mnemonic security podcast

OSINT

mnemonic

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 43:12

In a world where images can be manipulated, eyewitnesses dismissed, and official accounts contradicted by what happened on the ground, proving what is real has never been more important.

In this episode, Robby speaks with Vladimir Zaha, a threat intelligence researcher and volunteer contributor to the Bellingcat community, about the growing role of open-source intelligence in journalism, cybersecurity, conflict monitoring, and democratic accountability.

Vladimir explains how OSINT investigators verify images and videos, geolocate events using seemingly insignificant details, monitor activity in active conflicts, and challenge false or misleading official narratives. He also discusses his work documenting civilian harm in Ukraine, investigating the actions of enforcement agencies in the United States, and helping analyse information that may eventually support legal proceedings.

The conversation explores how OSINT can help cybersecurity professionals understand their threat environment, how artificial intelligence is changing the investigative process, and why human verification remains essential even as collection and analysis become increasingly automated.

Send us Fan Mail

Speaker 2

From our headquarters in Oslo, Norway, and on behalf of our host, Robby Peralta, welcome to the mnemonic security podcast.

Robby Peralta

Not all heroes wear capes. Some spend their nights sifting through satellite imagery, social media posts, and shaky phone footage, searching for the fragments of truth that others have tried to bury. They identify where missiles have landed, document attacks on civilians, challenge governments when official statements don't match what happened on the ground. Sometimes their work helps locate missing people. Other times it preserves evidence that could one day bring war criminals to justice. In a world where anyone can manipulate an image, twist the truth, or simply deny that something ever happened, the work of OSINT investigators has never been more important. When trust in society is disappearing, someone has to prove what is real. So it was a great honor for me to get to know one of these heroes. Vladimir Zaha, welcome to the podcast.

Vladimir Zaha

Thank you very much. It's great to be here. Tell us what you do for a living. Yeah, so uh I work for iProov. It's a British company, and we deal with research and prevention of biometric security attacks. Primarily, we are focusing against combating fraud and identity reappropriation by specific threat actors. Cool.

Robby Peralta

So you're basically making it so people can't hack your face, basically.

Vladimir Zaha

Yes, essentially, yeah. And especially with the the prevalence of AI nowadays and uh deep fakes, face swaps, and uh all of these beautiful capabilities that now are in everyone's hands, this this is becoming a much bigger threat to a lot of companies.

Robby Peralta

This is not the topic of discussion today, but tell us how does one go about hacking a face recognition software?

Vladimir Zaha

Obviously, there's there's implications of whether or not they have the the passwords and the credentials and a leak to to a particular person, but they might just simply want to create a new account, for example, with the bank and not have that account linked to them because then they can operate that account for their own reasons without fear of repercussions from authorities. How they do it is is mostly through an advanced technique, which is the main reason why we have a security operations center detecting these attacks and a threat intelligence team, which I'm a part of, is they perform injections on either mobile or on web applications that these banks or institutions utilize, and they try to inject their own arbitrary imagery. So instead of them scanning their face and improving their liveness, they inject uh either an AI-generated model from scratch or a face swap on their like real bodies, but a a separate synthetic face. And we have mitigations in place for all of this, but there are so many different types of attacks that of course it's it's a thing to look out for constantly, right? Because it's always evolving. And you've seen the pace at which these tools have have evolved recently, and AI has evolved recently. And most AI models that have reached a particular level of maturity are are fully capable of generating imagery of if it's the case for image models. But even to write a script that can do this for you, many models are capable of this already.

Robby Peralta

And you work with threat intelligence because you keep up to date with that. So you follow the threat landscape and what people are doing on Telegram and all these places.

Vladimir Zaha

Absolutely. And and it's thrilling because you see constant movement at any hour of the night. It's it's literally coming from every possible continent, the these pings of intelligence where someone might want to try a new technique or they invent one.

Robby Peralta

Cool. But you have other hobbies. You have a you have a life outside of work.

Vladimir Zaha

I do. I do, and it's also worker related. It's also very much uh aligned with intelligence. I I volunteer for the Bellingcat volunteer community, and it's a crowdsourced group of vetted members that assist with analysis of different data points that might help the Bellingcat staff with processing very large cases.

Robby Peralta

What's the point of Bellingcat? What's their like purpose?

Vladimir Zaha

The the point of Bellingcat is to be essentially, in my opinion, they are the only journalistic source of truth that I've seen in today's online world. They are by no means a classical news publication. They take news what I like to describe as low and slow, which means that facts are not presented immediately as they arrive. They are first verified, they are cross-referenced, and they're they're sourced to to where they come from in order to be able to actually determine the veracity of the facts that are being presented and not just easily get, you know, publication and clicks for for the speed of it.

Robby Peralta

So they're there to verify facts.

Vladimir Zaha

Absolutely.

Robby Peralta

Yeah. Are there any other communities that are similar to Bellingcat that you're aware of?

Vladimir Zaha

There are fringe communities that I wouldn't call them fringe necessarily, but they are adjacent to this cause. For example, geo-confirmed is one that relates to geolocating um conflict content. So videos, images from from active conflicts around the world, they put them on a map and they require the volunteer members of those community to assist with geolocating and verifying that these events have actually occurred in the places that they're they're alleged to occur. But in terms of the complete journalistic workflow and the presentation and the assurance that the data is factual, I have not so far met anything similar to Belling cat.

Robby Peralta

But they work with open source intelligence, basically. OSINT.

Vladimir Zaha

Absolutely. Everything needs to be verifiable through uh sources that are already available on the internet and anyone can find.

Robby Peralta

Right. When I think of OSINT, I think of that that challenge. I think it's called the Where Am I challenge. And there's a bunch of different examples, but one of them was somebody put up just a picture of a shadow and they where am I? Can you just explain how how hard it is or how easy it is to do something like that?

Vladimir Zaha

Yeah, absolutely. This is uh this is prevalent on on Twitter and other social media if if you search for #OSINT, # Where Am I or challenge, you'll find plenty of people that are uh trying to see if how easily they are they are able to be found. And uh essentially this this one case, I believe it it referred to simply the shadow of a of a window being projected onto a white wall with no other context whatsoever. So at first glance it was a a pretty hard challenge. But I I think even when you look at a at a specific point of data and you feel overwhelmed by the lack of detail in it, you can still find many things. And this speaks a lot to your own experience as a person. For example, if you have architectural knowledge or a background in architecture or in design, you might recognize that a windowsill has a particular shape or that the light is hitting at a particular angle inside of the building. And if you know about buildings and how they're built, they're mostly desired to be facing either east or west in order to either benefit from dusk or or dawn. Right. And in this case, I believe it was someone who found the shape of the windowsill was completely atypical, and uh reconstructing the full shape just from the shadow cast on the wall was able to determine the actual location of the building, and also correlating that with the position of the sun at the point where the image was taken, that actually gave a tremendous amount of information, which looking or scrolling past the picture, you would not believe this would be the case. But uh it absolutely is helpful.

Robby Peralta

So people that work with OSINT, they're puzzle solvers.

Vladimir Zaha

Very much so, yeah. Very much people with attention to detail and people with a desire to determine facts.

Robby Peralta

Besides solving puzzles for fun, because they have this is a community that a lot of people just do it for fun. You have applied it to other matters. Tell us about some of the things you've applied it to.

Vladimir Zaha

Yeah, absolutely. So some of the work I've been involved in, these are published articles. I've had the tremendous opportunity to to help with monitoring conflict in uh in Ukraine, and this is part of the civilian uh civilian harm in Ukraine Time Map. And the civilian harm in Ukraine time map essentially geolocates uh videos from Telegram and Twitter and other social media where it's showcased that missiles were used against civilian populations in certain areas during and throughout the invasion and the war in Ukraine. And there have been vast amounts of data to sift through, of course. And it's not easy, but it's it's something to remember that there are people who are living through this. Um and for me, just to be able to look at this and geolocate it is nothing compared to having to live this as a as a day-to-day. Um other projects have been uh the ICE raids in in the US. So the the actions and the activity of ICE uh and and affiliated enforcement agencies throughout the US recently, and particularly focusing on the abuse of power from these agencies, uh especially due to the fact that they are masked and and um, so to speak, unaccountable for for what actions they take in the field.

Robby Peralta

There are facts in the world and their story contradict the facts.

Vladimir Zaha

Yeah, absolutely. Do in my own opinion, I I want to say I do participate in this because I have a very strong interpretation of what fairness is, and I believe that what we're seeing coming out of the US, uh both uh at the initialization of these agencies and the revival of these agencies has not been congruent with fairness and how I define it, and I think how many other people define it as well. Um but uh absolutely in terms in terms of analyzing the actions of authoritarianism in today's modern world, you do see the trend of public statements not really matching up with what is seen on the ground, and the invalidation of eyewitness records and uh victim experiences, the invalidation of these through through a simple waving of the hand and saying, no, the legal state has the final opinion on this. This is not this did not happen, and actually our actions are fully compliant with how we normally do things. When um that's when I feel people need to step in. And that's when I feel OSINT is a public tool more than a personal preference, is to to search for those facts and make everyone aware that it's not just what one party says. It's it's actually what is seen and verifiable on the ground.

Robby Peralta

One of the articles you wrote, there was the government said that, yeah, this individual drove into uh a cop car, an unmarked cop car, and then you saw the video, which is just from some somebody's iPhone, that the the cop car actually ran into her and dragged her out by her feet. So the government says one thing what are the steps that you actually take to prove this is actually what happened? I like how'd that look like for you?

Vladimir Zaha

There's a bifold approach to this, right? I mean, there's there's the odd uh person living in England that wants to to verify this and put it out as a fact. Uh, but then there's also the citizen part of the the particular state where this happens, which I believe has a lot more control over what can happen in the future in that state. So your elected officials, your your police departments, how they are, um how they face the repercussions of these types of actions is is also a very valid approach, right? In the case of the open source intelligence analyst, uh simply having multiple views of the same thing happening, which goes against what a public authority states happened, is already a telltale sign of what actually occurred on that day, right? There's obviously arguing with AI earlier, there can always be manipulations of this. And I I believe OSINT analysts around the world have seen at least once uh an AI manipulated piece of content that aims to disrupt the normal analytical flow and what we do. Um however, there's verifiable means through which this has not happened with the particular video you're referencing, right? Even though it's easy to tout uh an overall devil that uh you know invalidates everything one person says. Um I think everyone should be the devil's advocate in this case and and actually research it themselves. And see, there's no artifacts of modified imagery. There is uh there is full one-to-one matching between two perspectives from two different observers, is what we call the people with the phones on the on the sidewalks, right? Two different observers filming the exact same thing with no uh inconsistencies between the videos is already a one in a million chance that this this might be a fake, right? It's uh you can tell that it's real. In the case of the person living in the state, I I believe protesting is one is one form of reaction to the spread of this type of disinformation from from official governing bodies. But at the same time, being equipped with the knowledge to perform their own verification of events, being able to hold accountable their states using FOIA requests or any type of public inquiries, or even being prepared to understand the current political situation in their state will help them a lot to protect themselves and their family from this happening to them as well.

Robby Peralta

But what do you actually do when you're when you analyze these videos? Like how do you how do you know if they're fake? How do you verify facts? Like what is the verification process that what organizations like Bell ingcat would do or anybody else similar?

Vladimir Zaha

I'll give you my example because I think it's unique to every every person. Um let's take the example of the OSIN challenge. Um and there there has been another one, for example, where um a person recently posted a photo from a window this time looking outside. Um and I believe in the end it was determined that it was in France. Right. So in one of these challenges, the workflow is very straightforward. Essentially, you're looking at an image, if we simplify it. A video is more complex, and at that point you you get more of a view of what's going around, so it's easier. Let's say it's just a photo. In the case of a photo, you try to break down the visual elements that you're looking at. If we're talking strictly about geolocation, which is a subset of open source intelligence, you need to take each object within the picture as a specific data point that you can research upon. Does the window have a particular frame, which is a thing that we've analyzed before? Does the the sun uh shoot through the window in a particular color? Is it warm? Is it more akin to a to white or blue color? So is it dusk? Is it dawn? The angle is always a thing to keep in mind, regardless, because it can determine roughly a time estimate of when the photo was taken. But then you also need to look at other objects which you might not usually is is there parquet flooring? Is it hardwood flooring? Is it cement? This will tell you a lot about the building standards in that area. Is the furniture from the you know 18th century, or is it modern, or is it IKEA, or does it look like IKEA, but it's not quite that? So is it a country that offers mock-up IKEA furniture, which also tells you a lot about where the subject uh is or or where they're located? And more of it than that, you need to look outside. You need to think outside the box, which is very much a thing that um maybe listeners that are from the cybersecurity realm uh might very much relate to if they do offensive security. You need to think outside the box. You need to look at the person who posted the photo. Do they normally post within that time frame? Are those their normal active hours or are they posting at night? Uh this is called pattern of life analysis. And and when you look at this, you can deduce, uh, but not with 100% certainty, of course, because nothing is. But you can start to deduce the time zone that the person might be in. So that helps you narrow down a lot, actually. This would be a normal flow for geolocation, but there is, as you can imagine, the the many different aspects of the world can be dissected in and so many other different aspects of data points that you can look at and you can learn about them. Munitions are one thing, weather are is another one. Um, knowing the different models of cars that exist in certain countries, the different street signs that exist in different countries. All of this is a very particular subset of skills that anyone with the background knowledge immediate to the subject might find useful to apply.

Robby Peralta

Now you mentioned uh munitions. When I think of munitions, I think of there's a lot of work being done in OSINT in wars. Obviously, munitions is basically to see which sort of mercenaries, which sort of soldiers were there, or can you want to detail about that?

Vladimir Zaha

This helps a lot, yeah. It it helps a lot to determine what kind of parties have worked together to launch attacks. Um and especially it it points towards the more revealing fact of how many stockpiles a particular army has, for example. If they start using munitions from the Cold War, suddenly after only using cluster munitions or very advanced guided uh missiles or any of the sort, if they start suddenly relying on very old, almost close to being recycled munitions, then you can already draw a conclusion from that. It's it's a lack of resources that that pose this need, or it's a pause before a next very strong assault if they're trying to pull together more resource for the next one. So it can tell you a lot about the mentality of the generals on the on the battlefield and the decisions that are being made at a very high level. Um because no stock is being sent to the front line just by pure choice. There's active logistical solutions that are in play that are different from missile to missile, from munition to munition. Um, for example, a tornado multiple launch rocket system requires its own loader. Uh you have to now back up the loader on the train and freight it to the front line as well. It's very different from having some, I don't know, mortar shells, right? And and it varies from decade to decade of manufacturing these missiles. And you can always tell a lot from from what is being used.

Robby Peralta

There's a podcast that I follow, it's Ukraine today. Ukraine the Latest, I think it's called. And also a part of that, they have YouTube channels that show you every day what's going on on the front line. And that's it's I guess some of the military is sharing that for various reasons. Uh why is this war, or why are wars so visible these days, or how are they so visible? Is if you go on YouTube and you type in Ukraine or Russia, you see what happened yesterday. Can I trust that information, or like how would you look at those types of videos?

Vladimir Zaha

That's a very good question because a lot of people, I believe, are doing the same thing nowadays. I mean, making these exact Google searches, and it's important to know if if you are looking at the right thing. Yeah. You've got you've got channels like Preston Stewart and Ryan McBeth who are doing like an amazing job at dissecting the battlefield and the political decisions behind what is going on in Ukraine. So if you are looking for points of truth, I can personally vouch to the veracity of those accounts. Um, definitely 100%. However, the wars are becoming more visible now, at least in the Western hemisphere, where you have this mentality of crowdsourcing and public support, right? If you if you're looking at an authoritarian government trying to trying to stop a civil war, they're not gonna have a telegram channel or or a TikTok channel posting like short clips of of what they're doing militarily, whatever is safe to post, right? Because they don't care. They're having a civil war and they're an authoritarian government. But in in for example, in the Russia-Ukraine conflict, um you want to garner support from home viewers because pretty much both sides still rely on public donations uh in order to support their their militaries. Like as wild as it seems, Russia, as as big as as it is, lacks, of course, a lot of equipment and has failed to maintain a lot of its equipment since the last wars that it waged, right? Ukraine, a very much smaller country, ill-prepared at the beginning of the war, now a lot better, has very quickly adopted Western mentality in in warfare and methodologies that are that are very compatible with current weapon systems that are being donated to them by the by the West, right? But they they both need just as much crowdsourced financial help donations, either in terms of like material, like drones or uh vehicles. Vehicles is a big one because of course they are almost dispensable in specific parts, but also just monetary help to buy to buy their own gear, to buy vests, to buy plate carriers, ammunition, and everything else. So you see this trend of everything appearing on social media from the point where. Becomes operationally safe to do so. It gets edited, it gets put in a compilation, and it arrives on your phone. And um it's it's quite surprising actually to see some platforms where you might not expect this to exist, like Instagram. You can scroll through and the algorithm will simply suggest uh frontline combat from from Ukraine, which speaks towards the desensitivization of audiences towards this type of content. It's also quite ironic that we we can sit in our own comfort and suddenly we're looking at someone die on the on the battlefield in Ukraine. That's fucked up. Yeah, absolutely. And but it also garnishes support from people in the West who who are seeing this injustice and and they want to help.

Robby Peralta

We're talking about satellite data uh that you can buy. You said that you can get within a meter accuracy. How accurate is that satellite data and how easy it is it for somebody like you that knows where to look to actually get that information?

Vladimir Zaha

Absolutely. I think I think the the main blocking point there is money, uh, because of course satellite imagery providers are also in touch with what is going on. So obviously, if you are buying extremely accurate satellite imagery uh down to one meter in Ukraine or in Crimea or somewhere in in Russia, they're gonna get the idea of what what is going on. Um but essentially there are specific ways in which uh one one can do this. And of course, it it helps to be able to represent yourself to an organization rather than an individual randomly going to uh to to buy you know one meter imagery. Um however it's they do their own vetting because of course they don't want to provide this this imagery to, for example, the Russians or or to any threat actor that might be interested in joining a conflict or um just anyone realistically because these are targeting capabilities, right? At that point, you're speaking about targeting capabilities. Ukraine has solved a lot of this cost issue, for example, by crowdsourcing their own satellite. And uh and this this helps them operationally to achieve their objectives on the front line, even long distance as well. What I've seen recently, and actually I want this question to answer because I'm not I'm not quite sure if this is the case, but in uh Copernicus, which is a online tool, it's it's a satellite, but it's publicly available satellite imagery on a date selection basis, and it offers different filters and different satellites that are all open source, and you can look at their imagery when they passed over a specific area. The idea is you can uh you can you can look at infrared signatures depending on what's available and what satellite has passed over that area. You may be able to look at infrared signatures or or other sort of filters, which is called remote sensing. When you start filtering the image back from the satellite and you filter out different wavelengths, you can see vegetation more clearly than you can see cars or buildings, for example. You can see night lights in urban areas better than you can see the sun reflecting off rooftops, for example. So it lets you remote sense particular materials and areas of interest. I I'm seeing now recently with Copernicus, there's these streaks that come at diagonal angles over important parts of Russia and Crimea, which I'm very curious about. I haven't managed to find an answer to this. Um, but it almost looks as if someone is trying to obscure the satellite view from these critical areas because there is a conflict. And looking around the world, nowhere else have I seen these these streaks right now. So those there's obviously acknowledgement from both sides that uh these satellites offer open source uh information about what's what's being seen from space over these territories. They just want to limit accessibility to this imagery as much as possible.

Robby Peralta

Should have probably covered this earlier, but open source doesn't mean free. It just means that it's publicly available, you don't have to be military to get it.

Vladimir Zaha

Yes. So there's different approaches to this. Um open source originally comes from the fact that yeah, you don't need to be in the intelligence services or in the military to achieve this information. Um the uh the opposing side we call closed source intelligence, which is what you know the NSA have and what GCHQ has, which is collection data from who knows what, uh, but from centralized systems that nobody else has access to. Open source data is originally the opposite of that, it's just things that people leave behind publicly, intentionally. Organically, yeah. Organically think of like dumpster diving but online, right? That's essentially what I do to summarize your your previous question. But there's also the the concept that you don't need to pay for it, because payment in certain areas implies that not everyone can access it, so it's not democratized. So therefore, if it's not verifiable by everyone, then it's not accessible by by everyone. For example, Trace Labs, which is a really great organization from the US, they do capture the flag tournaments where you find missing persons. So they collaborate with police stations and police associations and institutions across the US and Canada, I believe, both of them. And any missing person cases that they get from those police institutions, they offer as a package for the CTF. And essentially you um you employ, you volunteer 100, 500. I'm not sure how many people participate in these. I've I've personally both been a participant and a coach, but you get crowdsourced intelligence polls about where the whereabouts of these people might be. Um some some of them um are you know people who who live a very active life. They are active socially, so there's a lot to search through. They are very well connected, all their friends post together with them, so it's easy to cross-correlate where they might be. Others are ghosts, they're they're simply people that are not using social media, but they might use one account once to check in someplace because someone asked them to leave a review, right? So it takes like different levels of skill sets to try to find as much as possible about these people, and then you submit it in the coach reviews uh this information to see if it's like valid for what we are looking for. And at the end, what happens is all this information gets submitted back to the police department that requested its review, and a lot of the times or sometimes, people are found. People are found uh well, people are found otherwise, but uh the family gets an answer. And one of the particularities of the CTF is that open source intelligence in this case does need to mean free. Because when you give this information back to the police station, or might it be a detective, might it be uh someone else in the police station, you don't know who gets this information and if they have the technical capability to review it, right? You cannot give them like terminal output from an automated collection tool. You need to give them factual evidence that they know how to access and is is easy for them as well. So part of it is yeah, it it can be paid. They need to be able to access it straight away.

Robby Peralta

How do you use OSINT and cyber? The majority of people listening to this episode or this episode and the nomadic security podcast or cybersecurity professionals. How would OSINT help them in their job? Or is there a connection there between their protecting a network and OSINT?

Vladimir Zaha

There is absolutely. I mean, at least to say the work that I do right now shows there's a direct correlation between the security of a product or of a company and the activities of threat actors that are interested in in nabbing those secrets from the company, right? Um there will always be a vested interest of someone to break into something. This is just the nature of criminality. And to be one step ahead doesn't just mean to implement your EDR or to implement your SOC team or to to install, you know, uh MDM and antiviruses on your laptops. To be one step ahead means to be in tune with what's going on in your operational environment. And it's very much what intelligence agencies do, it's very much what the military does, it's awareness of your operational environment, right? If you don't know that anyone has a vested interest or has posted on a forum uh to get help to hack your company or or to to find more information about you personally, the head of security of a company, if you don't know how to search these spaces, if you're completely oblivious of them, you can't rely on automated tools for this because the traffic is so organic and the behavior of threat actors is so varied and in different languages, right? You you can only do this yourself. You can only understand this at a human level. So it very much helps security professionals, I believe. Even though uh in CTFs, I think OSYNT is a little bit misrepresented, it's a little bit simplified and it's it's synthetically generated to make you find a flag on someone's like a sock puppet's Twitter account, right? But OSYNT in real life is so much more different because you've got so much more data to sift through and it's all organic, so it's all random. You can't classify it, you can't really put a tag on it, you need to to learn how to look.

Robby Peralta

Just put this in perspective, you're when you're protecting your company, the company you work for, which is you basically need to follow a bunch of like I'll call them underground environments to see how threat actors are planning to do something against face facial recognition software. Uh that's that's a very much B2C sort of use case. It's it's more so B2B, uh because the Yeah, B2B, but they're protecting their clients, so it's B2C or

Vladimir Zaha

Correct. Yeah, but through proxy kind of. Yeah. Yeah.

Robby Peralta

I see what you yeah.

Vladimir Zaha

Yeah. Because the person the person opening an account with a bank, for example, can never be held liable for someone bypassing the biometric system that the bank uses, right? That's the bank's fault. Or it's the bank's third-party service provider fault. So um mostly what we do is trying to raise awareness into this new field, which is biometrics. And especially in this, well, it's not a new field, but it's a new implementation of this because you're seeing now also there being a social media uproar about the overusage of these tools to verify you on social media to make sure you're over 16, over 18, depending on the country, whatever, to make sure you're an adult. My opinion, overusage. But to prevent threat actors from entering your bank account, sure, no problem. That makes sense. To prevent people or unknown persons from coming into the to the border of the country, sure, yes, your passport needs to match your face and who you are in real life, right? This this all makes sense. What we do is we try to create awareness of this issue, which is expanding not only the border controls and financial institutions, but everywhere else as well. So identity fraud can happen pretty much at any point, um, because there's steps you can take to escalate your control over this victim's identity as a threat actor. And the more you do, the more voracious your identity now becomes. And suddenly someone's got a hold of your SIM card number and and they've they performed a simjack attack on you, right? The the thing is we create these reports, they're called apex reports. And these reports are are given to customers, showcasing not only the typical industries that are being affected, which is what you expect borders financial, uh, but it's it's everything that we see, and it's the trends and the data that we pull from our own uh system being attacked as well. So it it we are the tip of the spear right now in in what's as an implementation biometric security. And we are obviously the most coveted kind of attack surface, if if you would like. Um the insight from that helps companies that do not utilize us also to prepare and and to make steps to to protect themselves without the need for them to you know one click buy a solution and that's the end of the day. It's the knowledge that saves them, not not the solution.

Robby Peralta

I have to ask it. Uh the concept of AI. I have colleagues that they're just vibe coding tools that are able to do things that you just they were reserved for nation states before, but now you can just vibe code your way to it because you don't need developers anymore. You can just use some tokens on it. How is AI changing the world of OSIN? Because I would assume that a lot of the things that you'd have to do very manually before are just completely automated now. How's that have you noticed that in when you're in your journeys?

Vladimir Zaha

Yeah, actually, um I've I've tried implementing it here and there. I've I've used it to the point where I I I understand it. And that honestly has accelerated my ability to do things because when did I not have a need, or any OSINT analyst or any security person in general, when did we not have a need that we were like, I wish I had a tool for that, but it like costs like 5,000 pounds a month, so I can't. It's like now you can code them. Now you now you can make it. And there have been people who have done like Palantir at home, and even just as a visualization tool, it's powerful because you get to present things in front of non-technical people and they understand because it has like a nice spinny graph of the world and you can tell where the subject is in the map. But also, yeah, information collection solutions, automated reporting, all of these, they're useful. Everyone just needs to keep in mind that it's intelligence, guys. Like you need to verify it, right? Part of it is collection, but part of it is analysis. And you need to make sure that once you analyze the intelligence is not hallucinated, it's it's voracious, it's you know, pinpointed in time and space exactly as as you might want it to present to another person.

Robby Peralta

Just to end on a philosophical note or forward-thinking note, like the future of OSIN, how do you think that's gonna affect democracy moving forward?

Vladimir Zaha

Oof, yeah, that's uh that's something I've been thinking about recently, especially obviously with the the death of factual analysis of of news.

Robby Peralta

As in nobody gives a shit about the facts anymore.

Vladimir Zaha

Yeah, absolutely. Yeah, yeah. And especially with this, um I'm asking, is it is it going to die? Oh or I don't think so. Or is it going to become finally paid enough for for more people to do this? I mean, this is these are two of the the pain points that I've seen, at least uh in in here and in in other countries, OSINT doesn't pay. It's it's so disregarded in terms of his its efficacy as well. For example, one of the struggles that people are having right now, unrelated to what I've done before, but with the Kherson and Bakhmut um war crime investigators um currently prosecuting cases against persons in the Russian government or the Russian army, uh it's the attempt to get this uh OSINT collected information valid in court. It's still a struggle. And just because it came from not uh an analyst in a government office using the analyst's notebook software, and instead they use MultiGo or like a telegram scraper they wrote themselves, just because of that, it's invalid. Like it can go through the same validation process as everything else. It's just a um lack of education about OSINT and its functionality and how much it has evolved over time that is that is causing this lag behind the uh normal systems.

Robby Peralta

So it's the tool you name analyst notebook. I used to work for IBM. So I know what analyst notebook is. I really want a subscription, by the way. Yeah, yeah, yeah. You can buy it from one of my friends, but it's gonna cost you. So it's the tool and also the the person that you are, the authority that you represent. Yes. That's what sort of works in court.

Vladimir Zaha

I think that's the secret sauce. I mean, obviously you have the I'm not I'm not a legal expert or anything, but there's also like a chain of custody, and there's a um requirement for the storage of this information to make sure it wasn't modified and transit and storage or when when opening it just to view it, right? It's the same as uh computer forensics, pretty much. It's the same standards there. Um the information cannot at any point be any different than from the point of collection. And the point of collection, preferably, needs to still be available in order to be able to be verified uh that it was indeed that the source that it was collected from. Though there's so many instances of this happening, I don't think it's an issue of scarcity. I think it's an issue of accepting technology, which is not new anymore, accepting methodology and desire to volunteer, which is again not new anymore. But it that it does come from kind of an older institution, which is the the Hague, right? Or or the International Criminal Court, which very much relies still on uh processes that are have been established over years to ensure the utmost efficacy when prosecuting war criminals, which is understandable why it's monolithic and why it's it's hard to get it to move, right? But this speaks to other courts and other industries, even as well.

Robby Peralta

But like when you when I've if I was to film you right now with an iPhone, I would hate the metadata, yeah, yeah, right. You need to have a better, you deserve a better camera, I'd agree. But like all the metadata is gonna be in that film, right? Like somebody that works with the iOS forensics will be able to say that is 100% legit. So the fact is still a fact. And even though I took it and nobody trusts me because I've had a beer or two, that's still a fact.

Vladimir Zaha

Yeah, it's still a fact. I mean, you could always modify it. You could use, you know, XF tools to to modify the metadata for that video, but as long as that iPhone doesn't touch anything else, or at least it's provable that anything else it has touched hasn't been able to interfere with the metadata of that video, then it's provable in court, right? But can that be proven? Is that possible to do as well? Uh or is it just word is it still word against word at the end of the day? It's word against word. It's it's legal matters, I believe. I believe it is word against word. I mean, anything can be proven only up to a point of credibility, right? I mean, if you look at fingerprints, for the longest time there there has been a debate if fingerprints are realistically admissible in court, right? Because of different factors, which I'm I'm not fully aware of, so I'm not going to speak about them. But the veracity and the correlation between the subject and its and its fingerprint has always been in question, at least at the beginning of fingerprints as well. Um and now I think I've seen recently another question about this. Like, have we been relying on this tool for prosecuting individuals the wrong way this whole time? Not sure. Watch the video. But um, yeah, there's there's always new things that we learn about the world. There's always new things that appear in technology that suddenly change everything. Like, how many times have analysts had tools that they relied on almost at a forensic level completely disappear off the face of the planet, or suddenly they're monetizing and they're like popping like mobile game ads in the in the interface, right? This is like completely possible for someone who relies on a tool. It's it's out of our control because it is open source. For example, one uh just one more note there, actually. The uh one of the things that OSINT analysts or people aspiring to be OSINT analysts need to do is sure, you can do it one time, you can do it um instantaneously if you just want to uh research something in the moment. You just download some tools that might help you, but it's mostly manual work, no problem there. If you plan to do it at scale or over a longer period of time, what you need to be aware of is is tool deprecation. And for example, with Bellincat, one of the projects uh that that uh is is constantly evolving and constantly present and a need for the community is the Bellincat Toolkit, which is essentially a a um Git book page, a Git book instance, which holds all of the tools that we have vetted uh that are not me, it's mostly Bellincat staff, but um we've we've can volunteer for these things. So we look at if they contain sponsorship links or any tracking methods within the tool, if the tool is safe to use in a terminal, if it um takes certain commands to install, like we we look at all of these parameters and uh you need to validate is it still up to date? Has anything changed? Is anything broken? Is anything fixed? So keeping it up to date is a big part of it. Same goes for sock puppet accounts, your investigative accounts that you need to look after and grow as if they're they're your own because you are posing as a real person.

Robby Peralta

On behalf of the world, thank you for all the great work that you do. As the Brits would say, Vlad, you're a you're a good lad. Thank you so much. Take care of yourself. It's been a pleasure. Keep up the great work. Thank you. Well, that's all for today, folks. Thank you for tuning in to the Mnemonic Security Podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us a mail to podcast @ mnemonic.no. Thank you for listening. We'll see you next time.