In Episode 23 of The OSINT Podcast, host Jake Creps covers three issues spanning operational security, community discovery, and platform-specific investigation technique. The episode opens with OpSec for investigators: why your own digital footprint is just as exposable as anyone else’s, how small habits like reused usernames or logged-in browser sessions create attribution risk, and why identity separation between your personal and investigative accounts is non-negotiable. From there, the conversation turns to Waybien, a community search engine that indexes public groups and channels across Telegram, WhatsApp, Facebook, Discord, and Slack from a single interface, useful for lead generation, SOCMINT work, and mapping where a subject is being discussed across platforms. The episode closes with a technical walkthrough of Vinted, the secondhand fashion marketplace, tracing what the sign-up flow, public profiles, and underlying APIs reveal about sellers, alongside a roundup of new OSINT tools and a story about a GitHub-based threat actor undone by, of all things, a photo of his cat.
Highlights
🕵️ OpSec fundamentals: digital footprint awareness, identity separation, and data exposure through browser autofill and saved sessions
🧵 Waybien: cross-platform community discovery across Telegram, WhatsApp, Facebook, Discord, and Slack
🛍️ A technical deep dive into Vinted’s sign-up flow, public profile data, and underlying search API
🐱 How OSINT and threat hunting traced a GitHub-based supply chain attacker through a single alias — and his cat
🎣 Fake Claude download pages surfacing as user-generated artifacts, promoted through paid Google Ads
🧰 New tools: Vinosinted (Vinted recon), EmailOSINT (reverse email lookup), and Osiris (real-time intelligence dashboard)
Links
