osint

OSINT

What is OSINT ?

OSINT means Open-Source Intelligence. It is a set of tools that are available for everyone and everywhere.

OSINT is used in many different areas such as:

  • Cyber Threat Intelligence
  • Human Intelligence
  • Political Intelligence
  • Journalist Intelligence
  • And others.

OSINT allows to collect any type of data available online and analyze it. The OSINT cycle is:

  • Data collection
  • Data Analysis
  • Report (Documentation and Recommendations)

The OSINT Report depends on which area you are using OSINT. For example in Cyber Threat Intelligence (Why do we need a Cyber Threat Intelligence? - osintafrica), OSINT report can be writing following one of the models CYBER KILL CHAIN or The Diamond Model of Intrusion Analysis, more details about the models can be found here Three attacks frameworks that Cyber Security members should know osintafrica. 

OSINT framework tools are available and easy to find online.

Some of them are:

OSINT Framework

Tools - Start.me

My OSINT Training's Tools

Advantages of using OSINT:

OSINT has many advantages such as many applications are free and accessible online, data available anywhere but the most important for us, are the following:

  • Detect Threats
  • Vulnerabilities
  • Information lookup
  • Data breached identification

Anything that has advantages, has inconveniences as well.

OSINT does have some.

OSINT Inconveniences:

Data can be query by anyone online

PII data accessible online

Vulnerability and threats are identifiable online

Data breached data are accessible on different platform (Dark Web, Hacking forum , OSINT tools and others ..).

OSINT tools can be vectors of attack.

The privacy concerning OSINT , the privacy concerns is quite similar to GDPR regulation requirements, such as collecting only information related to your investigation, having authorization to collect the data (PII or IP) and others.

OSINT is very useful, like said before, the tools are available for anyone to use. You can start using it by looking up some information related to your self. Do not forget about Privacy related to OSINT.

whistleblower

Best tools to protect the whistleblowers and journalists online

Imagine that you want to report a big financial corruption in your country or organization, the best way to safely report such information is to use a trustworthy and anonymous tool. There are many tools nowadays for such activities but the best and most secured are the following we are going to share with you in this article.

A few years back, it was quite easy to report such activity by making just a call, but nowadays, such way of doing is not secured anymore as the service providers record all the calls and also listen to them. Below we will share with you, the best tools used by the whistleblower and journalists to stay online safe and share the information without any risk.

  1. Share and accept documents securely (securedrop.org)

SecureDrop is an open source used by whistleblower to anonymously send and receive documents to journalists.

  1. Whonix - Superior Internet Privacy

Whonix is used for privacy and anonymity over the Internet.

The tool works with TOR to fully anonymize your connection. 

  1. Tor Project | Download

Tor is a browser used for maintaining the privacy over the internet. It can be used to access the DarkWeb. The TOR browser is based on onion routing to bring more privacy over the network.

  1. Tails - How Tails works

Tails is a portable OS that protect against surveillance and censorship by anonymity and privacy.

  1.  OnionShare

OnionShare is an open-source tool used to securely share files, chat, host websites using TOR browser.

  1. EQS Integrity Line - the secure whistleblowing hotline | integrityline.com

EQS Integrity Line is a whistleblower tool used by the EU to securely and anonymously allow the employees to raise wrongdoing such as discrimination, human abuse.

  1. GlobaLeaks - Free and Open-Source Whistleblowing Software

GlobalLeaks is a customizable open source that enable anyone to set up and maintain a secure whistleblowing platform.

  1. ObscuraCam: The Privacy Camera - Guardian Project

ObscuraCam Helps you to share photos and videos while protecting the privacy of people.

The tool can be used to blur faces and remove camera and location metadata with the privacy camera app.

  1. Haven: Keep Watch (BETA) – Apps on Google Play

Haven is a device sensor that provide monitoring and protection of physical spaces.

The tool can be used to detect motion, sound, vibration and light surrounding your environment.

  1. Dangerzone: Convert potentially dangerous documents into safe PDFs

Dangerzone is used to securely open a PDF files, office documents, images by converting into a safe PDF file.

In conclusion, you as a whistleblower or journalist, should always think about protecting the information that you hold in the most secure way. Before using any tool, verify how the data are protected and the privacy is maintained.