Blog
OSINT methodology for security professionals.
-
OWASP Amass for Attack Surface Mapping
2026-07-26
How OWASP Amass works, where it fits your recon pipeline, how it stacks up against Subfinder and SpiderFoot, and a reproducible 10-minute hands-on recipe.
-
Shahed Drones in Mali: What the OSINT Shows
2026-07-26
Bellingcat confirmed Shahed-136-type loitering munitions in northern Mali. Here's what the methodology and the finding mean for threat modeling and OPSEC.
-
US Military Smartphones Targeted via Roaming and Ad Tech
2026-07-19
Citizen Lab documents SS7 roaming exploitation and ad tech surveillance against US military personnel. Here's what the attack surface actually demands from security teams.
-
Felons Running a Zero-Day Broker: What It Means
2026-07-13
The KrebsOnSecurity report on convicted felons operating a zero-day broker exposes a known-vendor problem in offensive security. Here's the practical read.
-
FBI Seizes NetNut and Popa Botnet: Practitioner Analysis
2026-07-05
The FBI seized NetNut's proxy infrastructure and the Popa botnet. Here's what the action means for red teamers, SOC analysts, and OSINT practitioners.
-
Plonkit Asphalt Meta: What Geolocation Tradecraft Rewards
2026-07-05
How Plonkit's asphalt-meta signals—color, road markings, curb profiles—build a disciplined analytic chain for real-world OSINT geolocation work.
-
reconFTW: Recon Orchestration from Domain to Findings
2026-06-28
How six2dez/reconFTW orchestrates subdomain enum, port scanning, and Nuclei against a target — setup, config, triage, and when to skip it.
-
CTFTime OSINT Category: What Challenges Actually Test
2026-06-28
A methodology survey of the CTFTime OSINT archive: the analytic primitives well-designed challenges test, the difficulty curve, and the gaps no CTF format can fill.
-
Kinahan Cartel OSINT: What the Padel Investigation Shows
2026-06-28
Bellingcat geolocated a sanctioned Kinahan lieutenant at a Dubai padel club. Here's what the methodology means for threat intel, compliance, and physical security teams.
-
Passive Subdomain Enumeration with subfinder
2026-06-22
How projectdiscovery subfinder works, where it fits against Amass and assetfinder, and a reproducible pipeline from install to live-host list.
-
TraceLabs CTF: Building the Analytic Chain
2026-06-22
How to structure intake, collection, verification, and evidence packaging for a TraceLabs Search Party CTF — methodology over tool lists.
-
WhatsApp vs. NSO: What the Contempt Motion Signals
2026-06-22
Meta's contempt motion against NSO Group shows Pegasus ops continued through WhatsApp during active litigation. Here's what the record means for defenders and researchers.
-
projectdiscovery httpx: HTTP Enumeration at Scale
2026-06-15
How projectdiscovery httpx works, where it fits between subfinder and nuclei, how it compares to httprobe and EyeWitness, and a reproducible recon recipe.
-
Who Runs The Gentlemen Ransomware Group?
2026-06-15
OSINT tradecraft and threat intelligence takeaways from Krebs's attribution investigation into The Gentlemen ransomware group—now second by victim count.
-
OSINT Dojo: Reconstructing a Synthetic-Operator Chain
2026-06-07
A methodology walkthrough of an OSINT Dojo training scenario: username pivots, email artifacts, image analysis, and confidence statements at each step.
-
maigret: Username Recon Across 3,000+ Sites
2026-06-07
How soxoj/maigret works, where it beats Sherlock and WhatsMyName, and a reproducible CLI recipe for building a structured identity dossier.
-
Influence Operation Analytic Signatures: A DFRLab-Anchored Method
2026-06-01
How DFRLab structures influence operation attribution: narrative cloning, cluster topology, temporal anomalies, and confidence framing for working analysts.
-
BBOT: Recursive Recon for External Attack Surface Mapping
2026-06-01
How blacklanternsecurity/bbot's event-graph model works, where it beats Amass and Subfinder pipelines, and a passive scan recipe you can run in 10 minutes.
-
SS7 and Diameter: Mobile Network Espionage Tradecraft
2026-06-01
Citizen Lab and HPI's exchange on telecom-layer surveillance maps real SS7/Diameter attack patterns. Here's what it means for red teamers, defenders, and OSINT practitioners.
-
CISA's Leaked GovCloud Keys: What Practitioners Should Do
2026-05-25
A CISA contractor deliberately pushed AWS GovCloud keys to public GitHub. Here's the offensive and defensive analysis—and the concrete steps that follow.
-
MH17 BUK Route Reconstruction: OSINT Methodology
2026-05-17
How Bellingcat traced the MH17 BUK transporter using dashcam footage, social media imagery, and satellite corroboration — a step-by-step methodology breakdown.
-
ivre: Self-Hosted Network Recon Framework
2026-05-17
ivre gives you Shodan-style querying over scan data you own. Here's how it fits an analyst's workflow and how to stand it up in under ten minutes.
-
Patch Tuesday May 2026: What the Volume Spike Signals
2026-05-15
Near-record patch volumes from five major vendors in May 2026 aren't a fluke. Here's what the data signals for offensive and defensive security workflows.
-
OSINT Methodology for Security Professionals
2026-04-28
A structured OSINT methodology for security professionals — from requirements through evidence packaging, source diversity, and confidence vocabulary across pentest, bug bounty, and threat intel.
-
Domain & Infrastructure OSINT for Pentest Recon
2026-04-28
A practical guide to domain and infrastructure OSINT pentest recon: CT logs, passive DNS, Shodan, Censys, urlscan, certificate pivoting, and scope boundaries.
New posts roughly weekly. Subscribe →