<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>OSINT on Riga</title><link>https://riga.sh/tags/osint/</link><description>Recent content in OSINT on Riga</description><generator>Hugo 0.125.0</generator><language>en-us</language><lastBuildDate>Wed, 17 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://riga.sh/tags/osint/index.xml" rel="self" type="application/rss+xml"/><item><title>[PRIVACY] Imou Life, your security camera watches you back</title><link>https://riga.sh/investigations/imoulife-privacy/</link><pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/imoulife-privacy/</guid><description>I bought a security camera to watch my front door.
What I didn&amp;rsquo;t know is that the app on my phone would watch me back and share what it learns with TikTok&amp;rsquo;s parent company.
Here&amp;rsquo;s the full breakdown after tearing apart the Imou Life app (v10.0.6, com.mm.android.smartlifeiot).
Methodology: MITM proxy analysis via Burp Suite + APK decompilation + Frida dynamic analysis
1. The ID that never dies Every request the app sends contains this:</description></item><item><title> [OSINT/CTI] The Great Canadian Scammers</title><link>https://riga.sh/investigations/the-great-canadian-scammers/</link><pubDate>Mon, 28 Oct 2024 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/the-great-canadian-scammers/</guid><description>This article is made for educational purpose only, to show what&amp;rsquo;s going on behind the scenes of malicious actors and their digital platforms. Everything comes from open and legal sources.
I received an SMS asking me to log in to: auth-rbcroyalbank-online[.]com. Well, thanks to this scam, I was able to map a wide phishing network targeting Canadian institutions.
Key points:
⏺️ Mostly Russian and Chinese registrars/hosting providers (JSC Selectel, Nicenic&amp;hellip;) are involved.</description></item><item><title>🏭 Business (and People 👤)</title><link>https://riga.sh/toolbox/-business/</link><pubDate>Mon, 01 Jul 2024 00:00:00 +0000</pubDate><guid>https://riga.sh/toolbox/-business/</guid><description>I endorse nothing you&amp;rsquo;ll do with these tools, use them at your own risks.
LEAKS https://aleph.occrp.org https://offshoreleaks.icij.org https://www.opensanctions.org https://www.opensecrets.org/ CORPORATE INFOS https://b2bhint.com https://opencorporates.com 🇺🇸 USA https://www.judyrecords.com https://lookups.melissa.com/home/ https://www.followthemoney.org/ https://www.importyeti.com/ 🇫🇷 FRANCE https://www.societe.ninja/index.html https://www.societe.com https://pappers.fr 🇧🇪 BELGIUM https://trendstop.knack.be https://kbopub.economie.fgov.be http://www.actionnariatwallon.be AFRICA https://openafrica.net/ https://owners.africa 🇨🇬 RDC &amp;amp; CONGO 🇨🇩 http://www.pagewebcongo.com https://liziba.cg Mining specific https://resourcecontracts.org/ http://itie-rdc.masiavuvu.fr/ https://congo-repo.revenuedev.org 🇨🇦 CANADA https://opengovca.com/ 🇬🇧 UK https://www.pappers.co.uk/ 🇨🇭 SWISS https://www.pappers.co.uk 🇺🇸 US INDIVIDUALS SEARCH Free tools: https://www.</description></item><item><title>🕵️ Recon toolbox</title><link>https://riga.sh/toolbox/-recon/</link><pubDate>Fri, 28 Jun 2024 00:00:00 +0000</pubDate><guid>https://riga.sh/toolbox/-recon/</guid><description>I endorse nothing you&amp;rsquo;ll do with these tools, use them at your own risks.
Combining multiple sources while investigating is highly recommended. Remember, these tools are only there to help your investigation, the conclusion is up to you.
Using web tools can be beneficial when it comes to investigations, as you don&amp;rsquo;t directly interact with the target.
Recon (online) toolbox MAGIC TOOLBOX Bunch of tools:
https://intelx.io/tools Complet toolbox, all free, you can nmap and even find public buckets:</description></item><item><title>[OSINT] Leveraging OSINT to identify potential misinformation</title><link>https://riga.sh/investigations/countermisinformation/</link><pubDate>Mon, 30 Oct 2023 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/countermisinformation/</guid><description>OSINT is about gathering technical and social elements to draw a narrative about a situation and communicate a clear thought. Sometimes, misinformation campaigns regain attention as they are shared a few years later, taking advantage of the mass of shared information to reuse old images when they are forgotten. It&amp;rsquo;s also worth pointing out that a tragic event appeals the emotions, making us less inclined to verify it.
So, I stumbled upon a tweet published in March 2022, which gained substantial exposure at that time:</description></item><item><title> [OSINT/CTI] Investigating a terrorist IT infrastructure</title><link>https://riga.sh/investigations/terroristinfrastructure/</link><pubDate>Thu, 12 Oct 2023 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/terroristinfrastructure/</guid><description>With the ongoing war between Israeli forces and Hamas, I wanted to analyze different propaganda tools and how they are built.</description></item><item><title>[OSINT] Elon Musk vs OSINT</title><link>https://riga.sh/investigations/elonmusk/</link><pubDate>Tue, 01 Aug 2023 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/elonmusk/</guid><description>What the internet has to offer for a high value profile (who likes to troll a lot)</description></item><item><title>[OSINT] Oil giant Perenco: investigation</title><link>https://riga.sh/investigations/moneylaunderingkabila/</link><pubDate>Wed, 19 Jul 2023 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/moneylaunderingkabila/</guid><description>Oil giant Perenco’s suspicious deals with companies close to Congo’s ex-president&amp;quot;</description></item><item><title>[OSINT] The shady Pimeyes</title><link>https://riga.sh/investigations/theshadypimeyes/</link><pubDate>Fri, 13 Jan 2023 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/theshadypimeyes/</guid><description>Pimeyes is on a thin line</description></item><item><title>[OSINT] Anatomy of a crypto/banking scam</title><link>https://riga.sh/investigations/anatomycryptoscam/</link><pubDate>Sat, 27 Aug 2022 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/anatomycryptoscam/</guid><description>Scam me if you can</description></item><item><title>[OSINT] Public buckets, everywhere</title><link>https://riga.sh/tutorials/buckets/</link><pubDate>Mon, 01 Nov 2021 00:00:00 +0000</pubDate><guid>https://riga.sh/tutorials/buckets/</guid><description>I endorse nothing you&amp;rsquo;ll do with these tools, use them at your own risks.
Buckets A bucket contains various types of data such as public files (static assets), but sometimes it&amp;rsquo;s used to store sensitive infos (logs, passwords&amp;hellip;). Permissions are critical with buckets, it can leverage an attacker to abuse unauthenticated access or improper ACL permissions. An open upload policy could let an attacker upload a malicious file, such as a custom payload.</description></item><item><title> [OSINT] Phone number OSINT with Telnyx</title><link>https://riga.sh/tutorials/phonerecontelnyx/</link><pubDate>Mon, 18 Oct 2021 18:51:52 -0400</pubDate><guid>https://riga.sh/tutorials/phonerecontelnyx/</guid><description>I endorse nothing you&amp;rsquo;ll do with this tool, use it at your own risks.
Phone number OSINT with Telnyx Let&amp;rsquo;s say some scammer or aggressive dude is calling you a bunch of time, or you just need infos about a phone number, well it&amp;rsquo;s not the most funny part of OSINT.
Currently, I see 3 majors sources of recon:
Yellow pages Spam lists Breaches They&amp;rsquo;re not always up-to-date, and sometimes limited by the amount of infos listed.</description></item></channel></rss>