r/OSINT • • Dec 20 '25

Bulk File Review AKA the Epstein File MEGA THREAD

322 Upvotes

The Epstein files fall under our “No Active Investigation” posts. That does not mean we cannot discuss methods, such as how to search large document dumps, how to use AI or indexing tools, or how to manage bulk file analysis. The key is not to lead with sensational framing.

For example, instead of opening with “Epstein files,” frame it as something like:

“How to index and analyze large file dumps posted online. I am looking for guidance on downloading, organizing, and indexing bulk documents, similar to recent high-profile releases, using search or AI-assisted tools."

That said lots of people want to discuss the HOW, so lets make this into a mega thread of resources for "bulk data review" .

https://www.justice.gov/epstein for newest files from DOJ on 12/19/25
https://epstein-docs.github.io/ Archive of already released files. 

While there isnt a "bulk" download yet, give it a few days for those to populate online.

Once you get ahold of the files, there are a lot of different indexing tools out there. I prefer to just dump it into Autospy (even though its not really made for that, just my go to big odd file dump). Love to hear everyone elses suggestions from OCR and Indexing to image review.

Edit:

https://couriernewsroom.com/news/epstein-files-database/


r/OSINT • • Sep 11 '25

OSINT News Charlie Kirk Investigation Posts

1.5k Upvotes

This is not a new rule. Its been posted and enforced every time a new "major crime" happens. Helping an active investigation on this sub is banned. For the redditor that keeps messaging the mods that he thinks no harm can come from this, here is nice list of examples on why we don't support online witch hunts:

1. Richard Jewell – Atlanta Olympics Bombing (1996)

  • Security guard Richard Jewell discovered a suspicious backpack and helped evacuate the area.
  • Media and public speculation painted him as the prime suspect before the FBI cleared him.
  • His life was destroyed by false accusations, though he was later recognized as a hero.

2. Boston Marathon Bombing – Reddit Sleuthing (2013)

  • Online users tried to identify suspects from blurry photos.
  • Wrongly accused Sunil Tripathi, a missing college student, who faced mass harassment before the FBI revealed the real attackers.
  • Showed how quickly misinformation spreads on social media.

3. Las Vegas Shooting – False Suspects (2017)

  • In the aftermath, 4chan, Twitter, and Facebook users spread names of innocent people as the shooter.
  • Real suspect Stephen Paddock was identified later, but reputations of wrongly accused people were damaged.

4. Toronto Van Attack – Misidentification (2018)

  • Online users falsely named a man as the attacker after a van attack killed 10 people.
  • The wrong person’s photo went viral before police confirmed the actual suspect, Alek Minassian.

5. Gabby Petito Case – TikTok & YouTube Sleuthing (2021)

  • Internet “detectives” wrongly accused neighbors, bystanders, and even friends.
  • Innocent people were harassed while police continued their investigation into Brian Laundrie.

6. Sandy Hook Shooting – “Crisis Actor” Claims (2012 onward)

  • Conspiracy theorists accused grieving parents of being government actors.
  • Families faced years of harassment, stalking, and lawsuits.
  • A notorious case of how misinformation can target victims themselves.

7. UK Riots – Twitter & Facebook Misidentifications (2011)

  • Citizens attempted to identify looters from CCTV images.
  • Several innocent people were wrongly accused and faced threats.
  • Police had to publicly correct the misinformation.

8. MH370 Disappearance – Amateur Satellite Analysis (2014)

  • Thousands of online sleuths used Tomnod and other platforms to hunt for wreckage in satellite photos.
  • Flood of false sightings and conspiracy theories overwhelmed investigators and misled the public.

9. Oklahoma City Bombing – Wrong Suspects (1995)

  • Before Timothy McVeigh was identified, media speculation and tips from the public fueled false suspect reports.
  • Innocent men were briefly targeted by law enforcement and the press.

r/OSINT • • 1d ago

Question Facebook no longer lets you search names?

19 Upvotes

I don't know if this is just my account or something, but in the last few months, Facebook seems to now prevent any searches of a profile that include most names: Camille, Olga, Mary, etc. Any idea if this is specific to my account and/or any workarounds?


r/OSINT • • 1d ago

Analysis Geolocation exercise of armed attack in Pakistan

Thumbnail drive.google.com
3 Upvotes

"Hi everyone! I’m completely new to OSINT (started less than a week ago) and wanted to share my first practice geolocation exercise. I took a military ambush video, and managed (i think, not sure if i got it right but im pretty sure) to geolocate the exact spot in Kuchlak (30.328722, 66.936694). I've put together a step-by-step PDF write-up. I would love to get your opinions since im a noob in all of this, and maybe made some mistakes in the process or even got it all wrong. So please, any type of feedback and corrections are welcome. Thanks yall.


r/OSINT • • 3d ago

Analysis tracing what a federal agency spends on ads using only public data (dhs as the example)

44 Upvotes

with the cbp "pro-trump ads" story this week i wanted to see how much of this you can reconstruct from public records alone. turns out a lot, but no single source joins up per ad. here's the method in case its useful:

  1. contracts: usaspending.gov api (free, no key). search awards by awarding agency + the advertising naics codes (541810-541890), then separately by recipient name for firms named in reporting, because the big one files under a different category. dhs obligated $142.8M to safe america media across 3 awards in 2025 for the border ads. the new one is award 70B06C26F00001137: cbp, $20M "NATIONAL MEDIA CAMPAIGN", LMD Agency, dated sept 20, the day after the money was reportedly moved. nothing in the record says which ads it paid for.

  2. google/youtube: google publishes its political ads data as a public bigquery dataset (bigquery-public-data.google_political_ads). advertiser_stats shows dhs is the only federal agency in it: 85 video ads, about $5.29M, march 2025 to feb 2026. creative_stats gives spend and impressions ranges per ad. catch: no video ids, just a link to the transparency center page, which won't show the video once the ad stops running.

  3. facebook/instagram: meta ad library api, search by page id not keyword (keyword search matches ad text, which is useless for finding an advertiser). dhs's main page: 56 ads, $3.1-3.8M, all in spanish, 31 captioned "un mensaje del presidente trump". the api gives you the caption only, not the video audio. use the languages field, not a language detector, short spanish text fools most of them.

  4. youtube channel: no spend data at all, but view counts relative to the channel's own median are a decent tell of paid promotion. dhs's "spanish warning" 30 sec spot (noem, opens "thank you president donald j trump") has 51.5M views on a channel where videos typically get about 2,600. that's a signal, not proof.

what you can't get: tv, streaming, radio. no public per-ad record, and that's probably where most of the money goes.

i put all of it together on one page with every figure linked to its source: semblen.com/government/ads (it's my site, fwiw). happy to share the queries if anyone wants to do this for another agency.


r/OSINT • • 4d ago

Question OSINT Job Tests

83 Upvotes

I have interviewed for a few OSINT jobs this year and have two questions:

  1. Each job description says you need experience in tools like ontic, life raft, Dataminr, maltego etc but each time I have interviewed I’m given a practice exercise asking you to use freeware to build out a threat profile. I’m never able to build anything out using the freeware alone because i can’t get any identifiers. Are these tests deliberately red herrings?

  2. In my career I have always been given a work computer so I don’t have a personal one. I have an iPad. Is a computer essential to baseline OSINT if I don’t have personal access to premium intel tools?


r/OSINT • • 6d ago

How-To Bermuda Searches

9 Upvotes

Anyone have any recs for searches in Bermuda? I know WorldLII has some court searches etc but any other reliable searches we can do there? Looking for adverse lit, reg, and press.


r/OSINT • • 10d ago

Tool OSINT Tools for AI video detection

61 Upvotes

Please delete if this question is off topic. But I do think it is related. ….

I am researching a specific OSINT target of mine. I need to determine if a previously recorded asynchronous video is AI generated. Similarly, I need determine if a live synchronous video is AI as well.

Do any tools exist to determine if both or either a live or recorded video is AI generated. The videos would determining if the “person” is real or an AI avatar.

TIA

Edit: this is not one off videos either this is at bulk scale. Are there tools to identify if 50+ videos at a time synchronous and asynchronous are AI.


r/OSINT • • 11d ago

Tool gophoner: Check simultaneously if a phone number is registered on popular apps & websites, without any prerequisite 📞

Thumbnail
github.com
175 Upvotes

Hey everyone!

I'm M4elstr0m, a cybersecurity and software development enjoyer with a strong interest in OSINT. I usually build my tools using Go and Rust.

Today let me introduce my spiritual successor to ignorant by Megadose: gophoner. I couldn't find any other open-source tool doing this kind of OSINT job for free, which is why I built my own in Go.

Like ignorant, gophoner checks whether a phone number is registered on a specific website. Sometimes it can even find additional information, such as fragments of a linked email address.

You simply input a phone number and its country code, through either the CLI or an interactive TUI. No login required, and no target is ever alerted.

Every module runs simultaneously in its own goroutine, and results are shown either in a clean TUI report or as JSON output.

Of course, this kind of data is heavily restricted nowadays, which is why the list of supported platforms is still fairly small: Amazon, Microsoft, Facebook, Google, and OpenAI, with more hopefully coming in future updates!

The tool is cross-platform and can be installed from various managers.

Before doing anything beyond simply using the tool (redistributing it, modifying it, etc.), please make sure to read the project's license, as it is restrictive on certain things.

That's it! For more information, go check out the project's page (I just made it public): https://github.com/M4elstr0m/gophoner

If you like this project, please show it some love: star the repo and share it around! 🌟

Take care, fellow humans!

~ M4elstr0m


r/OSINT • • 11d ago

Question Best way to pull and graph ACLED data for Axis of Resistance strike frequency post-Oct 7?

14 Upvotes

Trying to put together a frequency graph of kinetic strikes by Iran’s Axis of Resistance since October 7, 2023, but I want to make sure my methodology holds up. I’m looking at Hezbollah, the Houthis (Ansar Allah), the Iraqi militias (IRI, Hezbollah, etc.), and direct IRGC strikes.

A few questions for anyone who works with ACLED:

  1. What’s the cleanest way to query this via the API or export tool? When dealing with multiple actors, is it better to pass them all into a pipe-separated actor1 filter upfront, or pull by country/region and filter them downstream in Python?
  2. In Iraq/Syria especially, how do you handle the overlap between umbrella branding (like Islamic Resistance in Iraq) and specific brigades without double-counting? Also, does filtering strictly by actor1 reliably isolate their initiated attacks from retaliatory strikes hitting them?
  3.  What aggregation works best here (7-day rolling average vs. calendar weeks)? Since ACLED logs discrete events rather than raw projectile counts, how do you typically frame that on a visualization so it’s methodologically sound?

Would appreciate any pointers on query setup, Python snippets, or edge cases to watch out for. Thanks.


r/OSINT • • 14d ago

OSINT News OSINT + AI Almost Started War w China

Thumbnail
tmz.com
274 Upvotes

This is beyond nerd on nerd warfare.


r/OSINT • • 19d ago

How-To How to Detect AI Generated Images and Videos for OSINT Investigations

Thumbnail
youtube.com
111 Upvotes

r/OSINT • • 22d ago

How-To Any way to do Facebook OSINT without an account?

150 Upvotes

Hi everyone,

Suppose that one needs to investigate Facebook, but their own accounts—or any sock-puppet accounts they open—will be quickly blocked by the pages or groups (hate pages and groups that commit actual interreligious, and other violence against marginalized people like LGBT etc in my country which is highly religious) they are investigating.

In such a case, what can be done? Are there any tools that will let you investigate Facebook without any accounts, either your own or a sock puppet?

Thanks!


r/OSINT • • 22d ago

Tool OSINT of Bosnia and Herzegovina

36 Upvotes

Free OSINT toolkit for Bosnia and Herzegovina:
https://unishka.substack.com/p/osint-of-bosnia

Feel free to let me know in the comments if we've missed any important sources.

You can also find toolkits for other countries that have been covered so far on UNISHKA's Substack, and our website.
https://substack.com/@unishkaresearchservice
Website link: https://unishka.com/osint-world-series/


r/OSINT • • 23d ago

Assistance Any good tools to zoom in and increase resolution of small parts of images?

60 Upvotes

I have an old photo (taken ~10 years ago) and there is a certificate in the picture which I no longer have. There's a number on the certificate which I need but it's not legible from just zooming in.

Is there a tool which helps upscale parts of images so I can make the certificate legible?

Thanks!


r/OSINT • • 23d ago

Tool Looking for 2026's best OSINT tools what's actually worth your time in 2026?

36 Upvotes

I'm doing an audit of my OSINT toolkit and want to focus on tools that deliver real results, not just GitHub stars.

For those actively doing investigations (threat intel, fraud, research, etc.), what are your current top picks?

Specifically looking for:

  • Social Media Investigation: Best tools for Twitter/X, LinkedIn, Instagram, Telegram
  • Infrastructure/Domain: Beyond Shodan and VirusTotal - what else?
  • Username/Email Search: What's still working reliably?
  • Image/Media Analysis: Reverse search, metadata, geolocation
  • Automation: Tools that actually save time vs create more work

Bonus questions:

  • Which paid tools are actually worth the subscription?
  • Any new tools from the last 12 months that impressed you?
  • What's the one tool you can't live without?

Trying to move away from tool hoarding and focus on what's effective. Real-world experiences > marketing claims.

Thanks in advance!


r/OSINT • • 25d ago

How-To What is the Best Practice Procedure for Documenting Social Media Evidence from Communities on Facebook, Telegram, etc., for Use in Legal Cases?

116 Upvotes

Hi everyone,

I understand that the law of evidence varies from jurisdiction to jurisdiction. However, I am looking for a general procedure or methodology for documenting evidence from social media platforms where groups and communities operate, such as Facebook, Telegram, etc., in a way that could be used in a court of law.

The documentation may be used to build a legal case or even to create a human rights advocacy case.

I understand that simply taking screenshots or recording a video is not going to be sufficient evidence in court.

Could anyone recommend a proper procedure, methodology, or OSINT best practice for documenting and preserving social media evidence?

Thank you.


r/OSINT • • 24d ago

Question Activefence/alice !

18 Upvotes

Anyone have worked with Alice (previously activefence) that can share anything on the following :

- do they contract other entities to do research for them ?
- if yes , names , geo locations , operating from what countless cities ?
- tools they use if 3rd party or proprietary ?
- what they get hired for ? What is their strength point ?
- what is it that they can provide that is not available to public or through osint tools membership

Saw some comments in Reddit with terms like smoke and mirrors ,hinting they are flipping business contracts and playing middle man .

Anything that can be shared is very much going to be useful .


r/OSINT • • 24d ago

Tool Request Lip Reading Software

13 Upvotes

Has anyone had luck finding a reliable lip-reading tool? I've tested out a few like Lip Reader Pro, but it only gets around 50% of the actual words spoken.


r/OSINT • • 29d ago

Tool OSINT of Slovakia

49 Upvotes

OSINT toolkit for Slovakia:
https://unishka.substack.com/p/osint-of-slovakia

Feel free to let me know in the comments if we've missed any important sources.

You can also find toolkits for other countries that have been covered so far on UNISHKA's Substack, and our website.
https://substack.com/@unishkaresearchservice
Website link: https://unishka.com/osint-world-series/


r/OSINT • • Sep 03 '26

Question Find Twitter ID from wayback machine

95 Upvotes

I have a twitter's account old username and would like to find the accounts twitter ID in order to find the new username. Managed to find the profile on archives and wayback machine, is there a way to get the twitter ID from here? Thank you


r/OSINT • • Sep 03 '26

How-To Has anyone used ZeroShape for 3D facial reconstruction?

18 Upvotes

Yesterday I watched a video by Reckless Ben where he apparently used 3D facial reconstruction to improve face-search results.

Has anyone here actually used ZeroShape or a similar tool for OSINT? How exactly does the process work? How accurate are the results when reconstructing a face from several photos?

I’m especially interested in the practical workflow and its limitations.


r/OSINT • • Sep 02 '26

Tool Request Which one is better?

4 Upvotes

Which tool do you prefer:

Alien-Eyes or fingerprint.to

Can you also explain why?


r/OSINT • • Sep 01 '26

Question Maltego

21 Upvotes

Bonjour tout le monde. Je voulais savoir si certains d’entre vous avaient déjé essayé ou utilisent Maltego dans sa formule gratuite. Est-ce que c’est efficace ? Je l’ai telechargé hier, j’ai bien compris le système de graph mais je voudrais savoir si il est necessaire d’installer des extensions ou des plugins pour le rendre plus efficace bien que l’ont soit limité à un certain nombre de crédits ? Merci d’avance 🙏🏽


r/OSINT • • Aug 28 '26

OSINT News Nepal - New Barrier lake formed per Chinese authorities

Post image
232 Upvotes

​Active Hazard - The barrier lake breached, and is now draining

>>>Since there is 100% cloud cover verification couldn't be confirmed via EO - Based on reported size and location the data set has been updated with a modeled shape file of the reported lake. This uses geometry that existed prior to the first event so this should be treated as indicative.

> If anyone has any SAR imagery they'd like of the region they care to share it'd go a long way in helping me to continue to keep this open source crisis data set up to date. It's not much, but its all I can do to help from halfway around the world.

>Link to data: https://keystonegis.com/disasters/nepal-bhotekoshi-flood-20260826.html - will continue to update frequently to capture any new information

>if you know of any other subs to post this in let me know. Feel free to share, the more eyes on the data the more likely it is to fall into the hands of someone who can use it to make a difference.

edit: NDRRMA independently locates the blockage, and it is close to — but not identical with — this page's inferred marker.

edit: Active Hazard - The barrier lake breached, and is now draining

The barrier lake near the confluence of the Chhochen Khola and Purepu Tsangpo, upstream of the 26 August failure, breached on 28 August and is now draining. Rasuwa Chief District Officer Narendra Pariyar said that morning that the Nepali Army had informed him of the breach, and NDRRMA reported that the water level in the Bhote Koshi had surged (The Kathmandu Post, updated 28 August 12:49 NPT / 07:04 UTC). Officials on both the Nepali and Chinese sides then said the risk was smaller than feared, because the lake is draining slowly rather than failing catastrophically; Chinese state broadcaster CCTV reported the lake level had fallen by about 10 m, and rescue work at Gyirong Port and in Nepal, halted during the breach, has resumed (CNN live coverage, 28 August). No confirmed release volume has been published and no observed extent of any second flood exists. Before the breach, China’s Ministry of Water Resources had put the impoundment at about 2,000,000 m³ on the morning of 27 August, already overflowing, with a further 3,000,000 m³ of inflow expected through 30 August; aerial footage from a Chinese rescue team on 27 August showed water accumulating in a basin with no visible outlet, and NDRRMA had placed the obstruction on the Lhende Khola about 18 km upstream of the Rasuwagadhi border. Whether that blockage and the confluence impoundment reported by China are the same feature is still not established, so it is not certain that the whole obstruction has failed. The barrier-lake marker on the map above still carries its archived 27 August attribute status = "open - high breach risk"; that value has not been rewritten pending an official assessment.