Articles, guides and updates.
Long-form pieces, tool reviews and operational notes. Every article declares its type, risk level and update cadence.
- total
- 28
- featured
- 2
- source
- lab.v_articles_base
Editor-picked.
Stop Calling Them Hackers
Calling every cyber actor a hacker collapses authorization, motive and attribution into one vague label. Better OSINT starts with language precise enough to preserve what the evidence actually says.
OSINT Is Not Just Searching
Search finds public information. OSINT begins when that information is resolved, verified, contextualized, corroborated and turned into a traceable answer to a defined question.
All articles · 28.
The Problem With Tool-Centric OSINT Education
Tool lists are useful, but training people around interfaces creates dependency. Durable OSINT education should teach questions, signal meaning, source criticism, limitations, evidence states and judgment — with tools inside the method.
Passive First: When Public Web Research Should Stay Narrow
A practical argument for staying narrow and passive as long as possible in public web research, before broader or more interaction-heavy methods start adding noise.
BuiltWith vs urlscan: Stack Hints vs Observed Page Behavior
Compare BuiltWith and urlscan as two different web-research evidence layers: structured current and historical technology profiling versus browser-observed requests, redirects, DOM and page behavior.
How to Use Sanctions and Risk Lists Without Overreading Them
A disciplined method for sanctions, PEP and risk-list research: resolve the entity, classify the signal, verify the authority, distinguish ownership and control rules, preserve time, and avoid turning adjacency into a verdict.
A Practical Method for Domain and Infrastructure Recon
A passive-first, layer-by-layer workflow for domain and infrastructure reconnaissance using DNS, certificate transparency, HTTP behavior, technology signals, historical context and broader internet observations without turning discovery into attribution.
OpenCorporates vs Aleph: Which One Fits Which Research Job?
Choose OpenCorporates when legal-entity identity and provenance are the main uncertainty; choose OCCRP Aleph when a known entity needs cross-dataset, document and relationship context.
crt.sh vs SecurityTrails vs Censys: Three Different Ways to Read Infrastructure
Compare crt.sh, SecurityTrails and Censys as three different infrastructure evidence layers: certificate history, DNS history and broad current internet-facing asset observations.
Start Here: How to Use an OSINT Tool Catalog Without Getting Lost
A practical starting guide to choosing OSINT tools by question, signal family, risk and evidence needs — and using the catalog as a decision system instead of a link directory.
A Responsible Method for Company Research with Public Sources
A practical framework for resolving legal entities, verifying registry records, mapping ownership and control, screening sanctions carefully, and preserving evidence without turning name matches into conclusions.
Wayback Machine vs SingleFile vs ArchiveBox: Which Preservation Tool Fits Which Job?
Choose the right web-preservation tool by job: Wayback Machine for public history, SingleFile for immediate portable local capture, and ArchiveBox for a self-hosted archive you control.
Building a Lightweight Evidence Capture Workflow
A practical evidence-capture workflow for preserving public web research with URL, timestamp, original artifact, integrity hash, provenance, notes and the right mix of local and third-party archives.
Getting Started with Public Surface Analysis
A practical, passive-first workflow for reading DNS, HTTP, robots, metadata, technology and historical signals without overclaiming.
What Security Headers Actually Tell You
A practical guide to interpreting HTTP security headers as evidence: what each control changes in the browser, what absence means, and why header counts are not security grades.
SPF, DKIM and DMARC: What They Reveal and What They Don't
A practical guide to reading SPF, DKIM and DMARC as public evidence: what each mechanism authenticates, how alignment works, what DNS records reveal, and what they cannot prove.
Data Is Not Intelligence
Clean data, large datasets and dense graphs can still produce bad judgments. Intelligence begins when observations are made relevant, contextualized, challenged and connected to a decision or question.
Verification Before Virality
Virality measures distribution, not truth. Serious OSINT should trace the original source, test time and location, seek independent corroboration, preserve uncertainty and publish only at the confidence the evidence supports.
SpiderFoot vs Maltego: Breadth, Structure and Workflow Maturity
Compare SpiderFoot and Maltego as two different OSINT operating models: broad module-driven collection and correlation versus entity-link graph reasoning, transforms and analyst-controlled pivots.
Hunchly vs ArchiveBox: Evidence Packaging vs Archive Ownership
Compare Hunchly and ArchiveBox as two different preservation operating models: investigator-centered evidence capture, hashing and reporting versus self-hosted, multi-format archive ownership and recurring URL preservation.
TinEye vs Forensically vs ExifTool: Three Different Jobs in Image Verification
Compare TinEye, ExifTool and Forensically as three separate image-verification layers: web provenance, file metadata and visual anomaly analysis — without turning any one signal into an authenticity verdict.
VirusTotal vs OTX: Context, Detections and When to Use Each
Compare VirusTotal and OTX as two different threat-intelligence lenses: technical object characterization and detections versus community Pulses, IOC context and campaign framing.
Choosing Between Manual, Semi-Automated and Automated OSINT Workflows
A practical framework for deciding which OSINT tasks should stay manual, which benefit from human-guided automation, and which are mature enough for repeatable automated pipelines.
How to Read a Redirect Chain Like a Technical Analyst
A hop-by-hop method for reading HTTP redirect chains: understand 301, 302, 303, 307 and 308, track URL and infrastructure changes, detect loops, and avoid overclaiming.
Why Robots.txt, Sitemaps and Metadata Still Matter
A practical guide to reading robots.txt, XML sitemaps, canonical links and indexing metadata as separate evidence layers — and using contradictions between them to generate better OSINT questions.
What a Tech-Stack Fingerprint Can and Cannot Tell You
A practical method for interpreting web technology fingerprints as evidence: separate CDN, platform, frontend and backend layers, assign confidence, corroborate signals, and avoid false certainty.
A Responsible Method for Reconnaissance on Public Web Surfaces
A practical framework for deciding what to collect, when public research becomes active testing, how to define authorization and scope, and when to stop.
How to Turn Weak Signals into Better Questions
A practical OSINT reasoning framework for turning ambiguous observations into testable hypotheses, seeking disconfirming evidence and expressing conclusions with calibrated confidence.