Cybercrime DB

OSINT Techniques Used to Identify Cybercriminals

Investigators layer public records to build airtight criminal profiles.

Correspondent · · 11 min read
Cover illustration for “OSINT Techniques Used to Identify Cybercriminals”
cybercrime investigations · September 29, 2026 · 11 min read · 2,571 words

OSINT stands for open source intelligence, and in plain terms it means gathering up whatever's already sitting in public view: websites, social media posts, DNS records, GitHub commits, photos, metadata, open ports on a server. None of it is hidden. All of it is legal to look at. Both sides know this. Attackers and defenders draw from the exact same well of public information, so the whole game comes down to who acts on a signal first and who reads it more carefully.

That race has real stakes attached to it. That's a mainstream discipline now. That's an entire industry racing to keep pace with criminals who are, frankly, pretty good at hiding in plain sight.

Attribution, done right, is a patient chain of small, verifiable connections built layer by layer. It's a chain: start with infrastructure, move to identity, extract what's buried in metadata, watch where the criminal chatter lives, and, where money's involved, follow it on-chain. Each layer either confirms or kills the last one. This piece walks through that chain in the order investigators actually build it. The FBI's Internet Crime Complaint Center reported more than USD 20.8 billion in losses from cyber-enabled crime in 2025, a figure that makes early, well-attributed threat intelligence a priority trmlabs.com. Global Market Insights valued the global OSINT market at USD 12.7 billion in 2025 and projects it will reach USD 133.6 billion by 2035 at a 26.7% CAGR Top 15 OSINT Tools For Cybersecurity In 2026.

Structuring the OSINT process before touching a single tool

Group-IB frames the whole discipline as a four-stage cycle: collection, processing, analysis, dissemination. Every technique in this article, from WHOIS lookups to blockchain clustering, slots into one of those four buckets. Skipping a stage makes confidence in the finding drop fast.

OSINT is also just one member of a five-discipline family that includes HUMINT, SIGINT, IMINT, and MASINT. Knowing where OSINT stops and human intelligence starts shapes hybrid investigations, where a forum post needs a human source to confirm what it actually means.

OSINT is passive by design. No hacking, no social engineering, no sneaking past access controls. The ethics aren't bolted on as an afterthought, they're baked into the method itself.

That passivity has a catch, though, and it trips up people who assume "public" means "invisible." Maltego's transforms, for instance, often query third-party services by sending the target domain as a parameter, and a sharp threat actor watching their own infrastructure logs might just see that query land. Passive collection has to stay passive all the way down, not just in spirit.

Before running a single query, the smart move is mapping out the intended pivot chain. A domain registration can lead to a registrar, then a registrant email, then a cluster of associated domains, then IP history, then the ASN, then a whole neighborhood of peer infrastructure. Knowing that chain ahead of time saves wasted queries and, more importantly, avoids tipping off the target before there's anything solid to show for it.

Starting with infrastructure: what domain registrations, IP addresses, and exposed services reveal

Infrastructure is where most investigations begin, and for good reason. Domain enumeration, WHOIS analysis, and passive DNS monitoring catch lookalike and impersonation domains before a phishing campaign even goes live.

theHarvester is the workhorse here: one command-line pass and it pulls names, emails, IPs, subdomains, and URLs from dozens of public sources, effectively mapping out a domain's external threat landscape in a single shot. OWASP Amass picks up where footprinting leaves off, mapping attack surfaces and discovering external assets through a mix of open source gathering and active reconnaissance.

Then there's Shodan, which indexes just about anything connected to the internet: servers, routers, webcams, industrial control systems, random IoT devices nobody remembered to secure guptadeepak.com. It's how investigators spot open ports, exposed services, and outdated software tied to a threat actor's infrastructure, and individual access runs $49 as a one-time cost guptadeepak.com. Censys covers similar ground but with an edge in certificate transparency logs, which makes it the sharper tool for finding phishing and typosquat domains. Most enterprise threat intelligence programs run Shodan and Censys side by side rather than picking one.

One phishing domain leads to a registrant email, which leads to a cluster of related domains, which leads to a shared hosting ASN, which leads to a much bigger piece of criminal infrastructure. All of it sitting in public records, no intrusion required. The urgency driving all this hunting is not evenly spread, either. Financial services absorbed 68.45% of the phishing attacks Group-IB tracked globally in 2025, with government and military at 9.19% and internet services at 8.78% Group-IB High-Tech Crime Trends Report 2026. That's where infrastructure hunting earns its keep first.

Tracing usernames and social profiles across platforms to build an identity picture

A username is rarely a one-off. Criminals reuse handles across forums, gaming networks, and code repositories where they were, frankly, a lot less careful than on the dark web market they thought was buttoned up.

Sherlock exploits exactly that habit. Feeding it one username causes it to hunt across more than 400 social networks, returning matches across a footprint most people didn't realize they'd left OSINT Tools in 2026: The Reconnaissance Layer | cloro OSINT Framework: What It Is, How It Works, and the Best Tools. From there, profile analysis takes over: bios, location clues, follower counts, post history, all stitched into a behavioral profile that can tie an anonymous alias back to a real person.

Network mapping adds another dimension, charting who follows whom, who mentions whom, who reposts whom, laying bare relationships between accounts that might otherwise look unconnected. This matters most when a "lone" threat actor turns out to be one persona among several run by the same small group.

None of this works in isolation, though. A username match by itself proves nothing, so analysts cross-check writing style, time zone patterns, shared images, and reused phrases across multiple independent sources before calling it confirmed. This social media layer, known formally as SOCMINT, isn't a side quest in the investigation. For a lot of cybercriminal cases, it's the exact point where a vague online persona turns into a name and a face.

Extracting intelligence from metadata embedded in files, images, and code repositories

Text is only part of the picture. Images, videos, metadata, DNS records, and GitHub commits are all fair game for collection, and often the richest part of the haul.

Photos carry EXIF data: GPS coordinates, camera model, timestamp, software version, all quietly riding along with the pixels. A threat actor who shares one careless screenshot of their setup has, in more than a few cases, handed investigators a location within a few kilometers without meaning to.

Documents leak in their own way. PDFs and Office files carry author fields, revision histories, software version strings, and internal file paths, and these artifacts have shown up in actual law enforcement attribution cases. Code repositories are their own goldmine: leaked API keys, tokens, internal hostnames, and commit author emails. Red teams use theHarvester and manual repo review as a standard part of reconnaissance, and defenders run the same playbook in reverse to catch what a criminal group left exposed.

Video and audio round out the picture, with timestamps, background noise, visible landmarks, and even screen reflections counted as a formal OSINT technique category. Collecting all this is mostly mechanical, honestly, a matter of knowing where to look. Interpreting it, figuring out what a specific timestamp pattern says about someone's time zone, work schedule, or team size, is where the actual analyst earns their paycheck.

Monitoring dark web forums and encrypted messaging platforms where criminal activity surfaces

Sometimes the highest-signal starting point is already sitting out in the open, waiting for anyone patient enough to look. It's already leaked: stolen credentials, session cookies, infostealer logs, forum chatter sitting out in the open for anyone patient enough to look. SpyCloud recaptured 53.3 billion distinct identity records in 2024, a 22% jump year-over-year, with nearly 80% of breaches tracing back to stolen credentials. That's the scale of exposure investigators are wading through.

Telegram has become something close to a criminal operations hub, and tools have followed the criminals there. Telegago runs as a Google Custom Search Engine built for OSINT research on public Telegram content, letting analysts search keywords across channels and groups to track conversations tied to cybercrime. VenariX takes a more automated approach, built for cyber threat monitoring and ransomware tracking, with a Telegram bot that fires off real-time alerts whenever a new ransomware victim claim or extortion post goes live.

Coverage gaps are opening up, though. Criminal activity is drifting into I2P and other alternets beyond Tor, and a lot of teams haven't caught up to that migration yet. CACI's DarkBlue Intelligence Group hosted the second annual Dark Web and OSINT Summit in July 2026, and alongside CACI Ltd. UK presented findings on the Funksec cybercrime kit at ISS World Europe 2025 in Prague, which gives some sense of how specialized this corner of the field has become. Monitoring non-standard protocols continuously isn't something most enterprise teams can staff on their own. Specialist tradecraft and outside support tend to fill that gap.

Blockchain forensics: turning on-chain transactions into threat actor attribution

Money leaves a trail that forums and servers don't. Chainalysis revised its illicit cryptocurrency transaction estimate for 2024 up to $57.2 billion, well above the original $40.9 billion figure, with 63% of that volume moving through stablecoins OSINT Framework: What It Is, How It Works, and the Best Tools. Even after a criminal wipes a server or a forum gets taken down, the ledger remembers.

The core technique is clustering: grouping wallets together, tracing funds as they hop across chains, and attaching real names to addresses that started out as anonymous strings of characters. Criminals don't make that easy, of course. Chain-hopping, mixing services, and layering funds through DeFi protocols are all standard laundering moves, and SANS FOR589 teaches analysts how to follow that trail and pair it with off-chain data to link transactions back to actual people.

On-chain data alone rarely closes the loop, though. An exchange's KYC records, a forum post that name-drops a wallet address, a regulatory filing, any one of these can anchor a blockchain cluster to a real individual, but neither the on-chain data nor the off-chain clue is enough by itself. They need each other.

Assembling the pivot chain: how each layer of evidence connects to the next in a real investigation

INTERPOL's Operation Secure, run in April 2025, shows the whole chain working end to end Group-IB High-Tech Crime Trends Report 2026. Group-IB's High-Tech Crime Trends Report 2026 documents how dark web activity and Telegram accounts tied to Lumma, Risepro, and META Stealer distribution fed intelligence into the operation, which ended with 32 arrests and the takedown of more than 20,000 malicious IPs and domains Group-IB High-Tech Crime Trends Report 2026. Dark web monitoring led to Telegram account analysis, which led to malware distribution infrastructure, which led to IP and domain takedowns, which led to arrests. Every technique covered in this article contributed a link somewhere in that sequence.

Maltego tends to be the tool that physically holds the chain together. The Graph (Browser) release, version 2.19.0, shipped in June 2026 with an AI assistant and credit usage tracking built in decryptiondigest.com. Budget matters here too: Maltego's Entry Standard tier runs 3,000 euros a year for 10,000 credits a month, while Professional Standard runs 7,500 euros a year for 20,000 credits monthly across up to five seats Group-IB High-Tech Crime Trends Report 2026 guptadeepak.com.

None of this earns the label "attribution" off a single artifact, however striking that artifact looks. The standard is corroboration across at least three independent sources. The most effective setups pair automation, which handles collection and triage, with skilled analysts who validate the findings and bring in human sources where needed, a combination that improves accuracy and cuts down false positives. And none of it stays finished. Adversaries evolve their tactics, rotate infrastructure, and abandon burned identities, so the pivot chain has to get rebuilt continuously rather than filed away as a closed case.

Failures in attribution from open-source information and safeguards against common errors

Raw OSINT is unverified by nature, and that's the root of most attribution failures. Misattributed IP addresses, false positives, and stale WHOIS records have steered investigators toward the wrong person more than once, and cross-verifying across multiple independent sources is the fix, even though it eats up time and resources.

Volume is its own problem. There's simply too much public data out there, and without automation to filter it, analysts spend more time sorting signal from noise than actually investigating anything. That's the real argument for platform-level tooling over just collecting a pile of favorite individual tools.

Adversaries know they're being watched, too, and some plant false flags or deliberately reuse infrastructure to muddy attribution, creating persona confusion on purpose. The same verification discipline that catches honest mistakes catches most of this deception as well.

The OPSEC risk from earlier in the process resurfaces here as a failure mode in its own right. Maltego transforms that send a target domain to third-party services as a query parameter can tip off a sophisticated adversary watching their own domain logs, alerting them to the exact investigation trying to stay quiet. Dark web coverage gaps compound the problem, since criminal activity migrating into I2P and other alternets creates blind spots for any team that hasn't updated its collection posture.

Legal boundaries aren't optional extras, either. OSINT depends entirely on publicly available information gathered through legal means, no hacking, no credential stuffing, no getting around access controls, and staying inside those lines is what makes a finding usable in a law enforcement context later. Timing closes the loop on all of it. Threat intelligence has a short shelf life, and by the time a finding gets manually discovered, processed, and written up, the actor may have already rotated infrastructure and moved on. Real-time alerting isn't a luxury feature bolted onto a platform, it's the baseline requirement for OSINT that's actually still useful when it lands.

Using content grounded in open-source information to build credibility with practitioner audiences

Practitioners reading vendor content are not a casual audience. Given that 94% of cybersecurity professionals named AI as the main catalyst reshaping cybersecurity, the readers evaluating a vendor's content are the same ones evaluating these techniques daily, and they can immediately spot shallow or inaccurate treatment.

That's where a lot of vendor content quietly falls apart. Publishing OSINT material built around keyword volume instead of live threat intelligence sends exactly the wrong signal to exactly the buyers a vendor is trying to reach. It reads as marketing dressed up as expertise, and practitioners can tell the difference fast.

What actually earns trust is demonstrated knowledge of how these investigations really run, the pivot chain, the failure modes, the OPSEC considerations, not brand storytelling and not a parade of tool names dropped for effect. Anchoring content in live, dated threat intelligence helps too. Figures like Group-IB's 68.45% financial services phishing share for 2025 or SpyCloud's 53.3 billion recaptured identity records carry more weight with a practitioner audience than any adjective a marketing team could reach for Group-IB High-Tech Crime Trends Report 2026. Specificity is the whole pitch. Vague confidence doesn't survive contact with someone who runs Shodan queries before breakfast guptadeepak.com.

Sources

  1. Top 15 OSINT Tools For Cybersecurity In 2026
  2. Open Source Intelligence (OSINT): Techniques & Uses | Group-IB
  3. OSINT Framework: What It Is, How It Works, and the Best Tools
  4. OSINT Tools in 2026: The Reconnaissance Layer | cloro

More in cybercrime investigations