Spokes.wiki Search About

Log — OSINT Wiki

Append-only history. Entries: ## [YYYY-MM-DD] <op> | <title> (ingest/query/lint/split).

[2026-06-30] split | osint-wiki created from _inbox security/OSINT cluster (3 sources)

Spun out the moment a 3rd coherent source landed. The cluster had sat at two parked strays — llm-osint (sshh12’s LLM-OSINT PoC, parked 2026-06-21) and awesome-social-engineering (giuliacassara’s SE/OSINT resource list, parked 2026-06-30) — and the user re-sent llm_osint then sent kallisto-osinter (avrtt’s multi-agent LLM OSINT) right after, completing the ≥3 trigger. Founding corpus: 3 source pages + 3 Thing pages + synthesis.

  • llm-osint (SoftwareSourceCode, T3, github.com/sshh12) — single-LLM autonomous profiler; the founding seed.
  • kallisto-osinter (SoftwareSourceCode, T3, github.com/avrtt) — multi-agent orchestration (search/ knowledge/deep-dive agents + LLM map-reduce, GPT-4/LangChain); the trigger.
  • awesome-social-engineering (Collection, T4, github.com/giuliacassara) — the human-element + manual-recon (Maltego/theHarvester/Shodan) baseline.
  • Thing pages: osint (umbrella discipline + classic toolkit), ai-osint (the single-LLM → multi-agent autonomy axis), social-engineering (human-element attacks; OSINT = its recon phase).
  • Synthesis thesis: OSINT is reconnaissance, LLMs are automating the analyst out of the loop (manual stack → single-LLM → multi-agent); OSINT + social engineering are one chain; the defining tension is dual-use (public-data aggregation → privacy/surveillance risk, cheap at automation scale). Open questions: human-in-the-loop, defense against automated OSINT, the ai-governance regulation seam.
  • Ethics/dual-use stance baked into CLAUDE.md + synthesis: document for defense/education/research; catalog and analyze, no operational targeting playbooks; foreground consent/privacy/defense.
  • Scope boundaries: vs ../agentic-tooling-wiki (agent machinery there; OSINT application here — cross-link by mechanism), vs ../ai-governance-wiki (privacy/surveillance regulation there).
  • Author/curator entities (sshh12, avrtt, giuliacassara) deferred (thin one-off creators at founding). Registry block added to ../wikis.md; _inbox/llm-osint.md + _inbox/awesome-social-engineering.md park records deleted (superseded by ingest).

[2026-06-30] ingest | kafSIEM (Scalytics) — the defensive/fusion pole

Routed from Telegram (day-of spin-out). New source kafsiem (SoftwareSourceCode, T3, github.com/scalytics; Apache-2.0, ~43★, v1.7.0) — an entity-graph platform that fuses Kafka-observed operational/OT data + OSINT context into an auditable, provenance-on-every-edge entity graph for analyst workflows; air-gapped defense + critical infrastructure (unmanned systems, SCADA). Three modes: OSINT / Operations / Fusion. Balances the spoke: the founding trio leaned offensive (autonomous gathering/ profiling) + an SE resource base; kafSIEM is the defensive, analyst-in-loop counterpart. Advanced two synthesis open-Qs — “human in the loop” (analyst-driven, every edge auditable = partial answer) and “defense against automated OSINT” (now seeded, with an OT/SCADA focus). Added a “defensive counter-current” paragraph to synthesis (two poles: autonomous gathering ↔ analyst-driven fusion); touched osint (OSINT cuts both ways). Entity-graph/provenance machinery cross-links research-wiki knowledge-graph / knowledge-rep (noted, not duplicated). Maker Scalytics entity deferred (founding posture). Ran avoid-ai-writing. +1 page (→7).

[2026-07-02] ingest | SwaggerSpy (UndeadSec) — first secrets-recon / non-AI tool

Routed from Telegram via the hub router. New source swaggerspy (SoftwareSourceCode, T3, github.com/UndeadSec; MIT, Python 100%) — automates OSINT on SwaggerHub, scanning published API documentation with regular expressions for exposed secrets/credentials. Author Alisson Moretto (UndeadSec), a CTI professional. Two firsts for the spoke: (1) a non-AI OSINT tool — plain regex, no LLM/agents, a deliberate contrast with the ai-osint pole; (2) recon aimed at machine secrets / attack surface, not at profiling people — a Shodan-class single-platform sweep. Added a second axis to synthesis: alongside the autonomy axis (manual → single-LLM → multi-agent), an object axis (person-profiling ↔ secrets/attack-surface). Advances the “how far past OSINT?” open-Q — first step into general offensive-security recon the scope boundary anticipated. Touched osint (classic narrow-slice pattern persists outside the AI wave). Author entity (UndeadSec/Alisson Moretto) deferred per founding posture, but flagged in index as a recurring offensive-security author to watch. Ran avoid-ai-writing. +1 page (→8).

[2026-07-02] ingest | OSINT encyclopedic overview (Wikipedia) — first T2/neutral anchor (Quality Cycle)

Quality-Cycle floor-raise: the spoke’s floor was 100% T3/T4 (tool repos + one SE resource list) and the umbrella osint page was grounded only via those tool pages. Ingested osint-overview-wikipedia (Article, T2, en.wikipedia.org) — the discipline’s neutral overview (analogous to the Wikipedia anchor quant-trading/knowledge-rep use). Adds substance the tool-only corpus lacked: the IC history (Foreign Broadcast Monitoring 1941 → Open Source Center 2005 → OSINT Foundation 2022 — OSINT is an old institutional practice the AI tools automate), the six source categories, the OSINT Framework (30+ tool categories), and a genuinely new risk axis — disinformation / source contamination (open sources can be deliberately poisoned), distinct from the standing dual-use/privacy tension. Grounded the osint page (new “old institutional practice” section) and added a synthesis section (“source contamination, not just privacy”) reframing kafsiem‘s provenance discipline as an input-integrity defense. Floor lifted T3×4/T4×1 → T2×1/T3×4/T4×1 (first non-tool, first neutral source). Ran avoid-ai-writing. +1 page (→9).

[2026-07-05] ingest | GitSint — GitHub OSINT profiler (N0rz3) → osint-wiki

Routed from hub (share.google → github.com/N0rz3/GitSint). T3 GitHub repo: a non-AI, single-platform OSINT tool that profiles a target through GitHub — -u user / -e email / -o org, fully async, GPL-3.0, tree output; credits GitFive (mxrch). Collects profile fields + followers/repos/gists/socials/orgs, and adds commit-history email harvesting and an email↔account pivot (Light mode via the API) + similar-name discovery. New source page gitsint. Synthesis: fills the non-AI/single-platform × person-profiling cell (SwaggerSpy held the secrets side), reframing classic-mode enumeration as a mode spanning both objects; opened the email↔identity pivot as a possible new thread; kept the defensive lens (devs leak PII via commit emails → use noreply, scrub history). Author N0rz3 deferred per the spoke’s thin-one-off-creator policy.

[2026-07-27] ingest | MyIP — a better IP toolbox (jason5ng32, GitHub)

Routed here by the hub (runner-up: defensive-security-wiki — the 258-item checklist and the leak-prevention framing brush it, but the substance is IP/DNS/ASN/WHOIS/fingerprint recon, which is this spoke’s named “IP/DNS reconnaissance” branch). T3 project README, self-reported, ~11.3k★. New: myip (source), ip-reconnaissance (technique). Updated: osint (the infrastructure branch beside people-profiling), synthesis (new “mirror” section + the defense open question), index. What it adds:

  1. The first subject-side tool. gitsint, swaggerspy, llm-osint all point outward at a target; MyIP runs the same primitives against the operator’s own connection. Gives the defense-against-automated-OSINT question its second source, at one-person scale next to kafsiem‘s organizational one.
  2. The attribution layer, itemized. Its config is an inventory of what everyone in this branch resolves against: MaxMind GeoLite2 (redistribution-barred, so every deployer holds a key), CAIDA as2org/as-rel2, RIPEstat AS history, and three commercial geo APIs queried in parallel because they disagree. Accuracy here is inherited from vendors, not measured.
  3. A named user. Censorship checks, DNS-pollution detection and a Clash-rule proxy-test harness say who this is for: someone on a filtered network verifying their circumvention doesn’t leak. Also recorded, without moralizing: the tool marks a Google Analytics ID required and ships a first-party route for relaying Sentry envelopes past ad blockers — disclosed, switchable when self-hosted, and a reminder that measuring exposure and reducing it are different jobs. Entity jason5ng32 deferred per the spoke’s standing creator rule. Verify deferred per hub policy (content-only). avoid-ai-writing run.

[2026-07-27] ingest | Strix — open-source autonomous AI pentesting agent (usestrix, GitHub)

Routed here by the hub (runner-ups: agentic-tooling-wiki for the “Graph of Agents” machinery — declined by this spoke’s standing rule that an agent-powered security tool files by subject; defensive-security-wiki for the CI-gating / SAST+DAST / compliance-report side — declined because that spoke is explicitly blue-team and this is the red side, cross-linked instead). T3 vendor README, Apache 2.0, ~44.8k★, no third-party evaluation. New: strix (source), autonomous-pentesting (practice), usestrix (entity — commercial, so paged rather than deferred under the standing one-off-creator rule). Updated: ai-osint (autonomy axis now runs monolithic → orchestrated → acting), osint (recon as phase one of an automated chain), synthesis (dual-use sharpened + the “how far past OSINT” question answered), index. Four things this adds:

  1. Agents that act, not gather. Every prior AI tool here assembles a profile. Strix’s specialists divide a kill chain and run exploits. That’s the widest the spoke’s subject has stretched.
  2. An evidence standard the corpus lacked. “PoCs, not false positives” — a finding counts when the agent demonstrates it. Available here because the target is the oracle: an exploit either fires or it doesn’t, which is ground truth a profile can never have. Stops at false negatives.
  3. Red team as a CI gate. GitHub Actions, non-zero exit on findings, PR diff-scoping, fix PRs. “Pentest” stops meaning an engagement and starts meaning a test suite — myip‘s point-it-at-yourself inversion, one layer down.
  4. The cost floor. One-line install, local models or a consumer ChatGPT subscription instead of a metered key. Authorization is a README warning with no technical scope enforcement. Recorded without alarm, per the spoke’s ethics stance: capabilities and licensing catalogued, no operational guidance, and the governance angle cross-linked to ai-governance-wiki. usestrix‘s enterprise pitch is the sharpest detail — what’s sold is the compliance artifact (SOC 2 / ISO 27001 / PCI DSS reports), not the exploitation. Domain note: three offensive-security sources now sit here (swaggerspy, gitsint, strix). Per CLAUDE.md the response is to broaden the domain line rather than fragment — flagged in synthesis for the human’s call, not done unilaterally. Verify deferred per hub policy (content-only). avoid-ai-writing run.

[2026-08-03] ingest | Termux Commands (termuxcommands.com) — phone-based recon distribution

Routed from the hub (Telegram). New: termux-commands-site (T4 source summary), termux (SoftwareApplication), username-reconnaissance (DefinedTerm/technique). Updated: osint (identity branch section), ip-reconnaissance (identity-side sibling), gitsint (its flagged email↔identity thread now has a page), synthesis (new distribution axis section + open question “who is actually running these tools?” + dev-tooling cross-spoke adjacency), index. Substance: 143 install-and-run guides since 2023-09-25, two thirds recon/offensive security (29 in the OSINT category), all assuming a phone with no root. The site verifies nothing and adds five lines of pkg install to public GitHub repos — so it is evidence of an audience and a delivery channel, not of the tools. That is a third axis for the corpus, independent of autonomy and object: how little equipment the operator needs, not how little skill. The platform’s constraints (no root → no packet capture) select for API-and-HTTP-shaped recon, which is exactly what the catalog contains. username-reconnaissance closes the thread gitsint left open — handle sweeps are the breadth-first sibling of the depth-first email pivot — and shows where AI actually lands in a mature technique: Aliens_eye advertises an AI confidence score on results, not AI enumeration, i.e. the judgment step absorbed while the request loop stays mechanical. Claimed, not demonstrated: no model, API or calibration named. Ethics: catalogued, no operational guidance; the tool posts drop the “educational purposes only” line their upstream READMEs carry, which is noted as a property of the site. T4 justified — self-published, single-author, ad-supported, no editorial process; trusted only for its own taxonomy/counts/dates (observed 2026-08-03 snapshot). Author entity (Achik Ahmed) deferred per the standing thin-creator precedent. Verify deferred per hub policy (content-only). avoid-ai-writing run.

[2026-08-05] ingest | CloakQuest3r

Routed from the hub (runner-up: defensive-security-wiki — the blue-team mirror; declined because the tool is offensive infrastructure recon by subject, and osint-wiki explicitly owns IP/DNS reconnaissance). cloakquest3r — spyboy-productions’ Cloudflare origin-IP discovery tool (MIT, ~2,222★), T3. No entity paged: spyboy-productions is a thin one-off creator at this point, deferred per the standing index note (page on recurrence).

Lands on the ip-reconnaissance branch and gives it a second direction. myip runs the infrastructure toolkit inward (self-audit); this runs the same primitives outward against a target that is actively hiding, recovering an origin IP from behind a CDN. First tool in the spoke whose target is a defensive control rather than a subject.

Folded into synthesis under “The mirror” as its outward face — and it sharpens the mirror rather than breaking it: what leaks the origin is never the proxy but the target’s own DNS history, forgotten unproxied subdomains, and re-used certificates, so origin exposure is a configuration failure the vendor cannot fix. Evidence discipline noted as better than a profiler’s — a recovered IP is self-verifying (reachable or not), narrow visible false-positive mode. Dual-use boundary is the usual one: README warning, no technical scope enforcement, consent as convention (same shape as strix, non-AI form).

[2026-08-05] ingest | Awesome-OSINT-List (Astrosp)

Routed from the hub (Telegram). Read the README in full (2,341 lines) rather than the rendered page — ~1,730 links under ~90 top-level sections, GPL-3.0, ~4.1k★, 343 commits.

New pages: awesome-osint-list (Collection, T4 — a link list with no testing, no inclusion criteria and no dates) and astrosp (Person). Paging the maintainer breaks this spoke’s standing “defer creator entities” rule; the exception is noted in index.md, and the reason is that the curator’s invisibility is itself load-bearing for the T4 grade.

Why a T4 link dump earned a synthesis section: it is the first source here that shows the toolkit’s composition instead of one instrument. Three consequences, all now in synthesis.md:

  1. Selection bias found in our own corpus. The field’s modal tool is a hosted web service; every source we hold except termux-commands-site is a runnable repository. Cause is mundane — GitHub links are what arrive — but the two classes fail differently (a service logs the searcher and can vanish). New growth edge 3 asks for a proper source on a hosted platform.
  2. A base rate against the AI thesis. The list’s “AI” section is mostly AI as target (LLM security, red teaming, jailbreak/prompt-injection resources); one short subsection is AI-for-OSINT. ai-osint stays the leading edge as a trajectory, but this is the first evidence that it is not yet the mainstream of practice.
  3. The “how far past OSINT” question answered from the field’s side. A full bug-bounty wing (attack surface, enumeration, fuzzing, exploitation) is filed inside the list. The broadening that swaggerspygitsintstrix forced one source at a time is the practitioners’ own filing, not our judgement call.

Dual-use, recorded not resolved: whole sections sort by who you investigate (People, Resident Database, Public Records, Police/LE, Informant, Extremist/Far-Right, War). The far-right shelf mixes DDoSecrets, Unicorn Riot, ProPublica and START’s Global Terrorism Database with raw leak dumps and no-fly-list mirrors, and unlike awesome-social-engineering the list carries no disclaimer and no scope statement at all.

[2026-08-05] ingest | Awesome OSINT MCP Servers (soxoj)

Routed from the hub (runner-up: agentic-tooling-wiki). New pages: awesome-osint-mcp-servers (source, T3) and soxoj (Person). ~60 MCP servers, 10 categories, MIT, 411★.

Graded T3 rather than the T4 the spoke gave awesome-osint-list this morning: every row states open-source status, pricing tier and API-key requirement, which is an inclusion standard applied per entry. Still untested and undated.

The substantive point, folded into synthesis as a sub-section under the census: this documents the interface, not an implementation. llm-osint and kallisto-osinter each had to contain their own tooling; MCP publishes the tool layer separately, so an OSINT capability is now available to whatever agent shows up. Recorded the composition risk in the same breath — the capabilities are old, assembling them behind one model is what gets cheap — and that this list, like the census, carries no disclaimer.

Two catalogs in one day count 1,730 links and 60. Read as different stages, not a conflict; the gap is the conversion still outstanding.

[2026-08-05] ingest | Mysterium Node (decentralized VPN)

Routed from the hub (runner-up: cloud-wiki). New page mysterium-node (source, T3 — project repo). Go, GPL-3.0, 1.3k★, WireGuard, Raspberry Pi / BalenaOS targets, Ethereum-compatible settlement.

First source against growth edge 4 (the defensive / counter-OSINT mirror), and it does not close a single leak path ip-reconnaissance lists — WebRTC, DNS and fingerprinting are untouched. What it changes is whose address you inherit, and the exits are residential, so the same property that defeats datacenter-ASN blocking is the one that supplies residential-exit abuse. Recorded as dual-use in the spoke’s usual shape, this time on a defensive tool.

The point worth keeping: the exit operator inherits the attribution for other people’s traffic, so the privacy gain is a redistribution of exposure rather than a reduction. Payout mechanics are undocumented, which is precisely what decides who takes that trade. Token/settlement layer noted as cross-spoke context and not developed.

[2026-08-05] route | Mysterium Node → osint-wiki (runner-up: cloud-wiki)

Decentralized VPN node software. Routed on the counter-reconnaissance angle — it sits directly in the ip-reconnaissance / myip exposure thread and answers a named growth edge. cloud-wiki was the runner-up (bandwidth as rented infrastructure); the blockchain/token layer has no spoke and is recorded as context in the source page, not split out.

[2026-08-07] ingest | Berkeley Protocol on Digital Open Source Investigations (via research pass)

OHCHR + UC Berkeley Human Rights Center; ISBN 978-92-1-154233-2, UN sales no. E.20.XIV.4, OHCHR listing dated 2022-01-03. T1 — intergovernmental primary standard. Closes growth edge #1 (first T1); the spoke had carried the zero-T1 auto-edge on the hub’s ## Most wanted since 2026-08-05 and lost the research budget on two prior cycles.

Fetched via the firecrawl fallback — ohchr.org 403s to a normal fetch. The linked ~120-page PDF downloaded but could not be text-extracted (no poppler in this environment), so the page records the Protocol’s publisher, standing, scope and stated axes, and explicitly does not assert its internal stages or chain-of-custody rules. That limit is written on the page and filed as growth edge #4 rather than papered over.

[2026-08-07] ingest | Evaluating the Reliability of LLMs in OSINT Investigations (via research pass)

Baloyi, Siphambili, Ntshangase, Letshwenyo, Makharamedzha, Mmbodi, Hlongwane (CSIR), ECCWS 2026, DOI 10.34190/eccws.25.1.4818. T1 — peer-reviewed conference paper. The spoke’s first measurement of any kind: eight LLMs against a fabricated “CtrlZ Society” with known ground truth, scored on accuracy, timeline reconstruction, account attribution, evidence traceability, hallucination and ambiguous data.

Key finding kept in the synthesis: forced narrative construction under adversarial prompting — the model builds the story it is led toward, which is the failure mode that matters most for investigation. Partly closes growth edge #2; the scope limit (it measures analysis, not autonomous collection) is recorded as the surviving half of that edge. Per-model rankings dated deliberately — the paper names model families, not versions.

No entity nodes created. CSIR, OHCHR and the Berkeley Human Rights Center are one-off publishers here, and the spoke’s standing rule defers thin one-off creator/publisher nodes until one recurs.

[2026-08-09] ingest | Termux page refreshed from the repository — distribution, and a shared test key

Not a new source in the ordinary sense. The hub spun out ../foss-applications-wiki today, and termux was in the cluster that triggered it. Per the one-canonical-node rule the page stays here — this spoke paged Termux first and owns it as an OSINT enabler — so instead of duplicating it, the new spoke links it as a bridge node and the facts found while fetching the repository were folded in here.

What the repository added (github.com/termux/termux-app, 58.9k★ / 7.2k forks, v0.118.3, Android 7+): the Play Store build is an “experimental branch” the maintainers advise against, and a Play install is incompatible with an F-Droid one after Google removed the sharedUserId requirement. Capability is split across six add-on apps installed from the same channel.

The finding worth having. The GitHub APKs are “signed with a test key that has been shared with community. This IS NOT an official developer key.” This spoke’s whole argument about Termux is that it drives the cost of reconnaissance to near zero; the download path that does that has no meaningful signature guarantee, and enforcement “can be bypassed with root or with custom roms.” Recorded on the page under a new section rather than in synthesis — it qualifies the access-cost argument, it does not change it.

[2026-08-10] ingest | IRONSIGHT — a third object for the recon axis, and an unmarked feed list

Routed from the hub (Telegram). github.com/NoblerWorks-HQ/IRONSIGHT — MIT, ~564★, Next.js 16 + Leaflet, a two-theatre conflict dashboard (Iran/Israel, Russia/Ukraine) over ~12 free keyless feeds. T3: a project describing itself, but the self-description includes its own weaknesses, which is more than awesome-osint-list manages.

New pages: ironsight (source), conflict-monitoring (DefinedTerm), nobler-works (Organization). The maker node is paged because the repo is explicitly a portfolio piece for paid work — a second, lighter commercial pattern beside usestrix‘s open core.

Why it mattered. The object axis had person and machine; this is place and event, and it behaves differently — no index to enumerate, so continuous aggregation replaces the query. Two observations went into synthesis. First, the autonomy axis runs backwards here: no model, no conclusion, the analyst doing all the correlation — kafsiem‘s pole turns out to hold two very different tools, only one of which leaves a trace of why anything is on screen. Second, and sharper: TASS, RT and PressTV sit in the feed list beside Reuters, Meduza and the Kyiv Independent with no reliability marking anywhere, which turns osint-overview-wikipedia‘s source-contamination risk from a hazard into a design decision the project never discusses.

Growth edges. #7 (geolocation/chronolocation) sharpened — the spoke now has the aggregation half of that discipline and none of the craft half. New #11: preservation and archival, because berkeley-protocol centres on keeping evidence usable later and this tool keeps nothing.

[2026-08-10] quality | Cycle: the Berkeley Protocol, actually read

Growth edge 4 closed. The berkeley-protocol page had been summarizing OHCHR’s abstract because the 2026-08-07 pass concluded the PDF “could not be text-extracted in this environment (no poppler)”. That was wrong — pypdf reads it. The OHCHR-hosted URL now 404s; a mirrored copy of the same publication (102 pages) was extracted instead and checked against the OHCHR record for title, ISBN and chapter list.

The page now carries the chapter structure, the fourteen principles in their three groups, and chapter VI’s source / technical / content analysis split. The finding that changes the spoke’s argument: the Protocol permits automation and imposes three tests instead — explainability in court (¶25), data minimization favouring itemized over bulk collection (¶31), and preservation against under-collection (¶32). The spoke’s tools fail different ones, and preservation is implemented by none of them. Folded into synthesis.md; edge 4 replaced with a narrower successor (what ¶25 disqualifies, untested by any source here).

2026-08-13 — quality cycle: the practicing institution, and the craft

Three sources, two coverage edges closed (7 geolocation/chronolocation, 9 the practicing institution). The spoke had the weakest source floor in the corpus at the start of this cycle — T1 2 / T2 1 / T3 10 / T4 3 — and every T3 in it is a repository README. Two T1s and a T2 were the point.

glan-bellingcat-methodology (T1) — the Bellingcat / GLAN Justice & Accountability Unit manual, 90 pages, published in full and extracted with pypdf after the usual WebFetch “binary PDF” non-answer. Held: the admissibility purpose, the phase structure, the Original Online Source rule, the examinable-vs-descriptive split that decides what may carry a conclusion, the named stack (Hunchly, Uwazi, the Mnemonic preservation sheet), the 2021 mock hearing, and a candid annex on why a fresh research account per investigation is not feasible.

sun-shadow-geolocation (T1) and llm-geolocation-test (T2), both Bellingcat — the craft the manual explicitly does not teach, and Bellingcat’s own scoring of 20 models on 25 unpublished photos against Google Lens. New Thing page geolocation-chronolocation; new entity pages bellingcat, global-legal-action-network, mnemonic, uwazi.

The finding that changes the argument: the corpus had recorded “no tool here implements berkeley-protocol ¶32 preservation” as a defect in the tool layer. Bellingcat does not implement it either — it delegates to Mnemonic and transfers responsibility when an investigation closes. That is a division of labour, not a missing feature, and no tool was ever going to close it.

The second finding is against the spoke’s own tools. In the model test, “deep research” and “extended thinking” modes scored worse than the same models’ plain modes, and one instance pulled the tester’s account history into an answer. The autonomous tools here (llm-osint, kallisto-osinter) are built on the premise that orchestration buys accuracy; on the one task with a right answer, scaffolding scored lower and the output was not reproducible from the image alone.

Edge 2 (measurement of the collection half) is sharpened and still open — the spoke now holds two independent measurements of the analysis stage and none of gathering. Successors written for edges 7 and 9; edge 11 re-pointed at Mnemonic’s own method.

[2026-08-13] ingest | Nothing Private — browser fingerprinting defeats incognito mode

Routed here by the hub from a Telegram link (github.com/gautamkrishnar/nothing-private). Runner-up: ../web-browsers-wiki — the source’s countermeasure table is a list of browsers, and that spoke owns the privacy current (brave, firefox, Tor). The route came here because the subject is the re-identification technique, which ip-reconnaissance had already named as one of three leaks it holds no source on.

T3. One developer’s proof of concept, created 2016-12-16, last pushed 2025-12-09, GPL-3.0, 2,251★/163 forks (counted 2026-08-13). Repository README and the countermeasures README read in full, plus the GitHub API for the metadata; the live demo was not visited, so nothing here rests on running it.

New pages: 3. nothing-private, browser-fingerprinting, gautam-krishna. Updated: ip-reconnaissance, synthesis, index.md.

What it closes. The third leak on ip-reconnaissance‘s surface. The page has listed WebRTC, DNS and browser fingerprinting since it was written and the spoke held only myip, which tests for them. Two of the three are still unsourced.

The finding worth keeping: issued versus derived. A cookie is given to you and can be deleted; a fingerprint is computed from what the browser already announces to every page. Sixteen properties are hashed by Client.js and matched in a server-side MySQL row, so private mode — which clears the client — clears nothing that identifies you. The demo’s whole argument is that negative, stated in the README: incognito “will just help you to clear your browsing history.”

The countermeasure table is the better half of the source. Both defences it lists aim at one data point, the canvas: randomise the readout (firefox 78+, Tor 10+, brave 1.11.104+, Ungoogled Chromium, Bromite, Pale Moon, BriskBard) or blank it (Tor 8.0–9.5, firefox 58–77). The README says this “only covers one aspect” and warns that a blanking browser leaves the demo looking functional while it has silently stopped discriminating — a self-disclosed false negative, which is why the tier is T3 rather than T4.

Dual-use, pointed the other way. Every other tool here is built for an investigator and read defensively; this one is built for the subject and works by tracking them. Recorded in synthesis.

What is missing and now stated as the ask: no entropy estimate, no uniqueness rate, no stability figure. Panopticlick and amiunique.org are in the source’s own reference list. Growth edge 6 stays open at its T1/T2 bar and now names measurement specifically.

Entities: 1 created (gautam-krishna); no page for him existed anywhere in the hub.

[2026-08-13] ingest | Research pass — browser fingerprinting, measured

The curator asked “Panopticlick?” hours after nothing-private landed, and approved the hunt. Three T1 sources in one hop, all of them already sitting in that demo’s own reference list:

  • eckersley-browser-uniqueness — Peter Eckersley, PETS 2010, 19pp. PDF from coveryourtracks.eff.org, read locally with pypdf.
  • laperdrix-amiunique — Laperdrix, Rudametkin & Baudry, IEEE S&P 2016, 18pp. PDF from INRIA’s HAL, same method.
  • cover-your-tracks — the EFF tool Panopticlick became in 2020; about/learn pages read, the test not run from this host.

New pages: 4 (the three sources plus peter-eckersley). Updated: browser-fingerprinting — which now carries the numbers instead of naming the hole — plus nothing-private, synthesis, index.md. electronic-frontier-foundation is paged in ../ai-governance-wiki and linked cross-wiki rather than duplicated.

The measurements. 2010: 470,161 browsers, 8 attributes, 83.6% instantaneously unique, 94.2% with Flash or Java, ≥18.1 bits of entropy — one in 286,777. 2016: 118,934 fingerprints, 17 attributes, 89.4% unique, with canvas joining fonts and plugins at the top. Two self-selected samples six years apart on different technology, agreeing; both papers declare the bias.

Two things the demo could not have told us. Fingerprint instability is not protection — 37.4% of returning browsers changed within a day and a simple heuristic re-linked them at 99.1% accuracy, 0.86% false positives. And mobile reversed: listed among the resistant groups in 2010, 81% unique by 2016, reaching it through the device model in the user agent rather than through plugin diversity (1% of mobile plugin lists unique, against 37% on desktop).

The defence ranking, which is the uncomfortable part. No Flash: 95% → 88%. Generic HTTP headers plus no plugins: −36% desktop uniqueness. No JavaScript: 89.4% → 29%, or 7% with generic user agents too. The two large levers belong to browser vendors, not to the user — and Eckersley’s paradox sits under all of them: a countermeasure used by few people makes its users more distinctive. 378 browsers in his sample forged an iPhone user agent while reporting Flash and were easier to identify for it.

Growth edge 6 (defensive / counter-OSINT) closes at its T1/T2 bar. Successor edge recorded: nothing measures the 2026 web — both studies predate the removal of NPAPI plugins, one of the two highest-entropy attributes in each, and neither says what took its place.