commit 62eda574272ef6f3aab3d8468fda90652fa80edf
parent 1b916cd283b7b20a7edda8ff4b148ed0cd420644
Author: DAEMON <zer0sec.xp@icloud.com>
Date: Mon, 28 Sep 2026 04:55:22 +0100
Add an OSINT section: 16 sheets across 10 subsections
New `osint` domain in the taxonomy, organised with `subcategory` so the tab
holds Foundations, People & Identity, Social Media, Images & Video,
Geospatial, Transport, Corporate & Financial, Infrastructure, Archiving &
Analysis and Thematic.
Content is drawn from Bellingcat's Online Investigation Toolkit and the
OSINT Newsletter Tools Library. Neither publishes a licence — bellingcat/
toolkit reports `license: null` — so nothing is copied: the prose and
method are this site's own, and the tool tables carry catalogue facts
(name, one-line description, cost, link). Both are credited on every
sheet via the `references` field added for ired.team, and each sheet links
its upstream category page.
Tool tables were generated from the upstream category tables rather than
written from memory, so names and URLs are accurate. All 345 external
links were checked; one stale FAA registry URL carried over from the
upstream catalogue is overridden to the working address.
Also adds `pentest-workflow` to validate-content.py's category set, which
was missing and made all 27 sheets in that category report a bad category.
Verified: astro build 1540 pages (was 1482), node --test 4/4,
validate-content.py reports no ISSUES and no warnings on the new sheets.
The one remaining MISSING entry (exploitation/shell-stabilization) and the
stale content-manifest.json predate this work.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Diffstat:
18 files changed, 2334 insertions(+), 2 deletions(-)
diff --git a/scripts/validate-content.py b/scripts/validate-content.py
@@ -6,7 +6,7 @@ ROOT = os.path.normpath(os.path.join(os.path.dirname(os.path.abspath(__file__)),
SHEETS = os.path.join(ROOT, "src", "content", "sheets")
TAX = {"active-directory","enumeration","exploitation","privilege-escalation",
"password-attacks","web","tunneling-pivoting","cryptography","dfir",
- "tools","linux-it","git-workflow"}
+ "tools","linux-it","git-workflow","pentest-workflow","osint"}
manifest = json.load(open(os.path.join(ROOT, "content-manifest.json")))
expected = {(s["category"], s["slug"]) for s in manifest["sheets"]}
diff --git a/src/content/sheets/osint/archiving-and-evidence.md b/src/content/sheets/osint/archiving-and-evidence.md
@@ -0,0 +1,136 @@
+---
+title: "Archiving & Evidence Preservation"
+description: "Capture sources so they survive deletion, with the hashes and timestamps that make a capture defensible."
+category: osint
+subcategory: "Archiving & Analysis"
+tags: [osint, archiving, evidence, preservation]
+tools: [auto-archiver, wayback, archive-today, yt-dlp]
+difficulty: beginner
+updated: 2026-09-28
+references:
+ - name: "Bellingcat's Online Investigation Toolkit"
+ url: "https://bellingcat.gitbook.io/toolkit"
+ author: "Bellingcat"
+ license: none
+ relation: derived
+ note: "Tool catalogue: names, descriptions, cost flags and links for this area."
+ - name: "OSINT Newsletter Tools Library"
+ url: "https://tools.osintnewsletter.com"
+ author: "The OSINT Newsletter"
+ license: none
+ relation: derived
+ note: "Second tool catalogue, cross-checked against the above."
+---
+
+## What this covers
+
+Making sure what you found still exists tomorrow, and that you can show it has not changed since
+you found it. Content gets deleted, edited and made private constantly — usually right after
+someone notices attention. Archive first, analyse second.
+
+## Method
+
+1. **Archive to something you do not control** — Wayback, archive.today — so the capture has a
+ third-party timestamp.
+2. **Also keep a local copy.** Public archives can be removed, rate-limited or unavailable.
+3. **Hash every local file** on acquisition, and record the hash somewhere separate.
+4. **Record provenance:** the URL, the moment you captured it, and how you reached it.
+5. **Capture the media, not a screenshot of it.** A screenshot loses metadata, resolution and
+ audio.
+
+## Public archives
+
+```bash
+# push a URL into the Wayback Machine
+curl -s "https://web.archive.org/save/https://example.com/page"
+
+# check existing captures before assuming you need a new one
+curl -s "http://archive.org/wayback/available?url=example.com/page×tamp=20240101" | jq .
+```
+
+`archive.today` (also `archive.ph`, `archive.is`) renders JavaScript-heavy pages that Wayback often
+fails on, and is markedly more resistant to takedown requests. Use both; they fail differently.
+
+## Local capture
+
+```bash
+# single page with everything needed to render it offline
+wget --page-requisites --convert-links --adjust-extension \
+ --no-parent --span-hosts --domains example.com,cdn.example.com \
+ 'https://example.com/page'
+
+# video and audio, with metadata and subtitles preserved
+yt-dlp --write-info-json --write-subs --write-thumbnail \
+ --no-mtime -o '%(upload_date)s-%(id)s.%(ext)s' URL
+
+# hash everything on acquisition
+find ./capture -type f -exec sha256sum {} \; | tee capture.sha256
+
+# verify later
+sha256sum -c capture.sha256
+```
+
+`--no-mtime` matters: without it `yt-dlp` sets the file's modification time from the upload date,
+which muddles your own acquisition timeline.
+
+## Purpose-built tooling
+
+| Tool | What it does |
+| --- | --- |
+| [Auto Archiver](https://github.com/bellingcat/auto-archiver) | Bellingcat's pipeline: reads URLs from a spreadsheet, archives pages and media, hashes everything, writes results back. The right tool for continuous collection. |
+| [Hunchly](https://www.hunch.ly/) | Captures every page you visit during a case automatically, with hashes and full-text search. Removes the discipline problem. |
+| [Atlos](https://www.atlos.org/) | Collaborative platform for visual investigations with source tracking and review workflow. |
+| [Lumen](https://lumendatabase.org/) | Archive of takedown notices — sometimes the only record that something existed. |
+| [Web Archives](https://github.com/dessant/web-archives) | Browser extension that queries many archive services at once. |
+
+Auto Archiver is the one to set up if you are collecting on an ongoing basis rather than
+case-by-case:
+
+```bash
+pipx install auto-archiver
+auto-archiver --config orchestration.yaml
+```
+
+## Tool reference
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [Archive.today](https://archive.today) | Archive any webpage and search for archived pages. | free |
+| [Auto Archiver](https://github.com/bellingcat/auto-archiver) | Bellingcat's tool to automatically archive social media posts, videos, and images. Free and Open-Source. | free |
+| [Bellingcat TikTok Hashtag Analysis](https://github.com/bellingcat/tiktok-hashtag-analysis) | Archive content and metadata from TikTok posts that contain one or more specified hashtags | free |
+| [Distill](https://distill.io/) | Distill is a website change monitoring tool that allows users to track changes on web pages. | partly free |
+| [Hunchly](https://www.hunch.ly/) | An archiving tool that tracks online activities and preserves essential information about the web pages researchers visit. | paid |
+| [Lumen](https://lumendatabase.org/) | A research project collecting and publishing legal takedown notices for online content transparency | free |
+| [Wayback Machine](https://web.archive.org/) | The Wayback Machine is the Internet Archive's free tool for viewing and saving archived web pages, with over a trillion pages captured, widely used for… | free |
+| [Web Archives](https://github.com/dessant/web-archives) | A browser extension to view archived and cached versions of a website on multiple archiving sites. | partly free |
+
+## Pitfalls
+
+- **Screenshots alone are weak.** No metadata, no hash, trivially edited. Capture the file.
+- **Archives honour robots.txt and takedowns.** A site can retroactively remove itself from
+ Wayback. Your local copy is what survives.
+- **Dynamic content does not archive well.** Infinite scroll, lazy loading and interactive maps
+ frequently fail; verify the capture actually shows what you saw.
+- **Hash after acquisition, not after editing.** A hash of a file you already cropped proves
+ nothing about the original.
+- **Archiving can notify.** Submitting a URL to a public archive creates a public record that
+ someone is interested in it.
+
+## Broader catalogues
+
+- [Archiving OSINT](https://tools.osintnewsletter.com/tool-categories/archiving-osint)
+- [Data Extraction OSINT](https://tools.osintnewsletter.com/tool-categories/data-extraction-osint)
+
+
+## Sources
+
+Both catalogues below are maintained by other people and are considerably larger than
+this page. Use them as the canonical index; this sheet is a working route through them.
+
+- [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
+ review page covering cost, difficulty, requirements and limitations.
+- [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
+
+Neither publishes a licence, so nothing here is copied from them: tool names, one-line
+descriptions, cost flags and links are catalogue facts, and the method and commentary are
+this site's own. See [credits](/credits).
diff --git a/src/content/sheets/osint/companies-and-finance.md b/src/content/sheets/osint/companies-and-finance.md
@@ -0,0 +1,145 @@
+---
+title: "Companies, Ownership & Finance"
+description: "Corporate registries, filings and beneficial-ownership data for working out who actually controls a company."
+category: osint
+subcategory: "Corporate & Financial"
+tags: [osint, companies, finance, ownership, filings]
+tools: [opencorporates, edgar, aleph, companies-house]
+difficulty: intermediate
+updated: 2026-09-28
+references:
+ - name: "Bellingcat's Online Investigation Toolkit"
+ url: "https://bellingcat.gitbook.io/toolkit"
+ author: "Bellingcat"
+ license: none
+ relation: derived
+ note: "Tool catalogue: names, descriptions, cost flags and links for this area."
+ - name: "OSINT Newsletter Tools Library"
+ url: "https://tools.osintnewsletter.com"
+ author: "The OSINT Newsletter"
+ license: none
+ relation: derived
+ note: "Second tool catalogue, cross-checked against the above."
+---
+
+## What this covers
+
+Establishing what a company is, who owns it, and what it has told regulators. The pattern that
+matters: the registry tells you the *legal* structure, and the legal structure is often designed to
+obscure who benefits. Getting to the human at the end takes several sources.
+
+## Method
+
+1. **Start at the national registry**, which is authoritative. Aggregators are convenient but stale.
+2. **Get the registration number** and use it thereafter. Company names are reused and change.
+3. **Pull the filings, not the summary.** Annual accounts, director appointments and charges carry
+ addresses, signatures, auditors and related parties that the summary page omits.
+4. **Follow officers sideways.** One director's other appointments frequently reveal the group the
+ company actually belongs to.
+5. **Cross-border means repeat the whole process** in each jurisdiction. A chain terminating in a
+ secrecy jurisdiction is the normal outcome, not a failure.
+6. **Check leak archives** where the chain goes dark — OCCRP Aleph and ICIJ Offshore Leaks hold
+ what registries do not.
+
+## Core sources
+
+| Source | Coverage |
+| --- | --- |
+| [OpenCorporates](https://opencorporates.com/) | The largest open company database, ~200 jurisdictions. Best starting point for "does this company exist and where". |
+| [SEC EDGAR](https://www.sec.gov/edgar/search/) | All US public-company filings. Full-text searchable and genuinely free. |
+| [EDGAR Suite](https://edgar-suite.vercel.app/) | Friendlier interface over EDGAR for exploring filings. |
+| [OCCRP Aleph](https://aleph.occrp.org/) | Registries, leaks and court records in one index. The tool for cross-border work. |
+| [ICIJ Offshore Leaks](https://offshoreleaks.icij.org/) | Panama / Paradise / Pandora Papers entities and officers. |
+| [Open Ownership](https://register.openownership.org/) | Beneficial-ownership data, where it is published at all. |
+
+UK Companies House deserves a specific mention: it is free, has a clean API, and publishes full
+filing history including scanned documents. It is the best-documented major registry.
+
+```bash
+# Companies House API — free key from developer.company-information.service.gov.uk
+curl -s -u "$CH_KEY:" \
+ 'https://api.company-information.service.gov.uk/search/companies?q=example+ltd' | jq '.items[] | {title, company_number, company_status}'
+
+curl -s -u "$CH_KEY:" \
+ 'https://api.company-information.service.gov.uk/company/12345678/officers' | jq '.items[] | {name, officer_role, appointed_on}'
+```
+
+EDGAR full-text search is equally scriptable:
+
+```bash
+curl -s 'https://efts.sec.gov/LATEST/search-index?q=%22specific+phrase%22&forms=10-K' \
+ -H 'User-Agent: researcher you@example.com' | jq '.hits.hits[]._source | {display_names, file_date}'
+```
+
+EDGAR requires a `User-Agent` identifying you, and will block you if you omit it.
+
+## Reading the structure
+
+- **Nominee directors** appear on dozens or hundreds of companies. A director with 200 appointments
+ is a service provider, not a decision-maker.
+- **Registered-address clustering** — many companies at one address usually means a formation agent.
+- **Shareholders that are themselves companies** are the chain you have to walk. Keep going until
+ you hit a natural person or a jurisdiction that will not tell you.
+- **Charges and mortgages** name lenders, which reveals banking relationships the company did not
+ advertise.
+
+## Tool reference
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [527 Explorer](https://projects.propublica.org/527-explorer/) | ProPublica's 527 Explorer is a database that allows users to examine the finances of organizations known as 527s in the United States, which can raise… | free |
+| [BlockExplorer](https://blockexplorer.com/) | Following a bitcoin trail or following a bitcoin account? | free |
+| [Companies House](https://find-and-update.company-information.service.gov.uk/) | Search companies and individuals in the United Kingdom and Gibraltar. | free |
+| [EDGAR Command Line Interface (edgar-tool)](https://pypi.org/project/edgar-tool/) | Tool for the retrieval of corporate and financial data from SEC's EDGAR (Electronic Data Gathering, Analysis, and Retrieval) database. | free |
+| [EDGAR](https://www.sec.gov/edgar/search/) | Database of corporate filings for the US | free |
+| [Etherscan](https://etherscan.io/) | An explorer that allows researchers to track wallets, transactions and more on the Ethereum blockchain. | free |
+| [EU consolidated corporate registers (BRIS)](https://e-justice.europa.eu/content_find_a_company-489-en.do) | Consolidated company registers covering most of the EU, Iceland, Liechtenstein and Norway. | free |
+| [EU Sanctions Map](https://www.sanctionsmap.eu/) | Database of sanctions imposed by the European Union and the United Nations | free |
+| [Global Suppliers Online](https://www.globalsuppliersonline.com/) | A site dedicated to connect suppliers and buyers of goods from all over the world. | partly free |
+| [ICIJ Offshore Leaks Database](http://offshoreleaks.icij.org/) | Find out who’s behind more than 810k offshore companies, foundations and trusts from the Panama Papers, the Offshore Leaks, the Bahamas Leaks and the… | free |
+| [ImportGenius](https://www.importgenius.com/) | Commercial supplier of trade data for 23 countries. Paid service but journalists can ask for free access. | paid |
+| [ImportYeti](https://www.importyeti.com/) | Search 60 million US customs sea shipment records, find company suppliers. | free |
+| [LittleSis](https://littlesis.org/database) | Connects the dots between influential / wealthy individuals in (mostly US) politics and business. | free |
+| [Lumen](https://lumendatabase.org/) | A research project collecting and publishing legal takedown notices for online content transparency | free |
+| [North Data](https://northdata.com) | Search for people and companies in EU corporate and trade registers + visualize relationships | partly free |
+| [OCCRP Aleph](https://aleph.occrp.org/) | Aleph offers a way to research sanctions lists, corporate registries, leaks, and more | free |
+| [Open Ownership](https://www.openownership.org/en/) | Links to beneficial ownership registers. | free |
+| [OpenCorporates](https://opencorporates.com/) | Comprehensive repository of company registries around the world | partly free |
+| [OpenSecrets](https://www.opensecrets.org/) | Data on campaign finance, lobbying, and spending in U.S. politics | free |
+| [OSINT Tools Map](https://cybdetective.com/osintmap/) | An interactive map serving as a curated archive of country-specific OSINT resources, including business registries, court records, and cadastral maps… | free |
+| [RuPEP](https://rupep.org/en/) | Online database of politically exposed persons in Russia, Belarus, Kyrgyzstan, Kazakhstan, Georgia and Moldova. | free |
+| [SanctionsExplorer](https://sanctionsexplorer.org/) | A comprehensive database of current and historical OFAC/UN/EU sanctions | free |
+| [UN Comtrade Database](https://comtradeplus.un.org/) | United Nations free database of global trade. | free |
+| [Wikipedia list of company registers](https://en.wikipedia.org/wiki/List_of_official_business_registers) | A list of official business registers around the world. | free |
+| China-related resources | Resources for research on companies in China. | — |
+| OpenSanctions | Open-source international database of sanctions data, persons of interest and politically exposed persons. | partly free |
+
+## Pitfalls
+
+- **Registry data is self-reported** and frequently not verified by anyone. A filed address may be
+ fictional.
+- **"Beneficial owner" is defined differently everywhere**, and thresholds (often 25%) let real
+ control sit just underneath the disclosure line.
+- **Aggregators lag.** For anything current, go to the registry itself.
+- **Name collisions across jurisdictions** are constant. Always carry the registration number.
+- **Dissolved does not mean gone.** Historical filings often hold what you need, and some registries
+ purge them after a few years — capture early.
+
+## Broader catalogues
+
+- [Public Records OSINT](https://tools.osintnewsletter.com/tool-categories/public-records-osint)
+- [Blockchain/Cryptocurrency OSINT](https://tools.osintnewsletter.com/tool-categories/blockchain-and-cryptocurrency-osint)
+
+
+## Sources
+
+Both catalogues below are maintained by other people and are considerably larger than
+this page. Use them as the canonical index; this sheet is a working route through them.
+
+- [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
+ review page covering cost, difficulty, requirements and limitations.
+- [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
+
+Neither publishes a licence, so nothing here is copied from them: tool names, one-line
+descriptions, cost flags and links are catalogue facts, and the method and commentary are
+this site's own. See [credits](/credits).
diff --git a/src/content/sheets/osint/conflict-and-environment.md b/src/content/sheets/osint/conflict-and-environment.md
@@ -0,0 +1,140 @@
+---
+title: "Conflict & Environmental Monitoring"
+description: "Event datasets, munitions identification, fire and deforestation feeds, and the tools built for documenting harm."
+category: osint
+subcategory: "Thematic"
+tags: [osint, conflict, environment, monitoring, satellite]
+tools: [acled, liveuamap, global-forest-watch, firms]
+difficulty: intermediate
+updated: 2026-09-28
+references:
+ - name: "Bellingcat's Online Investigation Toolkit"
+ url: "https://bellingcat.gitbook.io/toolkit"
+ author: "Bellingcat"
+ license: none
+ relation: derived
+ note: "Tool catalogue: names, descriptions, cost flags and links for this area."
+ - name: "OSINT Newsletter Tools Library"
+ url: "https://tools.osintnewsletter.com"
+ author: "The OSINT Newsletter"
+ license: none
+ relation: derived
+ note: "Second tool catalogue, cross-checked against the above."
+---
+
+## What this covers
+
+Two thematic areas with mature, purpose-built open datasets: armed conflict and environmental
+change. Both are unusual in OSINT for having authoritative structured data rather than just tools —
+which means the skill is in reading the datasets' methodology, not in finding them.
+
+## Conflict
+
+| Source | What it gives you |
+| --- | --- |
+| [ACLED](https://acleddata.com/) | Coded conflict events — date, location, actors, fatalities — globally, with a documented methodology and a free API. The reference dataset. |
+| [Liveuamap](https://liveuamap.com/) | Near-real-time mapped events aggregated from social media. Fast but unverified; treat as a lead generator. |
+| [Open Source Munitions Portal](https://osmp.ngo/) | Identification reference for munitions and their remnants, which is how you turn a photo of debris into a weapon type. |
+| [Bellingcat's Civilian Harm datasets](https://ukraine.bellingcat.com/) | Verified incident databases with sourcing for each entry. |
+
+ACLED's API is the one to build on:
+
+```bash
+curl -s 'https://api.acleddata.com/acled/read?key=KEY&email=you@example.com&country=Ukraine&event_date=2024-01-01|2024-03-31&event_date_where=BETWEEN&limit=0' \
+ | jq '.data | length'
+```
+
+Read ACLED's codebook before drawing conclusions from it. What counts as an "event", how fatalities
+are attributed, and what sourcing threshold applies all materially affect the numbers, and
+comparisons across regions can be distorted by differences in local reporting density.
+
+**Munitions identification** is a specialist skill and the single most common place where
+open-source conflict reporting goes wrong. Match on markings, dimensions and fragmentation pattern
+against a reference, and say "consistent with" rather than "is" unless you have markings.
+
+## Environment
+
+| Source | What it gives you |
+| --- | --- |
+| [Global Forest Watch](https://www.globalforestwatch.org/) | Deforestation alerts and tree-cover change, near-real-time. |
+| [NASA FIRMS](https://firms.modaps.eosdis.nasa.gov/) | Active fire and thermal anomaly detections, updated several times a day. |
+| [Global Fishing Watch](https://globalfishingwatch.org/map) | Apparent fishing effort inferred from AIS; exposes probable illegal fishing. |
+| [Sentinel Hub](https://apps.sentinel-hub.com/eo-browser/) | Free Sentinel-2 imagery with band combinations for burn scars, water and vegetation. |
+
+Thermal detections are a strong OSINT primitive well beyond wildfires: gas flaring, industrial
+activity, shelling and burning all register. A FIRMS hotspot at an industrial site that should be
+idle is a finding.
+
+False-colour band combinations in EO Browser make change obvious that true colour hides:
+
+```text
+Burn scars (Sentinel-2): B12, B8A, B4
+Vegetation health (NDVI): (B8 - B4) / (B8 + B4)
+Water / flooding: B8A, B11, B4
+```
+
+## Tool reference
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [ACLED (Armed Conflict Location & Event Data Project)](https://acleddata.com/) | ACLED provides data and analysis on political violence and protest around the world, facilitating research, policy making, and journalistic reporting. | partly free |
+| [AllTrails](https://www.alltrails.com/) | AllTrails.com is a tool for discovering hiking, biking, and running trails worldwide, providing detailed trail maps, user reviews, and navigation support… | partly free |
+| [Amazonia Socio Ambiental (RAISG)](https://www.amazoniasocioambiental.org/en/) | Amazon rainforest maps and shapefiles of natural protected areas, concessions, indigenous territories, oil, mining, roads, fires, deforestation in… | free |
+| [Aqueduct Water Risk Atlas](https://www.wri.org/applications/aqueduct/water-risk-atlas/) | The Aqueduct water Risk Atlas, developed by the World Resources Institute (WRI), is an interactive platform for assessing water-related risks globally. | free |
+| [BirdNet](https://birdnet.cornell.edu/map) | Identify bird sounds - find bird sounds on a global map. | free |
+| [Bulletpicker](https://bulletpicker.com/pdf/bulletpicker-24-11-20.zip) | Bulletpicker.com is a collection of ammunition guidebooks and manuals from several different armed forces. | free |
+| [CITES Trade Database](https://trade.cites.org/) | Around 23 million records of trade in wildlife since 1975. | free |
+| [CryO Tools](https://cryo-tools.org/) | Scientific tools for investigating the cryosphere (areas with snow & ice) | free |
+| [EIA Global Environmental Crime Tracker](https://eia-international.org/global-environmental-crime-tracker/) | Map/tracker of environmental crimes including trade in ivory, rhino, big cats, and other exotic animals. | free |
+| [Environmental Justice Atlas](https://ejatlas.org/) | Map of environmental-related conflict globally | free |
+| [Global Fishing Watch](https://globalfishingwatch.org/map) | A digital platform for investigating fishing activities and vessel movements worldwide by utilising satellite and AIS data. | free |
+| [Global Forest Watch](https://www.globalforestwatch.org/map/) | Explore tree cover loss and gain data, recent deforestation and fire alerts, land use designations, carbon emissions, biodiversity metrics and more. | free |
+| [Global Monitoring System - ECOSOLVE](https://www.ecosolve.eco/dashboard) | Illicit online wildlife markets data from over 30 countries and regions | free |
+| [Google Flood Hub](https://sites.research.google/floods/) | A visual tool to monitor river levels and forecast floods based on AI models developed by Google Research. | free |
+| [LiveUAMap](https://liveuamap.com/) | LiveUAMap is a mapping tool that provides up-to-date information on global geopolitical events, conflicts, and crises. | partly free |
+| [Locust Hub](https://locust-hub-hqfao.hub.arcgis.com/) | A repository for desert locust data with maps and other resources for tracking movements, early detection and planning locust control interventions. | free |
+| [Merlin](https://merlin.allaboutbirds.org/) | Identify birds (visually), through an app. | free |
+| [Movebank](https://www.movebank.org/) | Platform for animal tracking data. | free |
+| [Nullschool Earth Map](https://earth.nullschool.net/#current) | View current and historic wind, weather, ocean and pollution conditions on an interactive animated map. | partly free |
+| [Open Source Munitions Portal](https://osmp.ngo/) | A searchable library of verified images for researchers, journalists, and practitioners trying to learn more about munitions and their use and impact in… | free |
+| [Police Records Access Project](https://clean.calmatters.org/) | A database providing searchable access to California law enforcement records including police use-of-force incidents, shootings, and misconduct cases. | free |
+| [Resource Watch](https://resourcewatch.org/) | A free open-data platform that hosts 300+ datasets on different topics relating to the environment and human well-being, including real-time datasets. | free |
+| [River Runner Global](https://river-runner-global.samlearner.com/) | Calculate which water stream a drop of rain will follow | free |
+| [Species+](https://www.speciesplus.net/species) | Centralized website with vulnerable species information. | free |
+| [UNOSAT Analyses](https://unosat.org/products) | UNOSAT Analyses is a tool that maps humanitarian emergencies across the globe utilising United Nations Satellite Centre data. | free |
+| [WildEye](https://global.wildeye.oxpeckers.org/) | Tracking tool for data on environmental and wildlife crime cases, including court cases and convictions, across the globe. | free |
+| [Wildlife Trade Portal](https://www.wildlifetradeportal.org/) | An open-source tool to search wildlife seizure data worldwide. | free |
+| [WildMe & WildBook](https://wildme.org/#/platforms/bass) | Open source pattern recognition software to identify unique whales, sharks, zebras, jaguars, skunks, fish and much more. | free |
+| [World Database on Protected and Conserved Areas](https://www.protectedplanet.net/en/search-areas?geo_type=site) | A comprehensive global database on terrestrial and marine protected areas. Also known as Protected Planet. | free |
+| CAT UXO | A repository for professionals working in the explosive ordnance disposal (EOD) space. | partly free |
+
+## Pitfalls
+
+- **Event datasets reflect reporting, not reality.** Areas with more journalists produce more
+ recorded events. Never read event counts as a direct measure of violence.
+- **Real-time aggregators are unverified.** Liveuamap and similar repost claims. Verify before use.
+- **Thermal detections have mundane causes.** Flaring, agricultural burning and industrial process
+ heat all look alike from orbit.
+- **Deforestation alerts include legal logging** and seasonal change. Alert ≠ crime.
+- **Documenting harm carries duty of care.** Graphic material needs handling policies, and
+ identifying victims or witnesses can endanger them. Minimise what you publish.
+
+## Broader catalogues
+
+- [Conflict OSINT](https://tools.osintnewsletter.com/tool-categories/conflict-osint)
+- [Environment & Wildlife OSINT](https://tools.osintnewsletter.com/tool-categories/environment-and-wildlife-osint)
+- [Public Media OSINT](https://tools.osintnewsletter.com/tool-categories/public-media-osint)
+
+
+## Sources
+
+Both catalogues below are maintained by other people and are considerably larger than
+this page. Use them as the canonical index; this sheet is a working route through them.
+
+- [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
+ review page covering cost, difficulty, requirements and limitations.
+- [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
+
+Neither publishes a licence, so nothing here is copied from them: tool names, one-line
+descriptions, cost flags and links are catalogue facts, and the method and commentary are
+this site's own. See [credits](/credits).
diff --git a/src/content/sheets/osint/data-analysis-and-visualisation.md b/src/content/sheets/osint/data-analysis-and-visualisation.md
@@ -0,0 +1,150 @@
+---
+title: "Data Analysis & Visualisation"
+description: "Clean messy collected data, map relationships between entities, build timelines, and publish a figure people can read."
+category: osint
+subcategory: "Archiving & Analysis"
+tags: [osint, analysis, visualisation, graphs, timelines]
+tools: [openrefine, gephi, datasette, datawrapper, qgis]
+difficulty: intermediate
+updated: 2026-09-28
+references:
+ - name: "Bellingcat's Online Investigation Toolkit"
+ url: "https://bellingcat.gitbook.io/toolkit"
+ author: "Bellingcat"
+ license: none
+ relation: derived
+ note: "Tool catalogue: names, descriptions, cost flags and links for this area."
+ - name: "OSINT Newsletter Tools Library"
+ url: "https://tools.osintnewsletter.com"
+ author: "The OSINT Newsletter"
+ license: none
+ relation: derived
+ note: "Second tool catalogue, cross-checked against the above."
+---
+
+## What this covers
+
+The part after collection. Thousands of rows of scraped posts, a list of company officers, a set of
+geotagged images — none of it means anything until it is cleaned, related and shown. Analysis is
+also where most errors enter an investigation, because a chart makes a weak claim look strong.
+
+## Cleaning
+
+Collected data is always dirty: inconsistent name spellings, mixed date formats, duplicate entities
+under slightly different labels.
+
+**OpenRefine** is the right tool and is underused. Its clustering function finds values that are
+probably the same thing — `Jon Smith`, `John Smith`, `SMITH, John` — and lets you merge them in one
+pass. Do this before any counting, or your counts are wrong.
+
+For anything scriptable, pandas:
+
+```python
+import pandas as pd
+
+df = pd.read_csv("collected.csv")
+df["date"] = pd.to_datetime(df["date"], errors="coerce", utc=True)
+df["name"] = df["name"].str.strip().str.casefold()
+df = df.drop_duplicates(subset=["name", "date"])
+
+# what did parsing fail on? this is where silent data loss hides
+print(df["date"].isna().sum(), "unparseable dates")
+```
+
+Always check what failed to parse. Rows silently dropped by a coercion are the classic way a
+dataset ends up telling you the wrong thing.
+
+## Relationships
+
+**Gephi** for network graphs — people, companies, accounts and the edges between them. The useful
+outputs are usually degree (who is most connected), betweenness (who bridges otherwise separate
+clusters) and modularity (what the communities are). Force-directed layouts look impressive and say
+little on their own; the metrics are the finding.
+
+**Maltego** automates collection *into* a graph via transforms, which is convenient but ties you to
+its data sources.
+
+For a company-ownership chain, a graph is usually overkill — a simple parent/subsidiary tree is
+clearer and harder to misread.
+
+## Querying
+
+**Datasette** turns a SQLite file into a browsable, queryable, publishable web interface. It is the
+fastest route from "I have a CSV" to "colleagues can explore this".
+
+```bash
+pipx install datasette sqlite-utils
+
+sqlite-utils insert data.db records collected.csv --csv
+datasette data.db
+datasette publish vercel data.db --project my-investigation
+```
+
+`sqlite-utils` alone is worth learning — it handles the CSV-to-database step that otherwise eats an
+afternoon.
+
+## Timelines and maps
+
+- **[Time.Graphics](https://time.graphics/)** — quick shareable timelines.
+- **[Pinpoint](https://journaliststudio.google.com/pinpoint/)** — OCR and entity extraction across
+ large document sets; finds names and places across thousands of scanned pages.
+- **QGIS** — for anything where position matters. See
+ [Maps & Satellite Imagery](/sheets/osint/maps-and-satellite-imagery).
+
+## Publishing figures
+
+**Datawrapper** produces clean, accessible, responsive charts and maps with almost no effort, and
+handles the things hand-rolled charts get wrong — colour-blind-safe palettes, mobile layout, proper
+axis labelling. **RAWGraphs** covers the less common chart types.
+
+Whatever you use: label the axes, state the source, show the sample size, and do not start a bar
+chart's axis anywhere but zero.
+
+## Tool reference
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [4CAT](https://4cat.nl/) | 4CAT is a tool designed for the easy collection and analysis of online datasets. It allows researchers to uncover patterns and trends in data from social… | free |
+| [Atlos](https://www.atlos.org/) | ATLOS is a platform for collaborative and large-scale open source investigations. | partly free |
+| [Blender](https://www.blender.org/) | Blender is an open-source 3D creation suite supporting the 3D pipeline—modeling, rigging, animation, simulation, rendering, compositing, and motion… | free |
+| [Datasette](https://datasette.io) | Open-source “WordPress-for-data” that turns any SQLite database into an interactive website and JSON API in seconds; ideal for publishing, exploring and… | free |
+| [Datawrapper](https://www.datawrapper.de/) | A tool for creating interactive charts, maps, and tables from your data, offering a user-friendly interface for visualizing information. | partly free |
+| [Gephi](https://gephi.org) | Open-source network analysis and visualization software | free |
+| [Logseq](https://logseq.com/) | Logseq is an open-source knowledge management tool that enables users to organize their notes, tasks, and projects. | free |
+| [Maltego Graph](https://www.maltego.com/downloads/) | Maltego Graph is an investigation platform that combines two things at once: (1) It acts as a search tool, and (2) It creates a graph establishing links… | partly free |
+| [Obsidian](https://obsidian.md/) | A knowledge management and note-taking app with extensive customization options. | partly free |
+| [Pinpoint](https://journaliststudio.google.com/pinpoint/about) | A tool by Google to catalogue uploaded documents and files, providing automated text recogntion, indexing, audiotranscriptions and other (AI-powered)… | free |
+| [QGIS](https://www.qgis.org) | QGIS is a free Open Source Geographic Information System (GIS). | free |
+| [RAWGraphs](https://app.rawgraphs.io/) | RAWGraphs is an open-source data visualization tool designed for non-technical users, enabling the creation of customizable, editable charts without… | free |
+| [Time.Graphics](https://time.graphics) | A tool for creating, visualizing, and managing timelines online. | partly free |
+
+## Pitfalls
+
+- **Cleaning changes findings.** Every merge and exclusion is a judgement. Write down what you did;
+ an undocumented cleaning step is an unreproducible result.
+- **Correlation in a graph is not connection.** Two accounts posting the same link are not
+ necessarily related.
+- **Missing data looks like absence.** A collection gap renders as a quiet period. Mark known gaps
+ on any timeline.
+- **Pretty visualisations oversell weak data.** The more convincing the figure, the more carefully
+ the caveats need stating.
+- **Small numbers do not support percentages.** "50% increase" on a base of four is noise.
+
+## Broader catalogues
+
+- [Data Extraction OSINT](https://tools.osintnewsletter.com/tool-categories/data-extraction-osint)
+- [Language Translation OSINT](https://tools.osintnewsletter.com/tool-categories/language-translation-osint)
+
+
+## Sources
+
+Both catalogues below are maintained by other people and are considerably larger than
+this page. Use them as the canonical index; this sheet is a working route through them.
+
+- [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
+ review page covering cost, difficulty, requirements and limitations.
+- [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
+
+Neither publishes a licence, so nothing here is copied from them: tool names, one-line
+descriptions, cost flags and links are catalogue facts, and the method and commentary are
+this site's own. See [credits](/credits).
diff --git a/src/content/sheets/osint/email-and-phone.md b/src/content/sheets/osint/email-and-phone.md
@@ -0,0 +1,154 @@
+---
+title: "Email & Phone Number OSINT"
+description: "Validate an address or number, find the accounts attached to it, and pivot to a name — without alerting the owner."
+category: osint
+subcategory: "People & Identity"
+tags: [osint, email, phone, pivoting]
+tools: [epieos, ghunt, holehe, phoneinfoga]
+difficulty: intermediate
+updated: 2026-09-28
+references:
+ - name: "Bellingcat's Online Investigation Toolkit"
+ url: "https://bellingcat.gitbook.io/toolkit"
+ author: "Bellingcat"
+ license: none
+ relation: derived
+ note: "Tool catalogue: names, descriptions, cost flags and links for this area."
+ - name: "OSINT Newsletter Tools Library"
+ url: "https://tools.osintnewsletter.com"
+ author: "The OSINT Newsletter"
+ license: none
+ relation: derived
+ note: "Second tool catalogue, cross-checked against the above."
+---
+
+## What this covers
+
+An email address or phone number is usually the strongest pivot in an investigation, because
+platforms treat them as account keys. From one address you can often reach a display name, a
+profile photo, a set of registered services and sometimes a physical location.
+
+## Method
+
+1. **Validate before enriching.** Confirm the address or number is real and routable. Time spent
+ enriching a typo is wasted.
+2. **Check what it is registered to.** Account-existence checks against signup and
+ password-reset flows reveal which services know the identifier.
+3. **Pull provider-side metadata.** Google accounts in particular leak a display name, a profile
+ photo, and public calendar and review activity.
+4. **Pivot outward.** Search the identifier as a plain string — in code search, paste sites,
+ breach indexes and the target's own site. Addresses get committed to repositories constantly.
+5. **Convert to a name, then switch approach.** Once you have a name, you are doing
+ [people search](/sheets/osint/people-search), not identifier work.
+
+## Email
+
+### Epieos
+
+The first tool to reach for. Given an address it returns Google and Microsoft account data,
+linked services, and gravatar hits, without sending anything to the address.
+
+Enter the address at [epieos.com](https://epieos.com/). No notification reaches the owner.
+
+### GHunt
+
+Deeper on Google specifically: account ID, display name, profile photo history, public Maps
+reviews and photos, YouTube channel, and calendar if public.
+
+```bash
+pipx install ghunt
+ghunt login # needs your own Google session cookies
+
+ghunt email target@gmail.com
+ghunt gaia 1234567890123456789 # pivot on the internal Google account ID
+```
+
+`ghunt login` requires authenticating with an account you control — use a throwaway, because
+this is exactly the kind of automation Google suspends accounts for.
+
+### holehe
+
+Checks an address against 100+ sites by watching how their password-reset and registration flows
+respond.
+
+```bash
+pipx install holehe
+holehe target@example.com
+holehe target@example.com --only-used
+```
+
+**This one is not passive.** Some providers email the address to say a reset was attempted. Know
+that before you run it on a live target.
+
+### Verification and syntax
+
+Use a validator to confirm deliverability and to spot disposable domains before you invest effort.
+`metadata2go`, Email Checker and similar services cover this. An MX lookup on the domain is the
+quick manual version:
+
+```bash
+dig +short MX example.com
+```
+
+## Phone
+
+### PhoneInfoga
+
+Format normalisation, carrier and line-type identification, and footprint searching for a number.
+
+```bash
+pipx install phoneinfoga
+phoneinfoga scan -n "+14155550123"
+phoneinfoga serve # local web UI
+```
+
+### Caller-ID and directory databases
+
+Crowd-sourced caller-ID apps hold name data for numbers that appear nowhere else, because their
+users uploaded their own address books.
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [TrueCaller](https://www.truecaller.com/) | Large crowd-sourced caller-ID database. Names come from other users' contact lists, so accuracy varies and the entry may be a nickname. | partly free |
+| [GetContact](https://www.getcontact.com/) | Same model, stronger coverage across Turkey, the Middle East and Central Asia. | partly free |
+| [ThisNumber](https://www.thisnumber.com/) | International phone directory listings. | free |
+| [NigeriaPhonebook](https://nigeriaphonebook.com/) | Nigerian number-to-name lookups. | free |
+
+Searching a number in these apps can be visible to other users of the same app, and uploading a
+contact list to get access hands over everyone in your phone. Use a clean device.
+
+### Messaging-app checks
+
+Many messengers confirm whether a number is registered, and often expose a profile photo and
+status. Adding the number as a contact may make you visible to them — check the platform's
+behaviour before you do it on a target who might notice.
+
+## Pitfalls
+
+- **Reset-flow probing is active.** holehe and similar tools can generate mail to the target.
+ Passive-only work means Epieos, GHunt and string searching, nothing that touches a login flow.
+- **Caller-ID names are user-submitted.** "John Smith Plumber" may be what one stranger saved the
+ number as years ago.
+- **Recycled numbers.** Carriers reissue numbers after a few months of disuse, so an old
+ registration may belong to someone unrelated.
+- **Catch-all domains** accept every address, so "the address exists" is meaningless on them.
+- **Aggregated identifiers age badly.** An address that reached someone in 2019 may be dead now.
+
+## Broader catalogues
+
+- [Email Address OSINT](https://tools.osintnewsletter.com/tool-categories/email-address-osint)
+- [Phone Number OSINT](https://tools.osintnewsletter.com/tool-categories/phone-number-osint)
+
+
+## Sources
+
+Both catalogues below are maintained by other people and are considerably larger than
+this page. Use them as the canonical index; this sheet is a working route through them.
+
+- [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
+ review page covering cost, difficulty, requirements and limitations.
+- [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
+
+Neither publishes a licence, so nothing here is copied from them: tool names, one-line
+descriptions, cost flags and links are catalogue facts, and the method and commentary are
+this site's own. See [credits](/credits).
diff --git a/src/content/sheets/osint/geolocation.md b/src/content/sheets/osint/geolocation.md
@@ -0,0 +1,124 @@
+---
+title: "Geolocation & Chronolocation"
+description: "Work out where a photo was taken, and when, from shadows, sun position, terrain and visible detail."
+category: osint
+subcategory: "Geospatial"
+tags: [osint, geolocation, chronolocation, shadows, verification]
+tools: [suncalc, shadowmap, geohints, qgis]
+difficulty: advanced
+updated: 2026-09-28
+references:
+ - name: "Bellingcat's Online Investigation Toolkit"
+ url: "https://bellingcat.gitbook.io/toolkit"
+ author: "Bellingcat"
+ license: none
+ relation: derived
+ note: "Tool catalogue: names, descriptions, cost flags and links for this area."
+ - name: "OSINT Newsletter Tools Library"
+ url: "https://tools.osintnewsletter.com"
+ author: "The OSINT Newsletter"
+ license: none
+ relation: derived
+ note: "Second tool catalogue, cross-checked against the above."
+---
+
+## What this covers
+
+Placing an image on the earth and in time without metadata. This is the discipline OSINT is best
+known for and the most labour-intensive thing in it: a hard geolocation is hours of work, not
+minutes.
+
+## Method
+
+1. **Inventory the frame.** List everything identifiable: road markings, utility pole design,
+ plug sockets, licence-plate format, language and script on signage, vegetation, kerb style,
+ architecture, mountain profile.
+2. **Narrow the region.** Those details constrain the country or region long before they give you a
+ point. Pole and bollard design alone often gets you to a handful of countries.
+3. **Find a searchable anchor.** A business name, a phone number on a van, a street name, a bus
+ route number. One readable sign collapses the search.
+4. **Match terrain.** Mountain ridgelines are effectively fingerprints and are visible from far
+ away. Compare against a terrain viewer.
+5. **Confirm with imagery.** Satellite and street view, ideally from the era of the photo. Check
+ building footprints, not just the general scene.
+6. **Chronolocate.** Shadow direction and length plus a known position gives you a time of day and
+ a range of dates.
+
+## Shadow and sun work
+
+Given a location and a date, the sun's position is exactly calculable — so a shadow in a photo
+constrains the time it was taken, and if you know the time it constrains the date.
+
+| Tool | What it does |
+| --- | --- |
+| [SunCalc](https://suncalc.org/) | Sun position, shadow direction and length for any place, date and time. The workhorse. |
+| [ShadowMap](https://shadowmap.org/) | 3D buildings with cast shadows rendered at a chosen time. |
+| [ShadeMap](https://shademap.app/) | Global shadow simulation including terrain and trees. |
+| [Shadow Finder](https://github.com/bellingcat/ShadowFinder) | Inverts the problem: given shadow length and a timestamp, maps every point on earth where that shadow is possible. |
+
+Shadow Finder is the one worth knowing about, because it works when you have *no* candidate
+location:
+
+```bash
+pip install shadowfinder
+shadowfinder --object-height 2 --shadow-length 3.5 \
+ --date-time "2024-06-15 14:30:00"
+```
+
+You need the object's height and its shadow's length in the same units, and a timestamp. It returns
+a band of possible latitudes.
+
+## Visual reference
+
+[GeoHints](https://geohints.com/) catalogues the regional details that narrow a location — bollards,
+traffic lights, road markings, utility poles, licence plates — by country. It was built for
+GeoGuessr and is genuinely the best reference for this step.
+
+[Bellingcat's OpenStreetMap Search](https://osm-search.bellingcat.com/) and
+[Spot](https://spot.bellingcat.com/) both let you search for *relationships* between features —
+"a church within 200m of a bridge over a river" — which is how you turn a described scene into
+candidate coordinates.
+
+## Tool reference
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [Bellingcat OpenStreetMap Search](https://osm-search.bellingcat.com/) | A user interface to search OpenStreetMap data for features in proximity to each other. | free |
+| [GeoHints](https://geohints.com/) | GeoHints is a website that provides information about things like traffic lights, utility poles, bollards etc. for different regions of the world to help… | free |
+| [GeoNames](http://www.geonames.org/) | The GeoNames geographical database covers all countries and contains over eleven million place names that are available for download free of charge… | free |
+| [Photo-Map.RU](http://photo-map.ru/) | Geotagged VK posts. | free |
+| [ShadeMap](https://shademap.app) | ShadeMap is a global simulation of mountain, building & tree shadows for a given date & time. Base data is free, but users can buy 30cm accurate data per… | partly free |
+| [Shadow Finder](https://github.com/bellingcat/ShadowFinder) | To analyse shadows in source imagery, Shadow Finder maps all points on the earth where a shadow of given length could occur at a given date & time, IF the… | free |
+| [ShadowMap](https://app.shadowmap.org/) | Global map of 3D buildlings and the shadows they cast at a specific time a day | free |
+| [Spot](https://www.findthatspot.io/) | A natural language interface for querying the OpenStreetMap database to find locations which meet the search criteria described by the user. | free |
+| [SunCalc](https://www.suncalc.org/) | Suncalc models the relationship between the date, time of day, the geographic location of a place, and the position of the sun in the sky, together with… | free |
+
+## Pitfalls
+
+- **Satellite imagery has a date.** A building present in the photo and absent from imagery may
+ simply be newer, or demolished. Check the capture date and look for historical imagery.
+- **Terrain matching defeats you at low elevation.** Flat terrain has no ridgeline to match.
+- **Shadow work needs the true timezone**, including DST, and the analysis is only as good as your
+ measurement of the shadow.
+- **Publishing a precise location endangers people.** For conflict imagery especially, consider
+ whether the coordinates need to be public.
+- **Plausible is not confirmed.** A location that fits is a hypothesis. Confirmation means a
+ specific feature matching in a specific place.
+
+## Broader catalogues
+
+- [Geolocation and Maps OSINT](https://tools.osintnewsletter.com/tool-categories/geolocation-and-maps-osint)
+
+
+## Sources
+
+Both catalogues below are maintained by other people and are considerably larger than
+this page. Use them as the canonical index; this sheet is a working route through them.
+
+- [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
+ review page covering cost, difficulty, requirements and limitations.
+- [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
+
+Neither publishes a licence, so nothing here is copied from them: tool names, one-line
+descriptions, cost flags and links are catalogue facts, and the method and commentary are
+this site's own. See [credits](/credits).
diff --git a/src/content/sheets/osint/image-video-forensics.md b/src/content/sheets/osint/image-video-forensics.md
@@ -0,0 +1,145 @@
+---
+title: "Image & Video Forensics"
+description: "Read a file's metadata, test it for manipulation, and work out what the camera and encoder can tell you."
+category: osint
+subcategory: "Images & Video"
+tags: [osint, forensics, metadata, exif, verification]
+tools: [exiftool, ffprobe, fotoforensics, forensically]
+difficulty: intermediate
+updated: 2026-09-28
+references:
+ - name: "Bellingcat's Online Investigation Toolkit"
+ url: "https://bellingcat.gitbook.io/toolkit"
+ author: "Bellingcat"
+ license: none
+ relation: derived
+ note: "Tool catalogue: names, descriptions, cost flags and links for this area."
+ - name: "OSINT Newsletter Tools Library"
+ url: "https://tools.osintnewsletter.com"
+ author: "The OSINT Newsletter"
+ license: none
+ relation: derived
+ note: "Second tool catalogue, cross-checked against the above."
+---
+
+## What this covers
+
+What the file itself says, as distinct from what its caption says. Metadata gives you camera, time
+and sometimes location; encoder artefacts tell you about the processing history; manipulation
+analysis suggests where to look harder. None of it is proof on its own, and all of it is easy to
+over-read.
+
+## Metadata
+
+`exiftool` is the tool. Everything else is a wrapper.
+
+```bash
+# everything, grouped by tag family
+exiftool -a -G1 -s image.jpg
+
+# the fields that usually matter
+exiftool -Make -Model -DateTimeOriginal -CreateDate -GPSLatitude -GPSLongitude \
+ -Software -Orientation image.jpg
+
+# GPS as a decimal pair you can paste into a map
+exiftool -n -p '$GPSLatitude,$GPSLongitude' image.jpg
+
+# recurse a directory into CSV for comparison across a set
+exiftool -r -csv -Make -Model -DateTimeOriginal -GPSPosition ./images/ > meta.csv
+
+# strip metadata before publishing (protect your own sources)
+exiftool -all= -overwrite_original copy.jpg
+```
+
+Reading it:
+
+- **`Make` / `Model`** should match the claimed device. A "phone photo" carrying a DSLR model is a
+ contradiction worth chasing.
+- **`Software`** naming an editor means the file was processed. That is not manipulation, but it
+ means what you have is not the original.
+- **Timestamps** come from the camera clock, which is often wrong and usually has no timezone.
+ `DateTimeOriginal` is capture; `CreateDate` and `ModifyDate` may be later.
+- **GPS** is genuinely useful when present. It is also the first thing platforms strip.
+- **Missing metadata is the normal case**, not a red flag. Every major platform strips EXIF on
+ upload. Absence tells you it went through a platform, nothing more.
+
+## Video
+
+```bash
+# full stream and container metadata
+ffprobe -v quiet -print_format json -show_format -show_streams video.mp4
+
+# creation time and encoder, which often identify the app that produced the file
+ffprobe -v quiet -show_entries format_tags=creation_time,encoder -of default=nw=1 video.mp4
+
+# frame-level detail: is the frame rate constant, are there splice points
+ffprobe -select_streams v -show_frames -show_entries frame=pkt_pts_time,pict_type \
+ -of csv video.mp4 | head -50
+```
+
+Encoder strings are a strong fingerprint of the producing application. A file claiming to be
+straight off a phone but carrying a desktop editor's encoder has been through an edit.
+
+## Manipulation analysis
+
+| Tool | What it does |
+| --- | --- |
+| [FotoForensics](https://fotoforensics.com/) | Error Level Analysis, JPEG quality estimation, metadata. Note that it publicly retains uploads — do not use it on sensitive material. |
+| [Forensically](https://29a.ch/photo-forensics/) | Clone detection, noise analysis, level sweep, magnifier. Runs client-side in the browser, so nothing is uploaded. |
+| [Reveal Image Verification Assistant](https://mever.iti.gr/forensics/) | Multiple filters in one pass, with a report. |
+| [Jimpl](https://jimpl.com/) | Quick browser-based EXIF and GPS viewer. |
+| [xIFr](https://xifr.eu/) | Detailed EXIF viewer including maker notes. |
+
+**ELA is widely over-interpreted.** Differing compression across regions has many innocent causes —
+resizing, text overlay, successive saves. Treat ELA as "look here", never as "this is fake".
+
+For anything sensitive, prefer the client-side tools. Uploading a source's photo to a public
+analysis site that retains submissions can expose them.
+
+## Tool reference
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [Am I Real?](https://seintpl.github.io/AmIReal/) | A simple online tool that allows users to check whether a photo might have been generated by ThisPersonDoesNotExist.com. | free |
+| [AutoStitch](https://mattabrown.github.io/autostitch.html) | Autostitch is a free tool for seamlessly combining multiple photos into a single panoramic image, making it ideal for creating wide-angle photography… | free |
+| [Cleanup.Pictures](https://cleanup.pictures/) | Web tool for quickly removing objects from an image. | free |
+| [DeepFake-O-Meter](https://zinc.cse.buffalo.edu/ubmdfl/deep-o-meter/) | DeepFake-O-Meter is an online tool designed to detect deepfake media and help users differentiate between genuine and manipulated content. | free |
+| [ExifPurge](http://www.exifpurge.com/) | EXIF Purge is a small portable application to remove EXIF metadata from multiple images at once. With the click of a button you can remove the camera… | free |
+| [fdupes](https://github.com/adrianlopezroche/fdupes) | Github - Locating exact matches of duplicate files. | free |
+| [Forensically](https://29a.ch/photo-forensics/#forensic-magnifier) | A collection of web-based image forensics tools. Can identify fake or doctored images. | free |
+| [FotoForensics](http://fotoforensics.com/) | Image forensics tool. | free |
+| [Hugin](https://hugin.sourceforge.io/) | Hugin is a free and open-source panorama photo stitching and HDR (High Dynamic Range imaging) merging software that helps users create seamless panoramic… | free |
+| [InVID](https://weverify.eu/verification-plugin/) | A toolkit that supports the verification of videos and images. | free |
+| [Irfanview](http://irfanview.com/) | Windows-based software to extract metadata. | free |
+| [Jimpl](https://jimpl.com/) | Online EXIF data viewer | free |
+| [metadata2go](https://www.metadata2go.com/) | Check metadata for both photos and videos online. | free |
+| [PureRef](https://www.pureref.com/index.php) | Image workspace; lets you arrange images in groups, organize them, etc. | free |
+| [Reveal Image Verification Assistant](https://www.rand.org/research/projects/truth-decay/fighting-disinformation/search/items/reveal-image-verification-assistant.html) | Forensic providing eight filters to detect still images alterations. "Web-based image tool. Also available within InVID verification plugin." | free |
+| [xIFr](https://addons.mozilla.org/en-US/firefox/addon/xifr/) | A Firefox add-on for extracting EXIF metadata by right-clicking an image. | free |
+
+## Pitfalls
+
+- **Metadata is trivially forged.** `exiftool` writes as easily as it reads. Metadata that supports
+ a claim is weak evidence; metadata that contradicts one is a lead.
+- **Platform stripping destroys the evidence** you want. Always ask for the original file.
+- **Clock error is normal.** Do not build a timeline on an unverified camera timestamp.
+- **Facial recognition on found images** raises real risk of misidentifying someone. Corroborate
+ before acting, and consider whether identification is necessary at all.
+
+## Broader catalogues
+
+- [Image and Video Analysis OSINT](https://tools.osintnewsletter.com/tool-categories/image-and-video-analysis-osint)
+
+
+## Sources
+
+Both catalogues below are maintained by other people and are considerably larger than
+this page. Use them as the canonical index; this sheet is a working route through them.
+
+- [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
+ review page covering cost, difficulty, requirements and limitations.
+- [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
+
+Neither publishes a licence, so nothing here is copied from them: tool names, one-line
+descriptions, cost flags and links are catalogue facts, and the method and commentary are
+this site's own. See [credits](/credits).
diff --git a/src/content/sheets/osint/maps-and-satellite-imagery.md b/src/content/sheets/osint/maps-and-satellite-imagery.md
@@ -0,0 +1,190 @@
+---
+title: "Maps, Satellite & Street-Level Imagery"
+description: "Choose the right imagery source for the question, find historical coverage, and work with the data in QGIS."
+category: osint
+subcategory: "Geospatial"
+tags: [osint, satellite, maps, gis, street-view]
+tools: [qgis, google-earth-pro, sentinel-hub, openstreetmap]
+difficulty: intermediate
+updated: 2026-09-28
+references:
+ - name: "Bellingcat's Online Investigation Toolkit"
+ url: "https://bellingcat.gitbook.io/toolkit"
+ author: "Bellingcat"
+ license: none
+ relation: derived
+ note: "Tool catalogue: names, descriptions, cost flags and links for this area."
+ - name: "OSINT Newsletter Tools Library"
+ url: "https://tools.osintnewsletter.com"
+ author: "The OSINT Newsletter"
+ license: none
+ relation: derived
+ note: "Second tool catalogue, cross-checked against the above."
+---
+
+## What this covers
+
+Which imagery to use, how to get at older coverage, and the street-level sources beyond Google.
+The main skill is matching the source to the question — resolution, revisit frequency and archive
+depth trade off against each other and no single provider wins on all three.
+
+## Choosing a source
+
+| Question | Source |
+| --- | --- |
+| What does this place look like in detail? | Google Earth Pro, Esri World Imagery — sub-metre, but infrequent |
+| What changed between two dates? | Sentinel-2 (5-day revisit, 10m), Landsat (16-day, 30m, back to 1972) |
+| What did it look like years ago? | Google Earth Pro's historical slider, Landsat archive |
+| Was there a fire / flood / new construction? | Sentinel-2 false-colour composites |
+| What is at street level? | Google Street View, Mapillary, KartaView, Yandex Panoramas |
+| What features exist here, as data? | OpenStreetMap via Overpass |
+
+Free high-cadence optical imagery bottoms out around 10m per pixel. Anything finer is commercial
+and usually costs real money, so plan around Sentinel for change detection and reserve high-res for
+confirming a specific thing.
+
+## Historical imagery
+
+**Google Earth Pro** is free desktop software and its historical imagery slider is the most
+accessible archive of high-resolution coverage. Note the imagery date shown at the bottom — it is
+the single most important piece of context and the most commonly ignored.
+
+**Landsat** goes back to 1972 and is the only free option for multi-decade change. Browse it via
+[EarthExplorer](https://earthexplorer.usgs.gov/) or Sentinel Hub's Playground.
+
+## Street-level beyond Google
+
+Google's coverage is deep but not universal, and its capture dates are sometimes years old:
+
+- **Mapillary** — crowd-sourced, often covers roads Google skipped, frequently more recent.
+- **KartaView** — similar model, strong in parts of Europe.
+- **Yandex Panoramas** — the best coverage across Russia and Central Asia by a wide margin.
+- **Baidu Total View** — mainland China.
+
+Always check several; a street with no Google coverage often has Mapillary imagery.
+
+## OpenStreetMap as a database
+
+OSM is queryable, which makes it far more powerful than its rendered map suggests. Overpass
+Turbo takes queries like:
+
+```text
+[out:json][timeout:25];
+// every pharmacy within the bounding box
+node["amenity"="pharmacy"]({bbox});
+out body geom;
+```
+
+```text
+[out:json][timeout:25];
+// bridges over waterways in the area — useful for matching a described scene
+way["bridge"="yes"]({bbox});
+out geom;
+```
+
+For relationship searches without writing Overpass by hand, use Bellingcat's OpenStreetMap Search
+or Spot, which wrap the same data in a proximity-search interface.
+
+## QGIS
+
+The free desktop GIS, and what you want once a question involves more than looking. Typical OSINT
+uses: loading satellite basemaps as XYZ tiles, georeferencing a photograph or a scanned map against
+known points, measuring distances and bearings, and building a map for publication.
+
+Add an XYZ basemap with Layer → Add Layer → Add XYZ Layer, for example Esri World Imagery:
+
+```text
+https://server.arcgisonline.com/ArcGIS/rest/services/World_Imagery/MapServer/tile/{z}/{y}/{x}
+```
+
+## Tool reference
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [Apple Maps](https://maps.apple.com) | Apple Maps is a digital mapping service with detailed maps, satellite imagery, and location-based information. | free |
+| [Baidu Maps](http://map.baidu.com/) | Baidu’s mapping service offering satellite imagery, street maps, and streetview (“Panorama” - zh:百度全景). | free |
+| [Bellingcat OpenStreetMap Search](https://osm-search.bellingcat.com/) | A user interface to search OpenStreetMap data for features in proximity to each other. | free |
+| [Bing Maps](https://www.bing.com/maps/) | Bing Maps is a web mapping service provided by Microsoft that offers detailed geographical information and tools for location search, and satellite… | partly free |
+| [Carte.ma](http://carte.ma/) | Mapping/streetview service for Morocco | free |
+| [Convert Geographic Units](http://rcn.montana.edu/resources/Converter.aspx) | A tool that converts various geographic coordinates to support diverse mapping and spatial analysis needs. | free |
+| [Copernicus Browser (formerly Sentinel Hub Playground, EO Browser)](https://browser.dataspace.copernicus.eu/) | A free web-based platform for viewing, analyzing, and downloading satellite imagery from the European Space Agency's Sentinel missions, with data updated… | free |
+| [EarthExplorer](https://earthexplorer.usgs.gov/) | EarthExplorer is an archive portal from the U.S. Geological Survey (USGS) that allows users search a location and time range to discover and access… | partly free |
+| [EOS Landviewer](http://eos.com/landviewer) | EOS Landviewer provides free services for up to 10 images. More images and analysis are available to journalists at a discount. Contact: Artem Seredyuk… | paid |
+| [F4Map](https://demo.f4map.com) | F4Map is an interactive 3D map visualization tool that provides detailed rendering of urban landscapes and geographical features. | free |
+| [Gaode Maps](https://amap.com) | Gaode Maps (also known as AMap) is a mapping application and technology from the Chinese company Alibaba. | free |
+| [GeoHints](https://geohints.com/) | GeoHints is a website that provides information about things like traffic lights, utility poles, bollards etc. for different regions of the world to help… | free |
+| [Gjirafa](https://gjirafa.biz/) | Mapping service for Albania (specially Kosovo) | free |
+| [Global Forest Watch](https://www.globalforestwatch.org/map/) | Explore tree cover loss and gain data, recent deforestation and fire alerts, land use designations, carbon emissions, biodiversity metrics and more. | free |
+| [Google Earth Engine](https://code.earthengine.google.com/) | Google Earth Engine is a platform for environmental monitoring, land use change and object/infrastructure detection through satellite imagery and… | free |
+| [Google Earth Pro](https://www.google.com/earth/about/versions/) | Google Earth is a geospatial tool that provides detailed, global satellite imagery, maps, 3D terrain models, and the ability to explore geographic data… | partly free |
+| [Google Maps](https://www.google.com/maps) | Google Maps provides mapping information, satellite imagery and Google Street View imagery including historical Street View images. | free |
+| [GovMap](https://www.govmap.gov.il/) | GovMap provides an interactive map of Israel, offering users a wide range of data including property boundaries, planning information, and infrastructure… | free |
+| [HERE WeGo](https://wego.here.com/) | Mapping service similar to Google Maps or Apple Maps. | free |
+| [Hitta.se](https://www.hitta.se/) | Mapping service for Sweden | free |
+| [Index Database](https://www.indexdatabase.de/) | A database which relates remote sensing indices with satellite imaging sensors | free |
+| [Kakao Map](https://map.kakao.com) | A mapping application provided by South Korean technology company Kakao Corp. | free |
+| [KartaView](https://kartaview.org/map) | KartaView is a crowdsourced platform for street view imagery. | free |
+| [Mapa.sk](http://mapa.sk/) | Mapping service for Slovakia | free |
+| [MapChecking](https://www.mapchecking.com/) | This tool helps you estimate and fact-check the maximum number of people standing in a given area. | free |
+| [Mapillary](https://www.mapillary.com/) | Mapillary is a crowdsourced street-level imagery platform. | free |
+| [Mappy](http://en.mappy.com/) | Mapping service (and streetview in a couple of French cities \[double check this!]) | free |
+| [MapSwitcher](https://github.com/david-r-edgar/MapSwitcher) | Chrome extension switches between online map apps, maintaining (as far as possible) the map centre, zoom level, & directions of the source map. | free |
+| [mapy.cz](http://mapy.cz) | Mapping service for Czechia | free |
+| [Maritime Awareness Project](https://map.nbr.org/interactivemap/) | South China Sea maps with oil and gas fields, fishing areas, air defense zones and administrative, claimed, disputed zones, submarine data cables. | free |
+| [NASA FIRMS](https://firms2.modaps.eosdis.nasa.gov/map/) | Displays a world map overlaid with infra-red data from one or more satellites, some, but not all of which may represent heat from fires and explosions. | free |
+| [NASA Worldview](https://worldview.earthdata.nasa.gov/) | NASA Worldview is an online tool for visualizing and downloading near real-time satellite imagery and scientific data of Earth's atmosphere, land, and… | free |
+| [OpenAerialMap](https://openaerialmap.org/) | Platform for accessing open-licensed satellite and unmanned aerial vehicle (UAV) imagery | free |
+| [OpenInfraMap](https://openinframap.org/#2/26/12) | Power lines, telecoms, solar, oil, gas & water infrastructure mapped globally. | free |
+| [OpenSeaMap](https://map.openseamap.org/) | Sea map of borders, special zones, shipping lanes, with overlays of MarineTraffic and other sources | free |
+| [OpenStreetMap](http://openstreetmap.org/) | OpenStreetMap is a collaborative project to create a free editable map of the world. | free |
+| [OrbTrack](https://www.orbtrack.org) | Predicts & describes the position & path of >15,000 satellites in Earth orbit, relative to points on the earth's surface input by the user, for 5 days… | free |
+| [Overpass Turbo](https://overpass-turbo.eu/) | Overpass Turbo is a web-based tool for querying and visualizing OpenStreetMap crowd sourced data, aiding in extracting specific information like locations… | free |
+| [PeakVisor](https://peakvisor.com/) | Dual window views for any global location: (1) a 2-D map & (2) a 3-D rendered terrain model, with photo fitting, shade/slope mapping, sun trails & weather… | free |
+| [Photo-Map.RU](http://photo-map.ru/) | Geotagged VK posts. | free |
+| [Planet Labs](https://www.planet.com/) | Planet Labs PBC is an American optical satellite imagery company that sells access to imagery. | partly free |
+| [QGIS](https://www.qgis.org) | QGIS is a free Open Source Geographic Information System (GIS). | free |
+| [Quick geolocation search](https://cybdetective.com/quickgeolocationsearch.html) | A tool that brings several maps into one place for easy location search. | free |
+| [Radar Interference Tracker (RIT)](https://ollielballinger.users.earthengine.app/view/bellingcat-radar-interference-tracker#lon=49.9507;lat=26.6056;zoom=4) | Bellingcat's radar interference tracker can be used to locate and monitor active military radar systems. | free |
+| [RAMMB SLIDER](https://rammb-slider.cira.colostate.edu/) | Real-time weather satellites of the entire globe | free |
+| [Satellites.pro](https://satellites.pro/) | Satellites.pro allows open source researchers to quickly switch between several free satellite imagery and mapping services. | free |
+| [ShadeMap](https://shademap.app) | ShadeMap is a global simulation of mountain, building & tree shadows for a given date & time. Base data is free, but users can buy 30cm accurate data per… | partly free |
+| [ShadowMap](https://app.shadowmap.org/) | Global map of 3D buildlings and the shadows they cast at a specific time a day | free |
+| [SkyFi](https://skyfi.com/) | SkyFi is used to purchase commercial satellite imagery and task (order the collection of images) satellites without a subscription. | paid |
+| [Strava](https://www.strava.com) | A fitness tracking platform where publicly shared GPS activity data can reveal movement patterns, routines, and precise locations of individuals… | partly free |
+| [Tencent Maps](http://map.qq.com/) | Tencent Maps (formerly SOSO Maps) is a desktop and web mapping service application and technology provided by Chinese company Tencent, offering satellite… | free |
+| [The European Space Agency (ESA) - Earth Online](https://earth.esa.int/eogateway/tools) | The ESA's Earth Online product offers a portal for accessing satellite imagery and environmental data, supporting a range of applications from climate… | free |
+| [Topotijdreis.nl](http://topotijdreis.nl) | Over 200 years of maps and topography from the Netherlands. | free |
+| [Umbra Space](https://umbra.space/) | Umbra is an American synthetic aperture radar (SAR) satellite imaging company that sells on-demand taskings for satellite imagery. | paid |
+| [UTM grid zones](http://dmap.co.uk/utmworld.htm) | An overview of the Universal Transverse Mercator coordinate system. | free |
+| [what3words](http://what3words.com/) | A proprietary geocode system which identifies any location on the surface of the earth to a resolution of 3 metres. The identifier is a unique combination… | partly free |
+| [Wikimapia](https://wikimapia.org/) | Wikimapia is a long-running collaborative mapping project that remains partially accessible, providing open source researchers with a unique database of… | free |
+| [Yandex Maps](https://yandex.com/maps/) | A platform offering detailed maps, satellite imagery, street views (static & sometimes dynamic imagery, including aerial views). Often the best available… | partly free |
+| About Maps and Satellites | A guide to using map and satellite tools. | free |
+
+## Pitfalls
+
+- **Undated imagery is useless for a time-sensitive claim.** Record the capture date every time.
+- **Cloud cover ruins optical revisit rates.** A 5-day nominal revisit can mean a month of usable
+ imagery in the wet season. Radar (Sentinel-1) sees through cloud but is much harder to read.
+- **OSM is crowd-sourced.** Completeness varies enormously by region, and an absent feature may
+ simply be unmapped.
+- **Basemap labels disagree**, particularly on disputed borders and place names. Say which source
+ you used.
+
+## Broader catalogues
+
+- [Geolocation and Maps OSINT](https://tools.osintnewsletter.com/tool-categories/geolocation-and-maps-osint)
+
+
+## Sources
+
+Both catalogues below are maintained by other people and are considerably larger than
+this page. Use them as the canonical index; this sheet is a working route through them.
+
+- [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
+ review page covering cost, difficulty, requirements and limitations.
+- [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
+
+Neither publishes a licence, so nothing here is copied from them: tool names, one-line
+descriptions, cost flags and links are catalogue facts, and the method and commentary are
+this site's own. See [credits](/credits).
diff --git a/src/content/sheets/osint/osint-foundations.md b/src/content/sheets/osint/osint-foundations.md
@@ -0,0 +1,115 @@
+---
+title: "OSINT Foundations & Tradecraft"
+description: "How to run an open-source investigation without burning yourself or your case: research accounts, collection hygiene, provenance, and knowing when to stop."
+category: osint
+subcategory: "Foundations"
+tags: [osint, methodology, opsec, verification]
+tools: [hunchly, obsidian, logseq]
+difficulty: beginner
+updated: 2026-09-28
+references:
+ - name: "Bellingcat's Online Investigation Toolkit"
+ url: "https://bellingcat.gitbook.io/toolkit"
+ author: "Bellingcat"
+ license: none
+ relation: derived
+ note: "Tool catalogue: names, descriptions, cost flags and links for this area."
+ - name: "OSINT Newsletter Tools Library"
+ url: "https://tools.osintnewsletter.com"
+ author: "The OSINT Newsletter"
+ license: none
+ relation: derived
+ note: "Second tool catalogue, cross-checked against the above."
+ - name: "Bellingcat — Stay Safe"
+ url: "https://bellingcat.gitbook.io/toolkit/resources/stay-safe"
+ author: "Bellingcat"
+ license: none
+ relation: inspired
+ note: "Operational-safety guidance for investigators."
+---
+
+## What this covers
+
+The habits that decide whether an investigation holds up: how you look at a target without
+telling them, how you record what you found so it survives the page being deleted, and how you
+avoid deciding the answer before you have it. Tooling is the easy part of OSINT. This is the part
+that separates a finding from a guess.
+
+## The rule that matters most
+
+**Every request you make is a signal to the other side.** Viewing a LinkedIn profile notifies its
+owner. Loading a Telegram channel with your real account puts your username in the member list.
+Hitting a small target's website leaves your IP in their logs. A reverse image search on a photo
+that only three people have seen tells those three people someone is looking.
+
+Decide before you start: is this target likely to notice, and does it matter if they do?
+
+## Collection hygiene
+
+1. **Separate identity.** A research browser profile, or better a separate VM, with its own
+ accounts. Never the account you use for anything else. Expect platforms to ban research
+ accounts eventually and do not build anything you cannot lose.
+2. **Capture as you go, not afterwards.** Anything interesting gets archived the moment you see
+ it. Pages disappear, get edited, or go private within hours of someone noticing attention.
+3. **Record the URL, the timestamp, and how you got there.** A screenshot with no source and no
+ date is worth nothing. The path you took to a finding is part of the finding.
+4. **Keep raw separate from conclusions.** One place for what you collected, another for what you
+ think it means. Conflating them is how an assumption becomes a fact three notes later.
+5. **Write down what you looked for and did not find.** Negative results stop you re-running the
+ same dead end next week, and they are what an honest report needs.
+
+## Verification
+
+Treat every claim as unverified until it is pinned to something independent:
+
+- **Where** — does the imagery match satellite, street view, terrain? Are the shadows consistent
+ with the claimed time? See [Geolocation](/sheets/osint/geolocation).
+- **When** — is the content older than the event it supposedly shows? Reverse image search first,
+ every time. See [Reverse Image Search](/sheets/osint/reverse-image-search).
+- **Who** — does the account have history, or was it created last week? Do the same photos appear
+ on other profiles under other names?
+- **What** — is the file original, or a re-encode of a re-encode? See
+ [Image & Video Forensics](/sheets/osint/image-video-forensics).
+
+Two sources that both trace back to the same original post are one source.
+
+## Note-taking and case management
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [Hunchly](https://www.hunch.ly/) | Browser extension that silently captures every page you visit during a case, with hashes and timestamps, and builds a searchable case file. | paid |
+| [Obsidian](https://obsidian.md/) | Local markdown notes with backlinks. Good for entity-per-note investigations where the links between people matter as much as the people. | free |
+| [Logseq](https://logseq.com/) | Outliner-style local notes with daily journals. Suits chronology-heavy work. | free |
+| [Atlos](https://www.atlos.org/) | Purpose-built collaborative platform for visual investigations, with source tracking and multi-investigator review. | free |
+
+## Pitfalls
+
+- **Confirmation lock-in.** Writing the conclusion first and collecting support for it. Ask what
+ evidence would prove you wrong, then go look for that.
+- **Machine translation as fact.** A mistranslated verb changes a claim. Check anything load-bearing
+ with a speaker or a second engine.
+- **Automated tools as authority.** Username enumerators, facial recognition and breach lookups all
+ produce false positives. They generate leads, not findings.
+- **Losing the chain.** If you cannot say where a file came from and when you got it, you cannot
+ use it.
+- **Forgetting the human cost.** Publishing that someone can be located has consequences for them.
+ Minimise what you expose beyond what the finding requires.
+
+## Broader catalogues
+
+- [Foundational OSINT Tools](https://tools.osintnewsletter.com/tool-categories/foundational-osint-tools)
+- [Bellingcat — Guides & Handbooks](https://bellingcat.gitbook.io/toolkit/resources/guides-and-handbooks)
+
+
+## Sources
+
+Both catalogues below are maintained by other people and are considerably larger than
+this page. Use them as the canonical index; this sheet is a working route through them.
+
+- [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
+ review page covering cost, difficulty, requirements and limitations.
+- [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
+
+Neither publishes a licence, so nothing here is copied from them: tool names, one-line
+descriptions, cost flags and links are catalogue facts, and the method and commentary are
+this site's own. See [credits](/credits).
diff --git a/src/content/sheets/osint/people-search.md b/src/content/sheets/osint/people-search.md
@@ -0,0 +1,136 @@
+---
+title: "People Search & Public Records"
+description: "Registries, court records, aggregators and breach data for identifying a person and the records that mention them."
+category: osint
+subcategory: "People & Identity"
+tags: [osint, people, public-records, breach-data]
+tools: [pipl, intelx, dehashed, hibp]
+difficulty: intermediate
+updated: 2026-09-28
+references:
+ - name: "Bellingcat's Online Investigation Toolkit"
+ url: "https://bellingcat.gitbook.io/toolkit"
+ author: "Bellingcat"
+ license: none
+ relation: derived
+ note: "Tool catalogue: names, descriptions, cost flags and links for this area."
+ - name: "OSINT Newsletter Tools Library"
+ url: "https://tools.osintnewsletter.com"
+ author: "The OSINT Newsletter"
+ license: none
+ relation: derived
+ note: "Second tool catalogue, cross-checked against the above."
+---
+
+## What this covers
+
+Finding the records that name a person: civil registries, corporate filings, court dockets,
+electoral rolls, phone books, and the commercial aggregators that resell all of it. Coverage is
+wildly uneven by country, and the aggregators are frequently wrong, so this is an area where
+knowing which source is authoritative matters more than knowing many sources.
+
+## Method
+
+1. **Start with the authoritative registry**, not an aggregator. If a country publishes its company
+ register or land registry, use it — the aggregator is a stale copy with errors added.
+2. **Establish the jurisdiction first.** People-search coverage is national. A US-focused
+ aggregator has close to nothing on a Swedish resident, and Nordic registries are far more open
+ than most.
+3. **Cross-reference two independent sources** before accepting an address, date of birth or
+ relationship. Aggregators copy each other, so two of them agreeing means nothing.
+4. **Pivot through documents.** A court filing names an address, an employer and often relatives.
+ One good document beats twenty aggregator hits.
+5. **Treat breach data as intelligence, not evidence.** It tells you an email existed on a service
+ at some point. It does not tell you who typed it in.
+
+## Regional registries worth knowing
+
+Nordic countries publish personal data that is closed almost everywhere else, which makes them
+unusually productive:
+
+- **Sweden** — [Ratsit](https://www.ratsit.se/), [Hitta.se](https://www.hitta.se/), and the
+ Swedish Name Register give addresses, income brackets and dates of birth.
+- **Norway / Finland / Denmark** — equivalents exist; tax records are partly public in Norway.
+- **Nigeria** — NigeriaPhonebook for telephone-to-name lookups.
+- **United States** — county-level court and property records are the real source; national
+ aggregators are convenience layers over them. See Search Systems for a directory of the
+ underlying databases.
+
+## Breach and leak data
+
+Useful for confirming that an identifier was in use, and for pivoting between an email, a username
+and a phone number. Handle carefully: this is other people's stolen data.
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [Have I Been Pwned](https://haveibeenpwned.com/) | Authoritative check for whether an address appears in a known breach. Does not expose passwords. | free |
+| [DeHashed](https://dehashed.com/) | Searchable breach aggregator across emails, usernames, names, phones and IPs. | partly free |
+| [Intelligence X](https://intelx.io/) | Searches leaks, darknet, document archives and historical web by selector. | partly free |
+| [Leak-Lookup](https://leak-lookup.com/) | Breach index with API access. | partly free |
+| [DiscordLeaks](https://discordleaks.unicornriot.ninja/) | Searchable archive of leaked far-right Discord servers, maintained by Unicorn Riot. | free |
+
+Do not put a live target's credentials into a third-party lookup you do not control, and do not
+treat a password from a breach as authorisation to use it.
+
+## Tool reference
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [192](http://www.192.com/) | Searching for someone's address in the UK, phone number and who they live with according to electoral rolls. | free |
+| [DeHashed](https://dehashed.com/) | A platform that maintains a database of compromised credentials and a web domain registration search tool. | paid |
+| [DiscordLeaks](https://discordleaks.unicornriot.ninja/) | Search hundreds of thousands of messages leaked from 290+ white-supremacist / nazi discord servers. | free |
+| [Eniro](https://www.eniro.se/) | Yellow Pages (Swedish Edition) | free |
+| [Epieos](https://tools.epieos.com/holehe.php) | Checks where an email has been used. Based on Holehe. | paid |
+| [FastPeopleSearch](http://fastpeoplesearch.com/) | Mostly good for US. | free |
+| [GetContact](https://www.getcontact.com/en/) | Phonenumber ID app - draws from crowdsourced contactbooks | free |
+| [Ghunt](https://github.com/mxrch/GHunt) | A command line tool for obtaining information about Google accounts. | free |
+| [Have I Been Pwned](https://haveibeenpwned.com/) | Does an email address appear in data breaches? | free |
+| [Hitta.se](https://www.hitta.se/) | Mapping service for Sweden | free |
+| [Intelx](http://intelx.io/) | Find user details in data breaches | partly free |
+| [Leak-Lookup](https://leak-lookup.com/) | An online tool that allows you to search across public data breaches to surface credentials that may have been compromised. | partly free |
+| [NigeriaPhonebook](https://nigeriaphonebook.com/) | Look up by name, state, and phone number. Last names are partially censored for free accounts. | free |
+| [Person Lookup](https://personlookup.co.za/) | find individuals, phonenumbers, and adresses | free |
+| [Pipl](http://pipl.com/) | Identity information for professionals | paid |
+| [Ratsit](https://www.ratsit.se/) | Look up phone numbers/names (Sweden) | free |
+| [Search Systems](https://publicrecords.searchsystems.net/) | Finding public record information online in over 70,000 databases organized by type and location to help you find property, criminal, court, birth, death… | free |
+| [Skopenow](https://www.skopenow.com/) | Social Media Investigations - name, phone, email, username searches. | paid |
+| [Spokeo](http://spokeo.com/) | People search through email, phone, name | paid |
+| [Swedish Name Register](https://scb.se/hitta-statistik/sverige-i-siffror/namnsok/) | Find out how common a name is in Sweden based on census data | free |
+| [The Law Pages](https://www.thelawpages.com/court-cases/court-case-search.php?mode=1) | Search criminal court case details in the UK, such as sentence, hearing, defendant, etc. | free |
+| [ThisNumber](https://sur.ly/o/numberway.com/AA000014) | An international directory of white pages and yellow pages phone books, and online directory enquiries. It's a free, independent and up-to-date guide to… | free |
+| [TrueCaller](https://www.truecaller.com/) | Truecaller is a caller ID app that identifies incoming calls, blocks unwanted numbers, and gathers phone numbers and names from contact lists. It also… | partly free |
+| [TruffleHog](https://trufflesecurity.com/trufflehog) | Find leaked credentials. | free |
+| [Worldwide Osint Tools map](https://cipher387.github.io/osintmap/) | Global overview of yellow/white pages, court cases, business registries etc. | free |
+| USA court case databases | State-by-state guide for researching criminal and civil court cases | partly free |
+
+## Pitfalls
+
+- **Aggregators invent relatives.** "Possible relatives" lists are inference from shared addresses
+ and surnames. They are frequently wrong and occasionally defamatory.
+- **Stale addresses.** Someone moved five years ago; the aggregator still shows the old address as
+ current. Date every claim.
+- **Name collisions.** Common names across a large population produce confident, wrong matches.
+ Require a second identifier — date of birth, middle initial, employer.
+- **Jurisdiction and legality.** Accessing some records requires a declared lawful purpose. Bulk
+ collection of personal data about EU residents engages the GDPR regardless of the data being
+ public.
+
+## Broader catalogues
+
+- [People OSINT](https://tools.osintnewsletter.com/tool-categories/people-osint)
+- [Public Records OSINT](https://tools.osintnewsletter.com/tool-categories/public-records-osint)
+- [Breached Data Provider OSINT](https://tools.osintnewsletter.com/tool-categories/breached-data-provider)
+
+
+## Sources
+
+Both catalogues below are maintained by other people and are considerably larger than
+this page. Use them as the canonical index; this sheet is a working route through them.
+
+- [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
+ review page covering cost, difficulty, requirements and limitations.
+- [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
+
+Neither publishes a licence, so nothing here is copied from them: tool names, one-line
+descriptions, cost flags and links are catalogue facts, and the method and commentary are
+this site's own. See [credits](/credits).
diff --git a/src/content/sheets/osint/reverse-image-search.md b/src/content/sheets/osint/reverse-image-search.md
@@ -0,0 +1,115 @@
+---
+title: "Reverse Image Search"
+description: "Find where an image came from and whether it predates the event it supposedly shows — the first check on any visual claim."
+category: osint
+subcategory: "Images & Video"
+tags: [osint, images, verification, reverse-search]
+tools: [google-lens, tineye, yandex, invid]
+difficulty: beginner
+updated: 2026-09-28
+references:
+ - name: "Bellingcat's Online Investigation Toolkit"
+ url: "https://bellingcat.gitbook.io/toolkit"
+ author: "Bellingcat"
+ license: none
+ relation: derived
+ note: "Tool catalogue: names, descriptions, cost flags and links for this area."
+ - name: "OSINT Newsletter Tools Library"
+ url: "https://tools.osintnewsletter.com"
+ author: "The OSINT Newsletter"
+ license: none
+ relation: derived
+ note: "Second tool catalogue, cross-checked against the above."
+---
+
+## What this covers
+
+Establishing whether an image is what it claims to be, by finding earlier copies. This is the
+single highest-value check in visual verification and it takes under a minute, so it goes first,
+always. Most viral misinformation is old footage relabelled.
+
+## Method
+
+1. **Run several engines.** They index different corpora and disagree constantly. One engine
+ returning nothing means nothing.
+2. **Sort by oldest**, not by relevance. You want the earliest appearance, which is the likely
+ original.
+3. **Crop and re-run.** Engines match on the whole frame. Cropping to a distinctive element — a
+ sign, a building, a vehicle marking — often finds matches the full frame misses.
+4. **For video, search keyframes.** Extract frames and search each; a video is only as findable as
+ its most distinctive still.
+5. **Check the earliest hit's own context.** The oldest copy you can find is not necessarily the
+ original — read its caption and follow its sourcing.
+
+## Engines, and what each is good for
+
+| Engine | Strength |
+| --- | --- |
+| [Google Lens](https://lens.google.com/) | Best at objects, text in images, landmarks and products. Strong OCR. |
+| Yandex Images | Consistently the best at faces and at Eastern European and Central Asian content. Frequently finds what Google misses. |
+| [TinEye](https://tineye.com/) | Oldest-first sorting and exact-match focus. The best tool for "when did this first appear". |
+| Bing Visual Search | Good regional coverage; worth running as a third opinion. |
+| [Search by Image](https://addons.mozilla.org/en-US/firefox/addon/search_by_image/) | Browser extension that fires one image at many engines at once. |
+| [RootAbout](https://rootabout.com/) | Reverse image search across Internet Archive holdings. |
+
+Yandex's face matching is good enough to be an ethical question, not just a technical one. Think
+about what happens to the person in the photo if you identify them.
+
+## Video keyframes
+
+[InVID / WeVerify](https://www.invid-project.eu/tools-and-services/invid-verification-plugin/) is
+the standard browser plugin: it extracts keyframes from a video, runs them through several reverse
+image engines, and also surfaces upload metadata and a magnifier for detail work.
+
+Manually, with ffmpeg:
+
+```bash
+# scene-change keyframes — the frames worth searching
+ffmpeg -i video.mp4 -vf "select='gt(scene,0.3)'" -vsync vfr keyframe-%03d.jpg
+
+# one frame every five seconds, as a fallback
+ffmpeg -i video.mp4 -vf fps=1/5 frame-%03d.jpg
+
+# a contact sheet for eyeballing the whole video at once
+ffmpeg -i video.mp4 -vf "select='gt(scene,0.2)',scale=320:-1,tile=4x4" -vsync vfr sheet.png
+```
+
+## Tool reference
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [Google Lens](https://lens.google/) | Google Lens is an image recognition tool that can be used to identify locations or objects in photographs. | free |
+| [InVID](https://weverify.eu/verification-plugin/) | A toolkit that supports the verification of videos and images. | free |
+| [RootAbout](http://rootabout.com/) | Reverse search images on the Internet Archive | free |
+| [Search by Image](https://github.com/dessant/search-by-image) | A browser extension to reverse search an image on multiple search engines. | free |
+| [TinEye](https://tineye.com/) | TinEye is a search engine that allows the user to search using images (reverse image search). | free |
+
+## Pitfalls
+
+- **Cropped, mirrored or filtered images defeat exact matching.** Flip the image horizontally and
+ re-run; recompressed and mirrored reposts are extremely common.
+- **Absence of results is not originality.** It often just means the original is on a platform the
+ engine cannot index.
+- **The oldest hit can still be a repost.** Read its context rather than treating the date as the
+ answer.
+- **Screenshots of screenshots** lose the detail engines match on. Ask for the original file when
+ you can.
+
+## Broader catalogues
+
+- [Image and Video Analysis OSINT](https://tools.osintnewsletter.com/tool-categories/image-and-video-analysis-osint)
+- [Fact-checking/verification OSINT](https://tools.osintnewsletter.com/tool-categories/fact-checking-verification-osint)
+
+
+## Sources
+
+Both catalogues below are maintained by other people and are considerably larger than
+this page. Use them as the canonical index; this sheet is a working route through them.
+
+- [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
+ review page covering cost, difficulty, requirements and limitations.
+- [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
+
+Neither publishes a licence, so nothing here is copied from them: tool names, one-line
+descriptions, cost flags and links are catalogue facts, and the method and commentary are
+this site's own. See [credits](/credits).
diff --git a/src/content/sheets/osint/social-media-monitoring.md b/src/content/sheets/osint/social-media-monitoring.md
@@ -0,0 +1,99 @@
+---
+title: "Cross-Platform Monitoring & Collection"
+description: "Track accounts, hashtags and narratives across several platforms at once, and watch pages for changes."
+category: osint
+subcategory: "Social Media"
+tags: [osint, monitoring, collection, social-media]
+tools: [4cat, distill, snscrape]
+difficulty: intermediate
+updated: 2026-09-28
+references:
+ - name: "Bellingcat's Online Investigation Toolkit"
+ url: "https://bellingcat.gitbook.io/toolkit"
+ author: "Bellingcat"
+ license: none
+ relation: derived
+ note: "Tool catalogue: names, descriptions, cost flags and links for this area."
+ - name: "OSINT Newsletter Tools Library"
+ url: "https://tools.osintnewsletter.com"
+ author: "The OSINT Newsletter"
+ license: none
+ relation: derived
+ note: "Second tool catalogue, cross-checked against the above."
+---
+
+## What this covers
+
+Working several platforms at once, and watching things over time rather than looking once. Two
+distinct jobs: **bulk collection** for later analysis, and **change detection** on pages you care
+about.
+
+## Bulk collection
+
+[4CAT](https://github.com/digitalmethodsinitiative/4cat) is the serious option — a self-hosted
+capture-and-analysis platform that ingests from many platforms and ships analytical modules
+(co-word networks, time series, image clustering) on top of what it collects.
+
+```bash
+git clone https://github.com/digitalmethodsinitiative/4cat
+cd 4cat && docker compose up -d
+# web UI is then served on port 80
+```
+
+Self-hosting matters here: your dataset stays yours, and you can re-run analysis without
+re-collecting.
+
+## Change detection
+
+[Distill](https://distill.io/) watches a page or a page region and alerts on change. Good for
+noticing when a target edits a bio, deletes a post, changes a company officer list, or quietly
+updates a policy document.
+
+Point it at the narrowest element that carries the signal, not the whole page, or you will drown in
+alerts from rotating ads and timestamps.
+
+## Narrative and coordination analysis
+
+- **Posting-time clustering** exposes networks. Accounts that post within seconds of each other,
+ repeatedly, are coordinated.
+- **Identical phrasing across accounts** is the strongest single indicator of copy-paste campaigns.
+- **Follower overlap** between accounts is more telling than follower count.
+- [The Information Laundromat](https://information-laundromat.com/) compares content across sites to
+ find where the same text is being syndicated.
+
+## Tool reference
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [4CAT](https://4cat.nl/) | 4CAT is a tool designed for the easy collection and analysis of online datasets. It allows researchers to uncover patterns and trends in data from social… | free |
+| [Atlos](https://www.atlos.org/) | ATLOS is a platform for collaborative and large-scale open source investigations. | partly free |
+| [Datasette](https://datasette.io) | Open-source “WordPress-for-data” that turns any SQLite database into an interactive website and JSON API in seconds; ideal for publishing, exploring and… | free |
+| [Gephi](https://gephi.org) | Open-source network analysis and visualization software | free |
+| [Maltego Graph](https://www.maltego.com/downloads/) | Maltego Graph is an investigation platform that combines two things at once: (1) It acts as a search tool, and (2) It creates a graph establishing links… | partly free |
+| [Pinpoint](https://journaliststudio.google.com/pinpoint/about) | A tool by Google to catalogue uploaded documents and files, providing automated text recogntion, indexing, audiotranscriptions and other (AI-powered)… | free |
+| [Time.Graphics](https://time.graphics) | A tool for creating, visualizing, and managing timelines online. | partly free |
+
+## Pitfalls
+
+- **Rate limits end collections mid-run.** Check for gaps before you analyse; a missing day looks
+ like silence rather than a failure.
+- **Sampling bias reads as a finding.** If a tool only reaches accounts above some follower count,
+ its "network" is an artefact of that cutoff.
+- **Coordination needs a baseline.** Fans of the same thing post about it at the same time. Compare
+ against normal behaviour for the topic before calling it inauthentic.
+- **Storage and legality.** Bulk personal data attracts data-protection obligations even when every
+ individual item was public.
+
+
+## Sources
+
+Both catalogues below are maintained by other people and are considerably larger than
+this page. Use them as the canonical index; this sheet is a working route through them.
+
+- [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
+ review page covering cost, difficulty, requirements and limitations.
+- [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
+
+Neither publishes a licence, so nothing here is copied from them: tool names, one-line
+descriptions, cost flags and links are catalogue facts, and the method and commentary are
+this site's own. See [credits](/credits).
diff --git a/src/content/sheets/osint/social-media-platforms.md b/src/content/sheets/osint/social-media-platforms.md
@@ -0,0 +1,205 @@
+---
+title: "Social Media — Per-Platform Research"
+description: "What each major platform still exposes to an unauthenticated researcher, and the tools that work per platform."
+category: osint
+subcategory: "Social Media"
+tags: [osint, social-media, telegram, tiktok]
+tools: [telepathy, yt-dlp, instaloader]
+difficulty: intermediate
+updated: 2026-09-28
+references:
+ - name: "Bellingcat's Online Investigation Toolkit"
+ url: "https://bellingcat.gitbook.io/toolkit"
+ author: "Bellingcat"
+ license: none
+ relation: derived
+ note: "Tool catalogue: names, descriptions, cost flags and links for this area."
+ - name: "OSINT Newsletter Tools Library"
+ url: "https://tools.osintnewsletter.com"
+ author: "The OSINT Newsletter"
+ license: none
+ relation: derived
+ note: "Second tool catalogue, cross-checked against the above."
+---
+
+## What this covers
+
+Each platform exposes a different surface and closes it on a different schedule. This is the
+per-platform picture: what is still reachable without an account, what needs one, and which tools
+survive contact with the current APIs. Assume anything here can break without notice — platforms
+change access rules faster than tooling keeps up.
+
+## Telegram
+
+The most productive platform for open-source research, because public channels are genuinely
+public, history is retained, and forwarding metadata exposes the network between channels.
+
+- **Forward chains** are the key primitive. A forwarded message keeps its origin, so you can trace
+ content back through the channels that amplified it.
+- **Member lists** are visible in many groups. Your own account appears in them too — use a
+ research account.
+- **Channel creation dates and message IDs** are sequential, which lets you estimate when a channel
+ started and how much has been deleted.
+
+[Telepathy](https://github.com/proseltd/Telepathy-Community) is the standard toolkit for archiving
+channels, mapping forwards and exporting membership.
+
+```bash
+pipx install telepathy
+
+telepathy -t channelname # basic channel scrape
+telepathy -t channelname -c # comprehensive: members, forwards, media
+telepathy -t channelname -f 2024-01-01
+```
+
+It needs Telegram API credentials from [my.telegram.org](https://my.telegram.org/) tied to a real
+number, so use a number you are willing to burn.
+
+## Facebook
+
+Graph search is gone and most enumeration is dead. What still works:
+
+- **Numeric profile IDs** persist even when vanity URLs change, and map back to a profile.
+- **Public pages, groups and events** remain readable and are frequently forgotten by their owners.
+- **Ad Library** ([facebook.com/ads/library](https://www.facebook.com/ads/library/)) is genuinely
+ open, keyword-searchable, and covers political advertising with spend and reach data.
+- **Photo comments and reactions** on public posts still expose participant lists.
+
+## Instagram
+
+- Profile pictures, bios and post counts are visible without login; the feed usually is not.
+- `?__a=1` style JSON endpoints have been closed off repeatedly — assume they do not work.
+- [Instaloader](https://instaloader.github.io/) still handles public profile and hashtag downloads,
+ including comments and geotags where present.
+
+```bash
+pipx install instaloader
+
+instaloader profile_name # public posts + metadata
+instaloader --no-pictures --comments profile_name
+instaloader "#hashtag"
+```
+
+Aggressive use gets the account and IP rate-limited quickly, then blocked.
+
+## X / Twitter
+
+Heavily restricted since the API changes. Advanced search still works while logged in, and is
+still the best tool on the platform:
+
+```text
+from:username since:2024-01-01 until:2024-06-30
+"exact phrase" filter:images -filter:retweets
+geocode:51.5074,-0.1278,5km
+url:example.com
+```
+
+Archived snapshots are now often more reliable than the live site for deleted content — go to the
+[Wayback Machine](https://web.archive.org/) first.
+
+## TikTok
+
+- Profiles and individual videos are viewable without an account.
+- [Bellingcat's TikTok Hashtag Analysis](https://github.com/bellingcat/tiktok-hashtag-analysis)
+ collects posts by hashtag and charts co-occurrence, which is the useful bulk primitive.
+- Video download and metadata extraction both work through `yt-dlp`.
+
+## YouTube
+
+Still the most researcher-friendly large platform:
+
+```bash
+# metadata only, no download
+yt-dlp --dump-json 'https://youtube.com/watch?v=VIDEOID'
+
+# subtitles, including auto-generated, for keyword searching
+yt-dlp --write-auto-subs --sub-langs en --skip-download URL
+
+# full channel listing
+yt-dlp --flat-playlist --dump-json 'https://youtube.com/@channel/videos'
+```
+
+Upload timestamps are in the metadata and are a reliable earliest-possible date for footage.
+
+## Tool reference
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [4plebs](https://4plebs.org/) | Searchable archive of specific 4chan boards. Makes it possible to read threads after they are purged from 4chan. | free |
+| [Bellingcat TikTok Date Extract](https://bellingcat.github.io/tiktok-timestamp) | Get the exact upload date + time for tiktok video urls | free |
+| [Bellingcat TikTok Hashtag Analysis](https://github.com/bellingcat/tiktok-hashtag-analysis) | Archive content and metadata from TikTok posts that contain one or more specified hashtags | free |
+| [Blackbird](https://github.com/p1ngul1n0/blackbird) | Check usernames and email addresses on websites and social networks | free |
+| [BskyFollowFinder](https://bsky-follow-finder.theo.io/) | A tool that identifies which Bluesky accounts are followed by a profile’s contacts but not by that profile. Can be used for expanding networks and social… | free |
+| [Disboard](https://disboard.org/servers) | Search for public discord servers | free |
+| [Discord Chat Exporter](https://github.com/Tyrrrz/DiscordChatExporter) | A tool for exporting and backing up Discord chat logs in multiple formats. | free |
+| [DiscordLeaks](https://discordleaks.unicornriot.ninja/) | Search hundreds of thousands of messages leaked from 290+ white-supremacist / nazi discord servers. | free |
+| [F5Bot](https://f5bot.com/) | Sends you an email when a keyword is mentioned on Reddit. | free |
+| [Facebook Video Downloader](http://fdown.net/) | Handy website to download public Facebook videos. Copy paste the URL of the video and download it in the available definition formats. | free |
+| [FindClone](https://findclone.ru/) | Searches images from VK profiles (within certain limits) | free |
+| [Ghunt](https://github.com/mxrch/GHunt) | A command line tool for obtaining information about Google accounts. | free |
+| [Google Account Finder (EPIEOS)](https://tools.epieos.com/google-account.php) | Find the profile picture and public Google Map Reviews + Photos associated with a G-mail adress. Also checks for phone numbers, and checks for email… | free |
+| [Gravatar Email Checker](https://en.gravatar.com/site/check/) | Check if an email address has been used to comment on blogs and whether there is a profile image attached. | free |
+| [HaveIBeenZuckered](https://haveibeenzuckered.com/) | Check if a telephone number is present within the Facebook data breach. | free |
+| [Hoaxy](https://x.com/OSoMe_IU/status/1949394974262350098) | Hoaxy is a web-based search and visualization tool. It helps visualize the spread of information on Bluesky and X (Twitter). | partly free |
+| [Instagram Location Search](https://github.com/bellingcat/instagram-location-search/tree/main) | A command line tool that allows users to find location tags near a specified latitude and longitude. | free |
+| [InstaLoader](https://instaloader.github.io) | Download pictures or videos (with metadata) from Instagram. | free |
+| [Intelligence X Telegram SearchDDD](https://intelx.io/tools?tab=telegram) | Google-based search engine for Telegram (includes Telegago) | free |
+| [LinkdTime](https://github.com/Lucksi/LinkdTime) | Build a clean timeline of any LinkedIn activity from a single URL or a whole list of links. | free |
+| [Meta Content Library](https://transparency.meta.com/researchtools/meta-content-library) | Meta Content Library is a controlled-access tool that lets approved academic and non-profit researchers search the full public archive of Facebook… | free |
+| [MW Geofind](https://mattw.io/youtube-geofind/location) | MW Geofind is a tool designed to help users identify the filming location of YouTube videos, facilitating the exploration of global content from a… | free |
+| [Open Measures](https://public.openmeasures.io) | Open Measures helps open source researchers investigate harmful online activity such as extremism and disinformation. | partly free |
+| [Photo-Map.RU](http://photo-map.ru/) | Geotagged VK posts. | free |
+| [PSNprofiles](https://psnprofiles.com/) | Search PlayStation username, see daily activity, games played, country, and profile pic | free |
+| [RadiTube](https://tool.raditube.com/) | A search engine that searches the subtitles of about 380 (right/left) radical YouTube channels. You query for example for "q says" of "voter fraud" in… | free |
+| [RedditMetis](https://redditmetis.com) | RedditMetis is an online tool that analyses any public Reddit profile and returns charts and statistics on the user’s activity, language, sentiment and… | free |
+| [Sherlock](https://github.com/sherlock-project/sherlock) | Allows a user to search for the presence of specific usernames across more than 400 websites and social networks. | free |
+| [Snap Map](https://map.snapchat.com) | Searchable map of geotagged snaps. | free |
+| [Social Searcher](https://www.social-searcher.com/) | Search hashtags and usernames across various platforms. | partly free |
+| [SteamId.uk](http://steamid.uk/) | Lookup player names, view (more) previously used names, and when accounts befriended eachother (Free). View screenshots of account, (bulk) seach based on… | partly free |
+| [Story Saver](https://storysaver.net) | Download public Instagram Stories, Highlights and Videos. | free |
+| [Strava](https://www.strava.com) | A fitness tracking platform where publicly shared GPS activity data can reveal movement patterns, routines, and precise locations of individuals… | partly free |
+| [Telegago](https://cse.google.com/cse?cx=006368593537057042503:efxu7xprihg) | Telegago is a Google Custom Search Engine tailored for searching public Telegram content for OSINT purposes. | free |
+| [Telegram Group Joiner](https://bellingcat.github.io/telegram-group-joiner/) | Automate joining multiple Telegram groups and channels, ideal for researchers monitoring specific topics. | free |
+| [Telegram Phone Number Checker](https://github.com/bellingcat/telegram-phone-number-checker) | Command line tool for checking if phone numbers are connected to Telegram accounts and retrieving related information where available. | free |
+| [TelegramDB](https://www.telegramdb.org/) | TelegramDB is a searchable database service that allows users to explore public Telegram groups and channels via a dedicated bot. | partly free |
+| [Telemetrio](https://telemetr.io/) | Telemetr.io offers a range of Telegram-related services based on a catalog of Telegram channels: country and category-specific rankings, curated… | partly free |
+| [Telemetry](https://www.telemetryapp.io/) | An analytical search tool for Telegram groups and channels. | partly free |
+| [Telepathy](https://github.com/prose-intelligence-ltd/Telepathy-Community) | Telepathy is a versatile Telegram toolkit for OSINT analysts, enabling chat archiving, memberlist gathering, user location lookup, top poster analysis… | free |
+| [TGStat](https://tgstat.com/) | TGStat is a web-based analytics tool for Telegram that monitors active channels and provides profile analytics and statistics. It tracks channel… | partly free |
+| [TikTok Ad Library](https://library.tiktok.com/ads) | Search and review TikTok ads and related metadata for transparency and research. | free |
+| [TikTok-Api](https://github.com/davidteather/TikTok-Api/) | TikTok-Api is an open-source Python library (unofficial TikTok API) that allows developers and researchers to retrieve various public data from TikTok | free |
+| [tlgrm.eu channels](http://tlgrm.eu/channels) | Search Telegram channels. | free |
+| [Twitter Video Downloader](https://twittervideodownloader.com/) | Download videos from X (formerly Twitter) by converting tweet URLs into downloadable video links. | free |
+| [Twitter/X Location Search](https://twitter.com/explore) | Search for geocoded tweets by their distance from some coordinates. | free |
+| [Vk.watch](http://vk.watch/) | See public comments left by an account, profile photos used, and very basic facial recognition | free |
+| [Who posted what?](https://whopostedwhat.com/) | A tool that allows a keyword search on Facebook on a specific date or within a specific time frame. | free |
+| [X/Twitter Advanced Search](https://x.com/search-advanced) | Twitter/X Advanced Search is X's own tool to help users find more precise information on the platform by filtering posts according to criteria such as… | free |
+| [XboxGamertag](https://xboxgamertag.com/) | Search gamertags, see games played and recorded game clips | free |
+| [YouTube Metadata](https://mattw.io/youtube-metadata/) | An alternative to Amnesty's YT viewer, with slightly more information. | free |
+
+## Pitfalls
+
+- **Viewing can notify.** LinkedIn tells people who looked. Story views are attributed. Joining a
+ Telegram group adds you to a visible list.
+- **Tooling rots fast.** Anything depending on an undocumented endpoint is one deploy from broken.
+ Check a tool's commit history before trusting its output.
+- **Deleted is not gone, and present is not original.** Archive first, then analyse.
+- **Reposts dominate.** The account with the most engagement is rarely the origin. Trace back.
+
+## Broader catalogues
+
+- [Social Media OSINT](https://tools.osintnewsletter.com/tool-categories/social-media-osint)
+
+
+## Sources
+
+Both catalogues below are maintained by other people and are considerably larger than
+this page. Use them as the canonical index; this sheet is a working route through them.
+
+- [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
+ review page covering cost, difficulty, requirements and limitations.
+- [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
+
+Neither publishes a licence, so nothing here is copied from them: tool names, one-line
+descriptions, cost flags and links are catalogue facts, and the method and commentary are
+this site's own. See [credits](/credits).
diff --git a/src/content/sheets/osint/transport-tracking.md b/src/content/sheets/osint/transport-tracking.md
@@ -0,0 +1,141 @@
+---
+title: "Aircraft, Vessel & Vehicle Tracking"
+description: "Track flights and ships live and historically, and understand the gaps operators use to disappear."
+category: osint
+subcategory: "Transport"
+tags: [osint, aviation, maritime, adsb, ais]
+tools: [adsbexchange, flightradar24, marinetraffic, opensky]
+difficulty: intermediate
+updated: 2026-09-28
+references:
+ - name: "Bellingcat's Online Investigation Toolkit"
+ url: "https://bellingcat.gitbook.io/toolkit"
+ author: "Bellingcat"
+ license: none
+ relation: derived
+ note: "Tool catalogue: names, descriptions, cost flags and links for this area."
+ - name: "OSINT Newsletter Tools Library"
+ url: "https://tools.osintnewsletter.com"
+ author: "The OSINT Newsletter"
+ license: none
+ relation: derived
+ note: "Second tool catalogue, cross-checked against the above."
+---
+
+## What this covers
+
+Aircraft and vessels broadcast their own positions, which makes transport one of the richest OSINT
+domains. The important knowledge is not which site to open — it is where the data has gaps, because
+the gaps are where the interesting behaviour is.
+
+## Aircraft
+
+Aircraft transmit ADS-B: identity, position, altitude, speed. Receivers are crowd-sourced, so
+coverage follows population.
+
+| Source | Why use it |
+| --- | --- |
+| [ADS-B Exchange](https://globe.adsbexchange.com/) | **Does not honour blocking requests.** The only major aggregator that shows aircraft others hide — which is precisely why it matters for research. |
+| [Flightradar24](https://www.flightradar24.com/) | Best coverage and UI; filters blocked aircraft. Historical playback behind a subscription. |
+| [OpenSky Network](https://opensky-network.org/) | Research-oriented, free API, good historical archive. The right choice for bulk work. |
+| [Airframes](https://airframes.org/) | Registration-to-airframe history: owners, previous registrations, type. |
+| [GPSJam](https://gpsjam.org/) | Daily maps of GPS interference derived from aircraft navigation-accuracy reports. Reveals jamming zones. |
+| [Live ATC](https://www.liveatc.net/) | Archived air-traffic control audio, which sometimes names aircraft that were never tracked. |
+
+OpenSky's API is the one to automate against:
+
+```bash
+# current state of a specific aircraft by ICAO 24-bit address
+curl -s 'https://opensky-network.org/api/states/all?icao24=4ca7b5' | jq .
+
+# everything in a bounding box right now
+curl -s 'https://opensky-network.org/api/states/all?lamin=45&lomin=5&lamax=48&lomax=10' | jq '.states | length'
+```
+
+The **ICAO 24-bit hex address** is the durable identifier. Registrations and callsigns change;
+the hex usually does not, so track on that.
+
+**Gaps to expect:** ADS-B needs a receiver in range, so oceans, deserts and much of Africa and
+central Asia are dark. Military aircraft often transmit nothing. An aircraft that "disappears"
+mid-flight has usually just left coverage — check whether the last position is at the edge of a
+receiver's range before concluding anything.
+
+## Vessels
+
+Ships transmit AIS. Terrestrial receivers reach perhaps 40 nautical miles; beyond that, coverage
+depends on satellite AIS, which is mostly commercial.
+
+| Source | Why use it |
+| --- | --- |
+| [MarineTraffic](https://www.marinetraffic.com/) | The standard. Live positions, port calls, vessel particulars, photos. Historical track needs a subscription. |
+| [VesselFinder](https://www.vesselfinder.com/) | Good free tier; useful cross-check. |
+| [Equasis](https://www.equasis.org/) | **Ownership and management history, free with registration.** The best free source for who actually controls a ship. |
+| [IMO Registry](https://gisis.imo.org/) | Authoritative vessel identity data. |
+| [Global Fishing Watch](https://globalfishingwatch.org/map) | Fishing activity inferred from AIS behaviour; exposes probable illegal fishing. |
+| [IUU Vessel List](https://iuu-vessels.org/) | Vessels listed for illegal, unreported and unregulated fishing. |
+
+The **IMO number** is the durable identifier — it stays with the hull for life. Names, flags and
+owners change constantly, often specifically to frustrate tracking, so always record the IMO.
+
+**AIS is deliberately gamed.** Transponders get switched off during transfers, and positions are
+sometimes spoofed outright. A vessel going dark for six hours near another dark vessel is a
+finding, not a data problem.
+
+## Rail and road
+
+- [OpenRailwayMap](https://www.openrailwaymap.org/) — global rail infrastructure, including
+ electrification, gauge and signalling.
+- [Chronotrains](https://www.chronotrains.com/) — how far you can travel by train in N hours.
+- [License Plate Maps](https://www.licenseplatemania.com/) — plate formats by country, for
+ narrowing a location from a vehicle.
+
+## Tool reference
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [ADS-B Exchange](https://globe.adsbexchange.com/) | Live flight tracker (including many military aircraft). Live data available for the past month. Historical data available for purchase upon request. | partly free |
+| [Airframes](http://www.airframes.org/) | A database of aircraft details | free |
+| [Aviation Safety Network](https://aviation-safety.net/) | Aircraft incident database; can be searched by country, registration, year, etc. | free |
+| [Chronotrains](https://www.chronotrains.com/en) | Chronotrains is a free interactive map designed to explore the reach of Europe’s extensive rail network. Enter a starting point and travel time to see… | free |
+| [Equasis](https://www.equasis.org/) | Equasis provides vessel ownership and safety records, as well as shipping company fleet information. | free |
+| [Federal Aviation Administration](https://registry.faa.gov/AircraftInquiry/Search/NNumberInquiry) | Nationwide Plane Registry. Search by N-Number (a.k.a. callsign). Comprehensive list of privately owned planes in the US. | free |
+| [FlightAware](https://www.flightaware.com/live/) | FlightAware is a global flight-tracking platform that provides real-time data on aircraft movements. It offers live tracking, historical data, and… | partly free |
+| [Flightradar24](https://www.flightradar24.com ) | Flightradar24, a real-time flight tracking service, that provides comprehensive information about aircraft positions, flight numbers, routes, historical… | partly free |
+| [Global Fishing Watch](https://globalfishingwatch.org/map) | A digital platform for investigating fishing activities and vessel movements worldwide by utilising satellite and AIS data. | free |
+| [GPSJam](https://gpsjam.org/) | GPSJam.org is a daily map that visualizes the GPS/GNSS disruptions on aircraft worldwide. It collects and presents 24-hour data showing areas experiencing… | free |
+| [Illegal, unreported, unregular fishing Vessels List](https://iuu-vessels.org/Home/Search) | A combined list of known illegal, unreported, unregular fishing vessels | free |
+| [IMO Registry](http://webaccounts.imo.org/) | Ship/shipping-related information from the IMO | free |
+| [Live ATC](http://liveatc.net/) | Audio from air traffic control towers in the United States. Aircraft have to identify themselves to ATC towers, so in cases where aircraft are trying to… | free |
+| [MarineTraffic](https://www.marinetraffic.com/en/ais/home/centerx:25.0/centery:-34.5/zoom:8) | An open, community-based project, providing (near) real-time information on the movements of ships and their locations in harbours and ports. | partly free |
+| [OpenRailwayMap](https://wiki.openstreetmap.org/wiki/OpenRailwayMap) | a detailed online map of the world's railway infrastructure | free |
+| [OpenSky-Network](http://opensky-network.org/) | Community, open source flight tracking network. | free |
+| [ShipFinder](https://shipfinder.co/) | ShipFinder is an application designed to track vessels in near real-time across the globe, available on iPhone and Android platforms (but no longer PC) | partly free |
+| [VesselFinder](https://www.vesselfinder.com/) | Live marine vessel tracker | partly free |
+| License Plate Maps | Collection of tools and maps for discerning license plates by country | free |
+
+## Pitfalls
+
+- **Coverage gaps read as events.** Most disappearances are receiver coverage, not evasion. Check
+ the coverage map before claiming a vessel went dark.
+- **Callsigns and names are not identities.** Track on ICAO hex and IMO number.
+- **Historical data usually costs money**, and free sites silently retain only days. Capture what
+ you need when you see it.
+- **Flags of convenience** mean the flag state tells you little about real ownership. Use Equasis.
+
+## Broader catalogues
+
+- [Transport OSINT](https://tools.osintnewsletter.com/tool-categories/transport-osint)
+
+
+## Sources
+
+Both catalogues below are maintained by other people and are considerably larger than
+this page. Use them as the canonical index; this sheet is a working route through them.
+
+- [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
+ review page covering cost, difficulty, requirements and limitations.
+- [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
+
+Neither publishes a licence, so nothing here is copied from them: tool names, one-line
+descriptions, cost flags and links are catalogue facts, and the method and commentary are
+this site's own. See [credits](/credits).
diff --git a/src/content/sheets/osint/usernames-and-accounts.md b/src/content/sheets/osint/usernames-and-accounts.md
@@ -0,0 +1,159 @@
+---
+title: "Username & Account Discovery"
+description: "Pivot from one handle to every platform it appears on, and work out which hits are actually the same person."
+category: osint
+subcategory: "People & Identity"
+tags: [osint, username, accounts, pivoting]
+tools: [sherlock, maigret, blackbird, whatsmyname]
+difficulty: beginner
+updated: 2026-09-28
+references:
+ - name: "Bellingcat's Online Investigation Toolkit"
+ url: "https://bellingcat.gitbook.io/toolkit"
+ author: "Bellingcat"
+ license: none
+ relation: derived
+ note: "Tool catalogue: names, descriptions, cost flags and links for this area."
+ - name: "OSINT Newsletter Tools Library"
+ url: "https://tools.osintnewsletter.com"
+ author: "The OSINT Newsletter"
+ license: none
+ relation: derived
+ note: "Second tool catalogue, cross-checked against the above."
+---
+
+## What this covers
+
+You have one username. You want every other place that username exists, and then you want to know
+which of those are the same human. The first part is automated. The second part is not, and it is
+where the actual work is.
+
+## Method
+
+1. **Enumerate the exact handle** across platforms with an automated checker. Fast, noisy, a
+ starting point only.
+2. **Generate variants** before concluding anything. People append birth years, swap separators,
+ and drop vowels. `j.smith`, `jsmith90`, `j_smith`, `jaysmith` are all the same person often
+ enough to be worth checking.
+3. **Confirm each hit manually.** Enumerators check whether a profile URL resolves. They do not
+ check whether it is your target. Open it.
+4. **Pivot on content, not the handle.** Same profile photo, same bio phrasing, same follower
+ overlap, same posting hours. A shared handle is weak evidence; a shared photo is strong.
+5. **Work the timeline.** Account creation dates that cluster suggest one person registering
+ everywhere at once. A ten-year-old account and a two-week-old one with the same name are
+ probably not related.
+
+## Key tools
+
+### Sherlock
+
+The usual first pass. Checks a username against 400+ sites by constructing the expected profile URL
+and reading the response, so it touches only public pages and needs no API keys.
+
+```bash
+pipx install sherlock-project
+
+# single username
+sherlock user123
+
+# several at once
+sherlock alice bob charlie
+
+# only report hits, rather than every miss
+sherlock user123 --print-found
+
+# try common separators between name parts: john_doe, john-doe, john.doe
+sherlock 'john{?}doe'
+
+# narrow to specific sites
+sherlock user123 --site GitHub --site Instagram
+
+# machine-readable output
+sherlock user123 --csv
+sherlock user123 --xlsx
+
+# route through a proxy or Tor, since 400 requests from one IP is conspicuous
+sherlock user123 --proxy socks5://127.0.0.1:1080
+sherlock user123 --tor
+```
+
+Expect false positives from sites that return a soft 200 for missing users, and false negatives
+from sites that changed their markup since the site list was updated. Verify every hit.
+
+### Maigret
+
+Broader than Sherlock — around 3,000 sites — and it extracts profile data rather than just
+reporting existence, which shortens the confirmation step considerably.
+
+```bash
+pipx install maigret
+
+maigret user123
+maigret user123 --html # browsable report
+maigret user123 --top-sites 500 # trade coverage for speed
+```
+
+### WhatsMyName
+
+The community-maintained site-detection list that several other tools consume, with a web UI at
+[whatsmyname.app](https://whatsmyname.app/). Worth running alongside a CLI tool because its
+detection strings are often more current.
+
+### Blackbird
+
+Searches by username *and* by email, and will attempt AI-assisted relevance scoring on results.
+Useful as a cross-check when Sherlock and Maigret disagree.
+
+```bash
+python blackbird.py --username user123
+python blackbird.py --email target@example.com
+```
+
+### Bellingcat Name Variant Search
+
+Generates transliteration and spelling variants for names that cross alphabets — essential before
+you conclude a name is absent from a registry when it is simply spelled differently.
+
+## Tool reference
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [192](http://www.192.com/) | Searching for someone's address in the UK, phone number and who they live with according to electoral rolls. | free |
+| [Bellingcat Name Variant Search](https://bellingcat.github.io/name-variant-search/) | Quickly search many variants of a person's name on Google | free |
+| [Blackbird](https://github.com/p1ngul1n0/blackbird) | Check usernames and email addresses on websites and social networks | free |
+| [Epieos](https://tools.epieos.com/holehe.php) | Checks where an email has been used. Based on Holehe. | paid |
+| [Ghunt](https://github.com/mxrch/GHunt) | A command line tool for obtaining information about Google accounts. | free |
+| [Maigret](https://github.com/soxoj/maigret) | Maigret is a Python script that retrieves user information by searching for usernames across various websites and social media platforms. | free |
+| [NeutrOSINT](https://github.com/Kr0wZ/NeutrOSINT) | A tool for investigating Proton Mail addresses. | free |
+| [Sherlock](https://github.com/sherlock-project/sherlock) | Allows a user to search for the presence of specific usernames across more than 400 websites and social networks. | free |
+| [WhatsMyName](https://whatsmyname.app/) | Search for usernames on several hundred platforms | free |
+
+## Pitfalls
+
+- **A matching handle is not a matching person.** Common handles are reused by strangers. Treat a
+ hit as a lead until content ties it to your target.
+- **Enumerators are loud.** Several hundred requests from one address in a few seconds is a
+ pattern. Proxy it if the target might be watching, and slow it down.
+- **Coverage is skewed.** These lists are heavy on English-language and global platforms and thin
+ on regional ones. Absence from a tool's results is not absence from the internet.
+- **Paid aggregators recycle stale data.** A "verified" result from a people-search service is
+ often a years-old scrape. Check when the underlying data was collected.
+
+## Broader catalogues
+
+- [Username OSINT](https://tools.osintnewsletter.com/tool-categories/username-osint)
+- [People OSINT](https://tools.osintnewsletter.com/tool-categories/people-osint)
+
+
+## Sources
+
+Both catalogues below are maintained by other people and are considerably larger than
+this page. Use them as the canonical index; this sheet is a working route through them.
+
+- [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
+ review page covering cost, difficulty, requirements and limitations.
+- [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
+
+Neither publishes a licence, so nothing here is copied from them: tool names, one-line
+descriptions, cost flags and links are catalogue facts, and the method and commentary are
+this site's own. See [credits](/credits).
diff --git a/src/content/sheets/osint/websites-and-infrastructure.md b/src/content/sheets/osint/websites-and-infrastructure.md
@@ -0,0 +1,177 @@
+---
+title: "Websites, Domains & Hosting Infrastructure"
+description: "Attribute a site: registration history, DNS, certificates, analytics IDs and the hosting it shares with others."
+category: osint
+subcategory: "Infrastructure"
+tags: [osint, domains, dns, certificates, attribution]
+tools: [urlscan, crtsh, shodan, wayback]
+difficulty: intermediate
+updated: 2026-09-28
+references:
+ - name: "Bellingcat's Online Investigation Toolkit"
+ url: "https://bellingcat.gitbook.io/toolkit"
+ author: "Bellingcat"
+ license: none
+ relation: derived
+ note: "Tool catalogue: names, descriptions, cost flags and links for this area."
+ - name: "OSINT Newsletter Tools Library"
+ url: "https://tools.osintnewsletter.com"
+ author: "The OSINT Newsletter"
+ license: none
+ relation: derived
+ note: "Second tool catalogue, cross-checked against the above."
+---
+
+## What this covers
+
+Working out who runs a website and what else they run. Passive attribution — historical records,
+certificate logs, archives — gets you most of the way without ever touching the target. This
+overlaps with [Enumeration](/enumeration), but the goal here is attribution rather than attack
+surface.
+
+## Method
+
+1. **Historical WHOIS first.** Current records are almost always privacy-shielded; records from
+ before the shield often are not.
+2. **Passive DNS** shows which IPs the domain used over time, and which other domains used those
+ IPs.
+3. **Certificate transparency logs** enumerate subdomains for free, without touching the target,
+ and often expose staging and internal hostnames.
+4. **Archives** show what the site used to say, including contact details and staff pages since
+ removed.
+5. **Fingerprint the page.** Analytics IDs, ad IDs, favicon hashes and CMS quirks link sites that
+ share an operator.
+6. **Check what shares the host.** Shared hosting is meaningless; a dedicated IP hosting five
+ related domains is not.
+
+## Registration and DNS
+
+```bash
+# current registration
+whois example.com
+
+# DNS basics
+dig +short A example.com
+dig +short MX example.com
+dig +short TXT example.com
+dig +short NS example.com
+
+# mail and verification records often name the vendors in use
+dig +short TXT _dmarc.example.com
+```
+
+For history, use [DNS History](https://dnshistory.org/), Whoxy or a Domain Research Suite — the
+value is in what changed and when, not the current state.
+
+## Certificate transparency
+
+Every publicly trusted certificate is logged, so CT logs are a free and complete subdomain
+enumerator:
+
+```bash
+# all names ever certificated for a domain
+curl -s 'https://crt.sh/?q=%25.example.com&output=json' \
+ | jq -r '.[].name_value' | tr '\n' '\n' | sort -u
+
+# just the certificate issuance timeline
+curl -s 'https://crt.sh/?q=example.com&output=json' \
+ | jq -r '.[] | "\(.not_before) \(.name_value)"' | sort -u | head -40
+```
+
+A certificate issued for a hostname that does not resolve publicly still tells you the hostname
+exists.
+
+## Page fingerprinting
+
+| Signal | Why it links sites |
+| --- | --- |
+| Google Analytics / Tag Manager ID | Operators reuse one property across their sites constantly. The single strongest link. |
+| AdSense publisher ID | Same. |
+| Favicon hash | Shodan indexes it, so one favicon finds every host serving it. |
+| Distinctive HTML comment or typo | Copy-pasted templates carry unique strings. |
+| TLS certificate serial / key reuse | Same cert on two hosts means one operator. |
+
+[The Information Laundromat](https://information-laundromat.com/) automates much of this,
+comparing content and technical indicators across sites to surface shared operators.
+[Urlscan](https://urlscan.io/) records what a page loaded, including third-party requests, and its
+archive is searchable — so you can find other sites that made the same unusual request.
+
+```bash
+# search urlscan's archive without visiting the target
+curl -s 'https://urlscan.io/api/v1/search/?q=page.domain%3Aexample.com' \
+ | jq -r '.results[] | "\(.task.time) \(.page.url)"' | head
+
+# find pages sharing a specific analytics ID
+curl -s 'https://urlscan.io/api/v1/search/?q=page.url%3A*%20AND%20UA-12345678' | jq '.total'
+```
+
+Searching a code-search engine such as [Grep.app](https://grep.app/) or
+[PublicWWW](https://publicwww.com/) for an analytics ID finds the other sites that embed it.
+
+## Archives
+
+The [Wayback Machine](https://web.archive.org/) is the primary source. Its CDX API is the part
+worth automating:
+
+```bash
+# every capture of a path, with timestamps and status
+curl -s 'http://web.archive.org/cdx/search/cdx?url=example.com/contact*&output=json&collapse=digest'
+
+# first and last capture of a domain
+curl -s 'http://web.archive.org/cdx/search/cdx?url=example.com&output=json&limit=1'
+```
+
+`archive.today` catches things Wayback misses and is harder to have removed.
+
+## Tool reference
+
+| Tool | What it does | Cost |
+| --- | --- | --- |
+| [Distill](https://distill.io/) | Distill is a website change monitoring tool that allows users to track changes on web pages. | partly free |
+| [DNS History](http://completedns.com/) | Collection of historical DNS information. | free |
+| [Domain Research Suite](https://drs.whoisxmlapi.com/) | Domain Research Suite provides tools to obtain registration and ownership data for domain names, along with historical search and reverse lookup… | paid |
+| [DomainTools Whois Lookup](https://whois.domaintools.com/) | DomainTools Whois provides detailed domain name registration information, and can be used to investigate details about domains or IP addresses. | partly free |
+| [Geo Data Tool](https://www.geodatatool.com/) | IP geolocation service to identify the location and other technical information associated to IP addresses. | free |
+| [Grep.app](https://grep.app/) | grep.app is a free web-based search engine that allows users to search the contents of public GitHub repositories. | free |
+| [ICANN Lookup](https://lookup.icann.org/) | This tool allows you to search for the current registration data of internet domains. | free |
+| [IDN Checker](https://holdintegrity.com/checker) | IDN Checker detects visually similar versions of a domain. | free |
+| [Intelx](http://intelx.io/) | Find user details in data breaches | partly free |
+| [Moz Link Explorer](http://moz.com/link-explorer) | Analyse the links of any website. | free |
+| [PublicWWW](https://publicwww.com/) | PublicWWW is a source code search engine that allows you to search for any alphanumeric snippet, signature, or keyword within the HTML, JavaScript, and… | partly free |
+| [Shodan](https://www.shodan.io/) | A search engine for internet-connected devices, from webcams to databases. | partly free |
+| [The Information Laundromat](https://informationlaundromat.com) | A tool for analyzing content replication and site architecture to detect information laundering. | free |
+| [Urlscan](https://urlscan.io/) | urlscan.io is an online tool that allows investigators to analyse, monitor, and document websites in real time. | free |
+| [Wayback Machine](https://web.archive.org/) | The Wayback Machine is the Internet Archive's free tool for viewing and saving archived web pages, with over a trillion pages captured, widely used for… | free |
+| [Web Archives](https://github.com/dessant/web-archives) | A browser extension to view archived and cached versions of a website on multiple archiving sites. | partly free |
+| [What CMS](https://whatcms.org/) | WhatCMS is a web-based tool for anyone needing information about the technologies behind any website, including the content management system (CMS)… | partly free |
+| [Whoxy](https://www.whoxy.com/) | Whoxy is a domain search engine or "whois lookup" tool to find (the history of) registration information on a domain, such as the registrar, the status of… | partly free |
+
+## Pitfalls
+
+- **Privacy shields hide almost everything current.** History is where the answer is.
+- **Shared hosting proves nothing.** Thousands of unrelated domains share a CDN IP. Only a
+ dedicated or small shared host is meaningful.
+- **CDNs hide the origin.** Cloudflare in front of a site means the IP you see is Cloudflare's.
+- **Active scanning is not passive.** `nmap` against the target leaves logs. Urlscan and CT logs do
+ not.
+- **Archives have gaps and honour exclusions.** Absence from Wayback is not absence from the web.
+
+## Broader catalogues
+
+- [Domain Name OSINT](https://tools.osintnewsletter.com/tool-categories/domain-name-osint)
+- [Network Infrastructure OSINT](https://tools.osintnewsletter.com/tool-categories/network-infrastructure-osint)
+- [Cyberthreat Intelligence OSINT](https://tools.osintnewsletter.com/tool-categories/cyberthreat-intelligence-osint)
+
+
+## Sources
+
+Both catalogues below are maintained by other people and are considerably larger than
+this page. Use them as the canonical index; this sheet is a working route through them.
+
+- [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
+ review page covering cost, difficulty, requirements and limitations.
+- [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
+
+Neither publishes a licence, so nothing here is copied from them: tool names, one-line
+descriptions, cost flags and links are catalogue facts, and the method and commentary are
+this site's own. See [credits](/credits).
diff --git a/src/lib/taxonomy.ts b/src/lib/taxonomy.ts
@@ -1,4 +1,4 @@
-// Single source of truth for the 12 site domains.
+// Single source of truth for the 14 site domains.
// `accent` maps to a Rose Pine palette token used for the neon edge-glow.
// `tag` is the monospace module label shown on cards ( [AD], [ENUM], ... ).
@@ -14,6 +14,7 @@ export const CATEGORIES: CategoryDef[] = [
{ slug: 'pentest-workflow', title: 'Pentest Workflow', tag: 'FLOW', accent: 'love', blurb: 'CPTS attack-flow playbooks: common services & apps, privesc, web shells, and TTY upgrades.' },
{ slug: 'active-directory', title: 'Active Directory', tag: 'AD', accent: 'iris', blurb: 'Kerberos, ADCS, delegation, and domain takeover paths.' },
{ slug: 'enumeration', title: 'Enumeration', tag: 'ENUM', accent: 'foam', blurb: 'Port, service, web, and host discovery — mapping the attack surface.' },
+ { slug: 'osint', title: 'OSINT', tag: 'OSINT', accent: 'pine', blurb: 'Open-source investigation: people, places, platforms, imagery, and provenance.' },
{ slug: 'exploitation', title: 'Exploitation', tag: 'PWN', accent: 'love', blurb: 'Gaining a foothold: injection, upload, and shell delivery.' },
{ slug: 'privilege-escalation', title: 'Privilege Escalation', tag: 'PRIV', accent: 'gold', blurb: 'From user to root/SYSTEM on Linux and Windows.' },
{ slug: 'password-attacks', title: 'Password Attacks', tag: 'CRED', accent: 'rose', blurb: 'Cracking, spraying, and credential recovery.' },