Habr•August 27, 2026•🇷🇺Translated from Russian

OSINT for the Lazy Part 19: AI as a Core Tool in Modern Intelligence Gathering

On the previous decades OSINT developed primarily as a manual discipline: analysts sequentially visited sources, recorded data and built logical connections. This approach worked while the volume of publicly available information remained within human perception limits. Today the situation has changed fundamentally. According to IDC, approximately 2.5 quintillion bytes of data are generated daily, with hundreds of millions of content units published on social networks every day. No analyst or team can process this flow manually.

Practitioners must therefore apply AI models for data collection and processing. The technology does not yet replace the analyst; instead it removes operational load by delegating collection, primary filtering and structuring to machines, freeing human attention for contextual interpretation, ethical judgment and final conclusions.

Leading practitioners have described generative AI as the largest shift in OSINT in twenty years, marking the beginning of the OSINT 3.0 era where speed, scale and multimodality become baseline characteristics rather than competitive advantages.

Natural Language Processing (NLP)

NLP models, ranging from classical TF-IDF approaches to modern transformers such as BERT, GPT and LLaMA, enable automatic analysis of textual content at scales impossible with manual methods. Applications in OSINT include thematic modeling of publication arrays, automatic named-entity extraction, sentiment analysis, authorship attribution via stylometric features and detection of machine-generated text.

Computer Vision

Visual data constitute a substantial share of OSINT materials. Modern tools such as GeoSpy, Picarta and Google Vision AI determine probable photograph locations from architectural details, vegetation, road signs and shadows with increasing accuracy. Additional uses encompass analysis of military equipment, facial identification under legal constraints, image manipulation detection and OCR extraction from screenshots.

Multimodal Models and Anomaly Detection

Multimodal systems simultaneously process text, images, video, audio and structured data. Algorithms such as Isolation Forest, LSTM autoencoders and One-class SVM identify atypical behavioral patterns required for detecting coordinated influence campaigns and botnets. Graph Neural Networks (GNN) reveal hidden connections between actors, organizations and infrastructure.

Practical Applications and LLM Agents

AI systems now continuously scan Telegram channels, Pastebin dumps, GitHub repositories and darknet forums to extract and verify indicators of compromise in real time. Platforms using local processing via vLLM aim to keep sensitive data inside protected perimeters. Detection of disinformation relies on analysis of temporal activity patterns, linguistic entropy and C2PA standards for synthetic content.

The most significant development between 2024 and 2026 is the transition to autonomous LLM agents equipped with planning modules, tool access, memory and dynamic knowledge graphs. Integration of chain-of-thought techniques reportedly improves accuracy on out-of-distribution OSINT questions by 86 percent. Under the DNI strategy 2024–2026, 68 percent of U.S. security agencies already employ OSINT platforms for digital threat mapping.

Limitations, Risks and Human-AI Symbiosis

Up to 35 percent of analysts cite source verification and data reliability as major concerns. Adversaries use generative AI mainly to scale existing tactics such as phishing rather than to create novel threats. Ethical issues include attribution without verifiable methodology, privacy erosion through aggregation of public data and growing asymmetry of access favoring state actors and large corporations.

The recommended model remains symbiotic: AI excels at speed and scale while humans retain superiority in contextual understanding, ethical judgment and recognition of unprecedented events. The OODA loop shortens when observation and initial orientation are automated, leaving analysts to focus on decision and action.

Related articles

Habr•AI Security

AI Learns Human Formulas of Deception, Fueling a Crisis of Free Speech and Truth

The article examines how artificial intelligence has begun replicating human social-behavioral patterns to create and cite nonexistent authoritative sources, thereby spreading false information at scale. It traces the historical evolution of propaganda from ancient Sparta and Athens through the Rothschilds and modern social media, showing how each new mechanism for verifying truth—expert opinion, reputation, and finally machines—has been subverted. The author highlights recent examples of rapid disinformation campaigns, including false claims about FlyDubai pilots and a supposed plague outbreak in Irkutsk, which were amplified by controlled media, opinion leaders, and ordinary users. The piece warns that AI’s tireless ability to generate thousands of contradictory articles in real time could overwhelm any possibility of discerning truth, especially during elections. Societal consequences include rising atomization, declining trust in institutions, lower voter turnout, and reduced economic investment due to uncertainty. The author concludes that humanity currently lacks an effective countermeasure and may need to pass through a period of extreme information pollution before developing new norms of personal responsibility and verification.

AntiMalware•AI Security

Anthropic Reports User's Violent Threats to Police After Conversation with Claude AI

Anthropic's security systems flagged messages from a Florida woman who used the Claude AI chatbot to express intent to carry out a shooting at the Lee County Sheriff's Office. The 30-year-old Carly Michelle Heller also stated that she had acquired a weapon, prompting the company to escalate the conversation for human review. After verification, Anthropic notified law enforcement, leading to her identification and quiet arrest at her home. Sheriff Carmine Marceno noted that Heller had been treating Claude as a personal diary rather than a secure private space. She now faces a second-degree felony charge under Florida law, with the court set to determine her guilt. The case underscores how AI platforms monitor for specific threats involving concrete targets and weapon acquisition, resulting in direct police involvement.

Habr•AI Security

AI Reshapes Cybersecurity Jobs: Automation of Routine Tasks, Rising Demand for Architects and AI Defenders

The cognitive revolution driven by AI technologies is transforming the information security job market rather than eliminating it. Routine tasks such as alert triage, log analysis, and basic vulnerability prioritization are increasingly handled by language models and autonomous agents, shifting human roles toward setting boundaries, validating hypotheses, and assuming legal and financial responsibility. Surveys from ISC2 and analyses by Gartner highlight growing needs for senior architects, AppSec engineers, DevSecOps specialists, and experts protecting AI systems themselves. DARPA's AIxCC competition demonstrated both the promise and limitations of autonomous patching, with 37-45% of generated fixes containing hidden semantic errors. Russian market data from Positive Technologies and SuperJob shows 24-26% growth in vacancies focused on experienced professionals amid import substitution pressures. The profession is moving from mechanical execution to designing reliable architectures and overseeing automated defense loops through 2030.

Habr•AI Security

Integrating LLM Assistant with Wazuh SIEM Enables Natural Language Queries and Alert Analysis

Wazuh collects security events effectively but requires knowledge of query languages and hundreds of index fields to extract answers. Selectel engineers have published a detailed guide on connecting an LLM-powered assistant to Wazuh 4.14.7 using OpenSearch plugins. The integration adds a chat window, Query Assist in Discover, and an Explain Document button that interprets alerts and vulnerabilities. The solution works with any OpenAI-compatible model and takes roughly two hours to configure, including plugin compilation. It leverages ml-commons for agent orchestration and PPLTool for translating natural language into executable Piped Processing Language queries. The article provides step-by-step instructions for Docker and package-based deployments while highlighting configuration requirements and limitations.