Topic

Censys

🇷🇺Aug 24

Statistical Analysis in OSINT: Tools, Methods and Real-World Intelligence Applications

The article explains why statistical processing has become an essential component of professional OSINT work when analysts face large volumes of raw data. It outlines five core tasks that statistical methods solve: actor profiling, disinformation monitoring through time-series and graph analysis, financial intelligence, geospatial verification, and threat assessment. The text compares popular tools including Maltego, Gephi, Python, R, Power BI, Tableau and SpiderFoot, stressing that real investigations usually combine several of them. Detailed examples show how Pearson correlation, Louvain clustering and TF-IDF or BERT embeddings help identify coordinated botnets in social media. Famous leaks such as Panama Papers and Pandora Papers are presented as landmark cases where regression models, cluster analysis and network graphs exposed hidden ownership structures. The piece also lists open statistical sources from national agencies, international organisations and technical platforms, and reviews key mathematical techniques from basic descriptive statistics to ARIMA, CUSUM, DBSCAN and dimensionality reduction methods.

Habr•Other
🇷🇺Aug 13

OSINT for the Lazy Part 17: Versatile Framework Acts as Swiss Army Knife for Investigators

The article continues the series on tools for lazy OSINT practitioners by reviewing a multifunctional online toolkit hosted at htdark.com. This minimalistic yet powerful platform aggregates data across usernames, email addresses, phone numbers, IP addresses, cryptocurrency, social networks, and media files. It wraps Censys search capabilities into a more convenient interface while adding features such as JSON report export and basic relationship graphing. The tool checks 20 social platforms including Reddit and Spotify but omits Chinese and Russian resources, marking absent accounts in red and requiring manual verification for others. An Advanced section functions as a dork builder supporting Baidu and Naver with time-range filters and exclusion operators. While no single toolkit replaces specialized solutions, this framework provides broad initial visibility and helps analysts choose focused follow-up directions based on accumulated data rather than random checks.

Habr•Other
🇨🇳Jul 21

Russian Intelligence Hijacks Exposed Security Cameras in Europe and Ukraine for Military Surveillance

Dutch intelligence agencies AIVD and MIVD have revealed that Russian military intelligence is systematically compromising internet-connected security cameras across Europe and Ukraine. The attackers scan for exposed devices using brand fingerprints, then log in with default passwords and outdated firmware without needing zero-day exploits. In Ukraine, live camera feeds are used not only for reconnaissance of military transport routes and weapon deliveries but also to directly support targeting of Ukrainian forces and equipment. Censys identified over 87,000 vulnerable cameras in the EU, NATO countries, and Ukraine, with more than 4,000 located in Ukraine alone. While the actual number of confirmed compromises is smaller, the cameras are strategically positioned along key military logistics routes. The agencies issued basic but critical recommendations including disabling public exposure, changing default credentials, and applying patches for known vulnerabilities such as CVE-2016-7407 and CVE-2021-39275.

安全客•State-Sponsored & APT