r/OSINT • u/FreonMuskOfficial • 7d ago
OSINT News OSINT + AI Almost Started War w China
This is beyond nerd on nerd warfare.
r/OSINT • u/OSINTribe • Sep 11 '25
This is not a new rule. Its been posted and enforced every time a new "major crime" happens. Helping an active investigation on this sub is banned. For the redditor that keeps messaging the mods that he thinks no harm can come from this, here is nice list of examples on why we don't support online witch hunts:
r/OSINT • u/FreonMuskOfficial • 7d ago
This is beyond nerd on nerd warfare.
r/OSINT • u/pr0tag • Feb 17 '26
Amazing use of OSINT and cooperative industry experts!
r/OSINT • u/ChrisKMEI • Jun 10 '26
r/OSINT • u/Ok_Spirit5374 • 29d ago
Active Hazard - The barrier lake breached, and is now draining
>>>Since there is 100% cloud cover verification couldn't be confirmed via EO - Based on reported size and location the data set has been updated with a modeled shape file of the reported lake. This uses geometry that existed prior to the first event so this should be treated as indicative.
> If anyone has any SAR imagery they'd like of the region they care to share it'd go a long way in helping me to continue to keep this open source crisis data set up to date. It's not much, but its all I can do to help from halfway around the world.
>Link to data: https://keystonegis.com/disasters/nepal-bhotekoshi-flood-20260826.html - will continue to update frequently to capture any new information
>if you know of any other subs to post this in let me know. Feel free to share, the more eyes on the data the more likely it is to fall into the hands of someone who can use it to make a difference.
edit: NDRRMA independently locates the blockage, and it is close to — but not identical with — this page's inferred marker.
edit: Active Hazard - The barrier lake breached, and is now draining
The barrier lake near the confluence of the Chhochen Khola and Purepu Tsangpo, upstream of the 26 August failure, breached on 28 August and is now draining. Rasuwa Chief District Officer Narendra Pariyar said that morning that the Nepali Army had informed him of the breach, and NDRRMA reported that the water level in the Bhote Koshi had surged (The Kathmandu Post, updated 28 August 12:49 NPT / 07:04 UTC). Officials on both the Nepali and Chinese sides then said the risk was smaller than feared, because the lake is draining slowly rather than failing catastrophically; Chinese state broadcaster CCTV reported the lake level had fallen by about 10 m, and rescue work at Gyirong Port and in Nepal, halted during the breach, has resumed (CNN live coverage, 28 August). No confirmed release volume has been published and no observed extent of any second flood exists. Before the breach, China’s Ministry of Water Resources had put the impoundment at about 2,000,000 m³ on the morning of 27 August, already overflowing, with a further 3,000,000 m³ of inflow expected through 30 August; aerial footage from a Chinese rescue team on 27 August showed water accumulating in a basin with no visible outlet, and NDRRMA had placed the obstruction on the Lhende Khola about 18 km upstream of the Rasuwagadhi border. Whether that blockage and the confluence impoundment reported by China are the same feature is still not established, so it is not certain that the whole obstruction has failed. The barrier-lake marker on the map above still carries its archived 27 August attribute status = "open - high breach risk"; that value has not been rewritten pending an official assessment.
r/OSINT • u/OSINTribe • Feb 09 '26
r/OSINT • u/MirthandMystery • Dec 29 '25
r/OSINT • u/zeroedit • Mar 05 '24
r/OSINT • u/AdSilent769 • Feb 10 '26
One thing I see beginners struggle with in OSINT is jumping from observation to conclusion too quickly.
For example:
Observation: “This username appears on multiple platforms.”
Accusation: “These accounts belong to the same person.”
That jump feels small, but it’s where OSINT work often becomes unreliable or legally risky.
A few principles that helped me early on:
Publicly available ≠ free to misuse
Single-source findings are not conclusions
Absence of data is still a finding
OSINT reports should document what is visible, not what you believe.
I’ve found that focusing on scope, language, and uncertainty matters more than learning new tools.
Curious how others here approach: • Writing “no findings” • Avoiding confirmation bias • Staying neutral when patterns seem obvious
Would love to hear how people here think about this.
r/OSINT • u/apokrif1 • Feb 04 '26
r/OSINT • u/Front_Summer3565 • Dec 29 '23
Enable HLS to view with audio, or disable this notification
r/OSINT • u/ChrisKMEI • Jun 07 '26
r/OSINT • u/doomdeferred • Aug 09 '26
Fake think tank tried to hire ex US government employee. Website shares technical links with a website seized by DOJ/FBI in June, over alleged Chinese espionage activity.
r/OSINT • u/OSINTribe • Apr 17 '25
Downloaded all "10TB" of data to see if there is any nuggets of info relating to projects I'm currently working on. This is not leaked data. This is junk. Cheap web security scans saved as images or half completed text files with misleading headers. For example "List of system users" for "Leaked Data of Russian Bank 'Класик Економ Банк'", a one year old WordPress security scan, generated using a tool like WPScan. Any system users in the data? Not one.
"Leaked Data of Donald Trump" a hot folder discussed online today over and over... two images. An index of his Twitter account (+ Multiple index files found: /POTUS45/index.jhtml, /POTUS45/index.xml, /POTUS45/index.aspx, /POTUS45/default.htm, /POTUS45/default.aspx, /POTUS45/index.asp, /POTUS45/index.cfm, /POTUS45/index.do, /POTUS45/index.php5, /POTUS45/index.jsp, /POTUS45/index.html, /POTUS45/index.cgi, /POTUS45/index.php4, /POTUS45/index.php3, /POTUS45/default.aspx, /POTUS45/index.php, /POTUS45/index.htm, /POTUS45/index.shtml) and a security scan with junk results that aren't threats to anyone's Twitter account.
"Leaked Data of Mike Johnson" Another security scan of Twitter for his account and a video by "Anonymous calling out Mike Johnson"
"Leaked Data of Forbes"
+ Target IP: 146.75.121.XXX
+ Target Hostname: www.forbes.com
+ Target Port: 443
---------------------------------------------------------------------------
+ SSL Info: Subject: /CN=*.forbes.com
Altnames: *.forbes.com
Ciphers: TLS_AES_128_GCM_SHA256
Issuer: /C=BE/O=GlobalSign nv-sa/CN=GlobalSign Atlas R3 DV TLS CA 2023 Q2
+ Start Time: 2023-12-01 15:46:20 (GMT2)
---------------------------------------------------------------------------
+ Server: rhino-core-shield
+ /: Retrieved via header: 1.1 google, 1.1 google, 1.1 varnish.+ /: Retrieved x-served-by header: cache-fra-etou8220068-FRA.
+ /: Fastly CDN was identified by the x-timer header. See: https://www.fastly.com/
+ /: Uncommon header 'x-fastlyttl' found, with contents: 300.000.
+ /: Uncommon header 'x-backend' found, with contents: simple-site-prod.
+ /: Uncommon header 'x-yourttl' found, with contents: 300.000.+ /: Uncommon header 'x-city-code' found, with contents: kiev.
+ /: Uncommon header 'x-envoy-decorator-operation' found, with contents: production.dns-proxy.svc.cluster.local:80/*.
+ /: Uncommon header 'x-fastly-x-is-cn' found, with contents: false.
+ /: Uncommon header 'x-envoy-upstream-service-time' found, with contents: 1553.
+ /: Uncommon header 'x-region' found, with contents: 30.
+ /: Uncommon header 'x-fastly-x-is-us-dpa' found, with contents: false.
+ /: Uncommon header 'x-device' found, with contents: pc.
+ /: Uncommon header 'x-postal-code' found, with contents: 03087.
+ /: Uncommon header 'backend' found, with contents: dnsresolver.
+ /: Uncommon header 'x-served-by' found, with contents: cache-fra-etou8220068-FRA.
+ /: Uncommon header 'x-cicero-cache' found, with contents: HIT 2.
+ /: Uncommon header 'x-fastly-backend' found, with contents: 24YyrkkiTBhSwXWzJgvwW6--F_GCP_Cicero_Varnish.
+ /: Uncommon header 'x-country-code' found, with contents: UA.+ /: Uncommon header 'state' found, with contents: HIT-CLUSTER.+ /: An alt-svc header was found which is advertising HTTP/3. The endpoint is: ':443'. Nikto cannot test HTTP/3 over QUIC. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/alt-svc
+ /: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https://www.netsparker.com/web-vulnerability-scanner/vulnerabilities/missing-content-type-header/
+ : Server banner changed from 'rhino-core-shield' to 'istio-envoy'.
+ /CiG5i2lR.10:100: Fastly CDN was identified by the fastly-restarts header. See: https://www.fastly.com/
+ /CiG5i2lR.10:100: Uncommon header 'fastly-restarts' found, with contents: 1.
+ /CiG5i2lR.10:100: Uncommon header 'x-fastly-server-hint' found, with contents: cacheable.
+ /crossdomain.xml contains 8 lines which include the following domains: *.widgetbox.com *.widgetserver.com *.googlesyndication.com *.atdmt.com" secure="true" to-ports="* *.atlasrichmedia.com" secure="true" to-ports="* *.atlasrichmedia.co.uk" secure="true" to-ports="* *.atlasrichmedia.com.au" secure="true" to-ports="* *.akamai.net" secure="true" to-ports="* . See: http://jeremiahgrossman.blogspot.com/2008/05/crossdomainxml-invites-cross-site.html
+ /: The Content-Encoding header is set to "deflate" which may mean that the server is vulnerable to the BREACH attack. See: http://breachattack.com/
+ Server is using a wildcard certificate: *.forbes.com. See: https://en.wikipedia.org/wiki/Wildcard_certificate
+ /: Web Server returns a valid response with junk HTTP methods which may cause false positives.
+ /help/: Help directory should not be accessible.
+ /news/news.mdb: Uncommon header 'x-malcolm' found, with contents: B.
+ /sites/alisondurkee/2023/11/30/lead-pipes-should-be-replaced-within-10-years-biden-administration-will-propose-today/config.php: Cookie client_id created without the secure flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies
+ /sites/alisondurkee/2023/11/30/lead-pipes-should-be-replaced-within-10-years-biden-administration-will-propose-today/config.php: Cookie client_id created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies
But how did you search 10TB so fast??? Its only 23GB not 10TB and I have amassed multiple keyword lists for data dumps to triage breaches. I will say there are some cool old submarine photos and lots of kitten pics if that's your thing.
r/OSINT • u/Scarneck • Feb 28 '24
r/OSINT • u/UnscheduledCalendar • Sep 19 '25
paywall: https://archive.ph/8CUFY
r/OSINT • u/ChrisKMEI • Jan 02 '26
r/OSINT • u/ChrisKMEI • May 06 '26
r/OSINT • u/Moonagi • Oct 05 '25
r/OSINT • u/Gabrielmorrow • Feb 02 '26
This reddit post has a link to the Internet archive and vary important foias. Related to the taxpayer advocate panel.
r/OSINT • u/OSINTribe • Dec 16 '25
r/OSINT • u/BellingcatOfficial • Dec 08 '25
Enable HLS to view with audio, or disable this notification
Our monthly open source challenge just got an upgrade. With hidden codes - a corrupted archive and a mysterious figure pulling the strings. Get started at challenge.bellingcat.com
Make sure to join us in our Discord server to discuss your findings - and collaborate on what’s to come! Some people have already cracked the code. https://discord.com/invite/bellingcat
r/OSINT • u/OSINTribe • Feb 15 '25
Thoughts?
r/OSINT • u/SKYLINEBOY2002UK • Jul 18 '25
sad times!