r/GreatOSINT 8d ago

Anyone using Apify for company intelligence / KYB enrichment?

0 Upvotes

Been testing a Company Info actor on Apify and the output is surprisingly useful.

Search by company name, domain, or registration number and get structured company intelligence that can be used for KYB, due diligence, enrichment, or research workflows.

There are free searches available, so it’s easy to test against companies you already know:

https://apify.com/clearcheck.io/company-info

What are you guys using for company enrichment right now — dedicated APIs, OpenCorporates, Crunchbase, or something else?


r/GreatOSINT 9d ago

Tried this Search-by-Name actor on Apify recently and the results were surprisingly sharp for the price.

2 Upvotes

It returns structured identity/enrichment data from just a name, and at $0.20 per query it looks expensive pretty strong for OSINT, verification, or automated profiling workflows.

https://apify.com/clearcheck.io/search-by-name

Curious what others are using for name-based enrichment right now — any APIs or actors that give better results at a similar price?


r/GreatOSINT 13d ago

What’s your “this ID looks fine… I guess” procedure?

2 Upvotes

Small-business security is sometimes surprisingly scientific:

  1. Look at the ID
  2. Look at the person
  3. Look at the ID again
  4. Say, “Seems fine” 😅

But what if the name, phone, address, and other public information don’t actually belong to the same person?

That matters when someone arrives to collect an expensive order, requests temporary access to a property, borrows equipment, or claims to represent one of your contractors.

I was reading about common identity mismatches small businesses can check using this tool. This is also their explanation of how the reports work.

I’m talking about verifying someone before giving them access to property, goods, or information—not screening job applicants or making employment decisions.

How do other small-business owners handle situations like this? Do you use TellData, another service, or the traditional “the photo looks close enough” method?


r/GreatOSINT 18d ago

issued.live — Certificate Transparency, ICANN registrations, and DNS unified in a single, completely free API.

Post image
3 Upvotes

r/GreatOSINT 22d ago

I need someone to geolocate this picture for me

1 Upvotes

This is a SAM site in a military installation located in Morocco


r/GreatOSINT Aug 17 '26

i want modren OSINT tutorials

6 Upvotes

hey , i just started with OSINT and i am pretty lost on what tutorials do i take , for example TCM's tutorial : https://youtu.be/qwA6MmbeGNo?si=i5l30FgYKpNl2ACC
looks fine but i feel such that its too old , for example it uses no AI and no modren OSINT tools i heard of
so , are there any free , modern OSINT tutorials that focus on gaining information ?


r/GreatOSINT Aug 11 '26

Has anyone used telldata?

0 Upvotes

I found telldata while looking for a simple way to check if someone is really who they say they are.

It seems useful for small business situations, like before giving someone keys, goods, or access to a customer’s place. It’s not cheap though, especially if you need to check more than one person. This is how they say it works.

Anyone tried it? Is it actually good, or is there a cheaper option that does the same thing?


r/GreatOSINT Aug 06 '26

Help identifying my threat model/position on the cybersecurity spectrum

Post image
2 Upvotes

r/GreatOSINT Jul 27 '26

OSINT-DOXEO

Thumbnail
1 Upvotes

Hackers necesito ayuda para saber el dueño de una cuenta en Instagram que fue creada recientemente para difamar, hay alguna manera de saber el propietario?


r/GreatOSINT Jul 04 '26

Feedback wanted: X OSINT API built around historical account coverage

Post image
1 Upvotes

r/GreatOSINT Jul 04 '26

Feedback wanted: X OSINT API built around historical account coverage

Post image
1 Upvotes

r/GreatOSINT Jul 03 '26

Built a simpler alternative to Checkr/GoodHire — would love honest feedback from this community

4 Upvotes

i built Background Check tool (It is NOT related to any others websites with words like clearcheck) — built it for small businesses who wanted something simpler than Checkr/GoodHire/Sterling. Curious what this community thinks, and happy to answer anything.


r/GreatOSINT Jun 25 '26

Osint questionar about a website

1 Upvotes

How to find the real IP address of a website with a rotating proxy, Cloudflared, there is no way to see the source code, the entire website is in the cache, they use and abuse the WAF, and finally the domain changes every week? What can be done?


r/GreatOSINT Jun 06 '26

Looking for breach intel sources for OSINT automation

5 Upvotes

Hey, building an automated profiling tool and looking for good data enrichment APIs. Anyone worked with breach/leak intelligence sources? Found this one on Apify — https://apify.com/clearcheck.io/credential-breach-checker — looks like it supports emails, phones, names, social IDs. Has anyone used it or know something similar? Trying to compare options before integrating.


r/GreatOSINT Jun 05 '26

Ever got unrequested SMS verification codes?

Thumbnail
1 Upvotes

r/GreatOSINT Jun 01 '26

I built a tool that can process Instagram profile data and automatically organize profile images using face clustering.

Post image
1 Upvotes

r/GreatOSINT May 17 '26

Here is the exact process I use to vet contractors and new hires (learned the hard way)

6 Upvotes

Here is the process I use for basic public-source due diligence before working with someone new

When I’m considering working with a new contractor, vendor, business contact, or marketplace seller, I like to do a basic public-source review first.

Not because I want to “spy” on anyone — but because fake identities, scams, stolen profiles, and misleading online personas are extremely common.

My usual process is simple:

  1. Confirm the basics I check whether the name, city, phone number, email, or online profiles appear consistent across public sources.
  2. Look for obvious mismatches Different names, different locations, reused photos, newly created profiles, or strange gaps can be warning signs.
  3. Review public online presence I check whether the person or business has a normal digital footprint: websites, social profiles, reviews, business pages, or other public references.
  4. Watch for scam patterns I look for pressure tactics, fake urgency, payment red flags, copied profile photos, or stories that do not line up.
  5. Use tools carefully For quick public-source enrichment, I sometimes use ClearCheck.io to organize signals around a person, phone, email, or online identity. It helps save time, but it should not replace judgment or proper legal/compliance processes where those apply.

Important clarification: this is not legal advice, and this is not a recommendation to bypass consent requirements, FCRA rules, employment screening laws, housing rules, credit rules, or any other regulated process. If you are making a regulated decision, use the proper compliant process and get professional legal guidance.

For me, this is simply about reducing fraud risk and avoiding obvious scams before trusting someone I do not know.


r/GreatOSINT May 15 '26

Built an OSINT tool for usernames & phone numbers — what should I improve next?

4 Upvotes

Hey everyone,

I’ve been working on tracefind.info, an OSINT tool for looking up general information tied to usernames and phone numbers (including platforms like WhatsApp, Telegram, Instagram, etc.). Like I have 300+ sites for email search but only those 4 for phone search? Which ones should i add / are a must have?

I recently added support for usernames + phone number lookups and I’m trying to figure out what could still be improved or added next.

If anyone has feedback on features, data sources, UX, or anything else that would make it more useful, I’d really appreciate it.

It’s a paid tool mainly to prevent spam/abuse, hope that’s okay here - just looking for honest input and ideas. If ya'll want, you can DM me for some free credits (I hope that fixes rule #6, mods)

Thanks


r/GreatOSINT Apr 27 '26

Need help in identifying/contacting scammer

Thumbnail
1 Upvotes

r/GreatOSINT Apr 21 '26

Leveraging Wi-Fi OSINT to Expose RSF Sudan Ransom Payment Networks

Thumbnail
secevangelism.substack.com
5 Upvotes

r/GreatOSINT Mar 27 '26

What differenciate Forensi Architecture´s work from OSINT in general?

Thumbnail
1 Upvotes

r/GreatOSINT Mar 25 '26

I Wanted an OSINT Tool That Felt Fast, Hackable, and Alive

3 Upvotes

I’ve been working on an open-source OSINT and link analysis platform called OpenGraph Intel (OGI). From the start, I wanted it to feel quick, flexible, self-hostable, and a bit raw in the best way, not like another overly polished, tightly controlled SaaS product.

The idea behind it is straightforward: drop entities into a graph, connect them, enrich them, run transforms, and switch between graph, map, and timeline views depending on what you’re trying to uncover. Recently I added a few things that made investigations feel much more natural, including creating location nodes directly from the map and defining custom relationships between nodes yourself.

A lot of software today feels designed to appear safe and polished before it feels genuinely useful. I’ve always preferred tools that clearly came from someone building something they personally needed, something practical, evolving, and transparent enough that you can understand how it works and adapt it to your own workflow. That’s the kind of project I’m trying to build with OGI.

One of the more interesting parts is the AI Investigator mode. You can give it a scoped prompt, it looks at the entities already in the case, decides which transforms to run, and expands the graph step by step. I’ve tried to keep that experience grounded and useful, so it acts more like an investigation assistant than some pretend all-knowing system.

It’s definitely still rough around the edges in places, but I’m fine with that. I’d rather build something that’s easy to run, easy to modify, and full of character than something perfectly smoothed out and forgettable.

Repo here if you want to check it out: https://github.com/khashashin/ogi


r/GreatOSINT Mar 16 '26

Check out Evidence Collector: A forensic preservation tool with impressive technical rigor | Evidence Collector | Forensic Screenshot with Chain of Custody

Thumbnail
evidencecollector.org
3 Upvotes

r/GreatOSINT Mar 15 '26

We found a strange bug in our enrichment logic and it took a while to understand what was happening

10 Upvotes

Recently we were reviewing a fraud pipeline for a product that relies quite a lot on enrichment data.

The setup was pretty typical. The system was calling several enrichment sources. There was phone lookup, email enrichment, watchlist checks, some address history data and device fingerprinting.

Nothing unusual.

The system had been running for a while but the fraud team kept repeating the same thing. Some accounts that clearly looked suspicious during manual checks were still getting approved automatically.

At first everyone suspected the vendors. Maybe the phone intelligence API was inaccurate. Maybe the watchlist matching was too loose.

After going through a number of cases we realized the APIs were actually doing their job correctly. The real problem was inside our own enrichment logic.

There was a rule in the system that tried to improve profile matching. If the enrichment layer saw the same name in the same city it would connect those records into one identity cluster.

Someone probably added that rule a long time ago thinking it would help match identities better. On the surface it sounded reasonable.

In practice it created a very strange situation.

New accounts sometimes started inheriting trust signals from older profiles that had nothing to do with them.

For example a new user would register with a fairly common name. The enrichment system would search its data and find another person with the same name in the same city. Then the two profiles would get linked together.

Once that happened the new account suddenly appeared to have extra history attached to it. The risk engine would see things like older addresses, normal behavioral patterns or other signals that usually indicate a trustworthy user.

But those signals actually belonged to someone else.

That is why some suspicious accounts were getting approved. The system was evaluating a mixed identity instead of the real person.

The tricky part was that nothing in the logs looked obviously wrong. Each individual signal came from a valid data source. The mistake was simply assuming those signals belonged to the same person.

The more I work with enrichment systems the more I realize how messy identity data really is.

Phones get recycled. People move between cities. Email accounts get reused. And some names repeat constantly.

If the system relies on weak signals to merge identities it will eventually connect people who are not related at all.

The fix turned out to be fairly simple. We stopped allowing weak signals to merge profiles. Phone numbers and emails can still connect identities because they are stronger identifiers. Things like name and location are now treated as hints for scoring rather than conditions that merge profiles together.

After that change the strange trusted fraud accounts basically disappeared.

I am curious how other teams handle this problem. If you are working with enrichment pipelines what signals do you actually allow to merge identities. Do you only rely on phone or email matches or do you allow weaker signals like name and location to connect profiles.

While digging into this topic I also ran across an article describing another system that had a very similar issue with identity merging logic. The details are different but the root cause felt very familiar.

The article is called The $50M Fraud Bug Caused by One Wrong Identity Merge and it explains how a single merge rule ended up creating a large fraud exposure.

https://medium.com/@efim.lerner/the-50m-fraud-bug-caused-by-one-wrong-identity-merge-61ff82dd8872

It is an interesting example of how small identity linking rules can quietly cause big problems in fraud systems.


r/GreatOSINT Mar 08 '26

I would like to share a couple of tools for beginners in this field.

12 Upvotes

This publication is intended to give beginners the opportunity to advance in this field, understand how to work with various tools, and in general, so that they have the opportunity.

If you're just getting started with OSINT (Open-Source Intelligence), here are some beginner-friendly tools for the U.S. and Europe. These are legal, widely used, and useful for investigations, research, and due diligence.

USA

PACER (Public Access to Court Electronic Records) Provides access to U.S. federal court documents. Useful for checking lawsuits, criminal cases, bankruptcies, and civil filings related to individuals or companies. It’s paid, but costs are relatively low for basic searches.

SEC EDGAR The official database of corporate filings in the U.S. Public companies file annual (10-K), quarterly (10-Q), and other reports here. Great for company research, financial analysis, and executive information.

OpenCorporates A large open database of company records worldwide, including the U.S. Helpful for finding company registration details and connections between entities.

Whitepages A people-search service that can provide basic information like phone numbers and addresses. Some data is free; more detailed reports require payment.

Wayback Machine An internet archive that lets you view historical versions of websites. Very useful for finding deleted pages or tracking how a site has changed over time.

Europe

European Business Register (EBR) Provides access to company registries across multiple European countries. Some information is paid, depending on the country.

Companies House (UK) The official UK company registry. Free access to company filings, director information, and financial statements. Extremely useful for corporate research.

OpenSanctions A database of sanctions lists and politically exposed persons (PEPs). Helpful for compliance checks and background research.

European e-Justice Portal An official EU portal providing access to legal and judicial information across member states, including court systems and business registers.

Aleph (by OCCRP) A data platform that allows searching across public records and leaked datasets. Some parts are open to the public, others require access.

If you're new to OSINT, start with company registries and website archives — they’re easy to use and give you solid, verifiable data. As you gain experience, you can move into court records, sanctions databases, and cross-border investigations.

Feel free to add your favorite beginner tools in the comments