Foothold OSINT
Satellite Imagery as OSINT: Lessons from Big Bend

Satellite Imagery as OSINT: Lessons from Big Bend

Bellingcat mapped 5 miles of CBP road construction in Big Bend using commercial satellite imagery. Here's what that methodology means for red teams and defenders.

Bellingcat published “Satellite Imagery Documents New Border Patrol Road Construction in Big Bend National Park” on August 20, 2026. Using commercially sourced satellite imagery — no leaked documents, no FOIA, no insiders — analysts measured and temporally sequenced more than five miles of new CBP road construction inside a federally protected park before any official acknowledgment appeared. That sequence matters: detection before disclosure. The rest of this is about what that sequence means operationally.

What the Investigation Actually Demonstrates

Bellingcat used imagery from providers like Planet Labs, Maxar, and Airbus Defence & Space to detect ground disturbance, measure road length, and assign construction dates by comparing sequential captures. The result is a documented, timestamped record of infrastructure that the owning agency had not publicly acknowledged.

The defining characteristic here: physical change on the ground is now faster to detect via satellite than it is to suppress through information control. Geographic remoteness — Big Bend is not a suburb — provided zero protection from open-source documentation. That’s the starting point for every implication below.

Implications for Offensive Security

Geospatial Reconnaissance Belongs in Pre-Engagement Workflow

If a Bellingcat team can map five miles of government road in a remote national park with commercial imagery, an adversary with equivalent access — which is to say, anyone with a credit card and a Planet or Maxar subscription — can do the same to any surface-visible infrastructure. That includes:

Red teamers who limit reconnaissance to digital surfaces are skipping an entire collection layer. Platforms like Google Earth Pro’s historical imagery, Planet’s Explorer tool, and Sentinel Hub’s EO Browser surface physical access routes, construction timelines, and facility expansion patterns that never appear in any organizational disclosure.

The Big Bend case is concrete: a new road is a new attack surface. New roads mean new vehicle access points, new sensor installations — in this case explicitly part of CBP’s documented Smart Wall architecture — and new personnel movement patterns. Each is a reconnaissance target. Free tools like NASA Worldview and the Copernicus Open Access Hub provide multi-temporal imagery sufficient to identify road construction, building footprints, and vehicle staging areas without spending anything.

Temporal Analysis Reveals Operational Tempo

Time-sequenced imagery does more than confirm that something was built. It shows how fast. If a facility consistently moves from ground break to operational status in 90 days, that cadence has adversarial value — it sets the window during which construction activity is visible and countermeasures are not yet in place. For threat modeling, construction tempo is a predictive signal, not just historical record.

Implications for Defensive Security

Your Physical Footprint Is Already an OSINT Product

If CBP — with significant operational security resources — could not prevent open-source documentation of a major construction project in a remote, restricted-access location, organizations operating in less isolated environments are more exposed, not less.

Defensive teams responsible for physical security, critical infrastructure protection, or intelligence functions need a geospatial threat model: a periodic OSINT audit of the organization’s physical footprint using the same commercial satellite tools an adversary would use. The questions that audit should answer:

That last question is pointed at defense contractors, semiconductor fabs, pharmaceutical manufacturers, and data infrastructure companies — sectors where facility investment directly signals business intent.

Sensor Network Layouts Are Often Implicit in Their Infrastructure

The CBP Smart Wall integrates roads, barriers, and sensor systems. Even when sensor specifications are not published, the physical infrastructure supporting them — conduit runs, maintenance access roads, camera mast footings, antenna pads — is frequently visible and mappable from satellite imagery. Assuming physical obscurity in remote or restricted areas is a weaker control than it was ten years ago. Sensors aren’t useless because of this; the assumption that their layout is unknown to a motivated adversary is.

The Methodology, Extracted

Read the Bellingcat investigation as a methodology document and the workflow is straightforward:

  1. Baseline acquisition — pre-event reference imagery for the target area
  2. Change detection — sequential comparison to identify ground disturbance, new structures, altered access
  3. Measurement and georeferencing — GIS quantification (five miles is a measurement, not an estimate)
  4. Temporal sequencing — assigning dates to construction phases via imagery timestamps
  5. Cross-referencing with public records — correlating satellite findings against procurement records, environmental impact filings, or permit databases

Step five is where this connects to the broader OSINT ecosystem. SAM.gov and USASpending.gov provide a textual layer that can confirm or contextualize what imagery shows visually. A road visible in imagery that corresponds to a CBP infrastructure contract in a matching geographic area and time window is corroborated intelligence. The NATO OSINT Handbook — Allied Intelligence Publication 2.2 — documents cross-domain corroboration as foundational to producing reliable assessments from open sources. Satellite imagery confirmed by procurement records confirmed by regulatory filings is how you get from observation to assessment confidence.

The USGS Landsat program and ESA’s Sentinel-2 mission provide free, publicly accessible multi-spectral archives going back decades. This is not an experimental capability — it’s mature, institutionally supported infrastructure that most security teams haven’t touched.

One honest failure mode: change detection at free-tier resolution (10–30m per pixel for Sentinel-2 and Landsat) works well for roads, building footprints, and large ground disturbance. It fails for small-footprint installations — individual sensor masts, equipment enclosures under tree canopy, or modifications inside existing structures. For those, you need commercial high-resolution tasking, which carries real cost and lead time. Don’t let the free-tier tools create a false ceiling on what’s actually detectable by a funded adversary.

What to Do

Red team and offensive security practitioners:

Defensive security and intelligence teams:

OSINT analysts:

The barrier to geospatial intelligence has collapsed for non-state actors and researchers — which means it’s collapsed for adversaries too. Geographic remoteness is not a security control. The tools are public, the data is public, and the methodology is documented. The variable is whether your program has updated its threat model to reflect that.