INVESTIGATIONS
OSINT
Tools, methods, and case studies from the open-source investigation discipline.
Open-source intelligence, from first principles to the toolchain. Methodology, geolocation, infrastructure hunting, leak-site investigation and on-chain tracing, written for journalists, researchers and due-diligence teams. Start with OSINT fundamentals, the 2026 starter toolkit and the Bellingcat methodology.
The applied end of this work runs through the breach verification desk and the leak-site investigation walkthrough.
Start here
- OSINT fundamentals: discipline, ethics, tools
- OSINT 101: a starter toolkit for 2026
- Best OSINT tools 2026: what analysts run
- Tracking ransomware leak sites: an OSINT workflow
- How to verify a leaked dataset before reporting
Latest OSINT coverage
- Best OSINT tools 2026: what analysts actually runThe OSINT tools worth your time in 2026: Maltego, Shodan, SecurityTrails, DarkOwl, theHarvester and more, ranked by what they do and what they leak.
- Maltego tutorial: OSINT link analysis in 2026A hands-on 2026 guide to Maltego for OSINT: entities, transforms, machines and how to build a corroborated link chart from a single selector using the free Community Edition.
- GraphSense tutorial: open-source crypto tracing in 2026A hands-on 2026 guide to GraphSense, the open-source cryptoasset forensics platform: address clustering, TagPacks and how to trace ransom funds without a paid licence.
- Pivoting on threat-actor handles: a 2026 OSINT methodHow to pivot from a single ransomware forum handle to a corroborated actor profile using usernames, PGP keys, emails and crypto selectors. A 2026 OSINT walkthrough.
- Tracing ransom payments on-chain: a 2026 OSINT walkthroughA practical 2026 walkthrough for following a ransom payment across the blockchain using open tools, wallet clustering and off-ramp attribution.
- Hunting C2 infrastructure: favicon, JARM, cert logsA 2026 OSINT methodology for pivoting from one malicious IP to a whole adversary cluster using favicon hashes, JARM fingerprints, and certificate transparency.
- Ransomware leak-site OSINT: 2026 investigation walkthroughA practical OSINT walkthrough for investigating ransomware leak sites: workflow, sources, pitfalls, and how to verify victim claims without breaking operational security.
- Audit your digital footprint 2026: Sherlock, Holehe, WhoxyA 2026 self-doxxing tutorial: run the same OSINT tools attackers use, on yourself, to find every account, leaked credential, and broker entry tied to your identity. With remediation steps for each finding.
- Attack-surface mapping 2026: Shodan, Censys, FOFA, NucleiA 2026 OSINT workflow for mapping the external attack surface of any organisation using only public data: internet-scan engines, certificate transparency, and authenticated vulnerability templates.
- OSINT.industries hands-on: a 2026 tutorial for journalists and due-diligence analystsA practitioner’s deep-dive on OSINT.industries: what it returns for username and email queries, how I use it for journalism and due diligence, and the ethics framework I won’t run a query without.
- Multi-tool OSINT search: tutorial using IntelX, Spiderfoot, and MaltegoA 2026 tutorial for running OSINT investigations across paste sites, breach data, and forums using IntelX for breach search, Spiderfoot for automated correlation, and Maltego for graph analysis.
- How to verify a ransom payment on-chain: tutorial with Mempool, OXT, and Ransomwhe.reA practitioner’s tutorial for verifying (or refuting) a claimed ransom payment on the Bitcoin blockchain using free tools. Useful for journalists, IR teams, and victims dealing with secondary-extortion claims.
- Inside a ‘cloud of logs’ Telegram subscription tierA practitioner’s look inside the “cloud of logs” subscription model: what attackers pay, what they get, and the operational mechanics that turn raw infostealer output into a productised threat.
- Stealer log forensics: tracing infections back to the userA practitioner’s forensic playbook for working backwards from a stealer log to the originating infection: what the log file structure tells you, where the malware sits, and how to clean it up properly.
- Hardening your home lab: the OPSEC checklist for indie security researchersA practical OPSEC checklist for indie security researchers, journalists, and bug-bounty hunters working from home. Network segmentation, hardware separation, identity hygiene, and the small habits that make the difference.
- Tracking ransomware infrastructure: a 2026 OSINT methodologyA practitioner’s OSINT methodology for tracking ransomware infrastructure in 2026: the seven sources to monitor, how to correlate them, and the operational hygiene that keeps your work credible.
- The Bellingcat geolocation toolkit: 10 sources that always workTen geolocation sources that never let me down on an OSINT investigation, ranked by how often they crack the case. Free where possible, paid where necessary.
- Telegram OSINT: how investigators trace channels and admins in 2026A practitioner’s playbook for Telegram OSINT in 2026: how to discover channels, fingerprint admins, archive content, and build defensible attribution without burning your access.
- Maltego workflows for ransomware research: a 2026 starter packA starter pack of Maltego transforms and graph patterns for ransomware research: entity model, transform recommendations, and three reusable graphs that pay rent on every investigation.
- How to verify a leaked dataset before you write about itNewsroom and researcher checklist for validating a leaked dataset before publishing: five tests that catch fabrication, recycled breaches, and misattributed dumps.
- Building an OSINT investigation workflow: from intake to reportThe five-stage workflow that separates an OSINT analyst from someone with a bookmarks bar full of tools.
- OPSEC for OSINT investigators: not contaminating what you researchHow journalists and OSINT analysts keep their personal accounts, devices, and identity separate from the investigations they run. Defensive opsec, not evasion.
- OSINT.industries: a hands-on walkthrough for usernames and emailsWhat OSINT.industries actually returns, how I use it for journalism and due-diligence work, and the ethics framework I won’t run a query without.
- Geolocating a photo from scratch: the Bellingcat workflow for normal humansA practitioner walkthrough of the photo-geolocation method used by Bellingcat and most newsroom verification teams. Worked example included.
Every OSINT article
Every article we have published in this section, newest first.
- Best OSINT tools 2026: what analysts actually run
- Maltego tutorial: OSINT link analysis in 2026
- GraphSense tutorial: open-source crypto tracing in 2026
- Pivoting on threat-actor handles: a 2026 OSINT method
- Tracing ransom payments on-chain: a 2026 OSINT walkthrough
- Hunting C2 infrastructure: favicon, JARM, cert logs
- Ransomware leak-site OSINT: 2026 investigation walkthrough
- Audit your digital footprint 2026: Sherlock, Holehe, Whoxy
- Attack-surface mapping 2026: Shodan, Censys, FOFA, Nuclei
- OSINT.industries hands-on: a 2026 tutorial for journalists and due-diligence analysts
- Multi-tool OSINT search: tutorial using IntelX, Spiderfoot, and Maltego
- How to verify a ransom payment on-chain: tutorial with Mempool, OXT, and Ransomwhe.re
- Inside a ‘cloud of logs’ Telegram subscription tier
- Stealer log forensics: tracing infections back to the user
- Hardening your home lab: the OPSEC checklist for indie security researchers
- Tracking ransomware infrastructure: a 2026 OSINT methodology
- The Bellingcat geolocation toolkit: 10 sources that always work
- Telegram OSINT: how investigators trace channels and admins in 2026
- Maltego workflows for ransomware research: a 2026 starter pack
- How to verify a leaked dataset before you write about it
- Building an OSINT investigation workflow: from intake to report
- OPSEC for OSINT investigators: not contaminating what you research
- OSINT.industries: a hands-on walkthrough for usernames and emails
- Geolocating a photo from scratch: the Bellingcat workflow for normal humans
- Reverse image search beyond Google: when to reach for Yandex, TinEye, and the rest
- OSINT 101: a starter toolkit for 2026
- The Telegram stealer-log economy: how stolen credentials are sold
- The Bellingcat methodology: how open-source journalism solved real cases
- Social media OSINT: from Twitter/X to Telegram
- Shodan, Censys, and the internet-wide scanners compared
- Passive DNS: the underrated investigative tool
- Tracking ransomware leak sites: an OSINT workflow
- Maltego, SpiderFoot, Recon-ng: a practical comparison of OSINT frameworks
- Domain and subdomain reconnaissance: tools and techniques for OSINT
- Geolocation techniques: how open-source investigators find where a photo was taken
- Reverse image search in 2026: beyond Google
- OSINT fundamentals: the discipline, the ethics, the tools






















