OSINT Methodology

OpSec

Create a Sock Puppet

Cryptocurrency Investigation

Transaction Analysis

  • Track transaction flows between wallets

  • Identify clusters of related addresses

  • Monitor large transfers and whale activity

  • Use block explorers to trace fund movements

  • Tools:

    • Cielo: Multi-chain wallet tracking (EVM, Bitcoin, Solana, Tron)

    • TRM: Create relationship graphs for addresses/transactions

    • Arkham: Multichain explorer with entity labels, graph creation, and alerts

    • MetaSleuth: Transaction visualization for retail users

    • Range: CCTP bridge explorer

    • Socketscan: EVM bridge explorer

    • Pulsy: Bridge explorer aggregator

    • Chainalysis: Horizon�2.0 cross?chain tracing suite (paid)

    • Elliptic: Lens visual link explorer (launched�Dec�2024)

    • Most compliance suites now provide real?time bridge?risk scoring dashboards (e.g., TRM, Chainalysis)

Wallet Profiling

  • Analyze wallet age and activity patterns

  • Check for connections to known entities

  • Monitor balance changes over time

  • Identify associated exchange accounts

Exchange Investigation

  • Track deposits/withdrawals

  • Monitor trading patterns

  • Identify linked accounts

  • Check for regulatory compliance

NFT Investigation

  • Track ownership history

  • Monitor sales and transfers

  • Analyze metadata and hidden content

  • Identify connected wallets and marketplaces

Image Analysis

Image Forensics

Mountain Geolocation

Fire Identification

Track and Find Planes

Video Analysis

  • Find context regarding the video

    • Signs, banners, and billboards.

    • Architectural styles and building materials.

    • Road markings and traffic signs.

    • License plates

    • Clothing styles and local customs.

    • Search for video snippets on platforms like YouTube, Twitter, or TikTok.

  • Metadata Extraction

  • Platform-Specific Techniques

    • TikTok and Instagram

      • Analyze user profiles for location tags.

      • Examine comments and hashtags for clues.

  • Auditory Clues

  • Extract Key Frames

    • Use tools like FFmpegarrow-up-right or VLC Media Playerarrow-up-right to capture frames.

    • Extract frames at regular intervals or when significant changes occur.

    • Stitch frames together if the camera pans to create a panoramic image.

    • Create a panorama if the camera pans across a scene.

  • Analyze frames using the same techniques as in image geolocation.

Chronolocation and Time Analysis

Shadow Analysis

  • Use shadows to estimate the time of day and date when the image or video was captured.

  • Methodology

    • Determine the length and direction of shadows in the image.

    • Identify objects casting the shadows (e.g., poles, buildings).

  • Calculate Sun Position

    • Use the object's height and shadow length to calculate the solar elevation angle.

    • Determine the azimuth (sun's compass direction).

  • Tools

    • ShadeMaparrow-up-right � interactive 3?D shadow simulator

    • Bellingcat Shadow?Finder micro?tool

      • Input location coordinates.

      • Adjust dates and times to match shadow lengths and directions.

    • SunCalc.net: Similar tool with additional features.

Astronomical Calculations

  • For night images, use celestial bodies to determine time and location.

  • Tools

  • Methodology

    • Identify visible stars, constellations, or the moon phase.

    • Use software to simulate the sky at different times and locations.

    • Match the celestial arrangement in the image to a specific date and time.

Satellite Imagery Time

  • Use historical satellite imagery to determine changes over time.

  • Tools

    • Google Earth Pro:

      • Use the historical imagery slider to view images from different dates.

    • Sentinel Hub EO Browserarrow-up-right

      • Access Sentinel and Landsat data.

      • Create TimeLapse animations.

  • Methodology

    • Enter the location coordinates.

    • Select appropriate satellite datasets (Sentinel-2, Landsat 8).

    • Analyze changes in the environment to narrow down dates.

People & Social Media Investigation

Username Enumeration

Social Graph & Content Analysis

Infrastructure OSINT

IP & Domain Discovery

Certificate & Passive DNS

Automation & Case Management

Synthetic Media Verification

Last updated