OSINT
Open source intelligence: piecing together what is already public to answer a real question. Who runs what, what is exposed, and what someone forgot to switch off.
OSINT ✦ Security reports ✦ Open data
OSINT, security reports and a soft spot for open data.
I dig through what the internet shares in public, spot what should not be out there, and report it privately to the people who can fix it.
example.com · illustrative
What I do
Open source intelligence: piecing together what is already public to answer a real question. Who runs what, what is exposed, and what someone forgot to switch off.
When something is exposed, I verify it, keep only what proves the point, and send the owner a clear private report with the steps to reproduce and fix it.
I love open data. Public datasets make research honest and repeatable, so I use them, cite them, and share back whatever helps the next person.
How I report
Spot it in public data. No logins bypassed, no passwords guessed, nothing broken to get there.
Confirm it is real with the smallest possible check, and keep only the evidence the owner needs.
A clear note to the owner: what, where, why it matters, and exactly how to fix it.
Once it is fixed, or after a fair wait, publish what others can learn from, with nothing that could hurt anyone.
Why open data
Data that anyone can read, check and reuse is how research stays honest. A finding built on open data can be verified by the next person, not just taken on trust.
Some of the public sources OSINT is built on
Free tool
Domains, IP addresses and AS numbers, straight from the registries’ own open data. No sign-up, no ads, 30 free lookups an hour.