Tell me what you have, or pick a starter below. I will point you to the right CSINT page and the next safe step.
CSINT Research
An independent research desk built on open sources.
Documented case files, live threat data, and in-browser verification tools in one place. Evidence and interpretation always stay separate on this desk.
Where to start?
Case readings
All readings →A floppy disk did not catch a killer on its own. The technical traces and DNA chain in the Wichita case
Online retellings often reduce this case to one sentence. A killer forgot his name on a floppy disk and the police caught him. In reality, the disk only pointed investigators in a direction. That lead was tested through open web research, security footage, surveillance, preserved biological evidence, and a targeted kinship DNA comparison authorized by a court. This article follows the evidence chain rather than the legend.
How a phishing campaign moved from an email to session token theft
A Microsoft report shows that modern credential phishing is no longer limited to a fake sign-in page. This file examines how a code-of-conduct email, a document attachment, and several redirect steps formed one social engineering chain.
The fuel blockade that locked a city's supply routes
The city's fuel crisis was not the result of one attack. Open source traces connected vehicle attacks, satellite imagery, videos, and growing queues to the same pattern of pressure.


