- Chrome Extension for OSINT Web Capture
- Capture Evidence Quickly Before It Disappears
- Includes: OSINT Knowledge base, Video Download and Data Insights!
๐ฅ A Client Question Worth Sharing: How to Download a Video from Threads
A subscriber reached out this week with a problem: our Forensic OSINT Video Downloader supports most major social platforms, but Threads isn't one of them yet.
They had a video they needed to preserve โ and couldn't wait for us to ship support.
So we walked them through a manual workaround using nothing but Chrome. Sharing it here in case anyone else is in the same spot.
We're always here to help our subscribers, whether the tool covers it or not.
โ๏ธ ๐ง๐ต๐ฒ ๐๐ผ๐ฟ๐ธ๐ณ๐น๐ผ๐ โ ๐ฎ๐ฏ๐ผ๐๐ ๐ฎ๐ฌ ๐๐ฒ๐ฐ๐ผ๐ป๐ฑ๐:
1๏ธโฃ Open the Threads post in Chrome.
2๏ธโฃ Open DevTools โ three-dot menu โ More tools โ Developer tools (or F12).
3๏ธโฃ Go to the Network tab, click the Media filter.
4๏ธโฃ Reload the page (Ctrl + R). Network only captures requests made after it's open.
5๏ธโฃ A single .mp4 file will appear. That's it.
6๏ธโฃ Click the file name to open the raw video in a new tab.
7๏ธโฃ Right-click โ "Save video as..." Done.
โ No extensions, no sketchy third-party sites, no malware risk.
โ ๏ธ ๐ข๐ป๐ฒ ๐ถ๐บ๐ฝ๐ผ๐ฟ๐๐ฎ๐ป๐ ๐ฐ๐ฎ๐๐ฒ๐ฎ๐:
This gets you the file. That's it. No chain of custody, no timestamp, no hash, no proof of where it came from or when. For personal use, fine. For an investigation, not enough.
๐ก๏ธ ๐๐ณ ๐๐ผ๐ ๐ต๐ฎ๐๐ฒ ๐๐ผ ๐๐๐ฒ ๐๐ต๐ถ๐ ๐บ๐ฒ๐๐ต๐ผ๐ฑ, ๐บ๐ฎ๐ธ๐ฒ ๐ถ๐ ๐ฑ๐ฒ๐ณ๐ฒ๐ป๐๐ถ๐ฏ๐น๐ฒ:
๐ Hash the file immediately (SHA-256).
Windows: Get-FileHash video.mp4.
Mac/Linux: shasum -a 256 video.mp4.
๐ Document contemporaneously โ write notes as you go, not after. Capture full URL, date/time with timezone, username, post ID, view count.
๐ธ Screenshot the page, the DevTools Network panel showing the .mp4 request, and the source URL bar.
๐ป Note your environment โ browser version, OS, your name, reason for capture.
๐๏ธ Preserve the original untouched. Work from copies.
Done right, this gives you a defensible record proving how the video was obtained and that it hasn't been altered since capture.
โฑ๏ธ But it's manual, error-prone, and time-consuming. Miss a step and the evidence may not hold up.
๐ฏ ๐ง๐ต๐ฎ๐'๐ ๐๐ต๐ฒ ๐ด๐ฎ๐ฝ ๐ผ๐๐ฟ ๐ฉ๐ถ๐ฑ๐ฒ๐ผ ๐๐ผ๐๐ป๐น๐ผ๐ฎ๐ฑ๐ฒ๐ฟ ๐ณ๐ถ๐น๐น๐.
Every download generates a Video Evidence Continuity Report โ a single-page, digitally signed and timestamped PDF including:
๐ค Who captured it, what, when, and how
๐ Full source URL and platform metadata
#๏ธโฃ SHA-256 hash of the video file
๐ผ๏ธ 10 screen captures from the video as a visual reference
๐ Trusted timestamp anchoring the exact capture moment
Everything needed to establish authenticity and chain of custody โ automatically, every time.
We support most major social platforms, and Threads is on the roadmap. Until then, follow the manual steps above. For everything else, let us handle it.
๐ฅ A Client Question Worth Sharing: How to Download a Video from Threads
A subscriber reached out this week with a problem: our Forensic OSINT Video Downloader supports most major social platforms, but Threads isn't one of them yet.
They had a video they needed to preserve โ and couldn't wait for us to ship support.
So we walked them through a manual workaround using nothing but Chrome. Sharing it here in case anyone else is in the same spot.
We're always here to help our subscribers, whether the tool covers it or not.
โ๏ธ ๐ง๐ต๐ฒ ๐๐ผ๐ฟ๐ธ๐ณ๐น๐ผ๐ โ ๐ฎ๐ฏ๐ผ๐๐ ๐ฎ๏ฟฝ๏ฟฝ ๐๐ฒ๐ฐ๐ผ๐ป๐ฑ๐:
1๏ธโฃ Open the Threads post in Chrome.
2๏ธโฃ Open DevTools โ three-dot menu โ More tools โ Developer tools (or F12).
3๏ธโฃ Go to the Network tab, click the Media filter.
4๏ธโฃ Reload the page (Ctrl + R). Network only captures requests made after it's open.
5๏ธโฃ A single .mp4 file will appear. That's it.
6๏ธโฃ Click the file name to open the raw video in a new tab.
7๏ธโฃ Right-click โ "Save video as..." Done.
โ No extensions, no sketchy third-party sites, no malware risk.
โ ๏ธ ๐ข๐ป๐ฒ ๐ถ๐บ๐ฝ๐ผ๐ฟ๐๐ฎ๐ป๐ ๐ฐ๐ฎ๐๐ฒ๐ฎ๐:
This gets you the file. That's it. No chain of custody, no timestamp, no hash, no proof of where it came from or when. For personal use, fine. For an investigation, not enough.
๐ก๏ธ ๐๐ณ ๐๐ผ๐ ๐ต๐ฎ๐๐ฒ ๐๐ผ ๐๐๐ฒ ๐๐ต๐ถ๐ ๐บ๐ฒ๐๐ต๐ผ๐ฑ, ๐บ๐ฎ๐ธ๐ฒ ๐ถ๐ ๐ฑ๐ฒ๐ณ๐ฒ๐ป๐๐ถ๐ฏ๐น๐ฒ:
๐ Hash the file immediately (SHA-256).
Windows: Get-FileHash video.mp4.
Mac/Linux: shasum -a 256 video.mp4.
๐ Document contemporaneously โ write notes as you go, not after. Capture full URL, date/time with timezone, username, post ID, view count.
๐ธ Screenshot the page, the DevTools Network panel showing the .mp4 request, and the source URL bar.
๐ป Note your environment โ browser version, OS, your name, reason for capture.
๐๏ธ Preserve the original untouched. Work from copies.
Done right, this gives you a defensible record proving how the video was obtained and that it hasn't been altered since capture.
โฑ๏ธ But it's manual, error-prone, and time-consuming. Miss a step and the evidence may not hold up.
๐ฏ ๐ง๐ต๐ฎ๐'๐ ๐๐ต๐ฒ ๐ด๐ฎ๐ฝ ๐ผ๐๐ฟ ๐ฉ๐ถ๐ฑ๐ฒ๐ผ ๐๐ผ๐๐ป๐น๐ผ๐ฎ๐ฑ๐ฒ๐ฟ ๐ณ๐ถ๐น๐น๐.
Every download generates a Video Evidence Continuity Report โ a single-page, digitally signed and timestamped PDF including:
๐ค Who captured it, what, when, and how
๐ Full source URL and platform metadata
#๏ธโฃ SHA-256 hash of the video file
๐ผ๏ธ 10 screen captures from the video as a visual reference
๐ Trusted timestamp anchoring the exact capture moment
Everything needed to establish authenticity and chain of custody โ automatically, every time.
We support most major social platforms, and Threads is on the roadmap. Until then, follow the manual steps above. For everything else, let us handle it.
After an incident, everyone looks back.
The warning signs were there.
A post at 9 PM the night before. Specific language. Specific intent.
It was public. It was visible. Anyone could have seen it.
But nobody was watching that profile at 9 PM.
The post was deleted by midnight.
By the time investigators got involved the next day, it was gone. The only reason anyone knew about it was that someone remembered seeing it in their feed.
A memory is not evidence.
This is the scenario that keeps investigators up at night. Not the evidence you lost. The evidence you never knew existed.
Subject Monitoring won't solve every case. But it watches when you can't.
Public profiles. Scheduled checks. Automated alerts.
You get notified. You go capture. You preserve the evidence.
https://t.co/8n7Q7i1aHp
#OSINT #ForensicOSINT #DigitalForensics
Even when someone tries to hide online, their social network gives them away.
Kirby Plessas published the full methodology behind her Friend Overlap tool.
Compare two accounts. If they share many of the same connections, there's a strong chance they belong to the same person.
Scale it across platforms, and the patterns become an identity fingerprint.
What it can surface:
โ Alternate accounts behind different usernames
โ Cross-platform identities across IG, X, TikTok
โ Hidden friend lists reconstructed through friends-of-friends
โ Pseudonyms where the persona changed but the network didn't
Privacy settings hide content. They rarely hide structure.
And structure is often enough.
Full methodology:
https://t.co/ooRglhWxga
Want more like this?
The Forensic OSINT Friday 5 is free.
๐ฉ https://t.co/WwFzhYh2OA
Your subject posted something at 2 AM.
By 11 AM, it was deleted.
You found out at 3 PM. By then, it was gone.
No screenshot. No capture. No evidence that it ever existed.
You can't monitor every profile 24/7. You have cases to work. Reports to write. A life outside the screen.
But what if something was watching for you?
That's what we're building.
Subject Monitoring tracks any public profile on a schedule you set.
Every 10 minutes. Every hour. Daily.
When something changes, you get notified.
New post. Deleted post. Edited content. Username change. Profile update.
You don't have to be watching. The system is watching for you.
Coming this summer to Forensic OSINT.
Spring promo subscribers lock in +50% monitoring capacity. Permanently. 4,500 polls/month instead of 3,000.
https://t.co/8n7Q7i1aHp
How many times has key evidence disappeared before you even knew it existed?
#OSINT #ForensicOSINT #DigitalForensics
AI can only be trained on tasks where you can tell if the answer is right or wrong.
Chess. Code. Translation.
But most of what expert analysts do has no clean, correct answer to check against.
Jacob H at OSINT Combine breaks it down:
โ Inductive reasoning (what AI does well) โ patterns in data. Geolocation, translation, entity extraction.
โ Abductive reasoning (what defines good analysis) โ the best explanation from an incomplete picture. Recognizing that silence is itself a signal.
Two underappreciated judgment calls right now:
โ Knowing when to start โ which questions, in which order
โ Knowing when to stop โ there's always more to collect
A 2025 MIT study is worth noting. EEG scans showed that AI-assisted writers had the weakest neural engagement among all groups tested. 83% couldn't recall a sentence from their own writing 60 seconds later.
The researchers called it "cognitive debt."
The 90% of OSINT that depends on human judgment isn't a temporary gap waiting for the next model release. It's structural.
Full article:
https://t.co/L3gucoId5X
Want more like this? The Forensic OSINT Friday 5 is free.
๐ฉ https://t.co/WwFzhYh2OA
China has a social platform with 300M monthly users.
Most Western investigators have never touched it.
It's called Xiaohongshu (Little Red Book) โ and a rape victim's warning posted there led to a serial predator's conviction in London.
@bellingcat dropped a practical OSINT guide. The key points:
โ Search in Chinese, not English. English shows a curated bubble.
โ Censored content is a lead. Blanked-out posts and coded language signal where the sensitive conversations live.
โ Track by unique ID, not username. Display names change. The ID doesn't.
โ Capture fast โ content disappears.
The barrier is language, not access. And if you don't know which emojis substitute for sensitive terms, you'll misread entire threads.
A native speaker isn't optional for serious work here.
Full guide: https://t.co/FAnjaKyQlR
Want more like this? The Forensic OSINT Friday 5 is free.
๐ฉ https://t.co/WwFzhYh2OA
Coming this summer to Forensic OSINT:
Subject Monitoring & Change Alerts.
โ Register any public profile or web page
โ Set polling from every 10 min to daily
โ Get alerted on new posts, edits, deletions, and username changes
โ One-click forensic capture from the alert
Spring promo subscribers lock in +50% poll budget. 4,500/month instead of 3,000.
Permanently. Never expires.
https://t.co/8n7Q7i1aHp
Seven hours of manual research. 300+ declassified PDFs. Zero AI shortcuts.
Matthias Wilson went deep into NRO documents to write a verified history of early U.S. SIGINT satellites. His conclusion after testing ChatGPT on the same task? AI wasn't even close.
The methodology is the real lesson here.
๐ https://t.co/ew8NF3lOws
The person who gets arrested is rarely the whole story. They're usually just the part we can still see.
@dutch_osintguy breaks down the seven-phase pipeline from online radicalization to physical action โ and where OSINT collection actually matters most.
One of the most important reads this year for analysts working on extremism cases.
๐ https://t.co/k932cOhnJW
AI agents don't solve the OSINT verification problem.
They compress collection and structuring so analysts can spend time on what actually requires judgment.
Ismael Alv worked through a full 6-step AI agent workflow for crisis response, and it's one of the better operational breakdowns I've seen.
๐ https://t.co/T7eCW6AFcW
We just released a free OSINT toolkit for investigators.
IP Lookup (VPN/proxy detection + court-ready PDF)
Username Search (600+ sites)
Domain-to-IP with security scoring
Email Header Analyzer
Image EXIF Reader
Timestamp Decoder
Try instantly. Free account for ongoing access. No search data tracked.
Most people give up when all they see is sand.
Benjamin S. (https://t.co/q8dG5sicIT) used it to solve the case.
He geolocated Taliban special forces drills in a featureless Afghan desert using only sand dunes as reference points.
By applying geo-profiling, he started wide โ Kandahar Airfield โ drop-off point โ finally pinpointed the exact dune that was bombed.
Instead of hunting the โexact spotโ first, he mapped the broader environment and let the terrain guide him in.
๐ก Key takeaway: When the target vanishes, map the surroundings first. Let nearby terrain anchors lead you to the truth.
Check the full breakdown here: https://t.co/okKYrADADE
Want more OSINT gems like this? Subscribe to the Forensic OSINT Friday 5 Roundup โ it's FREE! ๐ฉ https://t.co/wUHwNmAvTY
Courts have gotten IP geolocation wrong. An IP address is not a GPS coordinate.
It resolves to network infrastructure, not a person's location.
People have had their homes raided over this misunderstanding.
Our free IP Lookup report explains exactly what the data means and what it doesn't. Digitally signed, SHA-256 hashed, built for disclosure.
You get a legal return from a social media platform. Dozens of IP addresses are buried across pages of session data.
Miss one? Transpose a digit?
That's a lost lead or a wrong address.
Our IP Lookup tool parses the entire document and extracts every IPv4 and IPv6 automatically.
100% client-side.
Your sensitive material never leaves your browser.
https://t.co/8BRWR4T23d
That long number in an X post URL?
It's a Snowflake ID.
It encodes the exact date and time the post was created. Even if the post is deleted, the URL tells you when it was published.
Our free Timestamp Decoder instantly extracts it.
But paste in the page source code, and it goes deeper.
One Facebook page returned 853 hidden timestamps across the source.
Server times, creation dates, and authentication tokens. Dates that never appear on screen.
100% client-side. Nothing leaves your browser.