Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

OSINT

INVESTIGATIONS

OSINT

Tools, methods, and case studies from the open-source investigation discipline.

Open-source intelligence, from first principles to the toolchain. Methodology, geolocation, infrastructure hunting, leak-site investigation and on-chain tracing, written for journalists, researchers and due-diligence teams. Start with OSINT fundamentals, the 2026 starter toolkit and the Bellingcat methodology.

The applied end of this work runs through the breach verification desk and the leak-site investigation walkthrough.

Start here

  • OSINT fundamentals: discipline, ethics, tools
  • OSINT 101: a starter toolkit for 2026
  • Best OSINT tools 2026: what analysts run
  • Tracking ransomware leak sites: an OSINT workflow
  • How to verify a leaked dataset before reporting

Latest OSINT coverage

  • Best OSINT tools 2026: Maltego, Shodan, SecurityTrails, VirusTotal, theHarvester, DarkOwl, BGPView, Wayback Machine
    Best OSINT tools 2026: what analysts actually runAugust 4, 2026
    The OSINT tools worth your time in 2026: Maltego, Shodan, SecurityTrails, DarkOwl, theHarvester and more, ranked by what they do and what they leak.
  • Maltego tutorial: OSINT link analysis in 2026, ransomnews.com
    Maltego tutorial: OSINT link analysis in 2026July 20, 2026
    A hands-on 2026 guide to Maltego for OSINT: entities, transforms, machines and how to build a corroborated link chart from a single selector using the free Community Edition.
  • GraphSense tutorial: open-source crypto tracing in 2026, ransomnews.com
    GraphSense tutorial: open-source crypto tracing in 2026July 20, 2026
    A hands-on 2026 guide to GraphSense, the open-source cryptoasset forensics platform: address clustering, TagPacks and how to trace ransom funds without a paid licence.
  • Pivoting on threat-actor handles: a 2026 OSINT method, ransomnews.com
    Pivoting on threat-actor handles: a 2026 OSINT methodJuly 20, 2026
    How to pivot from a single ransomware forum handle to a corroborated actor profile using usernames, PGP keys, emails and crypto selectors. A 2026 OSINT walkthrough.
  • Tracing ransom payments on-chain: a 2026 OSINT walkthrough, ransomnews.com
    Tracing ransom payments on-chain: a 2026 OSINT walkthroughJuly 20, 2026
    A practical 2026 walkthrough for following a ransom payment across the blockchain using open tools, wallet clustering and off-ramp attribution.
  • Hunting C2 infrastructure synthwave cover, favicon JARM cert logs, ransomnews.com
    Hunting C2 infrastructure: favicon, JARM, cert logsJune 24, 2026
    A 2026 OSINT methodology for pivoting from one malicious IP to a whole adversary cluster using favicon hashes, JARM fingerprints, and certificate transparency.
  • Leak Site OSINT Walkthrough 2026 — Ransomnews cover
    Ransomware leak-site OSINT: 2026 investigation walkthroughMay 16, 2026
    A practical OSINT walkthrough for investigating ransomware leak sites: workflow, sources, pitfalls, and how to verify victim claims without breaking operational security.
  • Mirror reflecting a fragmented digital silhouette of circuit segments, dark editorial illustration
    Audit your digital footprint 2026: Sherlock, Holehe, WhoxyMay 10, 2026
    A 2026 self-doxxing tutorial: run the same OSINT tools attackers use, on yourself, to find every account, leaked credential, and broker entry tied to your identity. With remediation steps for each finding.
  • Network of nodes radiating from a central building outline, dark technical illustration
    Attack-surface mapping 2026: Shodan, Censys, FOFA, NucleiMay 10, 2026
    A 2026 OSINT workflow for mapping the external attack surface of any organisation using only public data: internet-scan engines, certificate transparency, and authenticated vulnerability templates.
  • A magnifying glass over a digital identity card with multiple connected account icons fanning out
    OSINT.industries hands-on: a 2026 tutorial for journalists and due-diligence analystsMay 7, 2026
    A practitioner’s deep-dive on OSINT.industries: what it returns for username and email queries, how I use it for journalism and due diligence, and the ethics framework I won’t run a query without.
  • Three cascaded browser windows with search results connected by lines to a central entity graph
    Multi-tool OSINT search: tutorial using IntelX, Spiderfoot, and MaltegoMay 7, 2026
    A 2026 tutorial for running OSINT investigations across paste sites, breach data, and forums using IntelX for breach search, Spiderfoot for automated correlation, and Maltego for graph analysis.
  • A Bitcoin transaction passing through verification checkpoints to a green checkmark
    How to verify a ransom payment on-chain: tutorial with Mempool, OXT, and Ransomwhe.reMay 7, 2026
    A practitioner’s tutorial for verifying (or refuting) a claimed ransom payment on the Bitcoin blockchain using free tools. Useful for journalists, IR teams, and victims dealing with secondary-extortion claims.
  • A Telegram-style subscription card with a stack of folder icons containing stealer-log silhouettes flowing to a buyer's hand
    Inside a ‘cloud of logs’ Telegram subscription tierMay 3, 2026
    A practitioner’s look inside the “cloud of logs” subscription model: what attackers pay, what they get, and the operational mechanics that turn raw infostealer output into a productised threat.
  • A forensic examination scene with magnifying glass over a stealer log file and a chain-of-evidence trail to an infected user
    Stealer log forensics: tracing infections back to the userMay 3, 2026
    A practitioner’s forensic playbook for working backwards from a stealer log to the originating infection: what the log file structure tells you, where the malware sits, and how to clean it up properly.
  • A top-down view of an indie researcher's home lab with hardened laptop, hardware key, faraday pouch, and network diagram monitor
    Hardening your home lab: the OPSEC checklist for indie security researchersApril 30, 2026
    A practical OPSEC checklist for indie security researchers, journalists, and bug-bounty hunters working from home. Network segmentation, hardware separation, identity hygiene, and the small habits that make the difference.
  • A network graph of connected onion sites and leak URLs with investigation lines and a magnifying glass
    Tracking ransomware infrastructure: a 2026 OSINT methodologyApril 30, 2026
    A practitioner’s OSINT methodology for tracking ransomware infrastructure in 2026: the seven sources to monitor, how to correlate them, and the operational hygiene that keeps your work credible.
  • A flat-lay arrangement of ten OSINT tool icons surrounding a central photograph in a circular pattern
    The Bellingcat geolocation toolkit: 10 sources that always workApril 30, 2026
    Ten geolocation sources that never let me down on an OSINT investigation, ranked by how often they crack the case. Free where possible, paid where necessary.
  • Telegram channel interface with investigation lines from a chat avatar to a real identity card
    Telegram OSINT: how investigators trace channels and admins in 2026April 30, 2026
    A practitioner’s playbook for Telegram OSINT in 2026: how to discover channels, fingerprint admins, archive content, and build defensible attribution without burning your access.
  • Entity graph focused on ransomware research with central operator node and branching infrastructure nodes
    Maltego workflows for ransomware research: a 2026 starter packApril 30, 2026
    A starter pack of Maltego transforms and graph patterns for ransomware research: entity model, transform recommendations, and three reusable graphs that pay rent on every investigation.
  • A leaked database file icon being run through a verification process with checkmarks on different attributes
    How to verify a leaked dataset before you write about itApril 30, 2026
    Newsroom and researcher checklist for validating a leaked dataset before publishing: five tests that catch fabrication, recycled breaches, and misattributed dumps.
  • A five-stage workflow pipeline with glowing connected nodes representing intake, collection, verification, analysis, and report
    Building an OSINT investigation workflow: from intake to reportApril 30, 2026
    The five-stage workflow that separates an OSINT analyst from someone with a bookmarks bar full of tools.
  • Split-screen showing a personal warm-toned setup separated from a hardened research setup by a neon green divider
    OPSEC for OSINT investigators: not contaminating what you researchApril 30, 2026
    How journalists and OSINT analysts keep their personal accounts, devices, and identity separate from the investigations they run. Defensive opsec, not evasion.
  • A glowing magnifying glass scanning a fragmented digital identity profile with username and email visible
    OSINT.industries: a hands-on walkthrough for usernames and emailsApril 30, 2026
    What OSINT.industries actually returns, how I use it for journalism and due-diligence work, and the ethics framework I won’t run a query without.
  • A photograph overlaid on a grid map with triangulation lines connecting visual landmarks to coordinates
    Geolocating a photo from scratch: the Bellingcat workflow for normal humansApril 30, 2026
    A practitioner walkthrough of the photo-geolocation method used by Bellingcat and most newsroom verification teams. Worked example included.

Every OSINT article

Every article we have published in this section, newest first.

  • Best OSINT tools 2026: what analysts actually run
  • Maltego tutorial: OSINT link analysis in 2026
  • GraphSense tutorial: open-source crypto tracing in 2026
  • Pivoting on threat-actor handles: a 2026 OSINT method
  • Tracing ransom payments on-chain: a 2026 OSINT walkthrough
  • Hunting C2 infrastructure: favicon, JARM, cert logs
  • Ransomware leak-site OSINT: 2026 investigation walkthrough
  • Audit your digital footprint 2026: Sherlock, Holehe, Whoxy
  • Attack-surface mapping 2026: Shodan, Censys, FOFA, Nuclei
  • OSINT.industries hands-on: a 2026 tutorial for journalists and due-diligence analysts
  • Multi-tool OSINT search: tutorial using IntelX, Spiderfoot, and Maltego
  • How to verify a ransom payment on-chain: tutorial with Mempool, OXT, and Ransomwhe.re
  • Inside a ‘cloud of logs’ Telegram subscription tier
  • Stealer log forensics: tracing infections back to the user
  • Hardening your home lab: the OPSEC checklist for indie security researchers
  • Tracking ransomware infrastructure: a 2026 OSINT methodology
  • The Bellingcat geolocation toolkit: 10 sources that always work
  • Telegram OSINT: how investigators trace channels and admins in 2026
  • Maltego workflows for ransomware research: a 2026 starter pack
  • How to verify a leaked dataset before you write about it
  • Building an OSINT investigation workflow: from intake to report
  • OPSEC for OSINT investigators: not contaminating what you research
  • OSINT.industries: a hands-on walkthrough for usernames and emails
  • Geolocating a photo from scratch: the Bellingcat workflow for normal humans
  • Reverse image search beyond Google: when to reach for Yandex, TinEye, and the rest
  • OSINT 101: a starter toolkit for 2026
  • The Telegram stealer-log economy: how stolen credentials are sold
  • The Bellingcat methodology: how open-source journalism solved real cases
  • Social media OSINT: from Twitter/X to Telegram
  • Shodan, Censys, and the internet-wide scanners compared
  • Passive DNS: the underrated investigative tool
  • Tracking ransomware leak sites: an OSINT workflow
  • Maltego, SpiderFoot, Recon-ng: a practical comparison of OSINT frameworks
  • Domain and subdomain reconnaissance: tools and techniques for OSINT
  • Geolocation techniques: how open-source investigators find where a photo was taken
  • Reverse image search in 2026: beyond Google
  • OSINT fundamentals: the discipline, the ethics, the tools

The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,711 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links; when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.