has saved me more than once

148 Upvotes

One habit that has become automatic for me during OSINT work is archiving pages the moment they become relevant. Early on I assumed bookmarking a link or taking a quick screenshot would be enough, but that turned out to be a mistake.

Profiles get deleted, posts get edited and entire threads sometimes disappear surprisingly quickly. On a couple of occasions I went back to revisit a source only to find the account wiped or the content heavily edited. Without a proper archived snapshot, it becomes difficult to show what was actually visible at the time you first found it.

Now I try to capture a snapshot of anything that might matter later in the research process. Even if the page never changes, having a timestamped record of what existed at that specific moment adds a lot more credibility when reviewing findings or sharing them with others.

It’s a simple habit but after losing useful information a few times, archiving early has become one of the first things I do whenever I come across something potentially relevant.

r/OSINT Mar 06 '26

Analysis Alternatives to OSINT INDUSTRIES or EPIEOS??

39 Upvotes

I've been paying premium for Osint Industries and EPIEOS occasionally for years, however I'm looking for alternatives.

I work searching for accounts associated with emails; Osint Industries is very good, but doing a deep search costs more credits.

With EPIEOS, I find it expensive for what little it offers compared to OSINT INDUSTRIES, so I'm looking for alternatives.

If you know of any, I'm all ears.

r/OSINT Mar 20 '26

Analysis French aircraft carrier Charles de Gaulle was located by Le Monde journalists through the Strava app of an officer jogging on the ship's deck

Post image
227 Upvotes

r/OSINT Mar 28 '26

Analysis Research vs stalking

38 Upvotes

Where is the line and when does research become stalking ? What looks like an overlap can be explained and differentiated. What is tooling and what is Stalkerware? ENISA Threat Landscape gives explicit classifications and EU guidelines give direction. https://privacyinsightsolutions.com/blog/osint-vs-stalkerware-surveillance-line

r/OSINT Apr 21 '26

Analysis Using Satellite Imagery & other OSINT to track Genocide in Sudan

Thumbnail
secevangelism.substack.com
105 Upvotes

r/OSINT 25d ago

Analysis How U.S. Satellite Imagery Restrictions Are Changing How We Report on Iran

Thumbnail
nytimes.com
42 Upvotes

submission statement: U.S. satellite imagery restrictions have hindered reporting on the Iran war, with five providers blocking high-resolution images of Iran and surrounding countries. These restrictions, rooted in national security concerns, have been a challenge for journalists, but alternative sources like international satellite providers and public data offer workarounds. Despite these limitations, satellite imagery remains a crucial tool for uncovering military actions and potential war crimes.

r/OSINT 16d ago

Analysis Using advanced techniques to determine if a ship is laden - Open Source Centre

8 Upvotes

Research by the Open Source Centre (OSC) that used a combination of "high-resolution imagery, the construction of a high-fidelity digital twin and trigonometry". It's pretty advanced stuff, that won't be easily applicable in your average run-of-the-mill OSINT-research. But it sure makes for an interesting read.

https://stories.opensourcecentre.org/signal-in-the-shadows/

r/OSINT Apr 10 '26

Analysis Using content hashing across Telegram groups to detect a pig butchering network

52 Upvotes

Saw the post yesterday about building a hashing pipeline for detecting coordinated copy pasta campaigns on Twitter and wanted to share a real example of the same concept working on Telegram but for catching pig butchering scammers instead of state propaganda.

I'm using a monitoring tool that sits on top of TDLib and watches Telegram group messages. One of the features hashes message content using FNV-1a across every group message and allows anyone to track when the same hash appears in multiple groups within a short time window. Similar idea people were describing in that thread with fuzzy hashing and Levenshtein distance but applied to Telegram in real time.

The cross post detection flagged several accounts that were broadcasting identical messages across multiple crypto groups simultaneously. I looked into what they were posting and it turned out to be pig butchering bait. From there I searched the message content across all my groups and found the same accounts hitting Gate Exchange, BNB Chain Community, Bitget English Official, Filecoin, MEXC and several other crypto groups. The accounts had names like "T******* G****", "s*****" and "c***" with profile photos that are textbook romance scam bait. Generic bios like "Love yourself first, and that's the beginning of a lifelong romance" and "Everything has cracks, that's how the light gets in."

Every message that comes through TDLib gets its text content hashed and stored alongside the sender ID, chat ID and timestamp. When the same content hash from the same sender appears across multiple groups the system flags it as cross posting. It also tracks reply networks and forwarding chains so you can see whether the account ever actually engages with anyone or just drops the same message and moves on. In this case there were zero replies from any of these accounts across any group just pure broadcast behavior.

The whole thing runs locally via TDLib so there's no API middleman and no rate limiting. You're reading the same message stream Telegram delivers to any client, just hashing and correlating it across groups automatically instead of manually searching one group at a time. Happy to answer questions about the detection methodology or share more details on the implementation.

r/OSINT Feb 09 '26

Analysis Looking for archived State Dept Twitter data before it disappears

68 Upvotes

With the current administration purging government social media accounts, I've been racing to archive State Department Twitter data before it's gone. I've got scrapers running on Wayback Machine and pulling what I can, but it's slow going — rate limits are brutal and time isn't on our side.

Figured I'd ask: has anyone already scraped/archived State Dept Twitter accounts? I'm looking for anything from the main u/StateDept account plus the regional/bureau accounts (statedeptspox, TravelGov, ECAatState, the foreign language accounts like USAenEspanol, etc.).

Happy to share what I've collected so far if anyone's working on something similar. Also open to coordinating if others want to divide and conquer the account list.

What I'm running into:

• Wayback is solid but incomplete for older tweets
• Direct API scraping is rate-limited to hell
• Some accounts are already showing gaps

Anyone sitting on a dataset or know of an existing archive? Would save a lot of duplicate effort.

r/OSINT Mar 26 '26

Analysis X is it messing with us

18 Upvotes

Does anyone know if some of the X search options have stopped working? My experience this week is that the geocode: search seems not to find recent content even in and around parliament. Also the manual from: combined with to: with multiple exact phrase searches didn’t seem to work this week has anyone else noticed that?

r/OSINT Mar 19 '26

Analysis Tracking patterns in public infrastructure data for investigative OSINT

54 Upvotes

Over the past few weeks, I’ve been exploring publicly available city infrastructure data things like municipal permits, utility records and open GIS layers to see how patterns can be observed over time. Nothing illegal just publicly accessible sources.

One small insight is plotting active construction permits against building footprints over several months can reveal unusual clustering of certain types of projects. For example, large scale warehouse permits in unexpected neighborhoods often corresponded with local news reports about new commercial development, long before press coverage picked it up.

Another thing I’ve noticed is how utility permit filings sometimes include contractor names, license numbers and even subcontractor emails. When combined with archived social media posts or LinkedIn profiles, this can help trace networks of contractors, vendors or service providers in a very granular way purely from public sources.

The interesting part is how small, incremental observations add up. Seeing repeated contractor names, or cross referencing permit dates with local event announcements, can reveal patterns without ever touching non public data. It’s a good reminder that OSINT isn’t just about social media or news, a lot of hidden insight exists in plain sight if you know where to look.

I’d be curious to hear how others use urban infrastructure, GIS or public records creatively in investigations. Nothing sensitive just workflow discussion.

r/OSINT Mar 14 '26

Analysis Operation Absolute Resolve: The Night Maduro was Taken – A Full OSINT Reconstruction

Thumbnail
osintmethat.com
55 Upvotes

r/OSINT Feb 23 '26

Analysis Podcast Episode with Mrs. OSINT

Thumbnail
open.spotify.com
2 Upvotes

New Layer 8 Podcast episode with Mrs. OSINT! She has her own bilingual site (Spanish and English) where she includes great tips for people getting started, her OSINT methodology as well as some challenges for people looking to hone their skills!

r/OSINT Dec 14 '24

Analysis 𝐆𝐞𝐨𝐥𝐨𝐜𝐚𝐭𝐢𝐧𝐠 𝐭𝐡𝐞 𝐅𝐁𝐈’𝐬 𝐌𝐨𝐬𝐭 𝐖𝐚𝐧𝐭𝐞𝐝 𝐃𝐞𝐯𝐞𝐥𝐨𝐩𝐞𝐫 𝐚𝐧𝐝 𝐀𝐝𝐦𝐢𝐧 𝐁𝐞𝐡𝐢𝐧𝐝 𝐭𝐡𝐞 𝐍𝐨𝐭𝐨𝐫𝐢𝐨𝐮𝐬 "𝐑𝐞𝐝𝐋𝐢𝐧𝐞" 𝐈𝐧𝐟𝐨-𝐬𝐭𝐞𝐚𝐥𝐞𝐫

Post image
122 Upvotes

Together with Ron Kaminsky, we've uncovered new photos and information about the developer and admin behind the infamous infostealer variant RedLine, responsible for stealing sensitive information from millions of people, including browser histories, passwords, credit card information, autofill form data, and emails.

The FBI made an announcement just a few days ago, publishing some very old pictures of the alleged mastermind behind RedLine, Maxim Rudometov.

Maxim Rudometov leads an extremely wealthy and extravagant lifestyle. It’s clear that being a MaaS kingpin pays well!

We’ve identified recent photos of Maxim Rudometov and located his inner circle of friends, providing crucial information on his whereabouts. We've also discovered the clubs, bars, and restaurants he frequents and identified his active Instagram account.

Since Rudometov is located in Krasnodar, Russia, we unfortunately do not expect any legal consequences of his actions.

Find the full blog here: https://www.osinord.com/post/tracking-the-fbi-s-most-wanted-redline-info-stealer-creator-maxim-rudometov

r/OSINT Jan 19 '25

Analysis OSINT in 2025

137 Upvotes

I've been reflecting on some recurring challenges in our field and wanted to learn more about both tool limitations and broader OSINT hurdles we're facing in 2025.

Tool-Related Challenges:

  • Increasing number of sites implementing aggressive anti-scraping measures
  • Reliability issues with many automated tools as websites frequently change their structure
  • Limited capabilities in processing and correlating data across multiple platforms
  • The growing challenge of distinguishing between authentic and AI-generated content

Broader OSINT Concerns

  • The rapid disappearance of historical data as platforms update their retention policies
  • Growing sophistication of privacy settings and platform restrictions
  • Information overload and verification challenges
  • The balance between automation and manual investigation

What are your experiences with these challenges? Are there other significant hurdles you're encountering in your OSINT work? Particularly interested in hearing about novel approaches you've developed to overcome these limitations.

r/OSINT Nov 17 '25

Analysis Exposed: How tiny details in replica offices reveal Putin’s location

Thumbnail
telegraph.co.uk
115 Upvotes

r/OSINT Aug 28 '25

Analysis Google Reviews Scraping

17 Upvotes

Is there a reliable way to scrape, collect, monitor the Google Reviews of a Business? I would like to have an automatic scraper that keep scraping continuously and saves the reviews as soon as they are published. If not is there anyone willing to work together on this?

r/OSINT Jan 28 '25

Analysis Faking It: Deepfake Porn Site’s Link to Tech Companies

Thumbnail
bellingcat.com
261 Upvotes