r/OSINTExperts 20d ago

đŸ‘€Mastering Visual OSINT : Turn pictures into Actionable Intelligence (Webinar)

7 Upvotes

đŸ‘€Mastering Visual OSINT : Turn pictures into Actionable Intelligence (Webinar)

UserSearch and OSINT Experts Society are running a live OSINT training that shows you exactly how to turn any image into actionable, court-grade intelligence, using the latest image recognition technologies.

📅 24th August
⏰ 4pm BST BST
đŸ‘€ Mark Bentley, UserSearch Subject Matter Expert and ex-Law Enforcement (NCA & CEOP)

Don’t miss out👇https://us06web.zoom.us/webinar/register/4317865685263/WN_iff6NVDoSgqwiPy4rodgeg

ïżŒâ€‹


r/OSINTExperts 16h ago

Question Is using OSINT much easier when the target is in the US?

7 Upvotes

One thing I've noticed is that most OSINT tools are geared toward US citizens, and finding information about someone who lives in the US is generally easier than finding information about someone who lives outside it. For example, my friend and I were messing around with Google Dorks and decided to search for her aunt. Literally less than five minutes later, we found her address, phone number, and zip code and all we did was Google her full name. But when you search for someone outside the US, the results are very limited. This is frustrating because I've been searching for someone for two months and still have minimal information about him, simply because he doesn't live in the US.


r/OSINTExperts 23h ago

Besoin d’aide svp ! trouver une personne avec son numĂ©ro

0 Upvotes

Bonjour ,
J’ai un commerce et j’ai voulu avancer une somme Ă  un client habituelle ( j’ai Ă©tĂ© naĂŻf ) mais il ne m’a pas rendu les sous et m’a bloquĂ© j’ai juste son numĂ©ro et son prĂ©nom. J’aimerais le plus de renseignements sur la personne.

Merci d’avance pour votre aide.

Je ne sais pas si le post va rester mais je jette quand mĂȘme une bouteille Ă  la mer.

Update
Le numéro est +33 0778049565


r/OSINTExperts 3d ago

[OC] Real-time interactive conflict map tracking geolocated OSINT events across Ukraine and Syria

Post image
1 Upvotes

r/OSINTExperts 4d ago

WhisperPair-Py: Bluetooth Vulnerability Scanner + Nearby Device Detector. Is It Worthwhile for OSINT?

Thumbnail
github.com
2 Upvotes

r/OSINTExperts 4d ago

Question Built an OSINT tool with Claude Code

Thumbnail
0 Upvotes

r/OSINTExperts 5d ago

How your follower list exposes your politics without a single post

Thumbnail
bednars.me
10 Upvotes

When people discuss social media privacy, the focus is almost always on content. Posts, comments, photos, likes, reposts. That focus is reasonable. If someone writes about a party or a politician often enough, inferring their views takes no cleverness at all. I wanted to know what happens when you remove content from the equation entirely and look only at the shape of the network around an account.


r/OSINTExperts 5d ago

Reading Material: OSINT report about the threat group TeamPCP, and how they were unmasked using different tools

5 Upvotes

r/OSINTExperts 6d ago

I need someone to geolocate this picture for me

4 Upvotes

This is a SAM site in a military installation located in Morocco


r/OSINTExperts 6d ago

MetaScout — an open-source, cross-platform FOCA alternative

14 Upvotes

I needed FOCA for a project recently, but setting up a Windows VM just to run an old, Windows-only tool felt unnecessary.

So I decided to build my own alternative.

MetaScout is an open-source, cross-platform document discovery and metadata analysis tool written in Python.

It can discover publicly exposed documents and extract metadata such as:

  • Usernames and document authors
  • Email addresses
  • Software and version information
  • OS hints
  • Internal file paths and network shares
  • Server and printer names
  • Passive subdomain discovery via crt.sh
  • PDF, DOCX, XLSX, PPTX and other document formats
  • HTML and JSON reports

It supports macOS, Linux and Windows, and includes both a CLI and a local web UI.

I built it as a modern, Python-based spiritual successor to FOCA, with a focus on making it easy to install and use across platforms.

GitHub: https://github.com/gorkemguler/MetaScout

I'd love to get feedback from people working with OSINT, pentesting, reconnaissance, or information disclosure.

What features would you like to see added?


r/OSINTExperts 6d ago

How can a virtual phone number be traced? How can I get info of a virtual number? One of my friends is being harassed by a person using virtual phone number, I need help as I don’t know how to do OSINT on that kind of phone numbers. Anyone knows anything? Even 1% of help is also welcome

Thumbnail
1 Upvotes

r/OSINTExperts 10d ago

See what he was searching for —

Post image
5 Upvotes

r/OSINTExperts 12d ago

Looking for open source tools to identify a location.

10 Upvotes

Any tools or techniques you recommend? Looking for something easy to set up and deploy


r/OSINTExperts 12d ago

A 4-stage workflow for AI research when citations are not enough

Thumbnail
2 Upvotes

r/OSINTExperts 12d ago

Linking accounts across breach dumps when nothing else matches

14 Upvotes

Ran into this on a case a few months back and it's stuck with me as one of the more useful low-tech tricks I use now, so figured I'd write it up properly instead of leaving it as a mental note.

The setup: two accounts, no shared email, no shared username, no shared bio text, no shared profile photo. Different platforms entirely. The only reason I even suspected they were the same person was a stylistic tic in how they phrased things. Nothing you'd take to a client on its own.

What ended up connecting them was passwords.

People reuse passwords constantly, and even the ones who don't reuse the exact string tend to reuse a base and mutate it: capitalize the first letter, tack on a year, swap an "o" for a "0", append "!" because some site demanded a special character. If you pull breach records for each identifier separately and look at the raw passwords (plaintext, or cracked hashes where available), those mutations are usually easy to spot once you strip the noise.

Here's roughly how I do it now. Pull every breach hit for each candidate identifier separately, and don't merge them yet, keep them in two buckets. Extract just the passwords from each bucket into a plain list. Normalize by lowercasing everything and stripping trailing digits and symbols, noting what you stripped, so "Blueberry22!" becomes "blueberry" plus a stripped suffix of "22!". Then compare the normalized bases across the two buckets. A shared, unusual base string is a real signal. A shared common one, "password", "qwerty123", "iloveyou", is basically noise, ignore it. If you get a hit, go looking for a second, independent signal before treating it as anything more than a lead: a secondary recovery email buried in one of the records, a phone number, a registration pattern, anything that isn't also derived from the password match itself.

Worked example, details changed since it's from real casework: one identity had a leaked password of "TeddyBear19," the other had "teddybear_2019!!" on a completely different platform. Normalized, both reduce to "teddybear." Not proof by itself, plenty of people like teddy bears. What made it a real lead was one of the two dumps also having a partially masked recovery number ending in the same four digits as a number already tied to the first identity from earlier in the investigation. The password match is what got me looking there in the first place.

A few things worth knowing before you rely on this. Weak, common passwords will burn you. If the shared base is something like "sunshine" or "monkey123," you'll get false positive after false positive. The signal gets stronger the weirder and more personal the base password is: inside jokes, pet names, misspellings, anything that isn't in the top 10,000 list. It's also getting less reliable every year as password managers spread, and that's a good thing. If someone's been using randomly generated passwords since 2021, this technique won't produce anything for them, no shared base to find. Don't force it.

And obviously, this only makes sense where you already have a legitimate reason to be linking these identities: an authorized investigation, your own accounts, a security assessment you're actually cleared to do. It's a correlation technique, not a magic trick, and it's exactly the kind of "lead, not evidence" thing that gets people in trouble when they skip the corroboration step.

Doing this by hand across five separate breach-search tabs got old fast, so I ended up scripting the normalize-and-compare part for myself. Not turning this into a plug, the manual version above works fine on its own if you'd rather do it that way.


r/OSINTExperts 12d ago

How contradictions across the City of Philadelphia’s property websites make 100% online confirmation of a rental licence impossible — and where the unanswered question goes instead.

Thumbnail
jlegal.pro
1 Upvotes

An OSINT investigation 
 and the 100% rule.

Twelve years of notice, delivered by telephone
Councilmember Mark F. Squilla has held the 1st District seat since January 2, 2012 — before any surface in the current map ecosystem existed (eCLIPSE portal live Jan 2015; the open dataset created Sept 2016; Atlas first appears Apr 2017, already without an expiration column; Property History live late 2021, with its one-day defect from birth; the Atlas rebuild 2024). He is currently Vice Chair of the Council Committee on Licenses & Inspections and Chair of the Committees on Commerce & Economic Development and Appropriations, and Majority Whip. Before politics he spent 25 years as a systems analyst in the Pennsylvania Auditor General's Office (1985–2011), holding a computer-science degree — a working IT professional, trained in databases, extraction pipelines, and where records systems capture, retain, or fail to surface information.

Full details:

https://jlegal.pro/verification-monopoly.html


r/OSINTExperts 13d ago

Newbie Topic UserSearch v2.0.21 — Just Went Live

17 Upvotes

We've just shipped v2.0.21 and the main change is something users have been asking for a while: an Insights tab.

The problem it solves: a single reverse email/phone/username search on our platform queries OSINT Industries, Epieos, Predicta Search and our own modules at the same time. Great coverage, but you'd get back a wall of results and the actual analysis — spotting that the same first name appears on three accounts, or that two profiles were created the same week — was manual.

Insights now does that pass for you. Sub-tabs for:

  • Timelines (profile created/updated dates, chronological)
  • Cross-overs (same/similar details flagged across accounts)
  • All recovered profile pictures in one grid
  • Linked emails and phones
  • Breach appearances

Also new in this release:

  • BehindTheEmail — a cheaper reverse email module (phones, pictures, profile info)
  • Reddit Search by Think-Pol — recovers deleted comments/posts and profile info on deleted accounts, with AI analysis of the profile
  • GeoSearch by GeoSeer — AI image geolocation from visual content only, no EXIF

Walkthrough video: https://youtu.be/YOF_lvyzQCQ


r/OSINTExperts 13d ago

Tracking

6 Upvotes

i found a guthub account that has an app which can track any number from the world and find the social linked to the number.

https://github.com/HunxByts/GhostTrack


r/OSINTExperts 13d ago

Need help for my company

2 Upvotes

First of all, greetings to everyone. I am involved in the export of fresh fruits and vegetables. I want to find out what other companies in Turkey are doing—where, when, and how—and I intend to develop a comprehensive OSINT project for this purpose. I would love to hear any ideas or sources regarding open-source intelligence that come to mind. Additionally, I want to closely monitor the market conditions and foreign export companies in the countries to which we export. I welcome input from anyone with ideas or a willingness to help; feel free to reach out via private message as well. Thank you.


r/OSINTExperts 15d ago

i want modren OSINT tutorials

Thumbnail
1 Upvotes

r/OSINTExperts 16d ago

SoCal Job Search — Intelligence / OSINT / Cybersecurity / Investigative Analysis

Thumbnail
0 Upvotes

r/OSINTExperts 18d ago

Mainland China Tools?

3 Upvotes

Hello. Does anyone here have any osint tools that can be used to track or find information of people in mainland china?


r/OSINTExperts 20d ago

Question How does one directly query OpenStreetMap? Without using a tool?

5 Upvotes

I guess this is a question more on the programming side of things

6 Open Source Tools to Query OpenStreetMap

So there's this link, which shows tools to query OpenStreetMap. It seems like they do all the code for you

Is there any way to write the code yourself, to be able to query OpenStreetMap?

What programming language(s) do you need?

This is a repo of one of the tools:

https://github.com/tyrasd/overpass-turbo

How does one start tackling it, to understand how it works?


r/OSINTExperts 20d ago

OSINT Case Management Tool

9 Upvotes

Check out GHOST, the CRM for OSINT Investigators. Already over 600 stars on Github, actively supported and features added: https://github.com/elm1nst3r/GHOST-osint-crm

Check it out, leave feedback, request features, help build it!

Core Features:

  • Digital Dossiers: Track names, aliases, dates of birth, case associations, and status (Open, Being Investigated, Closed, On Hold).
  • Categorize with Precision: Tag individuals as Suspects, Witnesses, Clients, Victims, Persons of Interest, or plain old 'Other'.
  • Travel and Transaction tracking: Track a persons movement patterns, their travel, and their asset movements or questionable transactions.
  • Comprehensive Profiling: Store profile pictures, notes, OSINT data (emails, socials, phone numbers), attachments, connections, locations, and custom fields.

We currently need help with translations - we currently are english based and have a strong Russian translation, German has been started. Feel free to start translating through Crowdin: https://crowdin.com/project/ghost-osint-crm


r/OSINTExperts 21d ago

Question Will OSINT techniques of today become useless one day when everyone becomes private and hackers will rule the world of information collecting?

15 Upvotes

I feel like as more and more people become aware of how much of their private info they are displaying publically and how non-hackers can find out so much info about people - people will start becoming super private

Personal data will only stay with the big companies etc. It’ll all be locked away behind encryption. Only hackers will be able to get to it

Governments might also make public records private, as people demand more privacy. Maybe?

So do you think that the OSINT techniques of today will go away, and only hackers will be able to do the information gathering that OSINT non-hackers can do today?

What about like in the year 2050?