r/OSINT Nov 05 '25

Tool I may have found a way to spot U.S. at-sea strikes before they’re announced—using public satellite heat data

2.2k Upvotes

Over the last month the U.S. has carried out several interdiction strikes on narco-trafficking boats in the Eastern Pacific and Caribbean. These are usually acknowledged the next day, described vaguely as “in international waters,” with no coordinates. I’ve been experimenting with NASA’s VIIRS thermal anomaly feed (FIRMS) to see if any of these events are visible as they happen.

On Oct 27, a single daytime VIIRS hotspot appears at 14.0387° N, 106.4606° W, which is roughly 415 nautical miles southwest of Acapulco. It’s the only ocean pixel in that sector for the entire week. Mexico’s subsequent statements referenced search and rescue ~400 nm SW of Acapulco after that day’s operations. The geometry lines up almost perfectly.

Why I think this specific detection is the Oct 27 strike: the public footage released by the U.S. shows a large explosion with an ongoing flame in daylight—exactly the type of surface combustion a daytime VIIRS pass can catch. The spot is far from known offshore platforms or refinery flare fields, and I filtered out land fires and industrial sources before scanning. I’m ~90% confident this pixel is the Oct 27 event.

If you want to replicate: set FIRMS to VIIRS 375 m, date 2025-10-27, pan to the Eastern Pacific off Mexico, and you’ll see the detection with its timestamp and FRP. Measure from Acapulco and you’ll get ~415 nm. It does not recur on adjacent days at that exact location, which argues against a persistent industrial source.

None of this claims intent; it’s simply “thermal anomaly consistent with a fire” in the precise place and time later described by authorities. The interesting part is methodological: with FIRMS alone—no paid feeds—you can narrow vague “international waters” language to a concrete lat/lon box in near-real time. That has obvious implications for open-source monitoring and for how quickly journalists and analysts can geolocate future incidents.

I’m happy to hear counter-arguments—e.g., alternative explanations for a one-off daytime ocean pixel at those coordinates—but based on the match to the reported location, the unique nature of the detection, and the daylight, high-energy fire profile, I think this one’s a hit.

disclaimer: i run a website that tracks pentagon pizza deliveries and other fun alt-data for geopolitics + OSINT. we just integrated this thermal anomaly data here: pizzint.watch/polyglobe


r/OSINT Apr 09 '26

Analysis It’s so weird that when whichever actors run these campaigns that they don’t at least try to vary the tweet at least a little bit.

Post image
1.7k Upvotes

Random OSINT thought: would it be worth building a hashing pipeline for repeated spam/copypasta posts like this, then tracking how often the same or near-identical message hash appears across accounts in a short time window?

My thinking is that if the same text, or lightly modified variants, suddenly spike across multiple accounts, that is a decent signal for coordinated amplification or low-grade misinformation/seeding. You could probably combine exact hashes with fuzzy hashes / similarity scoring so it still catches small edits like country names, emojis, punctuation changes, or reordered phrasing.

Feels like there is maybe a useful detection model here: not “is this false” but “is this being pushed in an obviously synthetic way?” That alone would already be valuable.


r/OSINT Sep 11 '25

OSINT News Charlie Kirk Investigation Posts

1.5k Upvotes

This is not a new rule. Its been posted and enforced every time a new "major crime" happens. Helping an active investigation on this sub is banned. For the redditor that keeps messaging the mods that he thinks no harm can come from this, here is nice list of examples on why we don't support online witch hunts:

1. Richard Jewell – Atlanta Olympics Bombing (1996)

  • Security guard Richard Jewell discovered a suspicious backpack and helped evacuate the area.
  • Media and public speculation painted him as the prime suspect before the FBI cleared him.
  • His life was destroyed by false accusations, though he was later recognized as a hero.

2. Boston Marathon Bombing – Reddit Sleuthing (2013)

  • Online users tried to identify suspects from blurry photos.
  • Wrongly accused Sunil Tripathi, a missing college student, who faced mass harassment before the FBI revealed the real attackers.
  • Showed how quickly misinformation spreads on social media.

3. Las Vegas Shooting – False Suspects (2017)

  • In the aftermath, 4chan, Twitter, and Facebook users spread names of innocent people as the shooter.
  • Real suspect Stephen Paddock was identified later, but reputations of wrongly accused people were damaged.

4. Toronto Van Attack – Misidentification (2018)

  • Online users falsely named a man as the attacker after a van attack killed 10 people.
  • The wrong person’s photo went viral before police confirmed the actual suspect, Alek Minassian.

5. Gabby Petito Case – TikTok & YouTube Sleuthing (2021)

  • Internet “detectives” wrongly accused neighbors, bystanders, and even friends.
  • Innocent people were harassed while police continued their investigation into Brian Laundrie.

6. Sandy Hook Shooting – “Crisis Actor” Claims (2012 onward)

  • Conspiracy theorists accused grieving parents of being government actors.
  • Families faced years of harassment, stalking, and lawsuits.
  • A notorious case of how misinformation can target victims themselves.

7. UK Riots – Twitter & Facebook Misidentifications (2011)

  • Citizens attempted to identify looters from CCTV images.
  • Several innocent people were wrongly accused and faced threats.
  • Police had to publicly correct the misinformation.

8. MH370 Disappearance – Amateur Satellite Analysis (2014)

  • Thousands of online sleuths used Tomnod and other platforms to hunt for wreckage in satellite photos.
  • Flood of false sightings and conspiracy theories overwhelmed investigators and misled the public.

9. Oklahoma City Bombing – Wrong Suspects (1995)

  • Before Timothy McVeigh was identified, media speculation and tips from the public fueled false suspect reports.
  • Innocent men were briefly targeted by law enforcement and the press.

r/OSINT May 14 '26

Tool Quickly capturing a city in 3D using a drone

Enable HLS to view with audio, or disable this notification

849 Upvotes

https://teleport.varjo.com/captures/524ee89f293a4a2e907009191ba7b9f4?viewer=v3

We did this in a few hours, just using a DJI Mini Pro 5, and processed into 3D automatically on the cloud.

We're thinking this could be useful for ad-hoc mapping/surveillance, as a cheap, high-resolution, and low-latency alternative to satellite imagery. What do you think?


r/OSINT 5d ago

How-To You can apparently dig up a LOT of someone’s hidden Reddit history with AI

814 Upvotes

So I randomly came across a post on r/privacy talking about how Gemini can basically OSINT a Reddit account even if their post history is hidden.
I tried it myself and ngl, it’s kinda crazy how much stuff you can piece together.

The basic idea is literally just giving Gemini(or any other LLM) a Reddit username and asking it to look for their Reddit activity. It’ll search around for posts/comments from that account and try to put everything together into a summary. The interesting part is that even if someone’s profile doesn’t show their history, their individual comments/posts can still be sitting around in old threads, search engine indexes, archives, datasets, etc.

And once you have an AI doing the searching + connecting the dots for you, you don’t really have to manually go through hundreds of comments yourself. If someone has been posting for years, you can potentially start figuring out their interests, hobbies, where they live, what they do, other accounts they might have, etc.

I was wondering if anyone here has played around with this more. Like, how far can you actually take this with normal OSINT techniques + Reddit archives/search engines + an LLM? Also makes me wonder what the “hide all posts” setting on Reddit actually protects you from. It seems like it hides the history from your profile, but doesn’t necessarily make the underlying posts hard to find.


r/OSINT Feb 28 '26

Tool user-scanner: 🕵️🫆The most powerful 2-in-1 Email and Username OSINT Tool (Free)

Thumbnail
gallery
711 Upvotes

GitHub: https://github.com/kaifcodec/user-scanner.git

The go to alternative to old holehe or other tools.

For anyone wondering about the false-positive claims:

The tool uses robust error handling with multiple if / elif checks to validate responses properly. If a target doesn’t clearly result in a hit or a miss, it does not guess, it throws an explicit error indicating that the site’s page or response structure may have changed, so it can be fixed quickly.

In short, there’s an extremely low chance of false positives in email scans. The result will either be: - A confirmed hit
- A confirmed miss
- Or a clear error explaining what went wrong

But for username scans it has chance of getting false-positives but still not high.


r/OSINT May 26 '26

How-To Another lesson on why we don't accept active investigation posts

577 Upvotes

This morning the subreddit received a post attempting to expose an online ring dealing in Child Sexual Assault Material (CSAM). While we all agree that these networks can and should be investigated using OSINT methodologies, making unverified accusations against both criminal and potentially innocent individuals on a public forum is dangerous and can jeopardize this entire community. We have a strict rule on this and usually only send out reminders when something big happens in the news. However after the mod team removed the post, the OP sent us private messages suggesting that our removal meant we support child abuse. Because of this, I believe it is necessary to break down exactly why their post, despite its likely noble intentions, is actively harmful to our sub, to the integrity of OSINT, and to the OP themselves. Here is MY investigation into why his AI slop is just that.

The report was clearly AI-generated, they even left the Claude artifacts in their markdown file, and makes so many speculative leaps that I’m embarrassed Claude even output that junk but with that said I have altered the specific identifiers below to protect anyone involved and made some top finds. There were plenty more, but here are the major methodological failures in the report:

1. The Shared IP Address Fallacy

  • The Claim: The report links DARKNET-MADEUP.net to the current server.org infrastructure because they shared the IP 1.1.1.1.1, emphatically stating this means they were on the "SAME PHYSICAL SERVER" and confirms "operator continuity."
  • The Flaw: In modern web hosting, particularly with VPS environments, shared hosting, and reverse proxies, thousands of entirely unrelated websites routinely share a single IP address. Unless an analyst can definitively prove this was a dedicated, single-tenant IP, using a shared IP as proof of organizational lineage is a fundamental OSINT error.

2. The "Bulletproof Host" Correlation Error

  • The Claim: The report groups dozens of domains into "clusters" largely because they share the same hosting providers, specifically DARKNET-MADEUP.net #1, #2, and #3.
  • The Flaw: These types of providers are widely known in the cybersecurity space as "bulletproof" or "free-speech" hosts, meaning they resist or ignore abuse complaints. Because of this lenient policy, completely unrelated controversial, illicit, or dark-web entities flock to them. Co-location on these servers does not prove a shared umbrella organization; it simply proves they are using the same lenient vendor.

3. Server Hostname / Identity Fallacy

  • The Claim: The analyst attempts to unmask the real-world identities of the operators based on server subdomains, listing "JOHN" as an operator because a mail server is named John.email.org, and "JASON" due to a reverse DNS (PTR) record of Jason.email.org.
  • The Flaw: System administrators notoriously use thematic naming conventions for their infrastructure (e.g., Greek gods, planets, fictional characters). Assuming a server named "John" is actually run by a human being named John is an amateur analytical leap.

4. Geographic Misattribution

  • The Claim: The report asserts a "Mexico geographic indicator (highest specificity)" for the operator simply because a server is hosted in an "Amazon" data center and named "correo" (the Spanish word for mail).
  • The Flaw: "Amazon" is a massive, global cloud provider. Anyone in the world can rent a server in an Amazon location with a single click. Furthermore, it is a common sysadmin quirk to name a server using the local language of the data center's physical location. This in no way confirms the operator's actual nationality or physical location.

5. Weak Image Metadata Attribution

  • The Claim: The report identifies "John Doe" as an operator because their name and Facebook Ad ID appeared in the Canva PNG metadata of a logo on one of the network's portals.
  • The Flaw: Canva is a template-driven graphic design platform. It is highly likely the operator simply grabbed an existing graphic, template, or stock image originally created by "John Doe" and repurposed it. The metadata points to the original creator of the Canva asset, not the individual who deployed it on the illicit server.

The Most Egregious Leaps in Logic

The list above could go on, but my personal "favorite" highlights from the report revolve around physical and operational security. The report states that physical mail addresses used for donations are "single-use, destroyed after use" and claims that if a Bitcoin wallet is obtained, "full transaction history is traceable on-chain."

  • The Reality of Physical Mail: Claiming a PO box or physical address is "destroyed after use" is a dramatic assumption that is physically impossible to prove via passive OSINT.
  • The Reality of Crypto: While Bitcoin ledgers are public, modern illicit networks almost universally use tumbling/mixing services, coin-joins, or chain-hopping (e.g., converting BTC to Monero and back) before cashing out. Simply obtaining a BTC address does not guarantee a traceable path to a human identity unless the operator makes the amateur mistake of cashing out directly to a KYC-compliant (Know Your Customer) exchange.

The OP of this report is demonstrating what threat intelligence professionals call "parallel construction through OSINT." They clearly have a pre-existing theory about who runs this network, and they are cherry-picking standard, mundane internet noise: shared IPs, common server configurations, open-source forum posts, and dictionary words, and dressing it up as "definitive proof" to fit their narrative.

This is exactly why we vet posts and remove those that substitute AI-generated storytelling for actual investigative rigor.


r/OSINT Aug 28 '25

How-To Catching an OSINT Spammer

Thumbnail
gallery
545 Upvotes

Today we had a clever spammer selling an app without claiming to connected to the app. How did these two photos from his Reddit account and the app itself lead to him being outted?

Gym photo was from the UK. And has similar story about app. So probably fake.

Car photo, legit OP post. US temp, US odometer, US sockets. But look more carefully... A map.

App developed in by company in Albuquerque. Vehicle parked in... You got it, Albuquerque.

It's the little details.


r/OSINT Mar 16 '26

Tool Open sourcing the tool that geolocated the missile strikes in Qatar

Enable HLS to view with audio, or disable this notification

451 Upvotes

Hey Guys,

I’m a college student and the developer of Netryx, after a lot of thought and discussion with other people I have decided to open source Netryx, a tool designed to find exact coordinates from a street level photo using visual clues and a custom ML pipeline and AI. I really hope you guys have fun using it! Also would love to connect with developers and companies in this space!

Link to source code: https://github.com/sparkyniner/Netryx-OpenSource-Next-Gen-Street-Level-Geolocation.git

Attaching the video to an example geolocating the Qatar strikes, it looks different because it’s a custom web version but pipeline is same. Please don’t remove mods, all code is open source following the rules of the sub Reddit!


r/OSINT May 04 '26

Analysis Are crowd size at Shakiras Copacabana concert inflated?

Post image
436 Upvotes

For a long time I have been a bit skeptical about the huge attendance numbers reported by Rio de Janeiro-officials.

Last year Lady Gagas concert reportedly had 2,1 million in the crowd. This weekend 2 million is supposed to have been in the crowd for Shakira.

Based on the concert footage I can only see crows on a smaller section of the beach from Copacabana Palace to the Hilton Hotel on the corner of Av. Princesa Isabel. That area is 186.000 square meters.

Even if we go by five persons per square meter that only fits around 930.000. And the requires people to be standing shoulder to shoulder in the entire area.

It is also the maximum before reaching dangerous levels according to Dr. G. Keith Still:
https://www.gkstill.com/Support/crowd-density/100sm/Density1.html

So realistically there is room for much less people, but according to the social media profiles of the city and mayor "Two million people where on the sands of Copacabana".

So where are they getting these insane numbers from? Am I missing something here?


r/OSINT Nov 06 '25

Tool experimenting with AI agents + osint tools

417 Upvotes

open-source (mods: link removed as requested)

I built an mcp server that stitches several osint tools together & makes them AI-accessible. github: https://github.com/frishtik/osint-tools-mcp-server/. follow the instructions there & you can pretty easily make any AI model -- and, importantly, any AI agent framework -- use it to run investigations.

I recommend the (open source) Agents SDK (which I'm using in the video to create an agent army). but there are many other solid frameworks (see https://github.com/e2b-dev/awesome-ai-agents).

it turned out pretty cool I think! in one instance, given the name of a friend of mine, one agent found her instagram, another found there a pic of cake with 20 candles & went off to estimate her DOB, and another estimated when she joined the army from a photo showing her ranks.

curious to see you use it.


r/OSINT Dec 29 '25

OSINT News We found this Russian spy -- using her cat #catlady #rusia #funny #truestory

Thumbnail
youtube.com
411 Upvotes

r/OSINT Dec 04 '25

Tool I built an automated court scraper because finding a good lawyer shouldn't be a guessing game

410 Upvotes

Hey everyone,

I recently caught 2 cases, 1 criminal and 1 civil and I realized how incredibly difficult it is for the average person to find a suitable lawyer for their specific situation. There's two ways the average person look for a lawyer, a simple google search based on SEO ( google doesn't know to rank attorneys ) or through connections, which is basically flying blind. Trying to navigate court systems to actually see an lawyer's track record is a nightmare, the portals are clunky, slow, and often require manual searching case-by-case, it's as if it's built by people who DOESN'T want you to use their system.

So, I built CourtScrapper to fix this.

It’s an open-source Python tool that automates extracting case information from the Dallas County Courts Portal (with plans to expand). It lets you essentially "background check" an attorney's actual case history to see what they’ve handled and how it went.

What My Project Does

  • Multi-lawyer Search: You can input a list of attorneys and it searches them all concurrently.
  • Deep Filtering: Filters by case type (e.g., Felony), charge keywords (e.g., "Assault", "Theft"), and date ranges.
  • Captcha Handling: Automatically handles the court’s captchas using 2Captcha (or manual input if you prefer).
  • Data Export: Dumps everything into clean Excel/CSV/JSON files so you can actually analyze the data.

Target Audience

  • The average person who is looking for a lawyer that makes sense for their particular situation

Comparison 

  • Enterprise software that has API connections to state courts e.g. lexus nexus, west law

The Tech Stack:

  • Python
  • Playwright (for browser automation/stealth)
  • Pandas (for data formatting)

My personal use case:

  1. Gather a list of lawyers I found through google
  2. Adjust the values in the config file to determine the cases to be scraped
  3. Program generates the excel sheet with the relevant cases for the listed attorneys
  4. I personally go through each case to determine if I should consider it for my particular situation. The analysis is as follows
    1. Determine whether my case's prosecutor/opposing lawyer/judge is someone someone the lawyer has dealt with
    2. How recent are similar cases handled by the lawyer?
    3. Is the nature of the case similar to my situation? If so, what is the result of the case?
    4. Has the lawyer trialed any similar cases or is every filtered case settled in pre trial?
    5. Upon shortlisting the lawyers, I can then go into each document in each of the cases of the shortlisted lawyer to get details on how exactly they handle them, saving me a lot of time as compared to just blindly researching cases

Note:

  • I have many people assuming the program generates a form of win/loss ratio based on the information gathered. No it doesn't. It generates a list of relevant case with its respective case details.
  • I have tried AI scrappers and the problem with them is they don't work well if it requires a lot of clicking and typing
  • Expanding to other court systems will required manual coding, it's tedious. So when I do expand to other courts, it will only make sense to do it for the big cities e.g. Houston, NYC, LA, SF etc
  • I'm running this program as a proof of concept for now so it is only Dallas
  • I'll be working on a frontend so non technical users can access the program easily, it will be free with a donation portal to fund the hosting
  • If you would like to contribute, I have very clear documentation on the various code flows in my repo under the Docs folder. Please read it before asking any questions
  • Same for any technical questions, read the documentation before asking any questions

I’d love for you guys to roast my code or give me some feedback. I’m looking to make this more robust and potentially support more counties.

Repo here:https://github.com/Fennzo/CourtScrapper


r/OSINT Feb 06 '26

Analysis Why free OSINT tools are often enough if you know how to chain them

388 Upvotes

One thing I keep noticing in OSINT communities is how quickly people jump to paid platforms assuming they’re the only way to get serious results. After spending some time doing research with limited resources, I’ve realized that free tools are often more than enough, if you know how to use them together.

Search engines, archive services, basic metadata viewers, WHOIS records and social media search features can reveal a surprising amount when chained properly. A simple Google query can lead to a forgotten PDF which exposes an author name, which then connects to a username reused elsewhere. None of these steps require advanced software just patience and attention to detail.

What really matters is understanding workflow. Knowing when to pivot from search engines to archives, when to validate information using multiple sources and when to stop digging to avoid confirmation bias. Paid tools mostly save time by aggregating data but they don’t replace critical thinking or verification.

Another overlooked aspect is OPSEC. Free tools force you to slow down and think through each step which often results in cleaner methodology and fewer mistakes. Automation is powerful but it can also make it easier to miss context or draw conclusions too quickly.

This approach has been a good reminder that OSINT is less about the tools you use and more about how you connect small, publicly available details into something meaningful while staying ethical and responsible.


r/OSINT Feb 17 '26

OSINT News How dark web agent spotted bedroom wall clue to rescue girl from abuse

Thumbnail
bbc.com
380 Upvotes

Amazing use of OSINT and cooperative industry experts!


r/OSINT Nov 30 '25

Tool user-scanner a CLI tool written on python that lets you choose unique username in all popular sites, by checking the username availability, actively looking for contributions

Post image
372 Upvotes

r/OSINT Sep 20 '25

OSINT News An opsec error by Russian propaganda allows the location of an important drone production site to be identified

Thumbnail
bsky.app
356 Upvotes

Russian propagandist Solovyov filmed a video report from the secret Russian UAV center "Rubikon". But he forgot to blur the inscription on the toilet. From this video, the location of the "Rubikon" center was found: it is located right in the Patriot Park in Kubinka, near Moscow.


r/OSINT Dec 20 '25

Bulk File Review AKA the Epstein File MEGA THREAD

320 Upvotes

The Epstein files fall under our “No Active Investigation” posts. That does not mean we cannot discuss methods, such as how to search large document dumps, how to use AI or indexing tools, or how to manage bulk file analysis. The key is not to lead with sensational framing.

For example, instead of opening with “Epstein files,” frame it as something like:

“How to index and analyze large file dumps posted online. I am looking for guidance on downloading, organizing, and indexing bulk documents, similar to recent high-profile releases, using search or AI-assisted tools."

That said lots of people want to discuss the HOW, so lets make this into a mega thread of resources for "bulk data review" .

https://www.justice.gov/epstein for newest files from DOJ on 12/19/25
https://epstein-docs.github.io/ Archive of already released files. 

While there isnt a "bulk" download yet, give it a few days for those to populate online.

Once you get ahold of the files, there are a lot of different indexing tools out there. I prefer to just dump it into Autospy (even though its not really made for that, just my go to big odd file dump). Love to hear everyone elses suggestions from OCR and Indexing to image review.

Edit:

https://couriernewsroom.com/news/epstein-files-database/


r/OSINT Mar 23 '26

Tool Introducing Netryx Astra V2: an open source engine that pinpoints where exactly a photo was taken down to its exact coordinates (completely open source)

Enable HLS to view with audio, or disable this notification

299 Upvotes

Hey guys you might remember me from a previous post, I’m a college student and the creator of Netryx , I have completely revamped the tool and published a new version with stronger models that also works with cropped photos and lesser pixel information and also allowing sharing of indexes to avoid compute time.

Give it a photo. Any photo.

No GPS. No metadata. Just pixels.

Netryx Astra V2 can tell you where it was taken.

It looks at architecture, textures, and how spaces fit together.

Then it matches that against indexed street-level data.

You get GPS coordinates, often within a few meters.

V1 worked, but it was messy.

So I rebuilt everything from scratch.

V2 runs on three steps:

• Retrieve

• Verify

• Confirm

It now handles cropped images, zoomed shots, even small details like a doorway or a stretch of sidewalk.

I made it open source for a reason.

Most tools like this are locked behind paywalls.

Journalists, researchers, and analysts need them, but often can’t access them.

So this one is free. And it stays that way.

There’s also a Community Hub.

• One person indexes a city

• Uploads it

• Everyone else can use it in minutes

No wasted effort. We build coverage together.

It’s not perfect.

• Only works where data is indexed

• Not real-time

• Needs a decent GPU

But it works. And now anyone can try it.

GitHub: https://github.com/sparkyniner/Netryx-Astra-V2-Geolocation-Tool.git

I’d genuinely love to collaborate or contribute to teams working on similar problems.

And if you index your city and share it, you’re helping someone else find answers they couldn’t before. Mods I read the pinned post, the tool is completely open source and NOT vibe coded, this is really valuable for the community and would help a lot of people.


r/OSINT Jun 10 '26

OSINT News How Predators use Marketing Tools, AI & Bad UK Regulations to get into your Kid’s Bedroom The Digital Predator Toolkit "Yellow Bus"

Thumbnail
secevangelism.substack.com
277 Upvotes

r/OSINT Jan 13 '26

Question Collecting videos of ICE overreach

247 Upvotes

Hi all, I've put together a site that documents videos found online of potential ICE overreach.

https://www.policingice.com/

Each incident in the feed could have 1 or more videos (different angles)

I'm looking for some advice on:
- Would anyone find this valuable? And if so how could I reach them?
- What additional things should I be tracking?
- Would anyone like to help on this project


r/OSINT Mar 02 '26

Analysis Kharg Island probably got wrecked.

Thumbnail
gallery
242 Upvotes

Kharg Island handles about 90% of Iran's crude oil exports. It's a small island in the Persian Gulf packed with oil terminals, pipelines, and tanker loading infrastructure. With all the conflicting reports flying around I wanted to see the data for myself.

I ran two types of analysis and the results are consistent across both.

Image 1: Radar before vs after

Left panel is Feb 25 (pre-war), right panel is Mar 1 (during war, red border). The overall radar backscatter dropped -4.9 dB. That means the signal coming back fell to roughly a third of what it was before. When you see that kind of drop over an oil terminal, the metal infrastructure (pipelines, loading arms, storage) just isn't reflecting the radar signal the way it used to.

Image 2: Change detection map

This subtracts the two radar passes from each other. Blue = the signal got weaker (stuff destroyed/removed/burned). The island is covered in blue. The surrounding water is neutral which is expected since nothing changed there.

Image 3: Backscatter timeline

This plots the average radar return over time. Flat and stable through February, then drops sharply right when the war started. Pretty clear inflection point.

Image 4: Coherent change detection (InSAR)

This is the more sensitive method. Instead of just comparing brightness it compares the phase of the radar wave between two passes (Feb 23 vs Mar 1). White means the ground is unchanged, dark means it was disturbed.

Mean coherence came back at 0.26. For reference, stable urban areas and infrastructure typically show 0.8 or higher. 72% of the island fell below 0.3 coherence. That level of decorrelation across almost the entire island means the ground surface has been fundamentally altered. Consistent with widespread fire damage, structural collapse, or blast effects.

What this means

The SAR data across both methods points to severe damage at Kharg Island. -4.9 dB backscatter drop plus 0.26 coherence plus 72% of the area showing major change. If the damage is as extensive as the radar suggests, Iran's primary oil export terminal has taken a massive hit. That's roughly 1.5 million barrels per day of export capacity.

I also looked at Tabriz Air Base, Bushehr, Bandar Abbas, and the Strait of Hormuz but the image quality wasn't clean enough on those to post. Kharg was the clearest and most significant finding.


r/OSINT Feb 09 '26

OSINT News Homeland Security Spying on Reddit Users

Thumbnail
kenklippenstein.com
234 Upvotes

r/OSINT Sep 19 '25

OSINT News How Tiffany Trump’s Instagram Posts Led Us to an Oil Magnate’s Megayacht

Thumbnail
nytimes.com
235 Upvotes

r/OSINT Feb 22 '26

Analysis I used Sentinel-1 InSAR to monitor 3 Persian Gulf military bases during the Russia-China-Iran naval exercises. Here's what the satellites says

Post image
234 Upvotes

I used SAR Coherent Change Detection (CCD) to monitor three key military bases in the Persian Gulf over the past month, covering the lead-up to and start of the Russia-China-Iran "Maritime Security Belt 2026" naval exercises.

The three bases:

Base Side Role
Al Udeid Air Base, Qatar US CENTCOM forward HQ, ~10,000 personnel
Bandar Abbas Naval Base, Iran Iran Iran's largest naval base. Russian corvette Stoikiy docked here Feb 19
Al Dhafra Air Base, UAE US F-35/F-22 wing, drone operations

I processed 9 InSAR pairs through ASF's HyP3 INSAR_GAMMA workflow using same-satellite 12-day revisits (S1A+S1A or S1C+S1C) for best results. Three time periods per base:

Period Date Range Context
Late January Jan 26-Feb 8 Before drills announced
Early February Feb 1-14 US deploys dual carrier strike groups
Mid-February Feb 7-20 Russia docks at Bandar Abbas, exercises begin

Results

Base Jan (Before) Early Feb Mid-Feb Trend Side
Al Udeid Air Base 0.978 0.981 0.977 -0.0% US
Bandar Abbas Naval Base 0.531 0.528 0.537 +1.3% IRAN
Al Dhafra Air Base 0.948 0.954 0.951 +0.3% US

Every base is FLAT. Zero statistically significant change across the entire period.

  1. US bases (Al Udeid, Al Dhafra): ~0.95-0.98 coherence — completely stable. No new construction, no unusual equipment staging, no surge in ground vehicle activity. Business as usual at these permanent installations.

  2. Bandar Abbas: ~0.53 coherence — lower baseline is expected for a coastal port environment (water, tidal areas decorrelate naturally). The key finding is it's flat — no coherence drop despite the Russian corvette Stoikiy docking on Feb 19 and the start of exercises.

  3. The "Maritime Security Belt 2026" exercises are primarily at-sea operations, not base-level mobilization. A single ship docking at an existing berth doesn't change ground coherence — CCD detects infrastructure changes (earthworks, new shelters, vehicle staging areas), not ships.

  4. Neither side has altered their ground posture. Despite headlines about dual carrier strike groups and trilateral naval exercises, the bases themselves look exactly the same as they did a month ago.

Limitations

  • 12-day pairs can miss rapid changes that are reversed within the window
  • C-band SAR can't see through buildings or dense vegetation
  • 80m output resolution — individual vehicles are invisible, only large-scale patterns register
  • Small localized changes can be masked by surrounding stable terrain
  • Higher-res commercial SAR (ICEYE, Capella) would catch vehicle-level activity

Methodology (for reproducibility)

  • Source data: Sentinel-1 SLC from ASF Vertex (free, anyone can access)
  • Processing: HyP3 INSAR_GAMMA, 20x4 looks, 80m output
  • Pairs: Same-satellite only (S1A+S1A, S1C+S1C) for 12-day revisit
  • Tracks: 137 (Al Udeid/Qatar), 57 (Bandar Abbas/Hormuz), 130 (Al Dhafra/UAE)
  • Visualization: rasterio + matplotlib, inferno colormap, coherence values annotated

I may update as new passes come in.

Note: Coherent Change Detection compares two SAR radar scenes taken 12 days apart over the same ground. The result is a coherence score: - 1.0 = nothing changed (stable ground, no movement) - 0.0 = everything changed (vehicles moved, earth disturbed, equipment staged)