Skip to content

OSINT

Enrich cases with attributable open sources

We connect wallets and platforms to domain registrations, hosting footprints, and public persona artifacts—within lawful collection bounds.

OSINT role

OSINT answers who operates the surface victims interact with—not just where coins moved.

Collection respects platform terms and privacy law; we document source provenance.

Strong OSINT fits

  • Fake brokers with rotating domains and support chat personas
  • Need to tie multiple victim reports to one operator cluster
  • Infrastructure overlaps between scam brands
  • Law enforcement requests contextual attribution briefs

Research tracks

01

Domain & certificate history

WHOIS snapshots, CDN patterns, and TLS reuse across brands.

02

Persona footprint

Reverse image search, social graph overlaps, and handle reuse.

03

Technical pivoting

Shared analytics IDs, mail servers, or wallet donation addresses on sites.

OSINT methodology

  1. 01

    Source matrix

    List datasets consulted and retention policies.

  2. 02

    Entity resolution

    Merge aliases with explicit confidence tiers.

  3. 03

    Dissemination

    Separate facts from analytic judgments in deliverables.

OSINT products

Entity dossier

Domains, hosts, and public profiles with citations.

Pivot map

Visual links between brands sharing infrastructure.

Collection appendix

URLs, capture dates, and tool notes.

Frequently asked questions

Do you hack accounts?

No. We use lawful open sources and materials clients lawfully possess.

Can OSINT unmask anyone?

Attribution varies; we state limits when data is thin.

Add OSINT to your case

Share URLs, handles, and apps involved—we map open-source pivots.