OSINT Insider Issue #11: Exposing How Illicit OSINT Tools Harm Children
Today we dive deep into updates on illicit OSINT tools, discuss new legitimate OSINT tools with exciting novel capabilities, and share resources investigators can use to save money on licenses.
Today in our 11th issue we cover 21 total topics, we dive deep into updates on illicit OSINT tools (including one we potentially helped shutdown!), explain how these tools contribute to the harm of children, discuss new legitimate OSINT tools with exciting novel capabilities, and share resources investigators can use to save money on licenses. This issue is chock full of content and value, so much we can’t cover it all in this summary. Read through our topic list to learn more about what you can expect and see if anything catches your eye:
Free version of this edition will cover:
New Powerful and Cost Effective Leaked Data Tool with An AMAZING Feature
THINKPOL Unlocks Free Access to 6 Reddit Investigation Tools
Buried Signals Releases Journalism-Friendly Tools
Powerful SOCMINT Tool to Discover How People Are Connected Across Platforms
A New Anonymous Social Media Monitoring Platform
A Database of Debunked Images from Fact-Checkers Worldwide
Bookmarklet #1: Get Profile Visit Data Info When Visiting OnlyFans Profiles
Bookmarklet #2: Get Rid of “Blur” In A Web Page
Bookmarklet #3: Revealing Profile Information of Fansly.com Users
The full edition includes a wider arrangement of tool and platform reviews. It concludes with The Com Corner, a section that covers platforms that are used for illicit purposes. Here’s a breakdown:
An LLM-based Tool for Redacting Sensitive Personal Information in PDF Documents
Enter Pravda by OpenSanctions, An Alternative to WARC?
[Redacted] Adds Affordable Corporate Investigations Module, You Can Save Thousands Using This Tool Instead of Being Forced to Buy A OpenCorporate License
How a Description of What Is In Front of You Can Help Pinpoint A Location on OpenStreetMaps
Free Self Hosted Telegram Monitoring and Scraping Tool, DIY Threat Intelligence
An API Endpoint Sniffer That Allows Users To Find New OSINT Methods and Modules
Discover New OSINT Projects with This New Tool
Tool For Anonymously Viewing Someone’s LinkedIn Profile
New Tool To Unmask the Identity Behind Online Stores, Retrieve IBANS, Merchant Names, Emails, and More
Another Great Tool for Scraping Personal Details of GitHub Users
Automated Fake Github Engagement Detection Tool, Check Your Favorite Projects
And finally, as mentioned above, The Com Corner Section will look at the following:
[Redacted], Another Awful Com Platform Contributing to Immense Harm
[Redacted], Updates On the Com Tool Trying To Masquerade as a Legitimate Cybersecurity Platform
OPSEC Tools With No KYC Listed on This Directory
[Redacted] Adds 500+ New Databases, Major Platform Improvements, Very Dangerous Cookie Module
[Redacted] Releases Person Search Tool, Provides Unauthorized Access to LexisNexis Data
A Restart of [Redacted], Features Harmful Autodoxer Roblox Module That Empowers Pedophiles and Violent Extortionists
Is [Redacted] API Dead? Did OSINT Insider Help Kill It?
[Redacted] Revenge Services Telegram Channel Offering Swatting, Bricking, Arson, and Drive By Shootings
[Redacted] Italy Search Returns Sensitive Results that Could Enable Fraud
Mass Leads: Crypto, Banking, Real Estate Personal Information Leaked
Previous Edition:
In the previous edition of The OSINT Insider, we looked into the ways in which artificial intelligence challenges the OSINT industry and aimed to offer a practical and easily accessible guide on emerging OSINT tools and risks. We also covered new vessel-tracking platforms, comparing them against well-known OpenSanctions datasets.
OSINT Insider Issue #10: AI, Monitoring Tools, and the Future of OSINT
This edition of OSINT Insider covers the impact of artificial intelligence on open-source intelligence (OSINT), legal developments affecting digital investigations, a newly reported WhatsApp spyware campaign, tools for collecting data from VK and Facebook, and a comparison of vessel-tracking platforms against OpenSanctions datasets. The following issue offers investigators, journalists, researchers, and analysts practical guidance on emerging OSINT tools, risks, and tradecraft.
Read more here.
📌 New Powerful and Cost Effective Leaked Data Tool With An AMAZING Feature
Have I Been Ransomed is a search tool that allows you to see whether your personal data, such as emails, phone numbers, usernames, ID, wallet, or Telegram data, appears in ransomware leaks, infostealer logs such as Redline, Lumma, Vidar, and others, or traditional data breaches. The tool also lets its users set up a free account to get alerts when a new leak of their data appears.
The tool returns information about the leak including the date it was discovered, the country, the name of the leak file, and the location where they obtained it. You cannot view more information about what was leaked without paying for the tool.
Spot checks of the tool by the OSINT Insider found it surfaced leaks not seen in some professional OSINT tools our analysts use, including an obscure Moonpay database that is part of a scrape of Moonpay users that has never been disclosed to their users. However, while their data is different, it doesn’t make it better, the number of unique breaches (not repacks, compilations, collections, etc) tied to identifiers we searched in corporate solutions was higher.
HIBR does however parse a category of data leaks that other tools have long left untapped, unstructured ransomware leak data. In a paper the team behind the tool released they describe how they peform “(ii) analysis of information in multiple formats and languages by integrating well-known OCR, text/PDF, and image recognition, as well as multimodal currently available AI-related tools“. HIBR have coined their ransomware data processing architecture “RDBAlert”:
This processing of unstructured ransomware data is so far as we know unique to HIBR and not something any of their competitors offers.
We went a step further with our analysis of this tool and paid $105 for access to the data provided by HIBR and found that the tool verbosely parses many different fields, even more than the 17 fields they make searchable in their interface making this a low cost alternative for high end tools like IntelX and District 4 Darkside for investigators.
Have I Been Ransomed is created by Dark Eye Industries, which unlike man Com tools we have covered, is pubic about who is behind it. They have a registered LLC listed, their employees are listed on their LinkedIn, and they have published a paper regarding their project:
The main issue we found with this tool is its lack of KYC (Know Your Customer) practices. We were not asked who we were and could simply purchase an account with an email address and a valid payment method, meaning that anyone can access this data, the good guys and the bad guys. This means that like the com tools we cover in com corner, it can contribute to harm by allowing misuse, even if this tool is clearly not advertised for that purpose. Not enforcing KYC is a practice frowned upon by the legitimate OSINT community as it allows for easy abuse of the data for malicious purposes. If the platform can implement KYC policies, its got a bright future in the OSINT industry.
Learn more about this tool at HaveIbeenransom.com.
📌 THINKPOL Unlocks Free Access to 6 Reddit Investigation Tools
THINKPOL, a Reddit intelligence platform built for investigators, SOC teams, and fraud analysts, recently opened access to its 6 free tools, which require no account to try. These include:
User profile lookups provide an AI-generated profile along with key information associated with a pasted username, including cross-subreddit activity, writing style, aliases, and posting patterns.
Subreddit activity check, which returns a yes/no result on whether a certain user posted something in a given subreddit.
Keyword trend tracker, which is especially useful for tracking malware names and scam patterns.
Archive search, including deleted content Reddit no longer shows.
Subreddit intelligence tool that shows subscriber count, activity stats, and monthly trends.
View deleted Reddit posts, which allows users to recover a user’s deleted and removed comments from the archive after the content disappeared from the platform.
Learn more at Think-pol.com.
📌 Buried Signals Releases Journalism-Friendly Tools
In the June issue, Open Journalism reported that Buried Signals’ founder, Tom Vaillant, has launched a new repository of four tools for journalists and investigators to help parse documents, scrape the web, and automate browsers.
Specifically, the tools available include:
PDF extraction that helps preserve evidence from documents.
Browser automation, which allows working with multi-step public record workflows.
Web scraping, including civic and registry pages.
Search, which enables tailored search of source-linked material.
Learn more on GitHub.
📌 Powerful SOCMINT Tool to Discover How People Are Connected Across Platforms
CrossTrace is a cross platform social graph analyzer. Feed it exported follower/following lists, it finds the connections; that scales researcher potential to make identification and discovery of mutual followers much more efficient. It performs username and display name matching and network overlap analysis and gives a score depending on the level of confidence in results.
The tool also supports a “discovery mode”, in which multiple people’s lists could be added to identify names that appear most across all of them without the need to know the name of the target to begin with. The tool has a number of other features including:
Fuzzy matching: catches variations like johndoe, john_doe, johndoe_ and scores them by confidence
Famous person filter: mark celebrities and public figures so they never appear in results again
Top N most prevalent: see who shows up across the most lists at a glance, fully customisable
The tool is local and does not require any APIs or scraping, you must supply the data yourself.
Learn more about the tool on GitHub.
Ad Break/Promotional
Farnsworth Intelligence
Most private investigators can’t spend hours collecting digital evidence across dozens of sources or build a world class digital intelligence shop. We understand.
Farnsworth Intelligence helps firms deliver intelligence excellence to their customers with white-label reports and services backed by industry leading capabilities.
With our OSINT expertise, you get the best, without the cost of expensive tools and without the need for building a team like ours. Farnsworth will:
Prepare high quality standardized reports
Use industry leading capabilities
Handle your caseload, no matter what volume
Support case types such as insurance, asset tracing, due diligence, and digital executive protection
Generate new leads to support PI work like surveillance, canvasing, interviews, etc.
Deliver results for your clients, no matter the size, from individuals to local law practices to Fortune500’s
Results Delivered: Our team has already supported thousands of investigations, with highlights including C-suite and celebrity digital risk profiles, insurance claims hitting Fortune50’s, and multi-million dollar asset searches.
Your Trusted Intelligence Partner
Get your Reports and Services Brochure today
📌 A New Anonymous Social Media Monitoring Platform
Monitory is a new platform that allows users to monitor changes on a social media profile or website. It has prebuilt modules for X, Reddit, GitHub, TikTok, and Steam, which allow users to log or get alerted about any changes to the profiles by email, Discord, or Webhooks. Given its association with scraping.industries, Monitory also lets its users request access to modules for other platforms.
The tool creates scanners for the chosen platforms for the same user and provides a picture of the user’s behavioral changes.
Besides providing updates as changes to profiles happen and supporting a range of platforms, the tool is also anonymous, requiring no login or follow, and so allows to leave little to no trace. It also detects bio changes, new posts, follower shifts, SSH key additions, and provides a visual timeline with field-by-field differences. The tool is also relatively easy to integrate into your existing tooling because of webhooks support.
The first scanner is free to use for 24 hours, which allows you to test the platform before deciding on a plan.
Something to keep in mind is that while the tool is promising and the company behind it has an impressive track record of case studies regarding scraping, the company does not identify the real identities of its team members nor provide a business entity anywhere on its website.
Images are taken from a post in the Reddit thread r/OSINT Tools, published earlier this year. The above image gives a short view of the Monitory dashboard.
Learn more at Monitory.me.
📌 A Database of Debunked Images from Fact-Checkers Worldwide
Image Whisperer is a fact-check database that allows users to search debunked images from fact-checkers globally, including Reuters, Snopes, PolitiFact, AFP, BOOM Live, Lead Stories, and Full Fact. It is updated daily and covers images from April 2004.
The database is searchable by description, person, place, and event, and has useful filters such as “satire”, “fake image”, “AI generated”, and so on.
Image Whisperer also has an AI Image and Deepfake Detector Tool that checks an uploaded image to identify whether it is genuine.
Learn more at ImageWisperer.org.
📌 Bookmarklet #1: Get Profile Visit Data Info When Visiting OnlyFans Profiles
This OnlyFans User Bookmarklet displays data hidden in your browser when you visit an OnlyFans (OF) profile. This bookmarklet includes information about the profile, such as the date joined and the last seen dates. Analysts believe this will come in handy in investigations requiring monitoring OF accounts.
Note: Using this bookmarklet may reveal nude imagery on the OF website.
Learn more at the My OSINT Training website.
📌 Bookmarklet #2: Get Rid of “Blur” In A Web Page
This Deblurring Bookmarklet removes the “blur” class that some sites use to apply a blur filter to content on a site. These “blur” classes use a filter to blur content on your screen but the browser receives the raw unblurred content still, so by using this bookmarklet you can reveal the original unblurred content.
Learn more about how this blur effect works in your browser here.
Learn more about the bookmarklet on the My OSINT Training website.
📌 Bookmarklet #3: Revealing Profile Information of The Fansly.com Users
This bookmarklet reveals data associated with Fansly.com site user profiles, such as recent activity indicators, including the date and time of the last activity, when images were uploaded and modified, and URLs to the social media accounts associated with the profile. The bookmarklet also unblurs the banner and profile images.
Learn more at My OSINT Training website.
Thank you for your interest in The OSINT Insider! The above free content was made possible by our paid subscribers.
Thank you for your interest in The OSINT Insider! We look forward to bringing you more issues.
If you are benefiting from our research, why not share it with someone else who needs it?


















