Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Welcome to Bellingcat’s freely available online open source investigation toolkit. You can follow our work on via our website, Twitter and Facebook. (We also
provide three to five day open source investigation workshops.) Feel free to suggest tools not yet listed here. This is version 4.1 (October 21, 2018). The list
includes satellite and mapping services, tools for verifying photos and videos, websites to archive web pages, and much more. The list is long, and may seem
daunting. There are guides at the end of the document, highlighting the methods and use of these tools in further detail. We also provide tailored digital
forensics workshops. Feel free to contact me with questions or suggestions via email (christiaantriebert@bellingcat.com) or Twitter (@trbrtc). To view an
outline of the document, click “View” and then “Show document outline”. There’s also one below. The “OSINT Landscape” — a condensed version of the
online investigation toolkit below — can be download in high resolution here.
1
Topics
● Maps, Satellites & Streetview
● Geo-Based Searches
● Images, Videos & Metadata
● Social Media
● Transportation
● Date & Time
● WhoIs, IPs & Website Analysis
● Individuals
● Archiving, Downloading & Internet Storage
● Miscellaneous
● Guides & Handbooks
● Data Visualisation
● Online Security & Privacy
● Company Registries
● Expert/Source Tools
2
Bing Maps Bing’s mapping service offering satellite More recent and higher resolution Difficult to check the date of the bing.com/maps
imagery and street maps. imagery than Google, e.g. in Afghanistan imagery.
and Iraq.
Copernicus The site for the European Space Agency Better resolution than Landsat. See scihub.copernicus.eu
and for images from Copernicus’ six explanation from the website
Sentinel satellites. GISGeography on how to download free
images.
Descartes Labs A commercial service that collects data Will help journalists. “We do not charge descarteslabs.com
daily from public and commercial for these requests, only ask that they
imagery providers. are credited.” (via GIJN)
DigitalGlobe Satellite imagery vendor. Preview available via the catalogue, $ discover.digitalglobe.com
search tool very easy to use.
3
the process of developing a service
provisionally called EOS Media that will
be providing free images and analysis of
major natural disasters.
find2places Allows querying Google Maps API for It’s a script, no user-friendly interface. github.com/musafir-py/find2places
two specific places in precise distance
from each other within given radius.
Useful for geolocating photos and
videos.
GeoNames Database of location names. A wide variety of different spellings in geonames.org
various languages. Draws upon many
sources, including NGA’s Geonames.
Google Earth Pro Add a Bing Maps satellite imagery layer. [software] Training guides here.
Historical imagery.
Google Earth Engine Open-access satellite imagery and Virtually any satellite imagery collected Moderate and coarse resolution imagery earthengine.google.com/
analytical framework from NASA, NOAA, USGS, etc. is rather than high-resolution commercial
available. imagery; Learning curve with Javascript
Google Maps Google’s mapping service offering Many 3D modelled places in Americas, No historical satellite imagery, but maps.google.com
satellite imagery, street maps, and Australia, Europe, N Africa, and SE Asia. historic Streetview images available in
streetview. Probably the easiest-to-navigate many places.
mapping service of all.
IndustryAbout Maps per country showing industrial Specifically to industrial plants. Only mapped per country. industryabout.com/country-territories-3
plants, e.g. power, hydroelectric,
nuclear, coal, oil refineries, etc.
4
Map checking Calculate the amount of people that are mapchecking.com
standing in the selected Google Maps
area.
Mapillary Crowdsourced street-level photos. A useful addition to Google Streetview. Little to no coverage in countries like mapillary.com
Syria, Iraq, etc.
NASA EarthData WorldView allows visualization of near A wide array of satellite and aerial earthdata.nasa.gov
real-time imagery from NASA. images; broad search criteria; and other
mapping and visualization tools such as
FIRMS for fires. Access to more than a
dozen NASA data centres and
asso\ciated satellite data products.
NASA Earth Observations: More than 50
datasets on atmosphere, land, ocean,
energy, environment and more.
Old Maps Online Find old maps through numerous Easy-to-use, similar browsing as the oldmapsonline.org
databases all around the world. DigitalGlobe catalogue.
OpenStreetCam openstreetcam.org
OpenStreetMap openstreetmap.org
overpass-turbo overpass-turbo.eu
Radiant Earth A non-profit group that helps the global Radiant Earth is working with Code of radiant.earth
development community discover, Africa, among others. Apply to gain
explore and analyze satellite, drone and assistance via their website. Or contact
aerial imagery archives. Radiant Earth.
Resource Watch A nonprofit platform, still in beta, that Resource Watch data are free and users resourcewatch.org
provides hundreds of data sets on the can download data.
state of the planet’s resources and
citizens. It is sponsored by the World
Resources Institute and other
organizations.
Satellites.pro Combines different satellite services Includes web based Apple Maps satellites.pro
satellite view, great for seeing countries
like Afghanistan.
Sentinel Hub Playground A user-friendly place for Sentinel Updated every 5-10 days with new Generally low resolution of 10m/px. apps.sentinel-hub.com/sentinel-playgr
2/Landsat images. imagery, dependent on cloud cover. ound
Ability to explore a variety of GIS
variables eg NDVI or NDWO. The EO
Browser facilitates time-lapse reviews.
5
Tencent Maps Tencent Maps (formerly SOSO Maps) is a map.qq.com
desktop and web mapping service
application and technology provided by
Chinese company Tencent, offering
satellite imagery, street maps, street
view (coverage) and historical view
perspectives, as well as functions such
as a route planner for traveling by foot,
car, or with public transportation.
Android and iOS versions are available.
TerraServer Satellite imagery vendor. Highest resolution available (0.3m). $ to preview high-resolution satellite terraserver.com
imagery.
Wikimapia Crowdsourced information related to Possibility to switch between Can be laggy, and need to refresh page wikimapia.org
geographic locations. Google/Bing/OSM. Massive amount of after a view searches. Lost Google API.
UCG information.
Geo-Based Searches
Name Description Pros Cons Link
Animaps Created custom animated maps. Useful for timeline recording for Not secure, and not well developed. http://www.animaps.com
investigations
Echosec Geo-based searches. Twitter, VKontakte, Foursquare $ (doesn’t list Facebook, genuine echosec.net
Instagram)
Custom Satellite View Tools Link to allow search as well as Quick, easy inteltechniques.com/osint/maps.html
auto-populate multimap links for
address searching
GeoGig Users are able to import raw geospatial Well Developed. If you're not Linux/Github/Programming http://geogig.org/
data (currently from Shapefiles, PostGIS saavy, you will be doing a lot of reading
or SpatiaLite) into a repository where from the manual.
every change to the data is tracked.
These changes can be viewed in a
history, reverted to older versions,
branched in to sandboxed areas,
merged back in, and pushed to remote
repositories.
GeoNames The GeoNames geographical database Extremely useful in Geo Tagging, geonames.org
covers all countries and contains over documentation, and data collection.
6
eleven million place names that are
available for download free of charge
Esri powerful mapping and analytics Robust and full featured Requires a level of account setup and esri.com
software configurations that may make some to
forget it.
Follow Your World track your points of interest and Simple, easy to use, dashboard for followyourworld.appspot.com/
manage your email subscription tracking.
settings here.
Liveuamap Interactive live map of conflict news. Variety of countries available: liveuamap.com
Afghanistan, Iraq, Syria, U.S., Ukraine,
Venezuela, etc.
Twitter Insert in search box: There’s a tool for it too. Easy to fake.
geocode:[coordinates],[radius-km], for
example:
geocode:36.222285,43.998233,2km
(only works with km, so 500m = 0.5km)
WarWire Geo-based searches. Twitter, VKontakte, Instagram $ (but does list Instagram) warwire.net
ExifTool Read, write, remove, and Floss, Cross-platform and very Yet to encounter any (Have only https://www.sno.phy.queensu.ca/ See forum and FAQ on linked
manipulate metadata for a vast easy to integrate into scripts. used on GNU/Linux). ~phil/exiftool/ page
number of file types. Note: no
GUI
7
technical information from a
batch of photos which is
embedded by the camera or the
photo editing software.
Foca Extracts metadata. Windows-based, open sourced No native Linux support. (needs elevenpaths.com/labstools/foca/ NullByte
2017. wine installed within Linux) index.html
FotoForensics Image forensics tool. Simple, web-based. Public access, information not fotoforensics.com
private.
GooFile Extract metadata. Simple to use. Doesn't work well outside Kali tools.kali.org/information-gather Ascii cinema
ing/goofile
Image Forensics Web-based image forensics tool. Can easily identify fake or Public access, information not 29a.ch/photo-forensics/#level-s
doctored images private. weep
Jeffrey's Image Metadata Viewer Extract metadata, online. Only requires a web browser. Public access, information not exif.regex.info/exif.cgi
private.
Reveal Image Verification Forensic providing eight filters Web-based image tool. http://reveal-mklab.iti.gr/reveal/i Documented with examples and
Assistant to detect still images alterations. Also available within InVID ndex.html explanations of the different
verification plugin. filters. Developed in Reveal
project.
reverse image search Locates similar images on the Easy, simple and works! Recommended plugin: RevEye, tineye.com
internet which searches Google, Yandex,
Baidu and Bing.
SpiderPig Extract metadata. Command line interface and Requires dependencies and github.com/hatlord/Spiderpig
scriptable. knowledge of web technologies.
Splunk Extract metadata. Report grade analysis and Not simple to set up and deploy. blog.sweepatic.com/metadata-h Sweepatic.com
presentation. ackers-best-friend
8
user-defined image dataset. It is
based on the original application
created by VGG to perform visual
searchers over a large dataset of
images from BBC News.
VGG Face Finder (VFF) Engine Visual Geometry Group and robots.ox.ac.uk/~vgg/software/vf
released under the BSD-2 clause. f/
VFF is a web application that
serves as a web engine to
perform searches for faces over
an user-defined image dataset. It
is based on the original
application created by VGG to
perform visual searchers over a
large dataset of images from
BBC News.
VGG Image Search Engine (VISE) This standalone application can robots.ox.ac.uk/~vgg/software/vi
be used to do a reverse image se
search on a large collection of
images.
Social Media
Facebook
9
StalkScan Automatic advanced searches per stalkscan.com
Facebook profile.
Websta Find other locations in Instagram’s websta.me Use direct URL with
database near a particular location. a location ID, e.g.
websta.me/location/
116231
Skype
Snapchat
Snap Map Searchable map of geotagged snaps. Here’s how you can download them. map.snapchat.com
10
Tumblr
botcheck botcheck.me
Botometer botometer.iuni.iu.
edu
InVID verification plugin InVID plugin provides a Twitter Allows documenting use cases from the InVID verification Automates the
advanced search by time interval up to past without APIs and time limit. Allows plugin conversion between
the minute. searching for content within a calendar date and
user-defined time range after a Unix timestamp in
breaking news. Twitter advanced
search:
https://youtu.be/nm
gbFODPiBY?t=4m21
s
Twitter advanced search Search by date, keywords, etc. twitter.com/searc Many useful search
h-advanced features are not
available from
Advanced interface,
e.g.
https://medium.com
/@preslavrachev/ho
w-to-use-twitter-mo
re-efficiently-with-t
hese-hidden-search-
features-8c80b450fa
bc
11
Twitter geobased search geocode:[coordinates],[radius-km], for There’s a tool for it too.
example:
geocode:36.222285,43.998233,2km
twint Advanced Twitter scraping tool written Need to know Python. github.com/twintp
in Python that doesn't use Twitter's API, roject/twint
allowing you to scrape a user's
followers, following, Tweets and more
while evading most API limitations.
Twlets Download anyone’s tweets, followers Easy and quick to use, there’s a Chrome Goes up to 3,200 tweets, followers and twlets.com
and likes in an Excel sheet. extension too. likes.
t command-line power tool for Twitter (it Highly flexible, can be put in Bash Set-up might be technical for some (ask github.com/sferik/ https://github.com/s
is an open source command line script scripts to automate Twitter activity and if you want help) t ferik/t/blob/master/
written in Ruby) searches README.md
Deeper search through REST API
Output spreadsheets/CSV
Fast performance for bulk operations
YouTube
Amnesty YouTube Dataviewer Reverse image (video still) search and Searches for a number of stills, not amnestyusa.org/si Advanced
exact uploading time. each frame is included (thus results tes/default/custo Guide on Verifying
may be left out). InVID plugin is m-scripts/citizene Video Content
probably better at this stage. vidence
Geo Search Tool Search for YouTube videos based on youtube.github.io/
location. geo-search-tool/s
earch.html
youtube-dl Python tool to download from a variety Select video / audio formats, quality etc Intellect needed (read: cli usage only) http://rg3.github.i
of sources. Updated frequently to support parsing o/youtube-dl/
the relevant sources
Transportation
Air
Name Description Pros Cons Link Guides
12
ADS-B Exchange Global Radar Tracking flights. Includes a number of military global.adsbexchange.com/Virtua
aircraft. lRadar/desktop.html
ADS-B Historical Flight Viewer Look up flight history of a Like FlightRadar24, but free https://flight-data.adsbexchange Search by ICAO (a.k.a.
specific aircraft as far back as .com/ registration number).
two years
Federal Aviation Administration Nationwide Plane Registry Comprehensive list of privately http://registry.faa.gov/aircraftinq Search by N-Number (a.k.a.
owned planes in the US uiry/NNum_inquiry.aspx callsign).
FlightAware flightaware.com
Live ATC Audio from air traffic control Aircraft have to identify More complicated to use than liveatc.net
towers in the United States. themselves to ATC towers, so in e.g. FlightRadar24.
cases where aircraft are trying to
obscure their information from
other sites, it might be another
way to grab tail numbers or just
generally track flights.
PlaneFinder planefinder.net
Water
Equasis Vessel ownership and Lists historical information equasis.org
identification records
VesselFinder vesselfinder.com
Land
Licence Plate Mania .licenseplatemania.com
13
Trains Full interactive maps of various Denmark, France, Germany,
railway networks in European Netherlands, Poland
countries.
Misc
WikiRoutes Public transport database. wikiroutes.info
Passive DNS Collects, stores and analyses Complete unadulterated 15 API calls day, 15 searches a
data from thousands of passive historical and current DNS day. community.riskiq.com
DNS collection sensors. information.
DNS History Collection of historical DNS Free, simple and easy to use. Sometimes limited in DNS History
information. availability.
DNS Cyrillic check Check if malicious or Cyrillic Free, simple and easy to use. https://holdintegrity.com/checke
domains are registered r
DNS Trails The World's Largest Repository Free, simple and easy to use. dnstrails.com
of historical DNS data
14
Geo IP Tool Check your own IP, handy to geoiptool.com
check if your VPN is working,
Shodan Internet of things search engine. Can find heaps of misconfigured Lives in the gray zone... shodan.io
network-connected devices.
WebCookies.org A website security and privacy This data has been used to webcookies.org
scanner that, among many other identify some of the websites
features (mostly focused on posing as independent but really
GDPR compliance) aggregates managed by RT/Sputnik.
large amount of information
about advertiser and analytics
identifiers of scanned websites,
as well as the /ads.txt files.
People
Name Description Pros Cons Link Guides
● Network-Tools
● Open Site Explorer
● People search
○ Aggregated list of over 200 people search and data broker sites, reverse phone look ups, and other search tools with opt-out links.
○ Peekyou, peekyou.com
○ Yasni, yasni.com
○ Zaba Search, only US, zabasearch.com
○ publicrecords.searchsystems.net
○ cemetery.canadagenweb.org/search.html
○ opencorporates.com
○ www.numberway.com/ - a list of URLs to local White Pages and Yellow Pages, with the description in English. Useful in finding people and companies.
15
● Robtex
● Search IRC
● Shodan Computer Search
● Utrace
● ViewDNS
● DNS Historical Data, research.dnstrails.com
● SpyOnWeb, to retrieve websites by their Tracking codes, spyonweb.com
● Whois, for domain search and information, whois.net or whois.icann.org
Wayback Machine Archives websites. Download an Does not always include images github.com/hartator/wayback-m
entire website from the Wayback from web pages or multimedia achine-downloader
Machine. content
Wayback Machine for Github Finds and searches when and Easy terminal interface. Nil cons. github.com/MadRabbit/git-wayb
who did what! ack-machine
Gitrob Reconnaissance tool for GitHub Easy, free and open source. Nil cons. github.com/michenriksen/gitrob
organizations
Dumpster Diver Tool to search for secrets in Easy, free and open source. Nil cons. github.com/securing/DumpsterD
various file types. iver
TruffleHog Searches through git repositories Easy, free and open source. Nil cons. github.com/dxa4481/truffleHog
for high entropy strings and
secrets, digging deep into
commit history
Stone A “research transparency” app Free, “twitch for journalists” Beta writeinstone.com
that captures desktop research Audio and video files can also be
using screen capture and directly uploaded from
webcam commentaries..
16
Miscellaneous
Name Description Pros Cons Link Guides
Maltego Interactive data mining tool that Used in online investigations for There is a free version but full paterva.com/web7
renders directed graphs for link finding relationships between version costs $
analysis. pieces of information from
various sources located on the
Internet.
17
TimelineJS by Knight Lab Make an interactive timeline of timeline.knightlab.com
events.
WEAPONS
18
● An open guide called “Itrace” by Conflict Armament Research, lots of information on different kinds of munitions and weapons presented graphically on
a map format, itrace.conflictarm.com
Data Visualisation
Name Description Pros Cons Link Guides
Maptia maptia.com
19
HTTPS (to help prevent
man-in-the-middle attacks).
20
Provinces of the so-called Islamic State umap.openstreetmap.fr
Syria
Maps lib.utexas.edu/maps/syria.html
Company Registries
● French SIRENE, provided by Investigative Dashboard, a queryable version of the french RCS (Business registry), with OpenRefine reconciliation tool.
https://data.occrp.org/entities?filter:dataset=fr_sirene
● In France, https://www.societe.com/
● Business registries in Europe, on the Eur opean e-Justice portal, links to the nation
al business registry of each EU member.
https://e-justice.europa.eu/content_business_registers_in_member_states-106-en.do
● Portugal, https://publicacoes.mj.pt/DetalhePublicacao.aspx
● For the UK, which covers Gibraltar as well, Companies House https://beta.companieshouse.gov.uk
● https://opencorporates.com/
● https://data.occrp.org/
● https://public.enigma.com
https://challenge.burnerapp.com/
Expert/Source Tools
21
- https://www.numberway.com/ - a list of URLs to local White Pages and Yellow Pages, with the description in English. Useful in finding people and companies (I've already placed it in
the google doc)
Paint.net
Namechk.com
Very good for identifying online accounts with a username. Simply plug the username in and this tool will identify where there are users using that name.
TO ADD:
- https://www.delpher.nl/
Name: GRAPHLYTIC.biz
Description: Web application for visual analysis and investigation of large scale graphs stored in Neo4j graph DB.
22
Pros: Includes Data Ingestion engine and lot of configuration options. Can be used also for team collaboration and knowledge sharing. Supports Cypher query
language for pattern matching.
Cons: Free license available only for non-profit cases.
Link: https://graphlytic.biz
Guides: Feature videos: https://graphlytic.biz/features/#statistics_01 Documentation: https://graphlytic.biz/doc/latest/Graphlytic_concepts.html
https://hoaxy.iuni.iu.edu/#query=bellingcrap&sort=mixed&type=Twitter
www.teatmik.ee/en/personlegal/14144085-Asicvault-OÜ
egrul.nalog.ru
efiling.drcor.mcit.gov.cy/DrcorPublic/SearchForm.aspx?sc=0&lang=EN
offshoreleaks.icij.org/
4) Offshore Switzerland
ti.chregister.ch/cr-portal/suche/suche.xhtml
www.zefix.ch/en/search/entity/welcome
eservices.dls.moi.gov.cy/#/national/geoportalmapviewer
23