MEIOC
#Python automation tool to extract information from EML files:
Headers
Detailed server relay hops (IP addresses involved)
Extracted URLS/domains
Attachments with calculated hashes.
SPF (Sender Policy Framework)
DKIM (DomainKeys Identified Mail)
github.com/drego85/meioc
10.01.2025 22:47 β π 18 π 3 π¬ 0 π 0
The Predicta Lab team worked with NHK journalists to investigate the I-SOON leak. Using Predicta Graph, we mapped relationships between key figures.
π Uncover complex data networks with Predicta Graph: predictagraph.com.
07.01.2025 15:19 β π 14 π 5 π¬ 1 π 0
Telegram Archive
the Telegram Archive with Video and media files on the open web
The OSINTukraine archive #telegram data from 90+ Russian Telegram channels. Help us continue preserving this data:
03.01.2025 05:20 β π 8 π 3 π¬ 0 π 0
Good to be reminded of a timeless investigative lesson: if two pieces of evidence seem to be contradictory it is usually an indicator that one of your assumptions is incorrect.
Obvious when you think about it, but sometimes hard to see when it's right in front of you π
02.01.2025 23:37 β π 10 π 2 π¬ 0 π 0
This looks like a chance for some #geolocation fun π
18.12.2024 21:33 β π 5 π 2 π¬ 0 π 0
SPOT - the easy way to verify locations
Spot is a tool for finding combinations of objects in the public space world-wide.
It's been almost 2 weeks, since we launched www.findthatspot.io as a publicbeta - and it's amazing to see how different people are testing it.
We're taking another dive into feedback before the π-break today to see what we can improve.
Give it a try, if you haven't had the chance yet!
16.12.2024 10:56 β π 30 π 9 π¬ 1 π 2
riddle me this riddle me that is written in yellow letters
ALT: riddle me this riddle me that is written in yellow letters
Sure you're an APT who pwn governments all day but can you correctly configure parental controls for Alexa and Google Nest?
15.12.2024 13:30 β π 3 π 1 π¬ 0 π 0
OSINT Feeds | Notion
The following are the OSINT blogs, podcasts and other feeds available in the database.
I have organized (somewhat) an OSINT OPML feed. This will be updated periodically. The first version is linked here.
knowledgebase.plessas.net/OSINT-Feeds-...
13.12.2024 17:05 β π 34 π 17 π¬ 5 π 2
The Delusions of Crowds by William Bernstein digs into this phenomenon and is well worth reading.
13.12.2024 22:21 β π 4 π 1 π¬ 0 π 0
The Office of the Director of National Intelligence issued a warning for industrial sabotage - one of the indicators points to online posts made by potential perpetrators.
04.12.2024 15:02 β π 6 π 3 π¬ 1 π 0
One of my favorite search operators is βfiletype:β - PDFs or office docs often contain compressed and valuable information. Hereβs an example. Letβs say Iβm looking into the Russian FSB and I want to find phone numbers and email addresses to conduct further research. Their domain is βfsb.ruβ
03.12.2024 19:28 β π 13 π 3 π¬ 2 π 0
Tough on crime.
03.12.2024 13:17 β π 1 π 0 π¬ 0 π 0
I've put together an OSINT starter kit. Let's unite the OSINT community on Bluesky!
go.bsky.app/GaTRbT3
22.11.2024 18:16 β π 106 π 38 π¬ 6 π 0
A Timeline of Russiaβs Nuclear Threats Against the West
While Russia frequently accuses the West of escalation, we look at all the times Russia has made nuclear threats against the West.
For those not familiar with Russia's weekly threats to launch nuclear weapons, United Media has been keeping track. Roughly 70 threats since the 2022 invasion.
The threat *is* the deterrence.
We will still be here tomorrow.
united24media.com/war-in-ukrai...
19.11.2024 21:42 β π 14 π 5 π¬ 2 π 0
Fascinating use of ship tracking resources to link the Yi Peng 3 to the Baltic Sea cable sabotage. Currently looks like the ship has been stopped by the Danish navy.
19.11.2024 20:04 β π 12 π 6 π¬ 0 π 1
Chinese-flagged cargo ship Yi Peng 3 crossed both submarine cables C-Lion 1 and BSC at times matching when they broke.
She was shadowed by Danish navy for a while during night and is now in Danish Straits leaving Baltics.
No signs of boarding. AIS-caveats apply.
19.11.2024 09:50 β π 1500 π 532 π¬ 45 π 142
Probably in the case of undersea cables. But the power stations, oil rigs, British Airways?
No evidence yet of coordinated sabotage. The coincidence is likely illusory.
19.11.2024 07:42 β π 0 π 0 π¬ 0 π 0
Nixintel's OSINT Resource List - start.me
Translation missing: en.startpage_default_description
I've started to add these and some other bookmarks to the CNI section of my #OSINT resource collection.
start.me/p/rx6Qj8/nix...
18.11.2024 22:49 β π 21 π 8 π¬ 0 π 0
Cloud service provider status pages can also act as a proxy for undersea cable status.
In this case the CLion1 outage showed up in Hetzner's status page.
status.hetzner.com/incident/ec8...
18.11.2024 22:49 β π 2 π 0 π¬ 1 π 0
Semantic Net is the source for Fiber Atlantic.
It shows the approximate route of undersea cables and their current status.
#CLion1 shown in the image below.
www.fiberatlantic.com
18.11.2024 22:49 β π 1 π 0 π¬ 1 π 0
SemanticNet: Internet infrastructure data
SemanticNet - Detailed Internet infrastructure data to help untangle the complexity of the Internetβs global architecture. Data, analysis and reports.
Here are few interesting #OSINT resources relating to undersea cables.
Semantic Net contains location and status information for undersea cables and data centres.
www.semanticnet.net
18.11.2024 22:49 β π 44 π 12 π¬ 1 π 1
Share it & let the #OSINT community grow!
OSINT in general go.bsky.app/TSvKc6o
Flight Trackers go.bsky.app/NKZeoR9
Ship Enthusiastsπ’ go.bsky.app/ScoHkM9
π‘ #GEOINT #IMINT #SATπ°οΈ Enthusiasts go.bsky.app/PzSSWrC
OSINT βBREAKINGβNEWS ποΈ go.bsky.app/446515N
OSINT π» Cyber Enthusiastsπ€ go.bsky.app/N4W14ch
13.11.2024 21:15 β π 182 π 81 π¬ 14 π 6
We also need much more information before deciding that today saw one of the biggest CNI attacks of all time.
/end
18.11.2024 22:04 β π 1 π 0 π¬ 1 π 0
This does not exclude the possiblilty that the outages are malicious, but zooming out a little shows that NPP failures are regular occurrences.
Clustering illusions feel right, but we always need to seek evidence to the contrary.
6/
18.11.2024 22:04 β π 1 π 0 π¬ 1 π 0
Nord Pool - UMM Platform
So is there are pattern, or are we seeing things?
#Loviisa has suffered three unplanned outages already this year.
#Olkiluoto has had four, including one this month already.
5/
umm.nordpoolgroup.com#/messages/3e...
umm.nordpoolgroup.com#/messages/e5...
18.11.2024 22:04 β π 1 π 0 π¬ 1 π 0
Nord Pool - UMM Platform
Nord Pool provides up to date information about power availability across Europe.
The nuclear power plant failures at #Loviisa and #Olkiluoto both show up here.
umm.nordpoolgroup.com#/messages?pu...
4/
18.11.2024 22:04 β π 1 π 0 π¬ 1 π 0
...also two Finnish nuclear power plants also went offline today.
Must be Russian sabotage, can't be coincidence right?
Maybe it is, but we need more evidence than mere happenstance.
There are some open sources that can help to determine the full extent of the pattern. #OSINT
3/
18.11.2024 22:04 β π 1 π 0 π¬ 1 π 0
2/ Apophenia/clustering illusion is the tendency to see a pattern in data or events that does not really exist.
It is natural human behaviour but contrary to sound analysis.
Two undersea cables are cut - likely due to sabotage (but accident has not yet been publicly ruled out)...
2/
18.11.2024 22:04 β π 1 π 0 π¬ 1 π 0
It's interesting to see how the cutting of two undersea cables in the #Baltic spirals.
We don't have any significant public comment from investigating officials yet, but already the eternal problem of analytical bias rears its head.
1/
18.11.2024 22:04 β π 1 π 0 π¬ 1 π 0
Bike touring | mental health | food | beer | rugby | Europe | bridges | the coast | architecture | Scotland | big skies | trains | mountains.
Electrical/Power Systems Engineer, Internationally Recognized Queen of Anglo-Saxonia, βExpertβ
*sigh* there will be typos and long threads
Founder @ OSINord.com | Lead, Cyber Threat Intelligence @ LEGO | ex- @ Rapid7 | Blogger | Navy Veteran | OSINT Addict.
Privacy Advocate/Online Safety/#OSINT Investigator β’ Ghostwriter β’ π owner π 18+NSFW πΆ She/Her
All My Links: https://beacons.ai/lockdownyourlife
Paylinks, wishlist, Spicy ππ»
https://linktr.ee/lockdownyourlife
Social media network analysis. Digital ethnography. Formerly: Technology & Social Change Project: https://shorensteincenter.org/programs/technology-social-change/ she/her
I'm a Teams reaction GIF, I like OSINT, Consulting Director βοΈ CTI & Analytics book ~202X, Tracelabs Black badge x3, Ex-Podcaster, ex The many hats club, #cyber Views my own or the AI's.
Echo | OSINT | @lightl3aks from the other place
OSINT enthusiast
Artistic soul
Misophonic AF
#w00w00 #silobreaker #00m00m
Co-founder and Investigations Lead at Permanent Record Research | Bullshit Hunter at bullshithunting.com | OSINT and Analysis | Journalist at TheDebrief.org | Will Probably Die in Winnipeg
I share my modest #OSINT knowledge with journalism students at RMIT || Fact Checking & Verification/Photojournalism || ex Age || #FCnV || IG: gord_19
Association OSINT-FR | https://OSINTFR.COM/ | CommunautΓ© dΓ©diΓ©e Γ l'Open Source Intelligence. ΓvΓ©nements, apprentissage et collaborations autour des pratiques liΓ©es Γ l'OSINT.
Join the OSINT Ambition community and take your investigative skills to the next level! We share expert tips, tools, and insights on OSINT.
https://osintconference.com/
https://osintupdates.com/
https://osinttools.io/
π OSINT/InfoSec nerd raised in Portland, OR. Seattle dweller.
Prior: GreyNoise, Atredis Partners, some other random cyber companies
Conference wrangling: current HushCon & prior BSides PDX, SeaGL, etc.
Threat research, musings, coffee
Bullshit Hunter. Misidentified beet farmer. Fiery advocate. ADHD. He/Him. Saskatoon, SK - Find my work at bullshithunting.com
Intelligence analyst by day, OSINT in academia, engineer at heart. Now: Finnish Security and Intelligence Service. Adjunct, Johns Hopkins. Past: Finnish Defence Forces, Bellingcat, Microsoft, Nokia.
Interested in infosec / hacking / osint / dfir / bugbounty!
Formerly Zerocopter.com, currently Head of Triage at Intigriti.com
Head CSIRT over at divd.nl
Hacknotcrime Advocate
Aut viam inveniam aut faciam.
CTI, prev NSC44
Go Mammoths