# Global Threat Watch — full content corpus > Complete text of every Intelligence Briefing published at https://www.globalthreatwatch.com/blog. Free to cite with attribution to Global Threat Watch. Generated from the live site. Canonical HTML versions are linked in each section. --- # OSINT Framework: How to Use It (2026 Guide) > How to actually use the OSINT Framework in 2026 — its tool taxonomy, a repeatable investigation workflow, safer alternatives, and OPSEC rules. - URL: https://www.globalthreatwatch.com/blog/osint-framework-how-to-use-2026 - Published: 2026-07-31 | Updated: 2026-07-31 | 16 min read - Category: OSINT Tradecraft - Tags: osint-framework, osint-tools, open-source-intelligence, investigation-workflow, opsec, osint-tradecraft - Publisher: Global Threat Watch (https://www.globalthreatwatch.com) ## TL;DR The OSINT Framework (osintframework.com) is a free, browser-based directory that organizes hundreds of open-source intelligence tools into a clickable tree by investigation type — username, email, domain, IP, social network, geolocation, and more. It is a map, not a scanner: it does not collect data itself, it points you at the tool that does. Used well, it turns an unstructured search into a repeatable workflow — define the selector, pick the branch, pivot on every new artifact, and record provenance. Because parts of the tree are stale, pair it with maintained directories (Bellingcat's Online Investigation Toolkit, OSINT Combine, IntelTechniques) and always run queries from an isolated browser profile or VM. ## Key takeaways - The OSINT Framework is a directory, not a tool — it maps selectors (username, email, domain, IP, phone, image) to the external sites that resolve them. - Its value is workflow structure: start from a selector, walk the matching branch, and pivot on every artifact you recover. - Parts of the public tree are unmaintained — expect dead links, and cross-check against Bellingcat's Online Investigation Toolkit and OSINT Combine. - Never query it from your corporate IP or personal browser profile; use a dedicated VM, container, or hardened browser profile with a separate exit IP. - The framework is legal to use, but the sites it links to are not uniformly legal or ethical to use everywhere — jurisdiction governs, not the directory. - Record provenance for every finding — URL, timestamp, screenshot hash — or the intelligence is unusable in reporting, court, or newsroom review. - Pair it with live monitoring (feeds, dashboards, alerts) for time-sensitive work; the framework answers 'where do I look', not 'what changed'. Search "OSINT tools" and within two clicks you will land on the OSINT Framework — a sprawling, teal-on-black node tree hosted at osintframework.com that fans out from a single root into hundreds of branches: username, email address, domain name, IP address, images, social networks, dark web, terrorism, exploits. For a decade it has been the first bookmark most analysts save and, unfortunately, the first one most of them misuse. This guide explains what the OSINT Framework actually is, how to run a real investigation with it, where it fails in 2026, and how to combine it with live intelligence sources so it becomes a workflow rather than a link dump. We use exactly this method behind Global Threat Watch when we need to verify an actor, a domain, or a claim that appears in a live feed. The framework is the map; the discipline around it is what produces intelligence. ## What the OSINT Framework actually is The OSINT Framework is a static, open-source web application — originally built by Justin Nordine and maintained on GitHub — that renders a JSON file of categorized links as an interactive D3 tree. Click a parent node and it expands into child nodes; click a leaf and it opens the external tool in a new tab. There is no account, no telemetry, no API key, no results pane. It collects nothing about your target and nothing about you. That architecture explains both its strengths and its limits. Because it is just a curated JSON tree, it is fast, free, forkable, and runnable offline from a local clone. Because it is just a curated JSON tree, it also ages: a link added in 2019 to a service that shut down in 2023 stays there until someone opens a pull request. Treat the framework as a well-organized index of the OSINT landscape rather than an authoritative, live-verified catalogue. ### How to read the node markers Leaf nodes carry small indicators that most newcomers ignore, and they matter more than the tool names: - (T) — the resource is a downloadable tool that must be installed locally, not a website you can just click into. - (D) — Google dork; the link runs a crafted search query rather than opening a dedicated service. - (R) — requires registration, often with identity friction; plan your sock-puppet account before you click. - (M) — the URL contains a manual placeholder you must edit yourself, typically a username or domain in the query string. Reading these before clicking saves an enormous amount of time and, in the (R) case, prevents the classic mistake of registering for a niche people-search site with your real work email. ## The branches that matter most in 2026 The tree has dozens of top-level categories, but the overwhelming majority of real casework moves through six of them. Learn these deeply and the rest are situational. ### Username Username enumeration is the highest-yield opening move in person-centric investigations, because people reuse handles across a decade of platforms. The framework points at cross-platform checkers (WhatsMyName, Sherlock, Maigret, Namechk) plus per-platform lookup pages. Run at least two checkers — coverage differs sharply — and treat every confirmed hit as a new pivot point, not a conclusion. A matching handle on an obscure forum is a lead; the corroborating avatar, bio phrasing, and posting timezone are the evidence. ### Email address The email branch covers validation (does this mailbox exist), breach exposure (HaveIBeenPwned, Dehashed, IntelligenceX), reputation, and reverse lookups. In 2026 the highest-value use is breach and stealer-log correlation: an address appearing in a recent infostealer dump tells you not only that the person was compromised but often which sites they used and when. Keep an eye on the legal line here — querying whether an address appears in a breach index is very different from downloading and searching the underlying stolen dataset. ### Domain name The domain branch is the backbone of infrastructure investigations: WHOIS and historical WHOIS, DNS and passive DNS, certificate transparency logs (crt.sh, Censys), subdomain enumeration, reverse IP, and the Wayback Machine. Certificate transparency in particular has become the single most productive node on the entire tree — CT logs are exhaustive, timestamped, and impossible for an operator to retroactively scrub, which makes them ideal for mapping phishing and staging infrastructure before it is used. ### IP address Geolocation, ASN and netblock ownership, blocklist status, Shodan and Censys host records, and passive DNS reverse lookups. Two cautions: commercial IP geolocation is frequently wrong at city granularity, and Shodan-style scans reflect the last crawl, not the current state of the host. Always cite the observation timestamp. ### Images, videos and documents Reverse image search across multiple engines (Google Lens, Yandex, Bing, TinEye — Yandex remains disproportionately strong on faces and Eastern European content), EXIF extraction, and metadata analysis of PDFs and Office files. Document metadata still leaks author names, internal file paths, and organizational software inventories at an embarrassing rate. ### Geolocation and mapping Satellite and street-level imagery, historical imagery layers, sun-position calculators for shadow analysis, and terrain matching. This is the branch that powers open-source conflict verification: given a single photograph, chronolocation via shadows plus geolocation via terrain and building signatures can place an event within meters and minutes. ## A repeatable investigation workflow The framework will not impose structure on you. Impose it yourself. The following five-phase loop is the one we use, and it maps cleanly onto the traditional intelligence cycle. ### 1. Write the requirement before you click anything State the question in one sentence and define what would answer it: "Determine whether the domain in this phishing email is operated by the same actor as the campaign we saw in May, using infrastructure overlap." Undefined requirements produce forty open tabs and no conclusion. ### 2. Identify your starting selectors A selector is a hard, machine-searchable artifact: a username, email, domain, IP, hash, phone number, wallet address, license plate, or image. Every OSINT Framework branch is organized by selector type, so listing your selectors tells you exactly which branches to open. ### 3. Expand, then pivot Walk the branch top to bottom. Every result that yields a new selector goes on the list and starts its own pass. Domain to registrant email; registrant email to breach records; breach records to reused username; username to social accounts; social accounts to a second domain. Pivoting — not any individual tool — is what produces the map. ### 4. Record provenance as you go, not afterwards For each finding capture the source URL, retrieval timestamp in UTC, a full-page screenshot, and where possible a hash of the saved artifact. Sites change and delete content constantly; an uncaptured finding is a rumor. Archive important pages to the Wayback Machine or archive.today immediately. ### 5. Assess confidence and write it down Label every conclusion with a confidence level and the reason for it — corroborated by two independent sources, single-source, or inference. Analysts who skip this step end up presenting inference as fact, which is how OSINT investigations collapse under scrutiny. ## OPSEC: how to use it without exposing yourself Every click in the framework is a direct connection from your browser to a third-party site. Some of those sites log aggressively, some are operated by the very communities you are researching, and some will notify a domain owner that their infrastructure was queried. - Investigate from a dedicated VM or container with a clean browser profile — never your daily driver, never a corporate-attributed IP. - Separate identities: a research persona with its own email, phone (VoIP), and payment method for (R) registration-required resources. - Assume active-scan tools (Shodan queries are passive; port scanners and subdomain brute-forcers are not) may be legally regulated in your jurisdiction and may alert the target. - Disable browser sync, password autofill, and logged-in Google sessions in the research profile — a single autofilled work address burns the persona. - Keep a contemporaneous activity log; if the investigation is ever reviewed, the log is your defense that methods stayed passive and lawful. None of this is paranoia theater. The most common way an OSINT investigation is discovered is not sophisticated counter-intelligence — it is an analyst clicking a tracked link while logged into a personal account. ## Where the OSINT Framework falls short Being honest about the gaps is what separates practitioners from tool collectors. - Link rot: a meaningful share of leaf nodes point at services that are dead, paywalled, or acquired. Verify before you rely on any single node. - No quality signal: a world-class certificate transparency search sits next to an abandoned people-finder, visually identical. The tree conveys category, not credibility. - No automation: everything is manual and browser-based. For repeatable work you will want SpiderFoot, Maltego, recon-ng, or your own scripted pipeline. - No monitoring: it answers 'where can I look this up' but never 'tell me when this changes'. Time-sensitive work needs feeds, alerts, and a live dashboard. - Weak on non-English sources: coverage of Russian, Chinese, Farsi, and Arabic-language platforms is thin relative to their intelligence value. ## Better together: the 2026 stack Use the framework as the discovery layer of a three-layer stack. Layer one is discovery — the OSINT Framework plus a maintained directory such as Bellingcat's Online Investigation Toolkit or OSINT Combine's tool list, which are curated more actively. Layer two is automation — SpiderFoot or recon-ng for breadth-first collection against a selector, Maltego for link analysis and visualization, and a scripted collector for anything you run more than twice. Layer three is monitoring — RSS and API feeds, certificate transparency alerts, breach notifications, and a live situational-awareness dashboard so you learn about change without re-running the investigation. That third layer is the one most analysts skip, and it is the one that converts episodic research into continuous intelligence. A domain you cleared last month can be repurposed tomorrow; a threat actor you profiled in spring can shift infrastructure in a week. ## Worked example: from one domain to an actor picture Suppose a suspicious invoice arrives from billing-secure-portal[.]com. Requirement: determine whether this is a one-off or part of a broader campaign. Selectors: the domain, and later whatever it yields. - Domain branch → WHOIS shows privacy protection, but historical WHOIS from an archive service exposes a registrant email used before privacy was enabled. - Domain branch → certificate transparency reveals eleven sibling hostnames issued within the same 48-hour window, all following the same naming pattern. - IP branch → passive DNS puts nine of those hostnames on one small VPS netblock; the ASN is a bulletproof-adjacent reseller with prior abuse reports. - Email branch → the recovered registrant address appears in two infostealer datasets and, critically, in the WHOIS history of three unrelated 2025 domains. - Username branch → the local part of that address, run through cross-platform checkers, matches an account on a low-traffic hosting forum with posts requesting exactly this hosting profile. - Images branch → the forum avatar reverse-images to a stock photo, closing that thread but confirming persona construction rather than a real identity. The conclusion is not "we identified the attacker". It is a defensible, provenance-backed assessment: a single operator or crew is running a multi-domain invoice-fraud campaign on identified infrastructure, with eleven blockable hostnames and one netblock worth monitoring. That is an actionable output, produced entirely from free sources, in an afternoon. ## Frequently misunderstood: framework vs. methodology The name causes real confusion. The OSINT Framework is not a methodology, a standard, or a maturity model — it is a website of links. The methodology is the intelligence cycle: direction, collection, processing, analysis, dissemination, feedback. If you need a formal methodology, look to the NATO OSINT Handbook lineage, the Intelligence Community's analytic tradecraft standards (ICD 203), or Bellingcat's published verification workflows. Use the framework inside that methodology, at the collection step, and the confusion disappears. ## Getting started this week - Clone the GitHub repository and run it locally so you have an offline copy that link rot cannot take away. - Pick one selector type — username is the easiest — and work its entire branch against a target you are authorized to research, such as your own accounts. - Build your research VM and persona before your first real case, not during it. - Create a findings template with fields for source URL, UTC timestamp, screenshot path, and confidence; fill it every single time. - Add a monitoring layer so that the selectors you care about generate alerts rather than requiring re-investigation. The OSINT Framework rewards discipline more than cleverness. Analysts who treat it as a checklist of links plateau quickly; analysts who treat it as a pivot map — selector in, artifacts out, artifacts become new selectors — keep finding things the tools alone never surface. ### External Sources & Further Reading - [OSINT Framework (osintframework.com)](https://osintframework.com/) — The interactive tool tree itself. - [OSINT Framework on GitHub](https://github.com/lockfale/OSINT-Framework) — Source repository — clone to run locally or submit link fixes. - [Bellingcat Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — Actively maintained, verification-focused tool directory. - [Bellingcat Guides & Resources](https://www.bellingcat.com/category/resources/how-tos/) — Published how-tos for geolocation and chronolocation. - [IntelTechniques (Michael Bazzell)](https://inteltechniques.com/tools/) — Search-tool suite and OSINT methodology reference. - [OSINT Combine free tools](https://www.osintcombine.com/free-osint-tools) — Curated, regularly reviewed toolset. - [SpiderFoot](https://github.com/smicallef/spiderfoot) — Automated OSINT reconnaissance across 200+ modules. - [Maltego](https://www.maltego.com/) — Link analysis and graph visualization for pivots. - [WhatsMyName username enumeration](https://whatsmyname.app/) — Cross-platform username checker with a maintained site list. - [Sherlock](https://github.com/sherlock-project/sherlock) — Command-line username hunting across social networks. - [crt.sh certificate transparency search](https://crt.sh/) — Exhaustive, timestamped certificate records for domain pivots. - [Censys Search](https://search.censys.io/) — Internet-wide host and certificate index. - [Shodan](https://www.shodan.io/) — Exposed-service search for IP and infrastructure work. - [Have I Been Pwned](https://haveibeenpwned.com/) — Breach exposure checks for email selectors. - [Internet Archive Wayback Machine](https://web.archive.org/) — Historical page capture and evidence archiving. - [archive.today](https://archive.ph/) — On-demand snapshot archiving for provenance. - [ExifTool](https://exiftool.org/) — Metadata extraction from images, video, and documents. - [SunCalc](https://www.suncalc.org/) — Sun position and shadow analysis for chronolocation. - [ICD 203 Analytic Standards](https://www.dni.gov/files/documents/ICD/ICD%20203%20Analytic%20Standards.pdf) — Confidence language and analytic tradecraft standards. - [CISA free cybersecurity services and tools](https://www.cisa.gov/resources-tools/resources/free-cybersecurity-services-and-tools) — Government-vetted defensive tooling. ## FAQ ### What is the OSINT Framework? The OSINT Framework is a free, browser-based directory at osintframework.com that organizes hundreds of open-source intelligence tools into an interactive tree sorted by investigation type — username, email, domain, IP address, images, geolocation, social networks and more. It stores no data and performs no searches itself; it points you to the external tool that does. ### How do you use the OSINT Framework? Start by writing your investigative question, then list your selectors (username, email, domain, IP, image). Open the matching branch of the tree, work through its nodes, and pivot on every new artifact you recover so it becomes a new selector. Record the source URL, UTC timestamp and a screenshot for each finding, and assign a confidence level to every conclusion. ### Is the OSINT Framework free? Yes. The site is free, requires no account, and its source is published on GitHub so you can clone and run it locally. Some individual tools it links to are paid or require registration — those leaves are marked with an (R) indicator. ### Is the OSINT Framework safe and legal to use? Browsing the directory itself is legal and low risk. The risk comes from the third-party sites it links to, which log visitors, and from activities like active scanning or accessing stolen data that may be regulated in your jurisdiction. Use a dedicated research VM, a separate browser profile and persona, and never query from a corporate IP. ### Is the OSINT Framework still maintained in 2026? The repository still receives community contributions, but coverage is uneven and a meaningful share of leaf links are dead or outdated. Treat it as a map of the landscape and cross-check against actively curated directories such as Bellingcat's Online Investigation Toolkit, IntelTechniques, and OSINT Combine. ### What are the best alternatives to the OSINT Framework? For curated directories: Bellingcat's Online Investigation Toolkit, IntelTechniques tools, and OSINT Combine. For automation rather than link discovery: SpiderFoot for breadth-first collection, Maltego for link analysis, and recon-ng for scripted reconnaissance. Most practitioners use the framework for discovery and one of these for execution. ### Does the OSINT Framework collect data about my searches? No. It is a static site that renders a JSON file of links; clicking a leaf simply opens the external site in a new tab. The destination sites, however, see your request in full — which is why browser and network hygiene matter more than the framework's own privacy posture. --- Source: [OSINT Framework: How to Use It (2026 Guide)](https://www.globalthreatwatch.com/blog/osint-framework-how-to-use-2026) — Global Threat Watch, free real-time OSINT dashboard. --- # Dark Web Monitoring Tools in 2026: Free & Paid Guide > Practitioner's guide to dark web monitoring in 2026 — free and paid tools, Tor/I2P crawling, credential and brand-exposure detection. - URL: https://www.globalthreatwatch.com/blog/dark-web-monitoring-tools-2026 - Published: 2026-07-18 | Updated: 2026-07-18 | 17 min read - Category: Cyber Threat Intelligence - Tags: dark-web-monitoring, dark-web-monitoring-tools, threat-intelligence, credential-monitoring, stealer-logs, tor - Publisher: Global Threat Watch (https://www.globalthreatwatch.com) ## TL;DR Dark web monitoring tools continuously scan Tor hidden services, I2P sites, criminal forums, Telegram channels, paste sites, and stealer-log marketplaces for your organization's credentials, data, brand, and executives. The best 2026 stack pairs free sources (HaveIBeenPwned, IntelligenceX, Ahmia, Dehashed, Telegram OSINT bots) with one commercial platform (Recorded Future, Flashpoint, DarkOwl, SOCRadar, or KELA) for coverage of closed forums and stealer logs, wired into a TIP or SIEM with clear playbooks for credential resets and takedowns. ## Key takeaways - Dark web monitoring tools crawl Tor hidden services, I2P, criminal forums, Telegram, Discord, paste sites, and stealer-log markets — not just .onion sites. - In 2026 most breached credentials surface in infostealer logs (RedLine, Lumma, StealC) sold on Russian Market and Telegram, not in classic forum dumps. - Free baseline: HaveIBeenPwned, IntelligenceX, Ahmia, Dehashed, LeakIX, and a curated set of Telegram OSINT bots covers 70% of small-business needs. - Commercial leaders (Recorded Future, Flashpoint, DarkOwl, KELA, SOCRadar, ZeroFox) differentiate on closed-forum access, human analyst context, and takedown services. - Evaluate tools on five axes: source breadth, freshness, false-positive rate, enrichment (actor context + TTPs), and workflow integration (SIEM/SOAR/TIP). - Wire alerts into a TIP or ticketing system with pre-written playbooks — credential exposure, executive impersonation, code leak, and third-party breach each need a different response. - Legal and OPSEC matter: never log into criminal forums from a corporate IP, and follow jurisdictional rules on stolen data (GDPR, CFAA, UK CMA). Dark web monitoring is the continuous, automated surveillance of the parts of the internet that Google will not index — Tor hidden services, I2P eepsites, invite-only criminal forums, Telegram and Discord channels, paste sites, stealer-log marketplaces, and ransomware leak sites — for mentions of your organization's credentials, customer data, source code, brand, and executives. In 2026 it is a baseline capability for any security team above a handful of people, and it is one of the cheapest high-ROI investments in the modern SOC: a single credential alert acted on before the attacker uses it is worth more than most quarterly pen tests. This guide is the version we wish existed when we first stood up dark web monitoring behind Global Threat Watch. It covers what these tools actually watch in 2026, the free sources that get most small teams to "good enough", the commercial platforms worth their price tag, how to evaluate them objectively, and the pipeline architecture that keeps alerts actionable instead of noisy. No vendor pitch, no scare marketing. ## What dark web monitoring tools actually watch The phrase "dark web" is a marketing shorthand for at least four distinct source classes. A modern monitoring tool covers all of them, weighted by how much criminal activity has migrated there — and in the last three years the center of gravity has shifted decisively off classic Tor forums and onto Telegram and stealer-log markets. - Tor hidden services (.onion) — ransomware leak sites (LockBit successors, Play, Akira, Cl0p, RansomHub), classic markets, and mirror sites for forums like Exploit and XSS. - I2P eepsites — a smaller but growing set of Russian- and Farsi-language forums that migrated after Hydra was seized in 2022. - Closed-web criminal forums — clearnet or Tor forums that require invite, vouching, or paid membership: BreachForums (v3), XSS, Exploit, RAMP, Dread. These are where the highest-value chatter happens. - Telegram and Discord channels — since 2023 the dominant venue for stealer logs, combolists, initial-access broker (IAB) offers, and hacktivist coordination. Any tool that ignores Telegram is missing more than half of 2026 traffic. - Stealer-log marketplaces — Russian Market, 2easy, Genesis (successor sites), and dozens of Telegram-based sellers moving RedLine, Lumma, StealC, Vidar, and Meta logs by the million. - Paste sites and code leaks — Pastebin, Ghostbin, DoxBin, GitHub gists, Discord CDN links, and stealer-log "cloud" folders where credentials are dumped in bulk. - Clear-web breach aggregators — HaveIBeenPwned, Dehashed, LeakIX, IntelligenceX. Technically not "dark" but essential coverage. A useful tool is judged as much by what it does not miss as by what it finds. Coverage of Telegram, stealer logs, and closed forums is the differentiator in 2026; anyone can scrape .onion leak sites. ## The eight things dark web monitoring tools are used to detect Almost every credible use case reduces to one of these eight patterns. Map your tool selection to the patterns you actually need — most organizations only need three or four. - Credential exposure — corporate email + password pairs surfacing in breaches, combolists, or stealer logs. By far the most common and highest-ROI use case. - Stealer-log infection detection — a device belonging to your organization or a supplier was infected with an infostealer, and its full browser cookie/session/credential dump is now for sale. - Ransomware leak-site appearance — your name (or a supplier's) shows up on a leak site, often the first external signal of a breach. - Initial-access broker (IAB) offers — a broker is selling VPN, RDP, or Citrix access to "a US healthcare company with $200M revenue" that matches your fingerprint. - Brand and executive impersonation — fake domains, phishing kits, or social profiles targeting your brand or a named executive. - Source code and document leaks — repos, design docs, or contracts posted to paste sites or forums. - Third-party and supply-chain exposure — a vendor or contractor breached, with your data included in the dump. - Threat actor chatter and targeting — your industry, geography, or company named in forum posts as a target. ## Free dark web monitoring tools worth using in 2026 You can cover a surprising amount of ground with free tools. For a small business or an under-resourced SOC, the stack below catches most credential exposure and public leaks without a single invoice. ### HaveIBeenPwned (HIBP) Troy Hunt's HIBP is the baseline. The domain-search API is free for verified domain owners and returns every breached account under a domain. Wire it into a nightly script and route hits to your ticketing system. Coverage is broad on public breaches, sparse on stealer logs and private dumps — pair it with something else. ### IntelligenceX Intelx.io indexes an enormous archive of paste sites, leaks, Tor content, and darknet mirrors. The free tier is rate-limited but useful for ad-hoc searches on a domain, email, or bitcoin address. The API tier is inexpensive for small teams. ### Dehashed and LeakIX Dehashed indexes leaked credentials and lets you query by domain, email, IP, name, or phone. LeakIX crawls exposed services and open databases. Both are cheap and complementary to HIBP. ### Ahmia and Tor2Web mirrors Ahmia is a search engine for Tor hidden services that filters out CSAM. Combined with a headless Tor Browser and a scraping framework, it lets you monitor specific leak sites without building a full crawler. ### Telegram OSINT tools Telegram is where most 2026 leak traffic lives. Free/low-cost options include Telemetr.io, TGStat, and open-source scrapers like tgscan and Telepathy. Curate a list of channels tied to your industry and geography and monitor them daily. ### OnionScan, Ahmia + custom crawlers, and the ransomware-live project ransomware.live is a free, community-run dashboard that aggregates victim postings across 100+ ransomware leak sites — the simplest way to get an alert when your name or a supplier's name appears on a leak site. ### Google, GitHub, and Grep.app dorking Do not underestimate the clear web. Weekly dorking for site:pastebin.com "yourdomain.com", GitHub secret scanning, and Grep.app searches for internal repo names catches leaks that never touch Tor. ## Commercial dark web monitoring platforms worth their price Above a certain threat model — regulated industries, high-value brands, critical infrastructure — free tools stop being enough. You need closed-forum access, human analyst context, and a takedown workflow. The 2026 leaders, roughly grouped by strength: ### Recorded Future The most comprehensive intelligence platform on the market. Coverage spans dark web, technical feeds, geopolitical, and vulnerability intel with strong MITRE ATT&CK mapping. Expensive; overkill for teams smaller than a mid-market SOC. Best if you also want strategic and vulnerability intelligence in one platform. ### Flashpoint Deep coverage of closed forums, jihadist and extremist chatter, physical-security intel, and fraud. Strong analyst layer. The go-to for financial services and government. ### DarkOwl Massive raw dark-web archive with a searchable index — closer to a data provider than a fully managed service. Great if you have your own analysts and want to query at scale. ### KELA Israeli firm with excellent stealer-log and IAB coverage. Their "Threat Landscape" module is one of the better ways to see your organization through an attacker's eyes. ### SOCRadar Broad extended-threat-intelligence (XTI) platform covering dark web, attack surface, and brand protection. Aggressive pricing versus the top three; popular with mid-market. ### ZeroFox Strongest on brand, domain, and social-media impersonation with an in-house takedown team. Less deep on criminal-forum intel. ### Intel 471 Human-intelligence-heavy — a network of analysts embedded in criminal communities. Reports are lower-volume but higher-context; excellent for tracking specific actors and IABs. ### Digital Shadows (ReliaQuest GreyMatter DRP), Constella, Cybersixgill All credible players in the digital-risk-protection tier with meaningful dark-web coverage. Shortlist based on your sector and language coverage (Russian, Farsi, Mandarin, Portuguese all matter). ## How to evaluate a dark web monitoring tool Vendors will all claim "the deepest dark web coverage". Ignore the marketing and score every candidate on five objective axes: - Source breadth — do they cover Tor, I2P, Telegram, Discord, closed forums, stealer-log markets, and paste sites? Ask for a written source list. - Freshness — median time from a post appearing on a source to an alert in your inbox. Under 30 minutes is good; over 24 hours is a red flag. - False-positive rate — run a 30-day pilot with your real domains and count how many alerts required no action. Above 40% and analysts will start ignoring the tool. - Enrichment — does an alert include the actor, forum reputation, prior activity, MITRE ATT&CK mapping, and a recommended action? Raw hits are almost worthless. - Workflow integration — native connectors for your SIEM, SOAR, TIP (MISP, OpenCTI, Anomali), ticketing (Jira, ServiceNow), and chat (Slack, Teams). API-only tools cost engineering time forever. Two more that are non-negotiable in regulated environments: data-handling practices (where are they storing your matched credentials?) and legal posture (do they refuse to broker payments or facilitate access to CSAM?). ## A reference architecture: from raw dark-web hit to closed ticket The mistake most teams make is piping raw dark-web alerts straight into email or Slack. Within a month, analysts mute the channel. The right pattern is a five-stage pipeline that mirrors how mature SOCs handle IOCs: - Ingest — pull from every source (free + commercial) via STIX/TAXII, API, or webhook into a Threat Intelligence Platform (MISP or OpenCTI both work well). - Deduplicate and score — collapse repeated hits, assign a confidence score, and enrich with actor context and MITRE ATT&CK where possible. - Triage — route by category (credential exposure → IAM; leak-site mention → incident response; brand impersonation → legal + takedown) into pre-built playbooks. - Act — pre-approved automations: force credential reset, revoke sessions, block indicators at the edge, file a takedown, notify the affected customer. - Measure — dashboard the pipeline: alerts by category, mean time to action, false-positive rate, and dollar loss avoided. Without metrics you cannot defend the budget. ## Legal, ethical, and OPSEC considerations Dark web monitoring is legal in most jurisdictions when done carefully, but there are landmines. A short checklist your legal team should sign off on: - Never authenticate to criminal forums or purchase stolen data from corporate infrastructure — use a dedicated legal entity, funded persona, and isolated network. - Respect jurisdictional rules on possessing breached data (GDPR Art. 5–6, US CFAA, UK CMA, Singapore CMA). Retention should be minimum necessary. - Never engage with CSAM sources, even inadvertently — reputable tools filter it out, verify their filtering. - Do not pay ransoms or brokers to "take down" leaked data unless legal counsel and law enforcement are involved. Payments to sanctioned entities (OFAC SDN list) are criminal. - Have a written policy for what you do when you find employee credentials tied to non-work services (a compromised personal account may reveal legally protected information). ## What good looks like in 2026: a maturity model A quick self-assessment. Most organizations are at Level 1 or 2 and think they are at Level 3. - Level 0 — Ad-hoc. Someone Googles the company name occasionally. No tooling. - Level 1 — Free baseline. HIBP + IntelligenceX + ransomware.live checked weekly. Email alerts to the security lead. - Level 2 — Commercial tool, unintegrated. A DRP platform is bought but alerts land in an inbox nobody owns. High noise. - Level 3 — Integrated. Alerts flow into a TIP and SIEM, deduplicated, scored, routed to playbooks. Metrics reported monthly. - Level 4 — Proactive. Custom collection on your industry (Telegram channels, specific actors) plus red-team use of monitored intel to test controls. Feeds tabletop exercises. - Level 5 — Intelligence-led. Dark-web signals drive detection engineering, patch prioritization, and executive briefings. Threat model updated quarterly against observed actor behavior. ## A minimal viable dark-web monitoring stack you can stand up this week For a team with no budget and one part-time analyst: - Register your domains with HaveIBeenPwned's domain-search API and cron a nightly script. - Subscribe to ransomware.live's RSS feed and pipe it to a Slack channel filtered by your name and top 20 suppliers. - Set up a curated list of 30–50 Telegram channels and monitor with a free scraper into the same Slack channel. - Run weekly Google/GitHub dorks for your domain, internal repo names, and product code names. - Sign up for AlienVault OTX and any free MISP community you can access. - Write four one-page playbooks: credential exposure, leak-site mention, executive impersonation, source-code leak. Total cost: zero. Time to stand up: about two days. That baseline will catch more than most six-figure deployments do in their first month, because it is actually wired into a workflow. > The dark web itself is not the threat. The threat is that you find out about your own breach from a journalist calling for comment instead of from your own tools. ### External Sources & Further Reading - [Have I Been Pwned — domain search API](https://haveibeenpwned.com/API/v3) — Free tier for verified domain owners - [IntelligenceX](https://intelx.io/) — Paste, leak, and Tor archive search - [Dehashed](https://www.dehashed.com/) — Leaked-credential search by domain, email, IP or phone - [LeakIX](https://leakix.net/) — Indexes exposed services and open databases - [Ahmia — Tor search engine](https://ahmia.fi/) — Filtered Tor hidden-service search - [OnionScan](https://onionscan.org/) — Open-source tool for auditing Tor hidden services - [ransomware.live](https://www.ransomware.live/) — Community-run ransomware leak-site aggregator - [Ransomwatch](https://ransomwatch.telemetry.ltd/) — Alternate aggregator of ransomware victim postings - [Tor Project](https://www.torproject.org/) — Official Tor Browser and documentation - [I2P Project](https://geti2p.net/) — Invisible Internet Project — anonymous overlay network - [MITRE ATT&CK](https://attack.mitre.org/) — Adversary TTP framework for enrichment - [MISP Project](https://www.misp-project.org/) — Open-source Threat Intelligence Platform - [OpenCTI](https://filigran.io/solutions/open-cti/) — Open-source cyber threat intelligence platform - [AlienVault OTX](https://otx.alienvault.com/) — Free community threat-intelligence exchange - [abuse.ch](https://abuse.ch/) — URLhaus, ThreatFox, MalwareBazaar, Feodo Tracker feeds - [CISA — Stop Ransomware](https://www.cisa.gov/stopransomware) — US government ransomware guidance and reporting - [CISA Known Exploited Vulnerabilities (KEV)](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) — Authoritative list of actively exploited CVEs - [FBI IC3](https://www.ic3.gov/) — US Internet Crime Complaint Center — report incidents - [NCSC (UK) — Dark Web guidance](https://www.ncsc.gov.uk/) — UK National Cyber Security Centre resources - [Europol EC3](https://www.europol.europa.eu/about-europol/european-cybercrime-centre-ec3) — European Cybercrime Centre — takedown and coordination - [OFAC SDN Search](https://sanctionssearch.ofac.treas.gov/) — Check ransom payment counterparties - [OFAC ransomware advisory (2020, updated)](https://ofac.treasury.gov/media/912981/download) — US Treasury guidance on ransomware payment risk - [STIX 2.1 specification (OASIS)](https://oasis-open.github.io/cti-documentation/) — Structured threat intelligence interchange - [TAXII 2.1 specification (OASIS)](https://docs.oasis-open.org/cti/taxii/v2.1/os/taxii-v2.1-os.html) — Transport protocol for STIX intelligence - [NIST SP 800-150 — Cyber Threat Information Sharing](https://csrc.nist.gov/pubs/sp/800/150/final) — Foundational US government guidance on CTI sharing - [Krebs on Security](https://krebsonsecurity.com/) — Long-running investigative reporting on cybercrime and dark-web actors - [The Record by Recorded Future](https://therecord.media/) — Daily cyber and threat-intel news - [BleepingComputer](https://www.bleepingcomputer.com/) — Ransomware, stealer and breach reporting - [Verizon DBIR](https://www.verizon.com/business/resources/reports/dbir/) — Annual Data Breach Investigations Report — credential-abuse baselines ## FAQ ### What are dark web monitoring tools? Dark web monitoring tools are software platforms that continuously scan Tor hidden services, I2P, criminal forums, Telegram channels, paste sites, and stealer-log marketplaces for mentions of your organization's credentials, data, brand, or executives, and alert you when they find something so you can act before an attacker does. ### Are free dark web monitoring tools good enough? For small businesses and low-risk organizations, a free stack of HaveIBeenPwned, IntelligenceX, ransomware.live, curated Telegram monitoring, and Google/GitHub dorking covers the majority of credential exposure and public leak use cases. Regulated industries, high-value brands, and critical infrastructure need commercial tools for closed-forum access and human analyst context. ### What is the best dark web monitoring tool in 2026? There is no single winner. Recorded Future has the broadest coverage; Flashpoint leads on closed forums and financial-services use cases; KELA and SOCRadar are strong on stealer logs and IAB tracking; ZeroFox leads on brand and takedown; DarkOwl offers the deepest raw archive. Pick based on your sector, threat model, and existing SIEM/TIP stack. ### Is dark web monitoring legal? Yes, in most jurisdictions, when done carefully. Passive collection of publicly posted data is generally legal. Authenticating to criminal forums, purchasing stolen data, or engaging with sanctioned entities can create legal exposure under GDPR, CFAA, UK CMA, and OFAC rules — always work with legal counsel and use a dedicated legal entity and isolated infrastructure. ### How often should dark web monitoring run? Continuously. Credential exposure and leak-site appearances are time-sensitive — most tools alert within 15–30 minutes of a post going live. Weekly manual checks are acceptable only for the smallest organizations with a free-tool stack. ### What is a stealer log and why does it matter? A stealer log is the full data dump exfiltrated from a device infected with an infostealer like RedLine, Lumma, StealC, or Vidar — typically browser cookies, saved passwords, autofill data, cryptocurrency wallets, and session tokens. In 2026 stealer logs are the dominant source of corporate credential compromise and are traded in bulk on Russian Market, 2easy, and Telegram. ### How much does commercial dark web monitoring cost? Ranges widely. Entry-level DRP platforms start around $10,000–$25,000 per year. Mid-market coverage from vendors like SOCRadar or Cybersixgill typically runs $30,000–$80,000. Top-tier platforms like Recorded Future and Flashpoint often price in the low six figures depending on modules and seat count. --- Source: [Dark Web Monitoring Tools in 2026: Free & Paid Guide](https://www.globalthreatwatch.com/blog/dark-web-monitoring-tools-2026) — Global Threat Watch, free real-time OSINT dashboard. --- # Threat Intelligence Feeds: 2026 Guide (Free & Paid) > Practitioner's guide to threat intelligence feeds in 2026 — free and paid feeds, STIX/TAXII vs API delivery, quality scoring, and SIEM integration. - URL: https://www.globalthreatwatch.com/blog/threat-intelligence-feeds-guide-2026 - Published: 2026-07-01 | Updated: 2026-07-01 | 16 min read - Category: Threat Intelligence - Tags: threat-intelligence-feeds, cyber-threat-intelligence, ioc, stix-taxii, misp, siem - Publisher: Global Threat Watch (https://www.globalthreatwatch.com) ## TL;DR Threat intelligence feeds are continuous streams of indicators of compromise (IOCs), TTPs, and adversary context that let defenders block or hunt known-bad activity. The best 2026 stack combines free feeds (CISA KEV, abuse.ch, AlienVault OTX, MISP communities) with one or two commercial feeds tuned to your sector, delivered over STIX/TAXII 2.1 or API, filtered aggressively by confidence and age, and enriched inside a TIP before it ever reaches your SIEM. ## Key takeaways - A threat intelligence feed is a continuously updated stream of IOCs, TTPs, and adversary context — not a one-off report. - The 2026 free-feed baseline is CISA KEV, abuse.ch (URLhaus, ThreatFox, MalwareBazaar, Feodo Tracker), AlienVault OTX, and a MISP community. - STIX 2.1 over TAXII 2.1 is the de-facto interchange standard; JSON/CSV pull APIs still dominate for smaller feeds. - Feed quality is measured by four dimensions: relevance, timeliness, accuracy (false-positive rate), and enrichment depth. - Route feeds through a Threat Intelligence Platform (TIP) — never straight into a SIEM blocklist — to deduplicate, score, and age out indicators. - Prioritize feeds mapped to MITRE ATT&CK; raw IOC lists without TTP context age out in hours. A threat intelligence feed is a continuously updated, machine-readable stream of information about adversaries and their infrastructure — IP addresses, domains, file hashes, URLs, TLS fingerprints, YARA rules, and increasingly the tactics, techniques and procedures (TTPs) behind them. Feeds are the raw fuel of a modern security operations center. Used well, they let a defender block a phishing domain minutes after it is registered, hunt a nation-state implant across an entire estate before a vendor publishes a report, and prioritize the twenty CVEs actually being exploited over the twenty thousand that are not. Used badly, they generate so many alerts that the SOC ignores them all. This guide is the version we wish existed when we first stood up the threat intelligence pipeline behind Global Threat Watch. It covers what a feed actually is in 2026, which free and commercial sources are worth ingesting, the STIX/TAXII delivery standard everyone should be using, how to measure feed quality objectively, and the pipeline architecture that keeps a SOC sane. No paywall, no vendor pitch. ## What a threat intelligence feed actually is Formally, a threat intelligence feed is a data stream describing observed or predicted malicious activity, delivered in a structured format on a defined cadence. The industry breaks the content into three tiers. Strategic intelligence describes adversary goals and geopolitical context; it is human-readable prose and rarely arrives as a feed. Operational intelligence describes campaigns, TTPs, and adversary infrastructure at the network level. Tactical intelligence is the atomic layer — indicators of compromise (IOCs) that a firewall, EDR, or SIEM can consume directly. Most feeds sold or shared as 'threat intel feeds' are tactical, with a thin layer of operational context attached. The distinction matters because tactical indicators age fast. A malicious IP address may be useful for hours, a phishing URL for days, a file hash for weeks, and a TTP mapped to MITRE ATT&CK for years. A feed that only ships atomic IOCs — with no TTP mapping, no adversary attribution, and no confidence score — is functionally a blocklist, and blocklists have well-known operational costs. ## The free threat intelligence feed baseline for 2026 Before spending a cent on commercial intelligence, every security team should be ingesting the same core set of free feeds. Between them, they cover the majority of commodity threats, most actively-exploited vulnerabilities, and a meaningful slice of nation-state activity. All are legal to consume, all are updated at least daily, and all support programmatic delivery. - CISA KEV (Known Exploited Vulnerabilities) — the U.S. Cybersecurity and Infrastructure Security Agency's running list of CVEs with confirmed in-the-wild exploitation. Updated within hours of confirmation. JSON delivery. Non-negotiable for vulnerability prioritization. - abuse.ch family — URLhaus (malicious URLs), ThreatFox (IOCs by malware family), MalwareBazaar (malware samples and hashes), Feodo Tracker (botnet C2). Free, high-quality, MISP-compatible, and among the most trusted community feeds in existence. - AlienVault OTX — a community threat exchange with tens of thousands of contributors publishing 'pulses' that bundle IOCs with context. Free with an account, STIX-exportable. - MISP communities — MISP is the open-source Threat Intelligence Platform, and joining a MISP community (CIRCL, sectoral ISAC, CERT-EU where eligible) gives access to shared feeds curated by peers in your industry. - MITRE ATT&CK — not a feed of IOCs but the canonical TTP taxonomy. Every serious feed maps to ATT&CK; without it, correlation across sources is guesswork. - Spamhaus DROP / EDROP — high-confidence hijacked netblocks. Extremely low false-positive rate, safe to consume directly in perimeter blocking. - Emerging Threats Open ruleset — Snort/Suricata signatures with a long track record. The commercial ETPro tier adds coverage, but the open ruleset alone is credible baseline network detection. Together these sources deliver, at zero cost, coverage of exploited vulnerabilities, active phishing infrastructure, commodity malware, botnet C2, and network-level detection signatures. A defender who ingests only this baseline is already ahead of a defender relying on a single expensive commercial feed with no context on their sector. ## When commercial threat intelligence feeds are worth paying for The honest answer: when your sector, your adversary set, or your regulatory obligations demand coverage the free feeds cannot provide. Financial services need feeds with tuned coverage of banking trojans, ATM malware families, and fraud infrastructure. Critical infrastructure operators need ICS/OT-focused feeds and vulnerability intelligence for equipment vendors that never appear in KEV. Multinationals facing state-nexus threats need vendor-published tracking of named adversary groups. If none of those apply, a well-run pipeline of free feeds will outperform a poorly-integrated commercial one. When commercial is warranted, the market splits into three archetypes. Vendor-native feeds from EDR and firewall vendors (CrowdStrike, Microsoft, Palo Alto, Cisco Talos, Mandiant) are strongest inside their own tooling. Pure-play threat intelligence vendors (Recorded Future, Flashpoint, Intel 471, Kela) specialize in criminal underground collection and finished intelligence. Sector-specialist feeds (Team Cymru, Silobreaker, Group-IB, Kaspersky where legally permitted) offer regional or industry depth. Evaluate on the four dimensions in the next section — not on marketing. ## How to evaluate a threat intelligence feed Four dimensions matter, in this order: - Relevance — does the feed's collection focus overlap with your threat model? A world-class ICS feed is useless to a pure-SaaS shop. Ask the vendor for sector-tagged coverage stats before signing. - Timeliness — how long between an adversary observable existing in the wild and it appearing in the feed? For phishing URLs, measure in minutes; for TTPs, days is acceptable. Insist on a defined SLA. - Accuracy — what is the observed false-positive rate when the feed is applied to your traffic? Every feed should be piloted for at least thirty days in monitor-only mode before any blocking action is taken. - Enrichment depth — does each indicator ship with a confidence score, first-seen and last-seen timestamps, MITRE ATT&CK mapping, related IOCs, and a written analytic note? Raw lists without context are worth a fraction of enriched intelligence. A useful additional test: pull thirty days of the feed's history and count how many indicators are still valid — how many URLs still resolve, how many IPs are still hosting infrastructure, how many hashes still match samples on VirusTotal. A feed where 90% of indicators are dead by day seven is a feed you should not be blocking on. ## STIX 2.1 and TAXII 2.1 — the delivery standard STIX (Structured Threat Information Expression) is the OASIS-standard JSON schema for representing cyber threat intelligence, and TAXII (Trusted Automated Exchange of Intelligence Information) is the accompanying HTTPS-based transport protocol. As of 2026, STIX 2.1 over TAXII 2.1 is the de-facto interchange standard: every serious commercial vendor and most free feeds either publish TAXII endpoints natively or offer a STIX export. STIX 2.1 represents intelligence as typed objects — Indicator, Malware, Threat Actor, Attack Pattern, Campaign, Intrusion Set, Report — connected by Relationship objects. This graph model is what makes serious correlation possible: a single Indicator is not just an IP address but a node linked to the Campaign that used it, the Threat Actor behind the campaign, and the Attack Patterns (mapped to ATT&CK) they employed. When you ingest STIX, you ingest that graph, not a flat list. TAXII 2.1 is a straightforward HTTPS API with two access modes: Collections (poll) and Channels (publish/subscribe). Most feeds use Collections. Authentication is HTTP Basic or bearer token. A minimal TAXII client is a few dozen lines of Python or Go, and every major TIP ships one out of the box. Smaller feeds still deliver via REST JSON or CSV over HTTPS — perfectly acceptable, but plan a normalization step into STIX for anything you want to correlate. ## The pipeline: TIP first, SIEM second The single most common mistake in threat intelligence operations is piping feeds directly into a SIEM or firewall. Do not do this. Feeds overlap heavily, contain false positives, and age out on different schedules; a raw firehose into a SIEM produces alert volume no team can triage. Every mature program routes feeds through a Threat Intelligence Platform (TIP) that deduplicates, scores, enriches, and ages out indicators before any downstream tool sees them. The open-source TIP is MISP, and it is genuinely production-grade — used by CERTs, ISACs, and Fortune 500 SOCs worldwide. Commercial TIPs include Anomali ThreatStream, ThreatQ, EclecticIQ, and OpenCTI (open-core, sponsored by Filigran). Whichever you pick, the pipeline follows the same pattern: - Ingest — pull feeds via TAXII, API, or MISP synchronization on their native cadence. - Normalize — convert everything to STIX 2.1 objects with consistent tagging. - Deduplicate — collapse the same indicator seen across multiple feeds, retaining source attribution. - Score — assign a confidence value based on source reliability, corroboration across feeds, and recency. - Enrich — join to internal telemetry (has this IP been seen in our logs?), WHOIS, passive DNS, VirusTotal, GreyNoise. - Age — drop or de-prioritize indicators past their useful life (typically 7-30 days for network IOCs, longer for hashes). - Distribute — push only high-confidence, in-scope indicators to the SIEM, EDR, firewall, DNS filter, or SOAR playbook that will act on them. The downstream integrations matter as much as the feeds themselves. A high-confidence IP flagged as active C2 should not just create a SIEM alert — it should trigger a SOAR playbook that queries every EDR and proxy log for the indicator, isolates any host that matched, and files a ticket. Threat intelligence is only useful when it produces action. ## Common pitfalls - Blocking on unvetted feeds — always pilot in monitor-only mode for 30+ days before any perimeter block. - Ignoring aging — an indicator list from six months ago is not intelligence, it is a liability. Enforce TTLs. - Over-collection — five well-integrated feeds beat fifty raw ones. Cut anything that has not produced a validated hit in ninety days. - No feedback loop — analysts must be able to mark false positives back into the TIP so scoring improves over time. - Treating IOCs as intelligence — atomic indicators without TTP or campaign context expire in hours. Insist on ATT&CK mapping. - Skipping legal review — some feeds carry redistribution restrictions or contain data that must be handled under TLP:AMBER or TLP:RED rules. Document this before ingestion. ## A minimum viable threat intelligence program If you are starting from zero, here is a defensible thirty-day plan. Week one: stand up MISP (Docker image, one afternoon) and connect it to CIRCL's default OSINT feeds plus the abuse.ch family. Week two: add CISA KEV, AlienVault OTX (with the twenty pulses most relevant to your sector), and Spamhaus DROP. Configure aging: 14 days for URLs and IPs, 90 days for hashes, indefinite for KEV entries. Week three: pilot pushing high-confidence indicators to your SIEM as a correlation source (never as a blocklist yet); measure hit rates and false-positive rates against your own telemetry. Week four: turn on selective blocking for the highest-confidence categories (Spamhaus, ThreatFox botnet C2, KEV-referenced infrastructure), keep everything else as detection-only, and instrument a monthly review. That program costs nothing but engineering time, and will detect more threats than most commercial feeds delivered without process. Once it is running, adding a paid feed is a scoped, measurable upgrade — you know what your baseline false-positive rate is, so you can tell whether the paid feed is actually improving it. ## Where Global Threat Watch fits The Global Threat Watch dashboard is not a threat intelligence feed — it is an OSINT situational awareness surface built on top of the same public feeds discussed here (CISA KEV, abuse.ch, GDELT, ACLED, and dozens more). It is designed for analysts, executives, and journalists who need one legible pane of glass across cyber, conflict, financial, and geospatial signals, not for direct machine-to-machine consumption. For operational blocking and hunting, ingest the feeds directly through a TIP; for context and pattern-of-life, the dashboard is the free complement. The underlying discipline is the same in both cases: no single feed tells the truth, no atomic indicator is worth acting on without corroboration, and no intelligence program survives contact with an ungoverned firehose. Feeds are raw material. The analyst — augmented by a well-run pipeline — is what turns them into intelligence. ### External Sources & Further Reading - [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) — The authoritative KEV list, updated continuously. - [abuse.ch](https://abuse.ch/) — URLhaus, ThreatFox, MalwareBazaar, Feodo Tracker — the free-feed gold standard. - [MISP Project](https://www.misp-project.org/) — Open-source Threat Intelligence Platform used by CERTs and ISACs worldwide. - [OASIS STIX 2.1 Specification](https://docs.oasis-open.org/cti/stix/v2.1/stix-v2.1.html) — The current standard for structured threat intelligence. - [OASIS TAXII 2.1 Specification](https://docs.oasis-open.org/cti/taxii/v2.1/taxii-v2.1.html) — HTTPS transport for STIX. - [MITRE ATT&CK](https://attack.mitre.org/) — The canonical TTP taxonomy — every serious feed maps to it. - [AlienVault OTX](https://otx.alienvault.com/) — Community threat exchange, free with account. - [OpenCTI](https://www.opencti.io/) — Open-source TIP alternative to MISP with a modern data model. ## FAQ ### What is a threat intelligence feed? A threat intelligence feed is a continuously updated, machine-readable stream of information about cyber threats — typically indicators of compromise (IPs, domains, URLs, file hashes), tactics, techniques and procedures mapped to MITRE ATT&CK, and adversary context. Feeds are consumed by security tools (SIEMs, firewalls, EDRs) either directly or through a Threat Intelligence Platform that deduplicates, scores, and enriches indicators before they trigger alerts or blocks. ### What are the best free threat intelligence feeds in 2026? The 2026 free baseline is CISA KEV for actively exploited vulnerabilities, the abuse.ch family (URLhaus, ThreatFox, MalwareBazaar, Feodo Tracker) for commodity malware and phishing infrastructure, AlienVault OTX for community-shared IOCs, Spamhaus DROP and EDROP for hijacked netblocks, and a MISP community feed for peer-shared intelligence. All are free, updated at least daily, and support programmatic delivery. ### What is the difference between STIX and TAXII? STIX (Structured Threat Information Expression) is the data format — a JSON schema for representing threat intelligence as connected objects (Indicators, Malware, Threat Actors, Attack Patterns). TAXII (Trusted Automated Exchange of Intelligence Information) is the transport protocol — an HTTPS API for publishing and consuming STIX data. In practice they are used together: 'STIX over TAXII' is the current interchange standard. ### Do I need a Threat Intelligence Platform (TIP)? If you consume more than two or three feeds, yes. Feeds overlap, contain false positives, and age out on different schedules. A TIP (MISP is the leading open-source option; OpenCTI, ThreatQ, Anomali, and EclecticIQ are commercial alternatives) deduplicates, scores, enriches, and ages out indicators before pushing high-confidence subsets to your SIEM, EDR, or firewall. Piping feeds directly into a SIEM produces alert volume no team can triage. ### How do I evaluate the quality of a threat intelligence feed? Measure four dimensions: relevance (does the collection focus overlap with your threat model?), timeliness (how long between real-world observation and appearance in the feed?), accuracy (what is the false-positive rate against your own traffic?), and enrichment depth (does each indicator ship with confidence scores, timestamps, ATT&CK mapping, and analytic context?). Always pilot a feed in monitor-only mode for at least thirty days before enabling automated blocking. ### How much do commercial threat intelligence feeds cost? Commercial feed pricing varies enormously — from a few thousand dollars per year for a single sector-specific feed to six or seven figures for enterprise-wide access to a major provider (Recorded Future, Mandiant, CrowdStrike, Flashpoint, Intel 471). Pricing typically scales with number of analyst seats, API call volume, and access to finished intelligence reports. Most organizations should exhaust the free-feed baseline first, then add a single well-targeted commercial feed rather than several generic ones. ### How often should threat intelligence feeds be updated? Cadence depends on the indicator type. Phishing URLs and malicious IPs need near-real-time updates (measured in minutes) because they move quickly. Malware hashes update hourly or daily. Vulnerability intelligence like CISA KEV updates as new exploits are confirmed. TTPs and adversary profiles change on the scale of weeks or months. A well-designed pipeline pulls each feed on its own cadence rather than forcing a single global refresh interval. --- Source: [Threat Intelligence Feeds: 2026 Guide (Free & Paid)](https://www.globalthreatwatch.com/blog/threat-intelligence-feeds-guide-2026) — Global Threat Watch, free real-time OSINT dashboard. --- # Best Free OSINT Tools for Threat Intelligence in 2026 > No-paywall field guide to OSINT tools analysts rely on in 2026 — conflict trackers, cyber feeds, satellite imagery, sanctions data, and workflows. - URL: https://www.globalthreatwatch.com/blog/best-free-osint-tools-2026 - Published: 2026-06-10 | Updated: 2026-06-27 | 14 min read - Category: OSINT - Tags: osint, threat-intelligence, free-tools, analyst-workflow - Publisher: Global Threat Watch (https://www.globalthreatwatch.com) ## TL;DR The best free OSINT tools in 2026 are ACLED and GDELT for conflict events, abuse.ch and CISA KEV for cyber threat intelligence, Sentinel Hub for satellite imagery, OpenSanctions and Aleph for sanctions and corporate data, and OTX with MITRE ATT&CK for attribution. All are usable without a paid plan. ## Key takeaways - ACLED and GDELT are the two free backbones of global conflict-event OSINT in 2026. - abuse.ch, AlienVault OTX, and CISA KEV cover cyber threat intelligence without any paid plan. - Sentinel-1 radar imagery (free via Copernicus) sees through cloud cover and at night — the single most useful free geospatial product. - OpenSanctions and the OCCRP Aleph platform are the OSINT gold standard for sanctions and corporate ownership. - Discipline in cross-referencing sources beats access to any single feed — never treat one uncorroborated indicator as truth. Open-source intelligence — OSINT — is the discipline of building actionable understanding from public data. In 2026, the volume of useful public signal has exploded: satellite imagery is cheap, conflict event datasets stream in near real time, sanctions lists are machine-readable, and dark-web telemetry is partially indexed by academic projects. The hard part is no longer finding data; it is filtering it, corroborating it, and presenting it honestly. This guide walks through the free OSINT tools that working analysts, journalists, and researchers actually keep in their daily rotation, and how to combine them into a reliable workflow. Everything below is free at the tier described. We have deliberately excluded tools that gate basic functionality behind a paid plan, anything that requires institutional access, and anything that has gone dormant in the last twelve months. Where a tool has a paid upgrade, we say so — but the free tier alone has to be useful, or it is not on this list. ## 1. Conflict and geopolitical event data For armed conflict, two datasets dominate the OSINT landscape. ACLED — the Armed Conflict Location & Event Data project — publishes verified incident records with location, actor, fatality, and event-type fields, updated weekly. GDELT scrapes global news at the article level and emits coded event tuples every fifteen minutes. ACLED is higher signal; GDELT is higher volume. Most analysts use ACLED for weekly trend writing and longitudinal analysis, and GDELT for fast-moving situational awareness during active events. Beyond these two, the Liveuamap family of crowdsourced conflict maps remains the fastest visual indicator of activity in Ukraine, the Middle East, and the Sahel — though it should always be cross-referenced because crowd reports carry no editorial process. The UCDP (Uppsala Conflict Data Program) covers a longer historical window and is the academic standard for fatality counts. - ACLED — verified conflict events with structured metadata, weekly updates. - GDELT 2.0 — global news event stream, fifteen-minute cadence, free BigQuery access. - Liveuamap — crowdsourced live maps, fastest-but-noisiest signal. - UCDP — academic-grade historical conflict and fatality data. - Bellingcat's open toolkit — curated list of investigation utilities, regularly maintained. ## 2. Cyber threat intelligence Cyber threat intelligence (CTI) is the densest free-data ecosystem in OSINT. Three categories matter: indicator feeds, vulnerability catalogs, and attribution reporting. For indicators of compromise, AlienVault OTX gives community-contributed pulses for free with an account; abuse.ch runs no-signup trackers for ransomware, malware, and botnet C2 infrastructure. For exploited vulnerabilities, CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative U.S. government list — if a CVE is in KEV, it is being used right now. Attribution reporting is dominated by vendor blogs: Mandiant, CrowdStrike, Microsoft Threat Intelligence, Recorded Future, and Sekoia all publish detailed write-ups of APT activity. None of them are paywalled in the parts that matter for OSINT — the deep narrative reports, IOCs, and TTP mappings are public. The trick is subscribing to the RSS feeds and triaging by source reputation. - AlienVault OTX — community IOC pulses, free with account. - abuse.ch — ransomware, malware and botnet trackers, no signup. - Shodan (free tier) — internet-exposed device search; the free tier indexes a few results per query. - Censys (community) — alternative scanner with a similar free tier. - CISA KEV — running list of actively exploited CVEs. - MITRE ATT&CK — open TTP taxonomy mapped to attributed groups. - VirusTotal (free) — sample-level corroboration of malware and IOCs. ## 3. Geospatial and satellite imagery Sentinel Hub and NASA Worldview let any analyst pull recent satellite passes for free. For conflict and infrastructure monitoring, Sentinel-1 radar imagery is the single most useful free product: it sees through cloud cover and at night, which is exactly when interesting things tend to happen. Sentinel-2 multispectral imagery handles vegetation, fires, and burn-scar analysis. Planet Labs offers a limited free education tier for higher-resolution optical imagery. Beyond raw imagery, NASA FIRMS publishes near-real-time fire and thermal anomaly detections — invaluable for tracking burns, refinery flares, or large-scale destruction. The USGS earthquake feed and EMSC are the canonical seismic sources. For maritime tracking, MarineTraffic's free tier and the open AIS exchanges cover most commercial vessels; for aircraft, ADS-B Exchange and OpenSky Network are the two unfiltered free options. ## 4. Financial, sanctions, and corporate OSINT The OFAC Specially Designated Nationals list is downloadable in machine-readable formats and updated weekly. OpenSanctions consolidates OFAC with EU, UK, UN, and dozens of national lists into a single graph database — and it is fully open. For corporate ownership and beneficial-owner data, OpenCorporates and the OCCRP Aleph platform are the OSINT gold standard. Aleph in particular ingests leaks, court filings, and corporate registries into a searchable index that working investigative journalists rely on daily. For market signal that correlates with geopolitical events, CoinGecko's free API covers crypto comprehensively, Open Exchange Rates offers a small free forex tier, and the FRED database from the St. Louis Fed is the canonical source for U.S. macro indicators. ## 5. Social media and disinformation tracking The closure of Twitter's free API in 2023 fragmented this category badly. In 2026, the practical workflow combines Bluesky's still-open firehose, Mastodon's federated streams, and Telegram channel monitoring through Snscrape forks. For TikTok, the FakeNewsRadar and Pyktok projects remain the most usable free scrapers. For verification, InVID's browser plugin is still the standard for reverse image and video provenance checks. ## 6. Dark-web and underground monitoring True dark-web monitoring is a paid market — but for OSINT purposes, three free sources cover the headline signal. Ransomwatch and Ransomware.live aggregate leak-site postings from active ransomware groups, giving a live view of victim disclosures. The CTI League's public reports cover healthcare-targeted activity. For broader underground forum monitoring, academic projects like the Cambridge CamBeR archive periodically release research datasets. ## Putting it together: a sustainable workflow No single source gives a complete picture. The professional OSINT workflow we recommend has four layers: a fast-cadence situational layer (GDELT, Liveuamap, ransomware leak sites, ADS-B), a verified-event layer (ACLED, CISA KEV, vendor CTI reports), a corroboration layer (satellite imagery, AIS, OpenSanctions, Aleph), and an output layer where findings are written up with explicit source citation and confidence levels. The Global Threat Watch dashboard aggregates many of these feeds into one situational-awareness view, but the underlying philosophy is universal: pull multiple independent OSINT sources, cross-reference them, and never treat a single uncorroborated indicator as truth. The analyst's edge in 2026 is not access to data — it is discipline in interpreting it. A final practical note: build your own bookmark hierarchy. The analysts who get the most out of OSINT in 2026 are not the ones with access to the most sources — they are the ones who can navigate their twenty curated sources in under thirty seconds. Treat your bookmark bar as analytic infrastructure. ### External Sources & Further Reading - [ACLED — Armed Conflict Location & Event Data](https://acleddata.com/) — Verified conflict events, weekly cadence. - [GDELT Project](https://www.gdeltproject.org/) — Global news event stream, 15-minute cadence. - [abuse.ch threat trackers](https://abuse.ch/) — No-signup ransomware, malware, and C2 feeds. - [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) — Authoritative list of CVEs being actively exploited. - [MITRE ATT&CK](https://attack.mitre.org/) — Open taxonomy of adversary TTPs. - [AlienVault OTX](https://otx.alienvault.com/) — Community-driven IOC pulses. - [Copernicus Sentinel Hub](https://www.sentinel-hub.com/) — Free Sentinel-1 radar and Sentinel-2 optical imagery. - [NASA FIRMS — Fire & Thermal Anomalies](https://firms.modaps.eosdis.nasa.gov/) — Near-real-time global fire detections. - [OpenSanctions](https://www.opensanctions.org/) — Consolidated sanctions and PEP graph. - [OCCRP Aleph](https://aleph.occrp.org/) — Leaks, registries, and investigative records. - [Bellingcat Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit/) — Curated OSINT utilities, maintained. > Free does not mean low quality. It means the bar to entry is gone — and the bar for rigor just got higher. ## FAQ ### What is OSINT? OSINT — open-source intelligence — is the practice of collecting and analyzing publicly available information to produce actionable intelligence. Sources include news, social media, public records, satellite imagery, and open data feeds. ### Are there really free OSINT tools that professionals use? Yes. ACLED, GDELT, abuse.ch, CISA KEV, OpenSanctions, OCCRP Aleph, Sentinel Hub, and MITRE ATT&CK are all free and are used daily by professional analysts, journalists, and government researchers. ### What is the best free OSINT tool for cyber threat intelligence? For most analysts, abuse.ch (no signup, multiple threat trackers) plus CISA's Known Exploited Vulnerabilities catalog cover the highest-value free cyber threat intelligence — actively-exploited CVEs and live IOC feeds. ### Is satellite imagery really free in 2026? Yes. The European Copernicus program (Sentinel-1 radar and Sentinel-2 optical) and NASA Worldview both provide free, recent, global satellite imagery at moderate resolution. Higher resolution commercial imagery still requires a paid plan. ### How do I avoid being misled by OSINT data? Always cross-reference at least two independent sources before drawing a conclusion. Treat any single uncorroborated indicator as a question, not an answer. Note the source, timestamp, and confidence level in every finding. --- Source: [Best Free OSINT Tools for Threat Intelligence in 2026](https://www.globalthreatwatch.com/blog/best-free-osint-tools-2026) — Global Threat Watch, free real-time OSINT dashboard. --- # How to Build an OSINT Dashboard: A Practical Engineering Guide > Architecture, data-source strategy, CORS handling, rate-limit design, and hard-won lessons from shipping a real-time open-source intelligence dashboard that aggregates dozens of public feeds. - URL: https://www.globalthreatwatch.com/blog/how-to-build-osint-dashboard - Published: 2026-05-22 | Updated: 2026-06-27 | 16 min read - Category: Engineering - Tags: osint, engineering, dashboards, react, edge-functions - Publisher: Global Threat Watch (https://www.globalthreatwatch.com) ## TL;DR A production-grade OSINT dashboard needs a stateless edge-function proxy for CORS-blocked feeds, jittered polling to avoid rate limits, per-panel graceful degradation, aggressive edge caching, and explicit labeling of any simulated or composite indicators. Skip keyed APIs in favor of keyless ones whenever possible. ## Key takeaways - Browsers block most public OSINT feeds via CORS — solve with a stateless edge-function proxy, not client-side workarounds. - Prefer keyless APIs (USGS, NOAA, CoinGecko, GDELT, FIRMS) — they remove a class of secret-management failures. - Every panel must degrade independently: live → cached → simulated-and-labelled → tasteful error microcopy. - Jitter polling intervals so requests never cluster, and cache aggressively at the edge. - Be explicit about composite vs. raw data — credibility is the single largest design constraint. Building an OSINT dashboard sounds simple: poll some feeds, render some panels. In practice, the hard problems are CORS, rate limits, source reliability, graceful degradation, and presenting probabilistic information honestly. This is the architecture we landed on after iterating on Global Threat Watch — a public, free, real-time OSINT aggregator pulling from forty-plus sources. Everything below is implementation-grade and assumes you are shipping to real users, not just a portfolio piece. ## 1. Treat every public feed as hostile to your browser Most public RSS feeds and JSON APIs do not send permissive CORS headers, which means browsers will refuse to load them directly. You have two options: a thin server-side proxy, or pre-fetched static snapshots. We strongly recommend the proxy approach for anything that updates more than once a day. The clean implementation is a stateless edge function — Supabase Edge Functions, Cloudflare Workers, or Vercel Edge — that fetches the upstream feed and re-serves it with permissive CORS headers. Keep these proxies stateless. Cache aggressively at the edge (thirty to one hundred and twenty seconds is usually fine). Never proxy sources that require a per-user API key. Add a short timeout (five to eight seconds) so a slow upstream never wedges the dashboard. ## 2. Build the source list around reliability, not novelty It is tempting to wire in every interesting feed you find. Resist. Each additional source is an additional failure mode, and a dashboard with twenty reliable panels is more useful than one with fifty flaky ones. Score each candidate source on four axes: uptime, schema stability, update cadence, and license. If a source has changed its schema twice in the last year, expect it to change again. ## 3. Pick keyless APIs first Anything that requires an API key creates a secret-management problem and a billing risk. For a public dashboard, prefer keyless or anonymous-tier APIs: USGS earthquakes, NOAA space weather, CoinGecko, public RSS, GDELT's BigQuery public dataset, NASA FIRMS, Open Exchange Rates' free tier. You can always upgrade individual panels later when you know which ones justify the operational overhead. ## 4. Design for graceful degradation Feeds go down. Rate limits get hit. Schemas change without warning. The dashboard must never show a blank panel. Every component on Global Threat Watch has a fallback hierarchy: live data, last-known-good cached values, illustrative simulated data clearly labelled as such, or a tasteful error microcopy. A dashboard that occasionally lies is worse than one that occasionally admits it does not know. Concretely: wrap every fetch in a try/catch, persist the last successful response to localStorage with a timestamp, and render the cached value with a visible 'CACHED' indicator when fresh data is unavailable. After a configurable staleness threshold, switch to the simulated-illustrative fallback and label it clearly. Users tolerate honesty; they do not tolerate silent staleness. ## 5. Rate limits and request scheduling If your dashboard polls forty sources every thirty seconds, you will get rate-limited. The fix is jittered scheduling: stagger each panel's poll interval by a random offset, so requests do not cluster. For high-cardinality endpoints, batch on the server and serve the aggregated result to all clients from edge cache. For low-cardinality endpoints, let clients fetch directly through the proxy. ## 6. Be honest about what is real OSINT aggregation has a hard ceiling: you cannot verify what you do not source. Every dashboard should carry a visible disclaimer that the data is open-source, that some indicators are illustrative composites, and that nothing on the screen is a substitute for primary-source verification. Trust is built by being unambiguous about this. We learned this the hard way after early users mistook a clearly-labelled composite index for a real government feed. ## 7. UI patterns that work - Color-code by severity, never by source — users internalize the color, not the publisher. - Use motion to signal liveness, not decoration. A pulsing dot on a fresh fetch is fine; a fully animated background is noise. - Show the source name and timestamp on every panel. 'CoinGecko • 12s ago' beats a polished number with no provenance. - Treat the empty state as a first-class design — it is what users see most often during outages. - Provide a 'why this number' tooltip on every composite indicator. Composites without methodology are theater. ## 8. Performance budget A slow dashboard is an unused dashboard. Target a one-second time-to-first-meaningful-paint on mid-tier mobile hardware. That means: server-rendered shell where possible, lazy-load anything below the fold, defer heavy charting libraries, and ship one bundle per route. Mobile is now roughly half of OSINT traffic. Plan layouts for narrow viewports first, then enrich for desktop. ## 9. Observability You cannot run a dashboard you cannot see. At minimum: log every proxy request with source, status, and latency to a queryable store; emit a synthetic check that hits each panel's endpoint every five minutes; alert on consecutive failures, not single ones. Your users will notice the outage before you do if you do not. ## Lessons from production We shipped, broke things, fixed them, and iterated. The top five lessons, ranked by how much pain they would have saved us: - Latency budgets matter more than feature count — every additional panel costs perceived speed. - Cache aggressively at the edge; clients should almost never hit upstream directly. - Label simulated and composite data explicitly — the credibility cost of getting caught is enormous. - Make every panel independently fail — never let one bad source block the rest of the page. - Write the methodology page before you write the dashboard. If you cannot explain a number, do not display it. One more practical note on infrastructure: budget for both the proxy compute and the egress bandwidth. Most edge-function providers price aggressively on the request count but charge real money for sustained outbound transfer to slow upstreams. Measure before you scale; the unit economics of a public OSINT dashboard live or die on cache hit rate. ### Engineering References & Tooling - [Supabase Edge Functions](https://supabase.com/docs/guides/functions) — Deno-based serverless proxies; our default for CORS shims. - [Cloudflare Workers](https://developers.cloudflare.com/workers/) — Alternative edge runtime with generous free tier. - [MDN — Cross-Origin Resource Sharing (CORS)](https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS) — Canonical reference on the headers you'll be rewriting. - [USGS Earthquake GeoJSON Feeds](https://earthquake.usgs.gov/earthquakes/feed/v1.0/geojson.php) — Keyless, well-documented, ideal first feed. - [NOAA Space Weather Prediction Center API](https://services.swpc.noaa.gov/) — Free JSON endpoints for geomagnetic and solar data. - [CoinGecko Public API](https://www.coingecko.com/en/api) — Keyless free tier for crypto market data. - [GDELT 2.0 Documentation](https://www.gdeltproject.org/data.html#documentation) — Schema and BigQuery access details. - [web.dev — Core Web Vitals](https://web.dev/articles/vitals) — Performance budget targets that matter for dashboards. > A dashboard is a contract with the viewer: every pixel says something is true. Build it accordingly. ## FAQ ### Why can't I fetch OSINT feeds directly from the browser? Most public RSS and JSON APIs do not return permissive CORS headers. Browsers block the response. The fix is a stateless server-side proxy (edge function) that fetches upstream and re-serves with CORS headers. ### What stack do you recommend for an OSINT dashboard? React or any modern framework on the frontend, plus stateless edge functions (Supabase Edge Functions, Cloudflare Workers, or Vercel Edge) as feed proxies. Cache responses at the edge for 30–120 seconds. ### How often should the dashboard poll each feed? Match the upstream cadence and add jitter. USGS earthquakes update every few minutes; CoinGecko every 30 seconds is fine; GDELT every 15 minutes. Never poll faster than the source updates. ### What if a feed goes down? Fail gracefully per panel: serve the last cached value with a 'cached' indicator, then fall back to a clearly-labelled illustrative value after a staleness threshold. Never let one failed source blank a panel or block the rest of the page. ### How do I label composite or simulated data honestly? Add a visible badge ('illustrative', 'composite', 'simulated') on the panel itself, plus a methodology tooltip explaining how the value is built. Include a sitewide disclaimer that the data is open-source and not a substitute for primary-source verification. --- Source: [How to Build an OSINT Dashboard: A Practical Engineering Guide](https://www.globalthreatwatch.com/blog/how-to-build-osint-dashboard) — Global Threat Watch, free real-time OSINT dashboard. --- # Understanding Global Threat Indicators: A Beginner's Guide > What threat indices, DEFCON levels, conflict counts, and risk gauges actually mean — how they're constructed, how to read them, and how to avoid the most common interpretation mistakes. - URL: https://www.globalthreatwatch.com/blog/understanding-global-threat-indicators - Published: 2026-04-30 | Updated: 2026-06-27 | 12 min read - Category: Primer - Tags: threat-intelligence, primer, risk, methodology - Publisher: Global Threat Watch (https://www.globalthreatwatch.com) ## TL;DR Threat indicators — global threat indices, DEFCON levels, conflict counts, and risk gauges — are composite scores built from underlying open-source signals. They are useful as directional indicators of change over time, but the absolute number depends entirely on methodology. Read the methodology page, watch the trend, and cross-reference at least two independent indicators before acting on any single reading. ## Key takeaways - Composite threat indices are weighted averages — the weighting is a judgement call, so absolute levels are not comparable across providers. - Real DEFCON levels are classified; public DEFCON trackers are stylized estimates, not operational truth. - Trend and rate of change matter more than absolute level. - Indicators systematically miss covert activity and lag confirmed events — humility is required. - Always read the methodology page before quoting a number, and cross-reference at least two independent indicators. Open any geopolitical risk dashboard and you will see numbers: a global threat index of 67, a cyberwar risk of HIGH, twelve active conflict zones, DEFCON 3, financial risk at 84/100. These figures look authoritative. Most of them are composite scores built from underlying observations, and reading them well requires understanding what is being summarized — and what is being hidden by the summary. This guide walks through the main families of threat indicators you will encounter, how they are constructed, where they break, and how to read them without overreacting. It is written for analysts, journalists, and curious readers who want to use these tools without being misled by them. ## Composite threat indices A composite threat index is a weighted average of several normalized inputs — conflict event counts, sanctions activity, market volatility, cyber incident rates, diplomatic tensions. Each input is rescaled to a common range (usually 0–100), multiplied by a weight, and summed. The exact weighting is a judgement call. Two analysts with identical inputs will produce different indices. This is not a flaw — it is the nature of composites. The right way to use a threat index is to watch the trend and the rate of change, not the absolute level. A threat index moving from 45 to 67 over a week is meaningful; whether 67 is 'high' depends entirely on the methodology. Always click through to the methodology page before quoting a number. ## DEFCON levels and readiness scales DEFCON is a U.S. military readiness scale ranging from 5 (peacetime) to 1 (imminent nuclear war). The real level is classified — it is not publicly announced. Every consumer-facing 'DEFCON tracker' is therefore a stylized estimate built from open-source signals: nuclear posture statements, exercise activity, sanctions, public readiness changes, and major incident reporting. Treat any public DEFCON indicator as an illustrative summary, not as operational truth. The same caution applies to the Doomsday Clock from the Bulletin of the Atomic Scientists — useful as a symbolic synthesis of expert opinion, useless as a real-time signal. ## Conflict counts and event rates 'Twelve active conflicts' sounds precise. It is not. A conflict count depends entirely on the definition: does insurgency count? Do drug-cartel wars count? What is the fatality threshold? UCDP, ACLED, and the Council on Foreign Relations all publish different counts because they use different definitions. None is wrong; they answer different questions. Event rates — incidents per week, fatalities per month — are more useful than counts because they show direction. A region with twenty events per week trending up is more interesting than one with one hundred events per week trending flat. Always ask: 'compared to what baseline?' ## Risk gauges (financial, war, cyberwar) Risk gauges combine domain-specific signals into a single 0–100 score. Each is a model — useful as a directional signal, dangerous as a precise number. - Financial risk typically blends volatility indices (VIX), currency stress, credit spreads, and yield-curve metrics. - War risk blends conflict event rates, troop-movement OSINT, sanctions activity, and diplomatic indicators. - Cyberwar risk blends CVE exploitation rates, ransomware leak-site activity, state-attributed incident counts, and critical-infrastructure targeting. - Strategic risk is the most subjective — it is essentially an analyst's gestalt summarized as a number. ## How indicators fail Indicators fail in three predictable ways. First, lagging: any indicator built on confirmed events is by definition backward-looking, often by days or weeks. Second, missing: indicators only measure what is measurable, so they systematically underweight covert activity. Third, gaming: when an indicator becomes influential, the actors it measures begin shaping their visible behavior to manage it. None of these failures invalidate indicators; they just require humility in interpretation. ## How to read them sensibly - Look at direction and rate of change before absolute level. - Cross-reference at least two independent indicators before drawing a conclusion. - Treat any single high reading as a question, not an answer — investigate the underlying events. - Read the methodology page. If there is no methodology page, distrust the number. - Ignore breathless framing. Real escalations show up across multiple, uncorrelated indicators. - Remember that 'no signal' is not the same as 'no threat' — adversaries optimize for invisibility. Finally, treat indicator dashboards as starting points, not destinations. A well-built composite tells you that something in its input mix changed; it does not tell you what or why. The analytic work — opening the underlying ACLED records, reading the CISA advisory, comparing satellite passes — happens after the gauge moves, not before. Use the number as a tasking aid, not a conclusion. ### Methodology & Index References - [Bulletin of the Atomic Scientists — Doomsday Clock](https://thebulletin.org/doomsday-clock/) — Symbolic synthesis of expert opinion on existential risk. - [Global Peace Index — IEP](https://www.economicsandpeace.org/global-peace-index/) — Methodology page is worth reading before quoting the score. - [Fragile States Index — Fund for Peace](https://fragilestatesindex.org/) — Country-level fragility composite; published methodology. - [CFR Global Conflict Tracker](https://www.cfr.org/global-conflict-tracker) — Editorial conflict list with explicit selection criteria. - [UCDP — Uppsala Conflict Data Program](https://ucdp.uu.se/) — Academic-grade fatality and conflict data. - [CBOE VIX Index](https://www.cboe.com/tradable_products/vix/) — Canonical equity-volatility input to financial-risk composites. - [World Bank Worldwide Governance Indicators](https://www.worldbank.org/en/publication/worldwide-governance-indicators) — Stable cross-country governance benchmarks. > A good indicator tells you where to look, not what to think. ## FAQ ### What is a composite threat index? A composite threat index is a single number summarizing several normalized inputs — conflict events, sanctions, market volatility, cyber incidents — each weighted by the index author. It is best read as a directional indicator, not an absolute measurement. ### Is the public DEFCON level real? No. The real DEFCON level is classified by the U.S. military and never publicly announced. Public DEFCON trackers are estimates built from open-source signals — useful as a symbolic summary, not as operational truth. ### Why do different sites show different numbers of active conflicts? Each source uses a different definition. UCDP requires 25+ battle-related deaths per year; ACLED counts a broader set of political-violence events; CFR uses a curated editorial list. Different methodologies, different counts. ### Should I worry when a threat gauge jumps? Treat a jump as a question, not an answer. Check what underlying events moved it, cross-reference with at least one independent indicator, and read the methodology to understand which inputs are weighted heaviest. ### Can these indicators predict war? No indicator reliably predicts conflict initiation. They are lagging by construction and miss covert preparation. They are better used to monitor escalation pressure on an already-tense situation than to forecast new ones. --- Source: [Understanding Global Threat Indicators: A Beginner's Guide](https://www.globalthreatwatch.com/blog/understanding-global-threat-indicators) — Global Threat Watch, free real-time OSINT dashboard. --- # Cyberwar in 2026: A Field Guide to State-Sponsored Threat Actors > OSINT-grounded field guide to state-sponsored APT groups driving cyberwar in 2026 — Russia, China, Iran, North Korea tactics and tracking. - URL: https://www.globalthreatwatch.com/blog/cyberwar-2026-threat-actors - Published: 2026-03-18 | Updated: 2026-06-27 | 15 min read - Category: Cyber - Tags: cyberwar, apt, threat-actors, attribution, ttps - Publisher: Global Threat Watch (https://www.globalthreatwatch.com) ## TL;DR In 2026, the dominant state-sponsored cyber threat actors are Russia's APT28, APT29, and Sandworm; China's Volt Typhoon and Salt Typhoon; Iran's APT35 and MuddyWater; and North Korea's Lazarus Group. Activity has shifted toward critical-infrastructure prepositioning, telecom targeting, and AI-assisted social engineering. All groups are trackable through CISA advisories, MITRE ATT&CK, and major vendor threat-intelligence blogs. ## Key takeaways - Russia, China, Iran, and North Korea account for the overwhelming majority of state-attributed cyber activity in 2026. - Volt Typhoon and Salt Typhoon represent a strategic Chinese shift toward critical-infrastructure prepositioning and telecom compromise. - Lazarus Group's crypto theft remains a meaningful source of North Korean state revenue. - Edge-device exploitation and living-off-the-land techniques have replaced traditional malware as primary intrusion vectors. - CISA advisories, MITRE ATT&CK, and major vendor threat-intel blogs are the canonical OSINT tracking sources. State-sponsored cyber activity has matured into a permanent dimension of geopolitical competition. The actors profiled below are publicly attributed by multiple Western intelligence services and corroborated by private vendor reporting. None of this is classified; all of it is OSINT-tractable. This guide is intended as a working reference for analysts, defenders, and journalists — not as exhaustive group taxonomy. A note on naming. The same group is tracked under different names by different vendors: APT28 is also Fancy Bear (CrowdStrike), Strontium (Microsoft's old taxonomy), Forest Blizzard (Microsoft current), and Pawn Storm (Trend Micro). MITRE ATT&CK provides cross-references. We use the most widely recognized names in each section. ## Russia-aligned groups Russian cyber activity is split across three main intelligence services. APT28 (Fancy Bear) is associated with GRU military intelligence and focuses on disruptive operations, influence campaigns, and political targeting — most famously the 2016 DNC operation, but the pattern has continued through 2026 with ongoing campaigns against European political parties and journalists. APT29 (Cozy Bear) is associated with the SVR foreign intelligence service and is the more disciplined operator — long-dwell espionage against diplomatic, defense, and technology targets. The SolarWinds supply-chain compromise is its signature operation, and follow-on activity against cloud identity systems has continued. Sandworm — also GRU-linked, Unit 74455 — is responsible for the most destructive ICS attacks on record: the 2015 and 2016 Ukrainian power-grid attacks, NotPetya, and ongoing OT-targeted activity in Ukraine through 2024–2026. If a state actor is going to cause kinetic damage via cyber means, Sandworm is the prototype. ## China-aligned groups Chinese cyber activity has shifted strategically in the past three years. Where the 2010s were defined by APT1 / Comment Crew and bulk IP theft, the 2024–2026 period is defined by prepositioning in critical infrastructure. Volt Typhoon is the headline group: CISA and allied agencies have publicly described its activity as 'living off the land' inside U.S. communications, energy, water, and transportation networks — establishing access for potential coercive use, not for espionage. Salt Typhoon has driven the 2024–2025 reporting cycle through deep compromises of U.S. telecommunications providers, including access to lawful-intercept systems. The strategic implication is significant: a single group with access to telecom backbones has effective passive collection capability against a large fraction of routine American communications. APT41 remains the unusual hybrid — state-aligned espionage by day, financially motivated crime by night. APT40 focuses on maritime and naval-adjacent industries. Mustang Panda continues to target Southeast Asian governments and NGOs. ## Iran-aligned groups Iranian groups operate with less technical sophistication than Russian or Chinese services but compensate with operational tempo and willingness to take risks. APT35 (Charming Kitten) focuses on diaspora surveillance, journalists, and academics. APT42 specializes in spearphishing of policy and political targets. MuddyWater conducts broader regional espionage. Several Iranian-linked clusters also dabble in opportunistic ransomware and hack-and-leak operations, blurring the line between state and criminal activity. ## North Korea-aligned groups North Korean groups remain the most financially motivated state actor on Earth — cryptocurrency theft funds a meaningful share of state revenue. The Lazarus Group umbrella covers most attributed activity, including the 2014 Sony attack, the Bangladesh Bank heist, the WannaCry outbreak, and an ongoing string of crypto-exchange and DeFi compromises that have netted multiple billions of dollars cumulatively. APT37 and APT38 are sub-clusters with espionage and financial mandates respectively. ## Tactics worth tracking - Edge-device exploitation — VPN appliances, firewalls, and email gateways are now the primary initial-access vector across all four actor groups. - Living-off-the-land — using built-in administration tooling instead of malware to evade detection; the defining Volt Typhoon trait. - Supply-chain compromise — APT29's signature, now imitated broadly. - AI-assisted social engineering — voice cloning, fluent multilingual phishing, and deepfake-augmented pretexting are now routine across all four ecosystems. - Telecom and identity provider targeting — Salt Typhoon's model is being copied. ## Tracking with OSINT - CISA advisories — joint statements with allied agencies, technically detailed, free, and unusually fast to publish. - Mandiant, CrowdStrike, Microsoft Threat Intelligence, Recorded Future, Sekoia — vendor reporting, IOCs and TTP mappings, all free for the reports themselves. - MITRE ATT&CK — open taxonomy of TTPs mapped to attributed groups, the lingua franca of attribution. - VirusTotal and abuse.ch — sample-level corroboration of new tooling, free. - Google Mandiant's GTIG blog and Microsoft's Threat Intelligence blog — fastest-moving public attribution sources. - Academic projects — Citizen Lab on commercial spyware, Stanford Internet Observatory on influence operations. ## What 2026 looks like The trend lines are clear: more prepositioning in critical infrastructure, more telecom and identity-provider targeting, more AI-assisted social engineering, and more deliberate blurring of state and criminal infrastructure. The defenders' edge in 2026 is speed of public attribution and the political willingness of governments to name groups quickly — both have improved markedly since 2022, and both remain the single highest-leverage defensive intervention available. For defenders, the practical implication is that the OSINT cycle has compressed. Joint advisories, vendor reporting, and ATT&CK updates now ship within days of major intrusions — sometimes hours. Building a personal pipeline that ingests CISA RSS, the top five vendor blogs, and ATT&CK changes is the single highest-leverage habit a defensive analyst can adopt. ### Threat Intelligence & Attribution Sources - [CISA Cybersecurity Advisories](https://www.cisa.gov/news-events/cybersecurity-advisories) — Joint advisories with allied agencies; fastest authoritative attribution. - [MITRE ATT&CK Groups](https://attack.mitre.org/groups/) — Cross-referenced APT taxonomy with TTP mappings. - [Google Threat Intelligence Group (Mandiant)](https://cloud.google.com/blog/topics/threat-intelligence) — Deep technical write-ups, IOCs included. - [Microsoft Threat Intelligence Blog](https://www.microsoft.com/en-us/security/blog/topic/threat-intelligence/) — Source of Typhoon / Blizzard naming taxonomy. - [CrowdStrike Adversary Universe](https://www.crowdstrike.com/adversaries/) — Bear / Panda / Kitten / Chollima profiles. - [Recorded Future — Insikt Group Research](https://www.recordedfuture.com/research) — Strategic and tactical CTI reporting, free. - [Citizen Lab](https://citizenlab.ca/) — Academic-grade investigation of commercial spyware and state surveillance. - [Volt Typhoon — CISA AA24-038A](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a) — Canonical public advisory on PRC critical-infrastructure prepositioning. > Attribution does not stop attacks. But it raises the cost of conducting them — and in cyberspace, cost is everything. ## FAQ ### Who are the most active state-sponsored cyber threat actors in 2026? Russia's APT28, APT29, and Sandworm; China's Volt Typhoon, Salt Typhoon, APT41, and APT40; Iran's APT35 and MuddyWater; and North Korea's Lazarus Group umbrella. Together they account for the overwhelming majority of state-attributed activity. ### What is Volt Typhoon? Volt Typhoon is a China-attributed threat group focused on prepositioning in U.S. critical infrastructure — communications, energy, water, transportation — using living-off-the-land techniques rather than custom malware. CISA and allied agencies have warned that its objective appears to be coercive disruption rather than espionage. ### What is the difference between APT28 and APT29? Both are Russian state actors but linked to different services. APT28 (Fancy Bear) is GRU military intelligence, focused on disruptive and influence operations. APT29 (Cozy Bear) is SVR foreign intelligence, focused on long-dwell espionage. The SolarWinds compromise is attributed to APT29. ### Why are APT groups named so many different things? Each vendor maintains its own attribution taxonomy. CrowdStrike uses Bear / Panda / Kitten / Chollima; Microsoft uses weather-themed names like Typhoon and Blizzard; Mandiant uses APTxx. MITRE ATT&CK cross-references them. ### How can I track APT activity using only free sources? Subscribe to CISA advisories, the major vendor threat-intel blogs (Mandiant GTIG, Microsoft, CrowdStrike, Recorded Future, Sekoia), MITRE ATT&CK updates, and abuse.ch / VirusTotal. Together they provide near-complete coverage of publicly-attributed activity. --- Source: [Cyberwar in 2026: A Field Guide to State-Sponsored Threat Actors](https://www.globalthreatwatch.com/blog/cyberwar-2026-threat-actors) — Global Threat Watch, free real-time OSINT dashboard. --- # AI for OSINT in 2026: How Analysts Use LLMs Safely > Practical guide to using LLMs in open-source intelligence — what they do well, where they hallucinate, and workflows that hold up under scrutiny. - URL: https://www.globalthreatwatch.com/blog/ai-for-osint-2026 - Published: 2026-02-14 | Updated: 2026-06-27 | 13 min read - Category: AI - Tags: ai, llm, osint, workflow, hallucination - Publisher: Global Threat Watch (https://www.globalthreatwatch.com) ## TL;DR Large language models are powerful OSINT accelerators for summarization, translation, structured extraction, and code generation — but they routinely fabricate citations and over-confidently misattribute events. The reliable 2026 workflow uses LLMs as a drafting and clustering tool while keeping a human analyst as the final source-verification step. Never publish an LLM citation you have not independently confirmed. ## Key takeaways - LLMs are excellent for summarization, translation, entity extraction, and clustering — and unreliable for citation and attribution. - Never publish a citation an LLM produced without independently verifying the source exists and says what the model claims. - Retrieval-augmented generation (RAG) over a curated source corpus dramatically reduces hallucination — but does not eliminate it. - Use LLMs to triage and draft, not to conclude — keep a human analyst on the final verification step. - Adversarial actors are using the same models for influence operations; verification discipline is the only durable defense. Large language models have become genuinely useful in open-source intelligence work over the past two years. They translate fluently across most languages, summarize long documents accurately, extract structured data from messy prose, and accelerate boilerplate code. They have also developed a well-earned reputation for confident fabrication — inventing citations, misattributing events, and producing analytically-shaped output that does not survive ten minutes of scrutiny. This guide is a practical breakdown of what LLMs do well in OSINT, where they break, and the workflows that hold up under real analytical pressure. Everything below assumes the analyst — not the model — is responsible for the final product. ## What LLMs are genuinely good at Four use cases consistently work. First, summarization of long source material into structured bullet points — a model will reliably condense a forty-page vendor threat report into ten high-signal lines. Second, translation across major languages, with quality now comparable to professional human translators for non-literary text. Third, structured extraction — pulling entities, dates, locations, and indicators of compromise from unstructured prose into a clean JSON record. Fourth, code generation for transient OSINT tooling: parsers, scrapers, format converters, ad-hoc visualizations. These tasks share a common property: the model is being used as a transform over input data it has been given, not as a knowledge source. When you feed the document in and ask the model to restructure or translate it, the output is generally trustworthy. When you ask the model to remember facts, the output is generally not. ## Where LLMs break badly Three failure modes dominate. The first and most dangerous is citation fabrication: LLMs routinely invent URLs, author names, paper titles, and publication dates that sound plausible but do not exist. The fabricated citations look indistinguishable from real ones — until you click the link and discover a 404. Never publish a citation a model produced without independently confirming the source exists and says what the model claims. The second is misattribution. When asked who carried out an attack, what group a sample belongs to, or which government issued a statement, LLMs will produce a confident, fluent answer — frequently a wrong one. The model has no notion of evidence quality; it produces the most statistically plausible attribution from its training data, which is not the same as the correct one. The third is currency. Even with web-search-augmented models, information freshness is uneven. A model may confidently describe an event from 2022 as current, or miss a major development from last week because no search query happened to surface it. Always confirm timestamps against a primary source. ## Retrieval-augmented generation (RAG) for OSINT RAG dramatically reduces hallucination. The pattern is: maintain a curated corpus of trusted OSINT sources (CISA advisories, vendor threat reports, ACLED records, your own past analysis); embed and index them; on every query, retrieve the top-N most-relevant chunks and pass them to the model as grounding context; instruct the model to answer only from those chunks and cite them by chunk ID. This approach changes the failure mode from 'invents a plausible answer' to 'admits it does not know' — a vastly more useful default. It does not eliminate hallucination entirely; models will still occasionally synthesize from retrieved chunks in ways the source material does not support. The mitigation is the same as in non-AI OSINT: cross-reference, source-trace, and require explicit chunk citations in the output. ## The reliable workflow The workflow that has held up across hundreds of OSINT engagements is straightforward. First, the analyst defines the question and gathers the source set. Second, the LLM is used as a drafting tool — summarizing sources, extracting structured data, suggesting clusters and entities of interest. Third, the analyst verifies every factual claim against a primary source before incorporating it into the output. Fourth, the LLM is optionally used again to polish the final write-up, but never to add new facts at this stage. The discipline that makes this work is treating the LLM as a senior analyst's intern, not a senior analyst. The intern is fast, fluent, and helpful; the intern also makes things up. You read the intern's work carefully before signing your name to it. ## Adversarial AI in OSINT The same models are being used against you. Influence operations now use LLMs to generate fluent multilingual content at scale; phishing campaigns use voice cloning and deepfake-augmented pretexting; state-attributed groups have demonstrated AI-assisted reconnaissance and social engineering. The defensive posture is the same as in pre-AI OSINT — provenance discipline, cross-source corroboration, and skepticism toward fluent-but-unsourced content — but the volume of such content has increased by orders of magnitude. Practical implication: a fluent, plausible-looking source is no longer evidence of legitimacy. The bar for trusting a source moved from 'sounds professional' to 'has a verifiable identity, history, and corroborating record'. This is a return to traditional verification, not a new discipline. ## Rules of engagement - Use LLMs to transform input you supply, not as a knowledge source. - Never publish a citation you have not opened and confirmed yourself. - Prefer RAG over open-domain prompting for any factual question. - Log model name, version, and prompt with every AI-assisted output for auditability. - Disclose AI assistance when it materially shaped an analytical product. - Treat AI-generated content from external sources with the same skepticism as anonymous tips — fluency is not credibility. On evaluation: build a small private benchmark of OSINT questions with known answers — past attribution calls, geolocations you have already verified, summaries you have already written. Re-run that benchmark against any new model before adopting it for production work. Vendor benchmarks measure general capability; your benchmark measures whether the model is useful for your specific workflow. ### AI & RAG Tooling References - [OpenAI API Documentation](https://platform.openai.com/docs) — Reference for GPT-class models and structured outputs. - [Anthropic Claude Documentation](https://docs.anthropic.com/) — Long-context model frequently used for OSINT summarization. - [Lovable AI Gateway](https://docs.lovable.dev/features/ai) — Unified gateway covering chat, embeddings, and image models. - [LangChain](https://python.langchain.com/) — Retrieval-augmented generation toolkit. - [LlamaIndex](https://docs.llamaindex.ai/) — RAG-focused indexing and retrieval framework. - [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) — Reference standard for trustworthy AI deployment. - [Stanford Internet Observatory](https://cyber.fsi.stanford.edu/io) — Research on AI-enabled influence operations. - [Bellingcat — AI Investigations](https://www.bellingcat.com/category/resources/) — Field write-ups of AI-assisted OSINT workflows. > An LLM is the fastest intern you will ever hire. Read its work like an intern's, not like a peer's. ## FAQ ### Can I use ChatGPT for OSINT analysis? Yes, for summarization, translation, structured extraction, and clustering of sources you provide. Do not use it as a knowledge source for facts, citations, or attribution — those are the failure modes where LLMs hallucinate most often. ### What is RAG and why does it matter for OSINT? Retrieval-augmented generation grounds the model in a curated source corpus by retrieving relevant chunks at query time and instructing the model to answer only from them. It dramatically reduces hallucination compared to open-domain prompting and is the recommended pattern for OSINT applications. ### Why do LLMs invent fake citations? LLMs generate the most statistically plausible next tokens, not factually correct ones. A citation that follows the format and tone of real citations from the training data is highly plausible — even when the specific paper, URL, or author does not exist. ### Are AI-generated influence operations a real threat in 2026? Yes. LLM-generated content has reduced the cost of fluent multilingual disinformation by orders of magnitude. The defensive response is provenance discipline and cross-source corroboration — the same OSINT verification practices, applied with more rigor. ### Should I disclose when I used AI in an OSINT product? When AI assistance materially shaped the output — drafting, summarization, clustering, translation — disclosing it is best practice. Auditability and reproducibility matter more in analytical work than in most domains. --- Source: [AI for OSINT in 2026: How Analysts Use LLMs Safely](https://www.globalthreatwatch.com/blog/ai-for-osint-2026) — Global Threat Watch, free real-time OSINT dashboard. --- # How to Verify Breaking News with OSINT: A 2026 Playbook > Step-by-step playbook for verifying breaking news with OSINT — geolocation, chronolocation, reverse image search, and source provenance checks. - URL: https://www.globalthreatwatch.com/blog/verify-breaking-news-osint - Published: 2026-01-22 | Updated: 2026-06-27 | 12 min read - Category: Verification - Tags: osint, verification, geolocation, fact-checking - Publisher: Global Threat Watch (https://www.globalthreatwatch.com) ## TL;DR To verify breaking news with OSINT, run five checks: source provenance (who first published, when, and where), reverse image search (InVID, Google Lens, Yandex), geolocation against satellite and street-level imagery, chronolocation against weather, shadows, and time-stamped events, and corroboration against at least two independent primary sources. Skip any of these and you are guessing. ## Key takeaways - Run five checks on every breaking-news claim: provenance, reverse image search, geolocation, chronolocation, corroboration. - InVID, Google Lens, and Yandex Images cover most reverse-image-search needs — Yandex remains strongest for non-Western imagery. - Sentinel-2 and Google Earth's historical layer are the workhorses for confirming location and time. - Provenance — who first posted, where, and when — is the single most-skipped step. - If five minutes of verification cannot confirm a claim, the responsible default is to not amplify it. Breaking news has always been hard to verify. In 2026 it is harder: AI-generated imagery, deepfake video, and coordinated inauthentic posting have made fluent fakery cheap. The defensive response is not new technology — it is disciplined OSINT verification, applied quickly and consistently. This playbook covers the five-step verification process working journalists, OSINT researchers, and fact-checkers use on every claim before amplifying it. The goal is not certainty. Verification can rarely deliver certainty under time pressure. The goal is to distinguish 'multiple independent corroborating signals point the same way' from 'one anonymous post and a screenshot'. The first is publishable with appropriate hedging; the second is not. ## Step 1 — Source provenance Before looking at the claim itself, look at where it came from. Who posted it first? When? On what platform? Is the account a known entity with verifiable history, or a recently-created handle? Has the account previously posted reliable content, or does its history suggest amplification of unverified claims? Provenance is the single most-skipped verification step and the single highest-leverage one. Tools: the Wayback Machine for prior content from the account or site; CrowdTangle alternatives like Junkipedia for cross-platform posting patterns; the platform's own native tools for account creation date and verification status. If an image or video has been re-posted, trace it back to the earliest version before treating any later version as authoritative. ## Step 2 — Reverse image search Any image accompanying a breaking-news claim deserves a reverse search before publication. The three workhorses are InVID's WeVerify plugin (which runs queries across Google, Bing, Yandex, and TinEye simultaneously), Google Lens, and Yandex Images. Yandex remains the strongest for non-Western, Russian, and Middle Eastern imagery — its index of those regions is materially better than Google's. What you are looking for: prior appearances of the same image (suggesting it has been recycled), visual matches in older news archives, and matches against stock-photo or AI-generation telltales. A 'breaking' image that already appeared in 2019 is not breaking. An image that appears nowhere else is either genuinely new or AI-generated; both possibilities require further verification before publication. ## Step 3 — Geolocation If a claim specifies a location, can the imagery be matched to that location? Geolocation cross-references visible landmarks, signage, road layout, building patterns, vegetation, and topography against satellite imagery (Sentinel-2, Google Earth, Bing Maps), street-level imagery (Google Street View, Mapillary), and architectural databases. The workflow: identify any distinctive features in the image — a uniquely shaped building, a road intersection, a mountain ridgeline, a foreign-language sign; search satellite imagery for that feature in the claimed area; confirm scale and orientation. Bellingcat's geolocation guides are the standard reference. For practice, the GeoGuessr-style training games run by SANS and several OSINT educators are unusually effective. ## Step 4 — Chronolocation Chronolocation is geolocation's time dimension: confirming when something happened. The standard inputs are weather (compared against historical archives like Wunderground or ECMWF), shadow direction and length (analyzed with sun-position tools like SunCalc), visible time-stamped objects (clocks, traffic patterns, time-coded broadcasts), and vegetation state (leaf-on vs. leaf-off, snow cover, crop stage). Chronolocation is harder than geolocation because the inputs are noisier. A confident chronolocation usually combines two or three independent signals — for example, shadow angle plus weather plus vegetation state all consistent with the claimed date. A single shadow angle on its own is suggestive, not conclusive. ## Step 5 — Independent corroboration Finally, can the claim be corroborated by at least two independent primary sources? 'Independent' matters: three outlets quoting the same anonymous social-media post are not three sources, they are one. Look for separate eyewitness accounts, separate imagery from different angles, official statements, and physical-world signal (USGS for seismic events, NASA FIRMS for fires, ADS-B for aircraft). When multiple independent sources align, confidence is high. When sources contradict, the responsible reporting acknowledges the contradiction explicitly rather than picking the more dramatic version. When only one source exists, the claim should be reported as 'reported by X', not as established fact. ## Common verification failures - Recycled imagery — old footage re-captioned as current; defeated by reverse image search. - Wrong-location imagery — real footage from elsewhere passed off as the claimed location; defeated by geolocation. - Synthetic imagery — AI-generated or composited images; defeated by reverse search returning no matches plus failure of geolocation. - Source laundering — claim amplified through reposts until original source is obscured; defeated by provenance tracing. - Single-source cascade — one outlet's mistake repeated by others without independent verification. ## The five-minute rule Under live-event pressure, the verification budget is often five minutes. That is enough for a reverse image search, a quick geolocation against a single landmark, and a provenance check on the original poster. If five minutes cannot produce two corroborating signals, the responsible default is to wait. The cost of a few minutes' delay is small. The cost of amplifying a fabricated claim — to your audience, to your credibility, and sometimes to people on the ground — is enormous. A final note on tone: how you publish matters as much as whether you publish. 'Reported by X, unverified' is a legitimate state; 'BREAKING' over an unverified screenshot is not. The verification process above is necessary but not sufficient — the framing around the claim has to match the confidence the evidence supports. ### Verification Tools & Guides - [InVID WeVerify Plugin](https://www.invid-project.eu/tools-and-services/invid-verification-plugin/) — Reverse image search across Google, Bing, Yandex, and TinEye in one click. - [Google Lens](https://lens.google/) — Strong general-purpose reverse image search. - [Yandex Images](https://yandex.com/images/) — Best coverage of Russian, Eastern European, and Middle Eastern imagery. - [Bellingcat — Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit/) — Curated verification and geolocation utilities. - [SunCalc](https://www.suncalc.org/) — Sun position by date and location, essential for shadow chronolocation. - [Google Earth Pro — Historical Imagery](https://www.google.com/earth/about/versions/) — Time-slider satellite layer for geolocation and change detection. - [Mapillary](https://www.mapillary.com/) — Crowdsourced street-level imagery for areas Street View misses. - [Wayback Machine](https://web.archive.org/) — Provenance and prior-version tracing of online content. - [First Draft Verification Guides](https://firstdraftnews.org/long-form-article/journalists-guide-to-verification/) — Newsroom-grade verification playbooks. - [EUvsDisinfo](https://euvsdisinfo.eu/) — Database of debunked pro-Kremlin disinformation narratives. > Speed is a feature; accuracy is the product. Trade one for the other and you lose both. ## FAQ ### What is the fastest way to verify a breaking-news image? Run a reverse image search using InVID's WeVerify plugin, which queries Google, Bing, Yandex, and TinEye simultaneously. If the image appears in older results, it has been recycled. If it appears nowhere, treat it as unverified pending further checks. ### What is geolocation in OSINT? Geolocation is the practice of confirming where an image or video was taken by matching visible landmarks, signage, road layout, and topography against satellite imagery (Sentinel-2, Google Earth) and street-level imagery (Google Street View, Mapillary). ### Why is Yandex Images recommended for reverse search? Yandex's image index has materially better coverage of Russian, Eastern European, and Middle Eastern imagery than Google or Bing. For OSINT work in those regions, Yandex frequently surfaces matches the Western search engines miss. ### How do I tell if an image is AI-generated? There is no reliable single test. Combine multiple checks: reverse image search returning no matches; geolocation failing to confirm any visible landmark; subtle visual artifacts (inconsistent shadows, distorted text, anatomically wrong details); and metadata mismatches. When in doubt, treat as unverified rather than amplify. ### How much time should I spend verifying a breaking-news claim? Under live-event pressure, budget at least five minutes for reverse image search, basic geolocation, and source-provenance checks. If those five minutes cannot produce two independent corroborating signals, the responsible default is to wait rather than amplify. --- Source: [How to Verify Breaking News with OSINT: A 2026 Playbook](https://www.globalthreatwatch.com/blog/verify-breaking-news-osint) — Global Threat Watch, free real-time OSINT dashboard.