Claudia Tietze, founder of the OSINT boutique Farallon LLC, has used this free note-taking app to reconstruct Russian espionage networks, track the transfer of Ukrainian minors before official confirmation, and uncover a money-laundering scheme within a complex corporate structure.
The method: a random vault, YAML metadata as a custom schema, Wikidata as the semantic layer, and a native relational graph extended with community plugins (Wikidata Importer, NLP/Graph Analysis, Juggl, Semantic Canvas).
The interesting detail isn’t the list of plugins. It’s where the method sets its own limits: the HITS and Jaccard scores produced by Graph Analysis do not prove causation or intent—they remain leads to be verified against the original documents, not conclusions.
For those working with OSINT, there are two transferable lessons: → separating “unlinked mentions” from “confirmed links” keeps ambiguity visible rather than forcing it into a premature conclusion → a YAML schema tailored to the specific case allows a general-purpose ontology (Wikidata) to answer a narrow investigative question
Full article (method, plugin, critical issues) →
The Drone That Follows a Thread. How to verify tactical strike videos
A tactical video can show impact, but it does not automatically prove location, date, method or intent.
A strike video is not evidence by itself.
It is a claim with images attached.
That distinction matters when footage appears on Telegram, X, YouTube or a mirrored channel with a confident caption and a few seconds of apparent certainty.
The new ProjectOSINT post looks at recent reporting on fibre-optic FPV drone strikes against Ukrainian electrical substations and turns it into a verification workflow.
The method is simple:
preserve
separate
geolocate
corroborate
classify
limit
A video may show impact.
It does not automatically prove location, date, method, repetition or strategic intent.
Full post:
Case: On July 20, 2026, Misbar reported that a viral video claiming to show Iranian sailors shooting down a U.S. helicopter with an advanced Russian missile was fake. The clip circulated on X with captions saying Russia had supplied Iran with thousands of anti-helicopter missiles. Misbar classified the video as AI-generated, not authentic footage of a real military incident.
The mistake was accepting a dramatic military video as battlefield evidence before verifying its origin, authenticity, and technical plausibility.
In conflict-related OSINT, a video should never be treated as proof simply because it looks realistic or matches an ongoing geopolitical narrative. The correct question is not:
“Does this look like war footage?”
The correct question is:
“Can we prove this was filmed at that place, on that date, by a verifiable source?”
In this case, the answer was no.
This type of mistake is dangerous because the claim involves a direct military confrontation between Iran and the United States. If accepted uncritically, it could lead analysts, journalists, or social media users to falsely conclude that a major escalation had occurred.
The analytical risk is high:
false attribution of an attack;
amplification of AI-generated war propaganda;
incorrect assessment of U.S.–Iran escalation;
contamination of OSINT reports with synthetic evidence;
increased panic during an already tense information environment.
Several warning signs made the video unsuitable as evidence:
1. No primary source chain
The clip circulated through social media accounts, not through official military channels, verified media, or a traceable original uploader.
2. Extraordinary claim, weak evidence
A U.S. helicopter allegedly being destroyed by Iranian sailors would be a major international incident. Such a claim requires strong corroboration, not a single viral video.
3. AI-generation indicators
Misbar reported the video as AI-generated, meaning the visual content itself could not be used as documentation of a real event.
4. Narrative convenience
The claim combined Iran, the U.S., Russia, missiles, and naval confrontation — exactly the kind of high-emotion geopolitical package that often drives viral disinformation.
A professional analyst should have done the following:
Step 1 — Preserve the claim
Archive the post, caption, uploader, timestamp, platform, and engagement metrics.
Step 2 — Extract keyframes
Use InVID-WeVerify, ffmpeg, or manual screenshots from the clearest frames.
Step 3 — Reverse-search the frames
Look for earlier uploads, AI-content origins, repost chains, or identical synthetic clips.
Step 4 — Check official and independent corroboration
A real shootdown involving U.S. forces would likely trigger statements from U.S. Central Command, Iranian authorities, major wire services, or maritime/security monitors.
Step 5 — Assess technical plausibility
Check whether the weapon, launch platform, helicopter type, sea conditions, camera angle, and explosion behavior are coherent.
Step 6 — Label confidence clearly
The correct assessment would be:
“The video is AI-generated and cannot be used as evidence of an Iranian attack on a U.S. helicopter.”
The high-risk pressure campaign the United States is applying against Tehran is rapidly drifting into a strategic stalemate, raising the possibility of a broader and potentially devastating war across the Middle East.
Recent U.S. intelligence assessments reportedly indicate that American military strikes inside Iran have not changed Tehran’s strategic calculus, nor have they forced meaningful concessions at the negotiating table. Instead, both Washington and Tehran appear locked in an unstable deadlock, where each side is escalating pressure without achieving decisive leverage.
According to Fox News reporting, President Trump is expected to make a decision in the coming days on whether to intensify the military campaign in coordination with Israeli forces. At the same time, rhetoric from Iranian hardliners is becoming more aggressive. Former Iranian Foreign Minister Manouchehr Mottaki has openly floated a radical countermeasure: ground incursions against U.S. military bases in Kuwait, Iraq, and Bahrain, with the stated aim of capturing up to 200 American soldiers and forcing Washington into an immediate retreat.
From an OSINT perspective, the key signal is not only the military activity itself, but the speed at which public rhetoric, media narratives, and strategic signaling are converging toward escalation. Military strikes that were intended to deter Tehran may instead be accelerating the logic of confrontation. If both sides interpret restraint as weakness and escalation as credibility, the risk of miscalculation increases sharply.
The current information environment is also highly unstable. Public statements, leaks, media briefings, and unofficial threats are shaping perceptions in real time. In such a context, OSINT analysts should distinguish carefully between verified military movements, political signaling, psychological pressure, and speculative threat narratives. Not every threat indicates imminent action, but repeated public discussion of hostage-taking, regional strikes, and joint military escalation lowers the threshold for crisis behavior.
The most dangerous development is that escalation is no longer being framed as an exceptional option, but as an increasingly available policy choice. Washington is reportedly weighing broader regional bombing options, while Iranian hardliners are promoting retaliatory ground operations and hostage-taking scenarios. This combination narrows the space for diplomacy and increases the likelihood that a single incident could trigger a chain reaction.
If the White House chooses a major escalation, the consequences could extend far beyond Iran. Gulf states hosting U.S. forces, Israel, Iraq, Bahrain, Kuwait, and thousands of American military personnel could all be pulled into a multi-front confrontation. The result would not simply be another round of strikes, but a regional crisis with the potential to spiral beyond direct U.S. or Iranian control.
For OSINT practitioners, the central takeaway is clear: this is a moment where rhetoric, military posture, and media signaling must be monitored together. The risk is not only what each side plans to do, but what each side believes the other is preparing to do.
Favicons — the small icons displayed in browser tabs — can be powerful OSINT indicators for identifying fraudulent websites and mapping threat actor infrastructure.
✅ Detect fraudulent websites
Favicons can help identify fake websites impersonating legitimate brands, especially when scammers copy visual elements from real platforms.
✅ Identify connected domains
Threat actors often reuse the same favicon across multiple fraudulent websites. This reuse can reveal links between domains that might otherwise appear unrelated.
✅ Expose hidden infrastructure patterns
A shared favicon can act as a pivot point, helping analysts uncover networks of scam sites, phishing pages, or impersonation domains.
For example, a scam operator may run several fake online stores using different domain names while reusing the same favicon across all of them. That small visual detail can expose a broader fraudulent network.
In OSINT, even minor website elements can become valuable investigative leads.
According to Israeli intelligence sources cited by the WSJ, Iran reportedly moved thousands of uranium-enrichment centrifuges last autumn into tunnels deep beneath Pickaxe Mountain.
If confirmed, the move would suggest a deliberate effort to harden key nuclear infrastructure against potential military strikes.
Open Source Intel@Osint613
Thousands of uranium-enrichment centrifuges were relocated by Iran into tunnels deep beneath Pickaxe mountain last fall, according to Israeli intelligence. - WSJ

8:04 AM · Jul 21, 2026 · 21.9K Views
31 Replies · 49 Reposts · 241 Likes
If this is useful, share it.
This is the weekly selection. But it’s not the only one.
If you’d like to read more: → full articles on the website
If you’d like to get the latest updates first: → Telegram
👉 https://t.me/osintprojectgroup
Location never lies.
It only waits to be decoded.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.