r/OSINT 2d ago

How-To How to effectively monitor/scrape specific Facebook Groups for time-sensitive posts in 2026? (My current Google Dork setup is hitting limits)

12 Upvotes

Hi everyone,

I’m looking for some advice on optimizing how I monitor Facebook Groups for highly specific, time-sensitive opportunities (specifically, urgent short-term event/festival crew gigs in Europe).

The native Facebook search is terrible, completely overrun by AI-generated spam, and its algorithm actively hides chronological, low-engagement posts, which are exactly the ones I need to find (e.g., a manager panicking because someone dropped out of a shift last minute).

What I am currently doing: I’ve been bypassing the FB search entirely by using Google Dorks to index specific groups. My current setup looks something like this:

site:facebook.com/groups(https://facebook.com/groups) ("urgent" OR "replacement" OR "ASAP" OR "need now") "festival" "August" ("security" OR "crew" OR "stagehand") -weekend -longterm

(Note: I run a localized version of this with Czech/German keywords to target central European groups, filtering results to the past 24 hours).

The Problem & My Ask: While this dork works well for bypassing spam, it requires manual execution and Google’s indexing of Facebook Groups isn't always real-time. Missing a post by a few hours usually means the spot is gone.

I want to automate this process to get real-time (or near real-time) alerts.

  1. Scraping: Are there any reliable web scrapers or cloud tools (like Phantombuster, Apify, etc.) that currently handle FB Group scraping well in 2026 without getting accounts instantly banned?
  2. Alternative OSINT methods: Is there a better, more elegant way to monitor specific keywords inside public/private FB groups that I am missing?
  3. Dorking limits: Any tips on forcing Google to index these specific site:[facebook.com/groups](https://facebook.com/groups) queries faster, or alternative search engines that crawl FB groups more aggressively?

I appreciate any pointers or recommendations for tools/scripts that could help automate this monitoring. Thanks!


r/OSINT 2d ago

Question Udemy worth it?

38 Upvotes

Is it worth paying to learn it from scratch or are there better options?


r/OSINT 3d ago

Question What’s the most interesting OSINT job you’ve ever had or heard of?

150 Upvotes

Most of us know the usual paths like due diligence, fraud investigations, and journalism. But I’m curious about the unusual and genuinely fascinating stuff. What’s the most interesting OSINT gig you’ve personally worked, or heard about secondhand?

Doesn’t have to sound glamorous on paper either. Sometimes the boring sounding jobs turn out to have the wildest stories. Would love to hear what corners of this field exist that most people never know about.


r/OSINT 3d ago

Question Anyone have experience with either Open Sky Network API or ADS-B Exchange API and know what the polling request limit is?

1 Upvotes

[Also asked in ADSB subreddit]

Hi, I am looking at 2 ADS-B APIs and wondering if anyone knows (either from experience or documentation - if you found it) what the request rate limit / polling limit is per minute.

OpenSkyNetwork API

\- I have a registered account which gives me 4,000 credits per day but I can't seem to find anything in the API documentation about how many requests I can make per minute though there is mention of a 429 error and backing off.

ADS-B Exchange API ($10 month tier)

\- API documentation says you can get 10,000 credits per month at this tier but I also can't seem to find anything about how many requests you're allowed to make per minute for this API either.

I currently have a Flight Radar 24 Explorer tier account and this works but I'm going to be pulling historical tracks for a number of flights on a recurring basis and the poll limit is 10 requests per minute.

That's not great but wondering if it's better than Open Sky Network API or ADS-B Exchange API.


r/OSINT 3d ago

Question How much can you find by Internet?

26 Upvotes

I wanna know how dangerous being connected to the same Internet is.

Im new to osint but one of the first things I wanna do is get my tiktok username + whatever else I can get all from my phone. My pc and phone are connected to the same WiFi so is it possible or not?


r/OSINT 3d ago

Analysis I have built a real-time conflict map that only fires alerts on multi-source corroboration. Feedback is welcomed

Post image
0 Upvotes

I have been building this solo for a while now, conflict signal, its a real-time global conflict map. wanted to post here because the thing im most interested in getting feedback on is the alert pipeline specifically.

Quick context on data: tried ACLED first but its gated behind org affiliation and needs a commercial license for anything SaaS-shaped. tried GDELT too but retired it, false positive rate was too high to be usable. ended up building live extraction from news via groq instead, which is now the only event source.

The part i actually want opinions on: alerts only fire once independent sources cross a corroboration threshold, and theres a full alert history feed (including expired ones) so you can go back and check whether an alert held up or not. No invented confidence scores, just source counts and honest "as of" timestamps on anything that lags (FIRMS thermal data especially).

No login needed for any of this, the 7-day timeline and all the base layers are open.

link: conflict-signal.vercel.app

Genuinely want the OSINT angle here if the corroboration threshold is too loose/strict, or if there's an obvious gap in how im sourcing events, tell me. I just want it to actually be useful to people who do this for real.

If you have time then please tell me any missing things which I should cover or harden any existing logic.

I have attached a quick screenshot if you wanna check out


r/OSINT 5d ago

Analysis Using advanced techniques to determine if a ship is laden - Open Source Centre

6 Upvotes

Research by the Open Source Centre (OSC) that used a combination of "high-resolution imagery, the construction of a high-fidelity digital twin and trigonometry". It's pretty advanced stuff, that won't be easily applicable in your average run-of-the-mill OSINT-research. But it sure makes for an interesting read.

https://stories.opensourcecentre.org/signal-in-the-shadows/


r/OSINT 7d ago

Tool Web Annotation Google Keep

4 Upvotes

When doing webint as part of an investigation. I am trying to figure out what the best way is to take notes about the websites themselves or their content.

Currently based on my understanding I'm familiar with two types of tools for this. One is web clipping. And the other is web annotation.

Are there other categories of tools that people use for this particular kind of task?

What are people's preferred work flows/ tool stack for this type of task?

Today I came across the chrome plugin for Google keep. Are there people here that already use Google keep in this way? Are there possible limitations or drawbacks of I using Google keep in this way that are good to aware of?


r/OSINT 9d ago

Question How useful is the platform Blind?

22 Upvotes

Has anyone used the anonymous business platform Blind ( https://www.teamblind.com/) ? That's the best way I can describe it.

If you have used Blind in your research, what was the use case? Did it provide any useful findings/evidence? What didn't you like about Blind as a source?

I've been reluctant to get an account because a work email is needed for full access and I'd rather not provide that. Has anyone successfully signed up using a free email service provider?


r/OSINT 11d ago

How-To Monitoring the Shadow Fleet

71 Upvotes

If you wanted to identify shadow fleet vessels loaded with sanctioned oil using open source tools, how would you do it? What tools would you use and what would be your process?
Challenge: could anyone here identify a suspected ship now?


r/OSINT 14d ago

How-To OSINT challenge explanation needed

4 Upvotes

BLUF: How would one narrow down a location from a photo background, particularly the floor pattern? I tried Bellingcat OSINT challenge "Cold Case" under "Background Check", but I got stuck on the location narrowing down part. I already looked up what the answer is, so I don't care about that part, but I want to figure out the correct steps to arrive at the solution. Reverse image searching gives multiple suggestions all over Asia, and even when narrowing down to South Korea. One blog said they built a database of floor tiles or designs, which seems a bit an overkill.


r/OSINT 14d ago

Analysis How U.S. Satellite Imagery Restrictions Are Changing How We Report on Iran

Thumbnail
nytimes.com
39 Upvotes

submission statement: U.S. satellite imagery restrictions have hindered reporting on the Iran war, with five providers blocking high-resolution images of Iran and surrounding countries. These restrictions, rooted in national security concerns, have been a challenge for journalists, but alternative sources like international satellite providers and public data offer workarounds. Despite these limitations, satellite imagery remains a crucial tool for uncovering military actions and potential war crimes.


r/OSINT 19d ago

Question Is OSINT automation actually doable?

42 Upvotes

With all the anti-bot protections, CAPTCHAs, rate limits, login walls, websites blocking scrapers, constantly changing page layouts, and platforms banning or restricting automated access…

Even paid APIs are incomplete, outdated, or return weak / inaccurate data about the target.

How do people building OSINT tools deal with this in practice?


r/OSINT 20d ago

How-To Cancelling Spokeo subscription

37 Upvotes

To anyone struggling with cancelling the Spokeo subsription heres how to do it. They are scammy and try to hide how to do it and their official instructions are incorrect https://help.spokeo.com/hc/en-us/articles/115010516568-How-do-I-cancel.

What you need to do is go to https://www.spokeo.com/user/account. Look for "If you have any questions about your plan or billing, need help searching, or want to manage your membership, you can view our support contact form [here]()." The word here is a link. Click that and it give you a drop down. Select "I would like to terminate my membership", which then renders a button "TERMINATE NOW ANYWAY"


r/OSINT 26d ago

Tool OSINT of Malaysia

27 Upvotes

OSINT toolkit for Malaysia:
https://unishka.substack.com/p/osint-of-malaysia

Feel free to let me know in the comments if we've missed any important sources.

You can also find toolkits for other countries that have been covered so far on UNISHKA's Substack, and our website.
https://substack.com/@unishkaresearchservice
Website link: https://unishka.com/osint-world-series/


r/OSINT 28d ago

Question Is there a lot of gatekeeping here in the osint community?

194 Upvotes

There seem to be many people who seem extremely hesitant or outright refuse to even try to help you in your search on here. I could ask, "How can I use this email address to find out more information about it?" and everyone would try to give you the most tame email address finder #1 top of the Google list result ever.

It didn't deter me, and I was still able to find what I needed after hours of searching, thankfully. However, is this how it usually goes? Do people just refuse to give information out just to gatekeep it even though they know it's on github?


r/OSINT Jun 18 '26

Question Best open-source or low-cost toolchain to map historical social graphs? [No Enterprise SaaS]

25 Upvotes

Are there any cheap or open source solutions to get historical social graphs either by account or industry or keyword/tag?


r/OSINT Jun 10 '26

OSINT News How Predators use Marketing Tools, AI & Bad UK Regulations to get into your Kid’s Bedroom The Digital Predator Toolkit "Yellow Bus"

Thumbnail
secevangelism.substack.com
272 Upvotes

r/OSINT Jun 09 '26

Question How to Narrow Down a Search Area Using Past Weather Data?

43 Upvotes

Is there a way to view a weather map like this for a specific date in the past? For example, if an account shares a screenshot showing a phone wallpaper with the exact date and temperature, being able to see which cities in a given country had that exact temperature on that exact day could be very useful.


r/OSINT Jun 07 '26

OSINT News OSINT Powered Student Evacuation from Occupied Ukraine

Thumbnail
secevangelism.substack.com
81 Upvotes

r/OSINT Jun 07 '26

Question what are the biggest gaps in current media verification workflows?

59 Upvotes

im part of a student team researching digital media verification and authenticity in the age of AI-generated content

while exploring this space, we've noticed that many tools focus on identifying whether content may be manipulated, but often provide limited insight into why a conclusion was reached or what evidence supports it

we're interested in learning how people working in OSINT, investigations, journalism, and related fields currently approach media verification

A few questions we'd love to hear your thoughts on:

  • what types of content are currently the hardest to verify?
  • what are the biggest limitations of the tools and methods you use today?
  • how important is explainability when evaluating a verification result?
  • are AI-generated images, videos, or audio creating new challenges in your workflow?

we r conducting a short research survey (takes <5 mins) to gather perspectives from professionals and practitioners in this space:

https://forms.gle/2WkK91kHVfqSNGfQA

we're still in the research and validation stage, so honest criticism and opposing viewpoints are genuinely welcome. our goal is to better understand the problem before deciding what solutions are actually worth building

thank you for your time!!


r/OSINT May 30 '26

Tool OSINT of Ukraine

130 Upvotes

OSINT toolkit for Ukraine:
https://open.substack.com/pub/unishka/p/osint-of-ukraine

Feel free to let me know in the comments if we've missed any important sources.

You can also find toolkits for other countries that have been covered so far on UNISHKA's Substack, and our website.
https://substack.com/@unishkaresearchservice
Website link: https://unishka.com/osint-world-series/


r/OSINT May 29 '26

How-To Is There a way to reverse such clustered images in a single forum/page?

37 Upvotes

So, in instagram OSINT, i found a person that has an account with everything absolutely being a dead end, no username give away, no posts or location, gibberish or following patterns that are hard to pin down, classic dorking doesn't give back any results, not much account history, but it has been lurking in my followers list for quite a while now.

However, there's a highlight, of two cats. And the account pfp is a Pinterest mirror selfie image that i reverse searched. Now, a single image search returns thousands of results for such an image, however, if an account has three of those distinct images saved simeltanously in a public board, the pool of potential candidates reduces drastically, ofcourse, given the profile is public, which is 50/50 in pinterest so there may be a chance.

Is there a way to reverse search multiple images and see if it comes from the same page?


r/OSINT May 26 '26

How-To Another lesson on why we don't accept active investigation posts

578 Upvotes

This morning the subreddit received a post attempting to expose an online ring dealing in Child Sexual Assault Material (CSAM). While we all agree that these networks can and should be investigated using OSINT methodologies, making unverified accusations against both criminal and potentially innocent individuals on a public forum is dangerous and can jeopardize this entire community. We have a strict rule on this and usually only send out reminders when something big happens in the news. However after the mod team removed the post, the OP sent us private messages suggesting that our removal meant we support child abuse. Because of this, I believe it is necessary to break down exactly why their post, despite its likely noble intentions, is actively harmful to our sub, to the integrity of OSINT, and to the OP themselves. Here is MY investigation into why his AI slop is just that.

The report was clearly AI-generated, they even left the Claude artifacts in their markdown file, and makes so many speculative leaps that I’m embarrassed Claude even output that junk but with that said I have altered the specific identifiers below to protect anyone involved and made some top finds. There were plenty more, but here are the major methodological failures in the report:

1. The Shared IP Address Fallacy

  • The Claim: The report links DARKNET-MADEUP.net to the current server.org infrastructure because they shared the IP 1.1.1.1.1, emphatically stating this means they were on the "SAME PHYSICAL SERVER" and confirms "operator continuity."
  • The Flaw: In modern web hosting, particularly with VPS environments, shared hosting, and reverse proxies, thousands of entirely unrelated websites routinely share a single IP address. Unless an analyst can definitively prove this was a dedicated, single-tenant IP, using a shared IP as proof of organizational lineage is a fundamental OSINT error.

2. The "Bulletproof Host" Correlation Error

  • The Claim: The report groups dozens of domains into "clusters" largely because they share the same hosting providers, specifically DARKNET-MADEUP.net #1, #2, and #3.
  • The Flaw: These types of providers are widely known in the cybersecurity space as "bulletproof" or "free-speech" hosts, meaning they resist or ignore abuse complaints. Because of this lenient policy, completely unrelated controversial, illicit, or dark-web entities flock to them. Co-location on these servers does not prove a shared umbrella organization; it simply proves they are using the same lenient vendor.

3. Server Hostname / Identity Fallacy

  • The Claim: The analyst attempts to unmask the real-world identities of the operators based on server subdomains, listing "JOHN" as an operator because a mail server is named John.email.org, and "JASON" due to a reverse DNS (PTR) record of Jason.email.org.
  • The Flaw: System administrators notoriously use thematic naming conventions for their infrastructure (e.g., Greek gods, planets, fictional characters). Assuming a server named "John" is actually run by a human being named John is an amateur analytical leap.

4. Geographic Misattribution

  • The Claim: The report asserts a "Mexico geographic indicator (highest specificity)" for the operator simply because a server is hosted in an "Amazon" data center and named "correo" (the Spanish word for mail).
  • The Flaw: "Amazon" is a massive, global cloud provider. Anyone in the world can rent a server in an Amazon location with a single click. Furthermore, it is a common sysadmin quirk to name a server using the local language of the data center's physical location. This in no way confirms the operator's actual nationality or physical location.

5. Weak Image Metadata Attribution

  • The Claim: The report identifies "John Doe" as an operator because their name and Facebook Ad ID appeared in the Canva PNG metadata of a logo on one of the network's portals.
  • The Flaw: Canva is a template-driven graphic design platform. It is highly likely the operator simply grabbed an existing graphic, template, or stock image originally created by "John Doe" and repurposed it. The metadata points to the original creator of the Canva asset, not the individual who deployed it on the illicit server.

The Most Egregious Leaps in Logic

The list above could go on, but my personal "favorite" highlights from the report revolve around physical and operational security. The report states that physical mail addresses used for donations are "single-use, destroyed after use" and claims that if a Bitcoin wallet is obtained, "full transaction history is traceable on-chain."

  • The Reality of Physical Mail: Claiming a PO box or physical address is "destroyed after use" is a dramatic assumption that is physically impossible to prove via passive OSINT.
  • The Reality of Crypto: While Bitcoin ledgers are public, modern illicit networks almost universally use tumbling/mixing services, coin-joins, or chain-hopping (e.g., converting BTC to Monero and back) before cashing out. Simply obtaining a BTC address does not guarantee a traceable path to a human identity unless the operator makes the amateur mistake of cashing out directly to a KYC-compliant (Know Your Customer) exchange.

The OP of this report is demonstrating what threat intelligence professionals call "parallel construction through OSINT." They clearly have a pre-existing theory about who runs this network, and they are cherry-picking standard, mundane internet noise: shared IPs, common server configurations, open-source forum posts, and dictionary words, and dressing it up as "definitive proof" to fit their narrative.

This is exactly why we vet posts and remove those that substitute AI-generated storytelling for actual investigative rigor.


r/OSINT May 25 '26

Tool built a local tool to find mutual followers between two Instagram accounts

91 Upvotes

I put together a tool to check the mutual followers between two or more Instagram accounts. It works for both public accounts and private accounts, provided you currently follow the private ones

It runs on a locally so you need to download it and run it from terminal (not too hard)

https://github.com/OscarFromNZ/InstagramMutualFollowerChecker

Thanks! This is a very early version, I'd really appreciate honest feedback if anybody wants to set it up (it's real quick) and try it out themselves