A Claude Code skill bundle for bug hunting and external red-team work - 51 skills, 15 slash commands, 574+ disclosed-report patterns curated across 24 vulnerability classes, plus enterprise identity + infrastructure attack matrices. https://t.co/MpxsmCqaM3
🌐‼️ Même les hackers se font doxxer par leur propre connerie !
Un chercheur OSINT mexicain @ivancastl a pris une fuite de mi-avril 2026 sur DarkForums (gros forum cybercriminel) et l’a transformée en outil de cartographie...
➡️ 312 600 enregistrements au total
➡️ 79 900 adresses IP uniques
➡️ Carte Leaflet interactive qui zoome direct sur les pays, villes, FAI et même les VPN foireux !!
Tu tapes un username et la carte te montre où ce gars se connectait depuis sa box résidentielle Totalplay, ALTAN REDES, ou un ProtonVPN mal configuré. Clusters en France (1,3k IPs), Allemagne, Pays-Bas… tout y passe
👉 Même les hackers font des erreurs.
Et l’erreur est très souvent humaine !
Des vendeurs de malware, de logs stealer ou de dumps cartes bleues qui se croyaient intouchables sur le darkweb ont fait la connerie classique : se connecter sans anonymisation digne de ce nom. Un VPN oublié, une connexion juste pour poster vite fait depuis leur FAI perso, et leur vraie IP + username finissent sur une carte publique 👌
La majorité des IPs pointent vers des connexions résidentielles ou des configs approximatives
Pour ceux qui veulent vérifier il a balancé le hash SHA-256 complet du JSON :
`77E12E11465CDAC07F3F24B968FD1EA2B089BCA01208510DD380FF9C07E0B33D`
L’outil est limité à ~3000 requêtes par jour. Le lien est temporaire dans son post du 11 mai
👉 Moralité : Même sur le darkweb, l’anonymat parfait, c’est mort. La technique la plus pointue ne sert à rien si l’humain merde. Un oubli, une flemme, une box résidentielle et ta "vie cachée" devient un point rouge clignotant sur une carte !
#CyberSécurité #OSINT
How I Investigate a Phone Number in Minutes 📱🔎
Most people jump straight to paid tools,
but the smartest OSINT approach actually starts with something simple: Google search.
When I’m investigating a phone number, the first thing I do is generate 𝐚𝐥𝐥 𝐩𝐨𝐬𝐬𝐢𝐛𝐥𝐞 𝐧𝐮𝐦𝐛𝐞𝐫 𝐟𝐨𝐫𝐦𝐚𝐭𝐬 so search engines can surface every trace tied to it.
Of course, it won’t always give results,
but sometimes it reveals 𝑚𝑜𝑟𝑒 𝑡h𝑎𝑛 𝑦𝑜𝑢 𝑒𝑣𝑒𝑟 𝑒𝑥𝑝𝑒𝑐𝑡𝑒𝑑 ⚡
One of my favorite tools for this is a phone variant generator that creates multiple versions of the same number instantly.
Real case:
I once analyzed a suspicious contact number
After generating variants and searching them, I uncovered forum posts, a marketplace listing, and a linked account that revealed the identity behind it 🧠
My quick method:
🔎 Search the number on Google first
📂 Try all format variations
💾 Save each version different formats reveal different results
Best tool for generating variants → https://t.co/FuhY8YZtur
In the next post, I’ll show you the next steps to investigate a phone number and what to do after the initial search 📱
__________
P.S. ♻️ Repost if you found this helpful.
If you liked this post and would like to learn more methods and techniques to discover information about people, check out my OSINT Mastery course https://t.co/o7UQQR6SNU
Instagram Stories delete after 24 hours ⏱️
But Story Saver lets you download public Stories and Highlights instantly - no account, no app, just paste the username and go.
Essential for preserving evidence before it disappears.
Free to use: https://t.co/3ArcMXEvhY
🚨 Launching: The OSINT Tools Library
A curated, investigator-first directory of tools used in real cases.
→ https://t.co/U5CJ3JJmHE
We’re building the largest and best maintained OSINT tools resource and need your help.
Reply and tag a tool we should add 👇
Fraud is no longer a peripheral threat, it is at the centre of polycriminality, intersecting with organized crime, human trafficking and cybercrime.
🔎 The 2026 INTERPOL Global Financial Fraud Threat Assessment, released today at the #GlobalFraudSummit, highlights:
🔵 The increased use of AI to plan and execute fraud campaigns
🔵 The systematic integration of sextortion into scams
🔵 The use of specialized money laundering groups
🔵 The globalization of trafficking-fuelled scam centres
The good news? Law enforcement authorities are collaborating more effectively.
Read more: https://t.co/HGSDhnUVC0
💻C1b3rwall Academy es una acción formativa gratuita en colaboración con la Universidad de Salamanca https://t.co/WXt8hEnrQi
🪙Consta de módulos sobre ciberseguridad como IA, OSINT, criptomonedas...
🥇A la conclusión de cada módulo se obtiene un certificado oficial.
ShadowBroker is a real-time OSINT dashboard that tracks everything on one map.
- Aircraft, ships, and satellites
- Earthquakes and conflict zones
- CCTV networks and GPS jamming
- Breaking geopolitical events
All live. All open source.
The world has never been this visible to anyone with a browser.
github- https://t.co/RNPdRvoVG2
🚨 This is the Final week to sign up for the FREE Social Media OSINT Workshop!
Participants will also receive a workshop Certificate.
🗓 Date: 14th March (Saturday)
⏰ Time: 2:00 PM to 3:00 PM (CET)
💻 Platform: Microsoft Teams
🔎 The Workshop will cover:
✅ Facebook OSINT
✅ Instagram OSINT
✅ X (Twitter) OSINT
✅ Pinterest OSINT
✅ Advanced practical OSINT techniques
🔗 Seats are limited — register now to secure your spot!
https://t.co/5lZiYB7IuJ
P.S. ♻️ Repost to invite more people to join!
🚩 IGNORE PREVIOUS INSTRUCTIONS: EL CTF DE TROPICON ESTÁ POR COMENZAR 🏆
¿Tienes lo necesario para dominar el tablero? El acceso está por abrirse y solo los más hábiles lograrán su pase directo a Cozumel. 🌴💻
Prepara tu entorno, revisa tus scripts y mantén el enfoque. Abrimos el CTF oficial de TROPICON 2026. Es momento de demostrar tus habilidades en resolución de desafíos y lógica.
📅 APERTURA: Del Viernes 13 al Domingo 15 de Marzo
🌐 TARGET: https://t.co/QecowWrMB9
Los perfiles con mayor puntaje en el ránking final obtendrán:
🥇 1er Lugar: Experiencia Tropicon Todo Incluido. Hospedaje en habitación doble para dos personas del 17 al 19 de abril (3 noches de inmersión total).
🥈 2do Lugar: Dos accesos generales para el evento.
🥉 3er Lugar: Un acceso general para el evento.
La entrada al paraíso no se compra, se gana byte a byte. ¿Nos vemos en el podio? 🏆
#Tropicon2026 #InfoSec #CTF #CyberCommunity #Cozumel #CyberSecurity
: ))! @KagiHQ - is another powerful search engine that helps investigators, researchers, and analysts navigate their hunts without noise > No ad-free, customizable results, AI assistants (opt-in), and "lenses" to filter searches. Great SE to give a try!!
#OSINT#Cybersecurity
This guy just built a real-time global intelligence dashboard and open sourced it for free.
>You can now monitor the war
>It tracks conflicts, military activity, infrastructure, protests, and market signals live.
>Runs in your browser
>MIT licensed.