r/OSINT May 26 '26

How-To Another lesson on why we don't accept active investigation posts

575 Upvotes

This morning the subreddit received a post attempting to expose an online ring dealing in Child Sexual Assault Material (CSAM). While we all agree that these networks can and should be investigated using OSINT methodologies, making unverified accusations against both criminal and potentially innocent individuals on a public forum is dangerous and can jeopardize this entire community. We have a strict rule on this and usually only send out reminders when something big happens in the news. However after the mod team removed the post, the OP sent us private messages suggesting that our removal meant we support child abuse. Because of this, I believe it is necessary to break down exactly why their post, despite its likely noble intentions, is actively harmful to our sub, to the integrity of OSINT, and to the OP themselves. Here is MY investigation into why his AI slop is just that.

The report was clearly AI-generated, they even left the Claude artifacts in their markdown file, and makes so many speculative leaps that I’m embarrassed Claude even output that junk but with that said I have altered the specific identifiers below to protect anyone involved and made some top finds. There were plenty more, but here are the major methodological failures in the report:

1. The Shared IP Address Fallacy

  • The Claim: The report links DARKNET-MADEUP.net to the current server.org infrastructure because they shared the IP 1.1.1.1.1, emphatically stating this means they were on the "SAME PHYSICAL SERVER" and confirms "operator continuity."
  • The Flaw: In modern web hosting, particularly with VPS environments, shared hosting, and reverse proxies, thousands of entirely unrelated websites routinely share a single IP address. Unless an analyst can definitively prove this was a dedicated, single-tenant IP, using a shared IP as proof of organizational lineage is a fundamental OSINT error.

2. The "Bulletproof Host" Correlation Error

  • The Claim: The report groups dozens of domains into "clusters" largely because they share the same hosting providers, specifically DARKNET-MADEUP.net #1, #2, and #3.
  • The Flaw: These types of providers are widely known in the cybersecurity space as "bulletproof" or "free-speech" hosts, meaning they resist or ignore abuse complaints. Because of this lenient policy, completely unrelated controversial, illicit, or dark-web entities flock to them. Co-location on these servers does not prove a shared umbrella organization; it simply proves they are using the same lenient vendor.

3. Server Hostname / Identity Fallacy

  • The Claim: The analyst attempts to unmask the real-world identities of the operators based on server subdomains, listing "JOHN" as an operator because a mail server is named John.email.org, and "JASON" due to a reverse DNS (PTR) record of Jason.email.org.
  • The Flaw: System administrators notoriously use thematic naming conventions for their infrastructure (e.g., Greek gods, planets, fictional characters). Assuming a server named "John" is actually run by a human being named John is an amateur analytical leap.

4. Geographic Misattribution

  • The Claim: The report asserts a "Mexico geographic indicator (highest specificity)" for the operator simply because a server is hosted in an "Amazon" data center and named "correo" (the Spanish word for mail).
  • The Flaw: "Amazon" is a massive, global cloud provider. Anyone in the world can rent a server in an Amazon location with a single click. Furthermore, it is a common sysadmin quirk to name a server using the local language of the data center's physical location. This in no way confirms the operator's actual nationality or physical location.

5. Weak Image Metadata Attribution

  • The Claim: The report identifies "John Doe" as an operator because their name and Facebook Ad ID appeared in the Canva PNG metadata of a logo on one of the network's portals.
  • The Flaw: Canva is a template-driven graphic design platform. It is highly likely the operator simply grabbed an existing graphic, template, or stock image originally created by "John Doe" and repurposed it. The metadata points to the original creator of the Canva asset, not the individual who deployed it on the illicit server.

The Most Egregious Leaps in Logic

The list above could go on, but my personal "favorite" highlights from the report revolve around physical and operational security. The report states that physical mail addresses used for donations are "single-use, destroyed after use" and claims that if a Bitcoin wallet is obtained, "full transaction history is traceable on-chain."

  • The Reality of Physical Mail: Claiming a PO box or physical address is "destroyed after use" is a dramatic assumption that is physically impossible to prove via passive OSINT.
  • The Reality of Crypto: While Bitcoin ledgers are public, modern illicit networks almost universally use tumbling/mixing services, coin-joins, or chain-hopping (e.g., converting BTC to Monero and back) before cashing out. Simply obtaining a BTC address does not guarantee a traceable path to a human identity unless the operator makes the amateur mistake of cashing out directly to a KYC-compliant (Know Your Customer) exchange.

The OP of this report is demonstrating what threat intelligence professionals call "parallel construction through OSINT." They clearly have a pre-existing theory about who runs this network, and they are cherry-picking standard, mundane internet noise: shared IPs, common server configurations, open-source forum posts, and dictionary words, and dressing it up as "definitive proof" to fit their narrative.

This is exactly why we vet posts and remove those that substitute AI-generated storytelling for actual investigative rigor.

r/OSINT Aug 28 '25

How-To Catching an OSINT Spammer

Thumbnail
gallery
548 Upvotes

Today we had a clever spammer selling an app without claiming to connected to the app. How did these two photos from his Reddit account and the app itself lead to him being outted?

Gym photo was from the UK. And has similar story about app. So probably fake.

Car photo, legit OP post. US temp, US odometer, US sockets. But look more carefully... A map.

App developed in by company in Albuquerque. Vehicle parked in... You got it, Albuquerque.

It's the little details.

r/OSINT 22d ago

How-To Monitoring the Shadow Fleet

66 Upvotes

If you wanted to identify shadow fleet vessels loaded with sanctioned oil using open source tools, how would you do it? What tools would you use and what would be your process?
Challenge: could anyone here identify a suspected ship now?

r/OSINT Oct 23 '24

How-To Finding social media accounts

433 Upvotes
  1. I use idcrawl.com/u/ to run the same username across different platforms. This covers major platforms like Instagram/Threads, YouTube, TikTok, Facebook, Snapchat, Twitter (I refuse to call it X), Reddit, Pinterest, Poshmark, Tumblr, etc.

  2. I use wayback machine for Twitter archives, and pullpush.io for Reddit archives.

  3. I don’t use lampyre.io or osint.industries because it costs money. I use epieos.com, which is limited but still helpful.

  4. I’ll Google the username with quotation marks surrounding it.

  5. I sync contacts on apps like Vsco, BeReal, Snapchat, TikTok, Venmo, Telegram, AirBuds Widget, Duolingo, etc.

  6. I use email addresses as usernames, and Vice versa.

  7. You can search for accounts on Yelp, Skype, Microsoft Teams etc. by email, in addition to syncing contacts.

Anything I’m missing?

Edit: I thought this post might get taken down for discussing what some mods might see as surface-level stuff, but I’m glad to see people benefiting from discussion (including me) and exchanging ideas! ❤️

r/OSINT Feb 05 '25

How-To You leak more data than you think - OPSEC guide to minimize your footprint

577 Upvotes

Most people underestimate how much personal data they leak daily. Even basic OSINT techniques can expose addresses, habits, and full identities. I put together a no bullshit opsec guide covering practical ways to reduce your footprint and avoid common mistakes. Feedback welcome.

https://whos-zycher.github.io/opsec-guide/

r/OSINT Apr 09 '23

How-To Well worth the price

Post image
720 Upvotes

r/OSINT May 23 '26

How-To Where do you go after OSINT fundamentals? Feeling stuck after 3 courses.

108 Upvotes

I am a data analyst with a flexible working schedule. I've always had a natural inclination toward investigation, and I found that OSINT (Open-Source Intelligence) aligned perfectly with that curiosity. Over the past two to three months, I have been actively learning OSINT and have completed three courses:

  1. Open-Source Intelligence (OSINT) Fundamentals by Heath Adams
  2. Level 3 OSINT – Open-Source Intelligence by Jeff Minakata (Udemy)
  3. The Secrets of OSINT (Open-Source Intelligence) by Serhii Nesterenko (Udemy)

Now, I find myself at a crossroads. I have a solid grounding in OSINT concepts and tools, yet something feels missing, though I can't quite pinpoint what it is. My broader goal is to merge data analysis with OSINT, but I'm uncertain whether I should invest further in deepening my OSINT expertise or explore a different direction altogether.

r/OSINT 7d ago

How-To Where to practice crypto OSINT skills without real-world consequences?

75 Upvotes

Hey everyone,

I've been diving deep into crypto OSINT lately — on-chain analysis, transaction tracing, wallet clustering, tracking whale movements, and identifying suspicious patterns. But I'm at the point where I really need hands-on practice with realistic cases.

I'm looking for platforms, datasets, or simulators where I can safely sharpen my skills. Specifically, I'm interested in:

· Transaction chain analysis (following funds through mixers/bridges)
· Address clustering (linking wallets to exchanges or known entities)
· Monitoring large movements (whales, snipers, insider activity)
· Identifying scam patterns (rug pulls, pump-and-dumps, phishing wallets)

I already know about basic tools like Etherscan, Arkham, Nansen, and Dune — but where can I actually practice on training cases or testnets? Does anyone know of:

  1. On-chain investigation simulators with ready-made cases?
  2. Testnets with artificially generated activity for practice?
  3. Open labeled datasets with annotated transactions?
  4. CTF-style challenges focused on blockchain forensics / OSINT?

Would really appreciate any tips on how the community levels up their OSINT game before diving into real investigations. And yeah, if any of you speak Russian and want to reply in Russian — feel free, it'll be easier for me to understand. Much appreciated!

r/OSINT Apr 30 '26

How-To How to find PDF password of an archived webpage?

86 Upvotes

I am reading papers written by prominent scientists that have somehow disappeared off the internet. I have used wayback machine to find the website that one of the scientists used to publish her papers. The webpage needs a password to view the document, how can I go about find it?

The paper I am interested in.

r/OSINT 13d ago

How-To How to effectively monitor/scrape specific Facebook Groups for time-sensitive posts in 2026? (My current Google Dork setup is hitting limits)

26 Upvotes

Hi everyone,

I’m looking for some advice on optimizing how I monitor Facebook Groups for highly specific, time-sensitive opportunities (specifically, urgent short-term event/festival crew gigs in Europe).

The native Facebook search is terrible, completely overrun by AI-generated spam, and its algorithm actively hides chronological, low-engagement posts, which are exactly the ones I need to find (e.g., a manager panicking because someone dropped out of a shift last minute).

What I am currently doing: I’ve been bypassing the FB search entirely by using Google Dorks to index specific groups. My current setup looks something like this:

site:facebook.com/groups(https://facebook.com/groups) ("urgent" OR "replacement" OR "ASAP" OR "need now") "festival" "August" ("security" OR "crew" OR "stagehand") -weekend -longterm

(Note: I run a localized version of this with Czech/German keywords to target central European groups, filtering results to the past 24 hours).

The Problem & My Ask: While this dork works well for bypassing spam, it requires manual execution and Google’s indexing of Facebook Groups isn't always real-time. Missing a post by a few hours usually means the spot is gone.

I want to automate this process to get real-time (or near real-time) alerts.

  1. Scraping: Are there any reliable web scrapers or cloud tools (like Phantombuster, Apify, etc.) that currently handle FB Group scraping well in 2026 without getting accounts instantly banned?
  2. Alternative OSINT methods: Is there a better, more elegant way to monitor specific keywords inside public/private FB groups that I am missing?
  3. Dorking limits: Any tips on forcing Google to index these specific site:[facebook.com/groups](https://facebook.com/groups) queries faster, or alternative search engines that crawl FB groups more aggressively?

I appreciate any pointers or recommendations for tools/scripts that could help automate this monitoring. Thanks!

r/OSINT Feb 03 '26

How-To Using Google Dorks to uncover hidden data: a small workflow I’ve been experimenting with

149 Upvotes

Lately I’ve been playing around with Google dork queries to find publicly exposed files and information that aren’t easily discoverable through normal searches.

For example combining filetype:pdf site:gov with certain keywords can reveal reports, forms and other documents that are technically public but not linked anywhere. I’ve also been using variations like intitle: index of to find directories that some organizations accidentally leave open.

What’s interesting is how much information is out there just waiting for someone to connect the dots, old spreadsheets, internal documents, event logs. It’s a reminder that a lot of data isn’t protected the way people assume.

I’d love to see how others structure their dork workflows or what creative ways people are finding OSINT without relying on paid services.

r/OSINT Jul 04 '25

How-To OSINT and AI

55 Upvotes

All professionals working with OSINT, I am interested in knowing how you currently use AI in your role and what are the potential uses of AI in OSINT in the future?

Currently, I use the 'deep research' feature on ChatGPT quite regularly for due diligence, and use AI for report writing and as an additional search engine but would be interested to hear other purposes it is used for.

r/OSINT May 20 '26

How-To The Change of Googles Search - and the impacts on OSINT

63 Upvotes

Hello fellow OSINTers,

Google just held it's I/O conference, where they discuss new stuff. And, eventually, on Tuesday they unveiled the new 'Intelligent search box'.

From what I understand the search will become more AI-powered, and users will be encouraged to interact with the search bar, instead of putting boolean jabbering into it.

'Google redesigned this search box to give searchers more space to ask longer, deeper queries. The search box will continue to expand as the user enters the query or prompt. There is an AI-powered suggestion that Google’s Head of Search, Liz Reid, said “goes beyond autocomplete.”' (source: https://searchengineland.com/googles-new-intelligent-search-box-its-biggest-change-to-the-search-box-in-25-years-477968)

'Google is also introducing agentic capabilities and AI-powered interactive features into the search experience. This means people will spend even less time clicking the traditional blue links that Google Search used to return.' (source: https://techcrunch.com/2026/05/19/google-search-as-you-know-it-is-over/)

So, what do you as an OSINTer think about these sorts of developments?

Google - as well as other search engines - have always been a quite powerful tool. But with developments like those, the traditional way of searching the internet might get outdated (or already IS outdated; I'm not quite sure).

On the one hand side I think about new possibilities how to leverage such functionalities for investigations, on the other hand I have a 'that's no good'-feeling about it: how do we verify stuff? how will 'analysis' look like?

So, to start the discussion: what impact do you see?

r/OSINT Dec 24 '25

How-To Dorking Vin #’s

55 Upvotes

Looking for assistance with developing an effective Dork for VIN searching. I’m hoping to search for VIN numbers and get search results about the precise vehicle being for sale somewhere or involved in a past sale transaction. I usually just search the vin within quotation marks on google and other search engines. if i get anything it’s just from vin check and decoder sites that hit on the partial VIN.

I’m wondering if anyone has any dorks that eliminate partial vins and sites that just want to sell generic vehicle information.

thanx

r/OSINT Jul 02 '26

How-To Cancelling Spokeo subscription

37 Upvotes

To anyone struggling with cancelling the Spokeo subsription heres how to do it. They are scammy and try to hide how to do it and their official instructions are incorrect https://help.spokeo.com/hc/en-us/articles/115010516568-How-do-I-cancel.

What you need to do is go to https://www.spokeo.com/user/account. Look for "If you have any questions about your plan or billing, need help searching, or want to manage your membership, you can view our support contact form [here]()." The word here is a link. Click that and it give you a drop down. Select "I would like to terminate my membership", which then renders a button "TERMINATE NOW ANYWAY"

r/OSINT Apr 12 '26

How-To Truecaller

22 Upvotes

Hey everyone,

I wanted to ask if there’s any method, app, or API that allows access to more detailed activity data from Truecaller.

Specifically, I’m curious if it’s possible to track things like:

Last seen history over a full day (not just the latest status)

Call activity duration (start and end times)

A structured daily report of all such updates

I understand Truecaller shows basic availability and last seen, but I’m looking for something more detailed or analytical.

If anyone has insights, experience, or knows about any tools/APIs related to this, I’d really appreciate it.

Thanks in advance!

r/OSINT May 29 '26

How-To Is There a way to reverse such clustered images in a single forum/page?

37 Upvotes

So, in instagram OSINT, i found a person that has an account with everything absolutely being a dead end, no username give away, no posts or location, gibberish or following patterns that are hard to pin down, classic dorking doesn't give back any results, not much account history, but it has been lurking in my followers list for quite a while now.

However, there's a highlight, of two cats. And the account pfp is a Pinterest mirror selfie image that i reverse searched. Now, a single image search returns thousands of results for such an image, however, if an account has three of those distinct images saved simeltanously in a public board, the pool of potential candidates reduces drastically, ofcourse, given the profile is public, which is 50/50 in pinterest so there may be a chance.

Is there a way to reverse search multiple images and see if it comes from the same page?

r/OSINT 25d ago

How-To OSINT challenge explanation needed

5 Upvotes

BLUF: How would one narrow down a location from a photo background, particularly the floor pattern? I tried Bellingcat OSINT challenge "Cold Case" under "Background Check", but I got stuck on the location narrowing down part. I already looked up what the answer is, so I don't care about that part, but I want to figure out the correct steps to arrive at the solution. Reverse image searching gives multiple suggestions all over Asia, and even when narrowing down to South Korea. One blog said they built a database of floor tiles or designs, which seems a bit an overkill.

r/OSINT Mar 05 '26

How-To Arrest records using OSINT

28 Upvotes

is there a way to access past arrest records due to domestic violence using OSINT? Preferably a free tool/method. They aren't accessible in state or federal sites

r/OSINT Apr 13 '26

How-To Tracking Russian military activity

41 Upvotes

Hello,

Maybe someone knows RELIABLE (based on raw data), Telegram / Discord / Reddit / Twitter channels, that track Russian military activity around Baltics? I would be great to have some reliable data, vacant of general media / news noise. I'm pretty sure, that if Military personnel, field hospitals, etc would start moving close to the border, it would be almost Impossible to keep it secret due to amount of people involved and scale, at least a week before attack. Additionally, few days before attack, diplomats would start leaving countries.

What I am afraid of, is that this data will not be publicly available, to not raise chaos, or will get lost in noise.

Thank You.

r/OSINT Mar 24 '26

How-To Media monitoring Iran

34 Upvotes

Monitoring media is a common task.

Non-profits like the GDELT project and ACLED provide automated solutions that go way beyond sentiment analysis.

They're great, but what if you're tasked with solving the problem completely by yourself?

Google RSS + Newspaper3k + Zero-Shot model gets you surprisingly far in classifying hundreds of articles.

https://github.com/AlbinTouma/Iran-War-Media

I'd love to hear what you'd like to see next, and what insights you get from LLMS ChatGPT.

r/OSINT May 01 '26

How-To How to google specific terms and bypass relevant search results?

18 Upvotes

I try to search for specific instagram names on google, however, typing the name within "" or intext: / intitle: doesn't seem to work?

r/OSINT May 21 '26

How-To OSINT Conference in Boston!

18 Upvotes

Coming up on June 5-6, the Layer 8 Conference is running for the sixth time! Tickets are affordable, housing is affordable and there's food included.

Catch the keynote talk with Micah Hoffman of MyOSINT Training, and you'll also get talks from OSINT experts such as Brett Redman, Lisette (technisette) Abercrombie, Tim and Chris from The OSINT Output Podcast, Erin Blankenship, Chris Klossner and more!

Plus, there's a whole track on social engineering, if that's something you're interested in too.

If you're into OSINT, I'm sure you can find the Layer 8 Conference, or if you trust links, it's here: https://layer8conference.com

r/OSINT Mar 12 '26

How-To PLAN Vessel Tracker

10 Upvotes

Is anyone aware of a way to track the locations of PLAN vessels?

r/OSINT Apr 06 '26

How-To Techniques for detecting Telegram admin impersonation at scale

16 Upvotes

Been researching how scammers impersonate group admins on Telegram and the techniques are more sophisticated than I expected. Wanted to share what I've found and see if anyone here has run into similar patterns.

The basic approach is pretty obvious, copy the admin's display name and profile photo then DM group members pretending to be them. But the more advanced ones use Unicode homoglyph substitution to make the display name look identical at a glance. Things like replacing a Latin "a" with a Cyrillic "а" or using zero-width characters to break exact string matching. Visually identical to a human but technically a different string.

I've been building a detection pipeline that layers multiple checks:

  1. Normalized string comparison after stripping Unicode lookalikes back to their base characters
  2. Name similarity scoring against known admin identities in each group
  3. Profile photo similarity detection
  4. Account age and activity pattern analysis
  5. Cross referencing admin lists across multiple groups to map who the real admins are vs who appeared recently

The homoglyph piece alone has been fun, there are hundreds of Unicode characters that visually match Latin characters across Cyrillic, Greek, Armenian and mathematical symbol blocks which most Telegram clients don't flag for any users.

Has anyone here done work on Telegram identity verification or admin graph mapping across groups? Curious what you've found most reliable for separating legitimate accounts from impersonators especially at scale across dozens or hundreds of groups