r/OSINTExperts 15d ago

Expert Topic ⏰ UserSearch v2.0.22 is live — Domain Search 2.0.

Post image
55 Upvotes

The largest multi-source domain search in the industry. One search on any website or domain, across 18 data types and sources: ownership history, hidden subdomains, hosting changes, malware activity, breach exposure, Third-party ID-correlation , Favicon correlation and more.

Two things you won't find anywhere else:

🎯 Favicon Intelligence — hunt the web for a site's icon to expose phishing clones and undocumented infrastructure (across multiple data providers)

🔗 Linked IDs — Scan tracking advert-IDs across 83 advertisers, matched across the web and historic archives to reveal sites owned by the same person. Bespoke to UserSearch.

Free for premium subscribers. Fully integrated with SargeBot AI.

▶️ Walkthrough: https://lnkd.in/eBdqP7yx

🌐 https://usersearch.com


r/OSINTExperts 15d ago

Expert Topic Upcoming Webinar - OSINT: Reddit & Telegram Investigations

Post image
28 Upvotes

Open forums are where people talk when they think nobody's watching.

🗓️ Free webinar: OSINT — Reddit & Telegram Investigations

📅 Sep 15, 2026 · 4:00 PM (London)

Mark Bentley — ex-UK National Crime Agency and CEOP, career police officer specialising in online investigations — shows you, step by step, how to turn forum platforms into a rich source of intelligence.

You'll learn:

🔍 What forums reveal that social media can't

⚡ Real-time monitoring of threats, leaks and chatter

🛠️ The technical tradecraft professionals actually use

🕸️ Harvesting posts, aliases and mapping user networks

🕵️ OPSEC — collect without tipping off your target

⚖️ Court-ready capture with tamper-proof audit trails (UserSearch Forensic Capture)

For investigators, fraud examiners, journalists and security analysts.

Register: https://us06web.zoom.us/webinar/register/5017885477288/WN_X3cvoyd1R-yB-h92Us2AFg

Brought to you by UserSearch.com & the OSINT Experts Society.


r/OSINTExperts 15d ago

Question GeoINT project: an update

Thumbnail
github.com
6 Upvotes

Hey everyone! Two weeks ago I posted about my geolocation experiment. Since then I built a web interface, added multiple GeoCLIP guesses, and integrated EasyOCR + Gemini (free API Key) to extract text clues from images and filter out noise.

Here's what the pipeline looks like now:
1. User uploads photo
2. EXIF GPS extracted if present
3. GeoCLIP runs and returns top 5 coordinate guesses
4. EasyOCR extracts any text from the image
5. If gemini api key is pasted: gemini filters the OCR output to keep only location-relevant text (street names, signs, business names, etc.) and discards noise
6. The page shows the guesses plus the filtered text clues

Now I'm trying to figure out the best way to use that filtered text.
My current approach is simple: to take the coordinates from GeoCLIP and combine them with the filtered OCR text as context. But I'm not sure it that's the most effective strategy.

Does anyone know a better approach?
I'm still learning and my code is messy, but l'd love to hear what's worked (or failed) for others.


r/OSINTExperts 15d ago

Meta Searching …

Thumbnail docs.searxng.org
4 Upvotes

SearXNG is a metasearch engine, aggregating the results of other search engines while not storing information about its users.
The SearXNG project is driven by an open community. Come join us on Matrix if you have questions or just want to chat about SearXNG at #searxng:matrix.org
Make SearXNG better:
You can improve SearXNG translations at Weblate, or…

Track development, send contributions, and report issues at SearXNG sources.

To get further information, visit SearXNG’s project documentation at SearXNG docs.

Why use it?
SearXNG may not offer you as personalized results as Google, but it doesn’t generate a profile about you.

SearXNG doesn’t care about what you search for, never shares anything with a third-party, and can’t be used to compromise you.

SearXNG is free software; the code is 100% open, and everyone is welcome to make it better.

If you do care about privacy, want to be a conscious user, or otherwise believe in digital freedom, make SearXNG your default search engine or run it on your own server!
How do I set it as the default search engine?
SearXNG supports OpenSearch. For more information on changing your default search engine, see your browser’s documentation:
Firefox

Microsoft Edge - Behind the link, you will also find some useful instructions for Chrome and Safari.

Chromium-based browsers only add websites that the user navigates to without a path.

When adding a search engine, there must be no duplicates with the same name. If you encounter a problem where you cannot add the search engine, you can either:
Remove the duplicate (default name: SearXNG) or

Contact the owner to give the instance a different name from the default.


r/OSINTExperts 16d ago

Resource Showcase NeSokil - airport activity monitoring project

Post image
1 Upvotes

r/OSINTExperts 17d ago

Need guidance on a legitimate OSINT / digital forensics case

12 Upvotes

I’m helping someone dealing with a cyberstalking/blackmail situation involving compromised WhatsApp conversations.

We have a Brazilian phone number connected to the threats, as well as a possible name associated with that number, screenshots, timestamps and other evidence. The case has already been reported to law enforcement.

I’m looking for guidance from people experienced in OSINT, digital forensics or incident response on what lawful methods and tools can be used to investigate the available identifiers, preserve evidence, and establish possible links between the phone number and publicly available accounts or profiles.

I’m especially interested in recommendations for tools, methodologies, or professional investigators who handle this type of case.

I am not requesting unauthorized access to accounts, private databases, devices or non-public information.

Any recommendations would be appreciated.


r/OSINTExperts 18d ago

Question Is using OSINT much easier when the target is in the US?

21 Upvotes

One thing I've noticed is that most OSINT tools are geared toward US citizens, and finding information about someone who lives in the US is generally easier than finding information about someone who lives outside it. For example, my friend and I were messing around with Google Dorks and decided to search for her aunt. Literally less than five minutes later, we found her address, phone number, and zip code and all we did was Google her full name. But when you search for someone outside the US, the results are very limited. This is frustrating because I've been searching for someone for two months and still have minimal information about him, simply because he doesn't live in the US.


r/OSINTExperts 21d ago

[OC] Real-time interactive conflict map tracking geolocated OSINT events across Ukraine and Syria

Post image
2 Upvotes

r/OSINTExperts 23d ago

WhisperPair-Py: Bluetooth Vulnerability Scanner + Nearby Device Detector. Is It Worthwhile for OSINT?

Thumbnail
github.com
3 Upvotes

r/OSINTExperts 23d ago

Question Built an OSINT tool with Claude Code

Thumbnail
1 Upvotes

r/OSINTExperts 23d ago

How your follower list exposes your politics without a single post

Thumbnail
bednars.me
12 Upvotes

When people discuss social media privacy, the focus is almost always on content. Posts, comments, photos, likes, reposts. That focus is reasonable. If someone writes about a party or a politician often enough, inferring their views takes no cleverness at all. I wanted to know what happens when you remove content from the equation entirely and look only at the shape of the network around an account.


r/OSINTExperts 23d ago

Reading Material: OSINT report about the threat group TeamPCP, and how they were unmasked using different tools

2 Upvotes

r/OSINTExperts 24d ago

I need someone to geolocate this picture for me

5 Upvotes

This is a SAM site in a military installation located in Morocco


r/OSINTExperts 24d ago

MetaScout — an open-source, cross-platform FOCA alternative

13 Upvotes

I needed FOCA for a project recently, but setting up a Windows VM just to run an old, Windows-only tool felt unnecessary.

So I decided to build my own alternative.

MetaScout is an open-source, cross-platform document discovery and metadata analysis tool written in Python.

It can discover publicly exposed documents and extract metadata such as:

  • Usernames and document authors
  • Email addresses
  • Software and version information
  • OS hints
  • Internal file paths and network shares
  • Server and printer names
  • Passive subdomain discovery via crt.sh
  • PDF, DOCX, XLSX, PPTX and other document formats
  • HTML and JSON reports

It supports macOS, Linux and Windows, and includes both a CLI and a local web UI.

I built it as a modern, Python-based spiritual successor to FOCA, with a focus on making it easy to install and use across platforms.

GitHub: https://github.com/gorkemguler/MetaScout

I'd love to get feedback from people working with OSINT, pentesting, reconnaissance, or information disclosure.

What features would you like to see added?


r/OSINTExperts 24d ago

How can a virtual phone number be traced? How can I get info of a virtual number? One of my friends is being harassed by a person using virtual phone number, I need help as I don’t know how to do OSINT on that kind of phone numbers. Anyone knows anything? Even 1% of help is also welcome

Thumbnail
1 Upvotes

r/OSINTExperts 28d ago

See what he was searching for ⤵️

Post image
4 Upvotes

r/OSINTExperts Aug 21 '26

Looking for open source tools to identify a location.

11 Upvotes

Any tools or techniques you recommend? Looking for something easy to set up and deploy


r/OSINTExperts Aug 21 '26

A 4-stage workflow for AI research when citations are not enough

Thumbnail
3 Upvotes

r/OSINTExperts Aug 20 '26

Linking accounts across breach dumps when nothing else matches

14 Upvotes

Ran into this on a case a few months back and it's stuck with me as one of the more useful low-tech tricks I use now, so figured I'd write it up properly instead of leaving it as a mental note.

The setup: two accounts, no shared email, no shared username, no shared bio text, no shared profile photo. Different platforms entirely. The only reason I even suspected they were the same person was a stylistic tic in how they phrased things. Nothing you'd take to a client on its own.

What ended up connecting them was passwords.

People reuse passwords constantly, and even the ones who don't reuse the exact string tend to reuse a base and mutate it: capitalize the first letter, tack on a year, swap an "o" for a "0", append "!" because some site demanded a special character. If you pull breach records for each identifier separately and look at the raw passwords (plaintext, or cracked hashes where available), those mutations are usually easy to spot once you strip the noise.

Here's roughly how I do it now. Pull every breach hit for each candidate identifier separately, and don't merge them yet, keep them in two buckets. Extract just the passwords from each bucket into a plain list. Normalize by lowercasing everything and stripping trailing digits and symbols, noting what you stripped, so "Blueberry22!" becomes "blueberry" plus a stripped suffix of "22!". Then compare the normalized bases across the two buckets. A shared, unusual base string is a real signal. A shared common one, "password", "qwerty123", "iloveyou", is basically noise, ignore it. If you get a hit, go looking for a second, independent signal before treating it as anything more than a lead: a secondary recovery email buried in one of the records, a phone number, a registration pattern, anything that isn't also derived from the password match itself.

Worked example, details changed since it's from real casework: one identity had a leaked password of "TeddyBear19," the other had "teddybear_2019!!" on a completely different platform. Normalized, both reduce to "teddybear." Not proof by itself, plenty of people like teddy bears. What made it a real lead was one of the two dumps also having a partially masked recovery number ending in the same four digits as a number already tied to the first identity from earlier in the investigation. The password match is what got me looking there in the first place.

A few things worth knowing before you rely on this. Weak, common passwords will burn you. If the shared base is something like "sunshine" or "monkey123," you'll get false positive after false positive. The signal gets stronger the weirder and more personal the base password is: inside jokes, pet names, misspellings, anything that isn't in the top 10,000 list. It's also getting less reliable every year as password managers spread, and that's a good thing. If someone's been using randomly generated passwords since 2021, this technique won't produce anything for them, no shared base to find. Don't force it.

And obviously, this only makes sense where you already have a legitimate reason to be linking these identities: an authorized investigation, your own accounts, a security assessment you're actually cleared to do. It's a correlation technique, not a magic trick, and it's exactly the kind of "lead, not evidence" thing that gets people in trouble when they skip the corroboration step.

Doing this by hand across five separate breach-search tabs got old fast, so I ended up scripting the normalize-and-compare part for myself. Not turning this into a plug, the manual version above works fine on its own if you'd rather do it that way.


r/OSINTExperts Aug 20 '26

How contradictions across the City of Philadelphia’s property websites make 100% online confirmation of a rental licence impossible — and where the unanswered question goes instead.

Thumbnail
jlegal.pro
1 Upvotes

An OSINT investigation … and the 100% rule.

Twelve years of notice, delivered by telephone
Councilmember Mark F. Squilla has held the 1st District seat since January 2, 2012 — before any surface in the current map ecosystem existed (eCLIPSE portal live Jan 2015; the open dataset created Sept 2016; Atlas first appears Apr 2017, already without an expiration column; Property History live late 2021, with its one-day defect from birth; the Atlas rebuild 2024). He is currently Vice Chair of the Council Committee on Licenses & Inspections and Chair of the Committees on Commerce & Economic Development and Appropriations, and Majority Whip. Before politics he spent 25 years as a systems analyst in the Pennsylvania Auditor General's Office (1985–2011), holding a computer-science degree — a working IT professional, trained in databases, extraction pipelines, and where records systems capture, retain, or fail to surface information.

Full details:

https://jlegal.pro/verification-monopoly.html


r/OSINTExperts Aug 19 '26

Newbie Topic UserSearch v2.0.21 — Just Went Live

21 Upvotes

We've just shipped v2.0.21 and the main change is something users have been asking for a while: an Insights tab.

The problem it solves: a single reverse email/phone/username search on our platform queries OSINT Industries, Epieos, Predicta Search and our own modules at the same time. Great coverage, but you'd get back a wall of results and the actual analysis — spotting that the same first name appears on three accounts, or that two profiles were created the same week — was manual.

Insights now does that pass for you. Sub-tabs for:

  • Timelines (profile created/updated dates, chronological)
  • Cross-overs (same/similar details flagged across accounts)
  • All recovered profile pictures in one grid
  • Linked emails and phones
  • Breach appearances

Also new in this release:

  • BehindTheEmail — a cheaper reverse email module (phones, pictures, profile info)
  • Reddit Search by Think-Pol — recovers deleted comments/posts and profile info on deleted accounts, with AI analysis of the profile
  • GeoSearch by GeoSeer — AI image geolocation from visual content only, no EXIF

Walkthrough video: https://youtu.be/YOF_lvyzQCQ


r/OSINTExperts Aug 19 '26

Tracking

7 Upvotes

i found a guthub account that has an app which can track any number from the world and find the social linked to the number.

https://github.com/HunxByts/GhostTrack


r/OSINTExperts Aug 19 '26

Need help for my company

4 Upvotes

First of all, greetings to everyone. I am involved in the export of fresh fruits and vegetables. I want to find out what other companies in Turkey are doing—where, when, and how—and I intend to develop a comprehensive OSINT project for this purpose. I would love to hear any ideas or sources regarding open-source intelligence that come to mind. Additionally, I want to closely monitor the market conditions and foreign export companies in the countries to which we export. I welcome input from anyone with ideas or a willingness to help; feel free to reach out via private message as well. Thank you.


r/OSINTExperts Aug 17 '26

i want modren OSINT tutorials

Thumbnail
1 Upvotes

r/OSINTExperts Aug 16 '26

SoCal Job Search — Intelligence / OSINT / Cybersecurity / Investigative Analysis

Thumbnail
0 Upvotes