Shodan, Censys, ZoomEye, FOFA, BinaryEdge, and a small set of others continuously scan every public IP on the internet and index what they find. They are essential tools for security research, attack-surface management, and OSINT. Here is the comparison.
Jesse William McGraw
Passive DNS is the recording of what DNS lookups have happened across the internet. For threat intel and OSINT investigations, it is one of the most powerful single data sources — it lets you see history that current DNS records cannot reveal.
Ransomware leak sites are the public-facing front of double-extortion operations. Tracking them — what’s posted, when, by which group, against which victim — is a useful OSINT skill for threat intelligence, journalism, and breach victim notification.
Three of the most popular OSINT frameworks each take a different approach. Maltego is the visual link-analysis platform; SpiderFoot is the automated scanning engine; Recon-ng is the modular CLI workflow. Here is when to reach for each.
For investigations of organisations, infrastructure, threat actors, or attack surface, the DNS and certificate ecosystem is one of the most productive places to look. Here are the tools — Certificate Transparency logs, passive DNS, and modern recon platforms — and how to use them well.
Locating a photograph or video to a specific spot on Earth is one of the most distinctive OSINT skills. Bellingcat’s geolocation work has cracked everything from MH17 to Russian war-crimes investigations. Here is how the technique actually works.
Reverse image search is one of the most useful OSINT primitives. Google was the original; in 2026 Yandex, TinEye, Bing Visual Search, and a handful of specialised tools each find different things. Here is when to use which, and what limits each one.
Open-Source Intelligence is older than the internet but has been transformed by it. Here is what OSINT actually is, what distinguishes it from passive web searching, the ethical lines that matter, and the tools that practitioners actually use.
Differential privacy is the mathematical technique that lets a company compute aggregate statistics over its users while provably bounding what can be learned about any individual. Apple, Google, and the US Census Bureau use it. Here is how it actually works, where the guarantee holds, and where it fails.
The two mobile operating systems have arrived at recognisably different privacy postures over the past five years. Apple’s App Tracking Transparency, Google’s Privacy Sandbox, and the steady accretion of features in both have produced a comparison that is still close — but no longer symmetric.