Open Source Signal logo
Open Source SignalСигнал відкритих джерел
Issue #082 15 August 2026 Saturday Tool Radar EN + UKR

Open Source Signal

Сигнал відкритих джерел

Saturday OSINT tools and datasets for vessel-history research, supply-chain facilities, offshore corporate networks, replaying preserved web evidence, consensual mobile forensics, fact-check discovery and open satellite damage screening.

Saturday Tool Radar #082: Global Fishing Watch Vessel Viewer for joining vessel identity, historical tracks, port visits and transshipment indicators; Open Supply Hub for searching production facilities and contributor-supplied supply-chain connections; ICIJ Offshore Leaks Database for graphing public-interest offshore entity relationships without treating inclusion as wrongdoing; ReplayWeb.page for local or browser-based replay of WACZ, WARC and related web archives; Amnesty International’s Mobile Verification Toolkit for consensual Android and iOS forensic review; Google Fact Check Explorer for searching published fact checks by topic or image; and Bellingcat’s Iran Conflict Damage Proxy Map for using Sentinel-1 SAR anomalies to shortlist locations for further damage verification.

Editorial frame

What this is: A weekly tool radar for public-interest OSINT. Each item explains what the tool or dataset does, why it matters, how to use it safely, and where its evidentiary, privacy and operational limits are.

What this is not: Doxxing, stalking, credential hunting, leaked-database abuse, private-person deanonymization, unsafe facial recognition, live targeting, unauthorised device access, penetration testing or a tool-generated verdict.

Rubric map

🧰 Tool of the Week
🏭 Supply Chains
🗃️ Offshore Records
🕰️ Web Archive Replay
📱 Mobile Forensics
✅ Verification Search
🛰️ Damage Proxy
🧰Tool of the WeekІнструмент тижня
#01

Vessel Viewer joins identity, historical tracks, port visits and transshipment indicators in one vessel record

Source: Global Fishing Watch Vessel Viewer · Official tool page, checked 15 August 2026

What happened

Global Fishing Watch’s Vessel Viewer is an open vessel-history and risk-insight tool developed with TMT. It searches hundreds of thousands of industrial fishing and non-fishing vessels and combines identity information from public registries with AIS and, where available, VMS-derived activity. Vessel profiles can show historical tracks, apparent fishing, port visits, transshipments, authorisations and related-vessel information. Registered users can access additional search, analysis and download features, while profiles and reports can be exported for offline review.

Why it matters

Maritime investigations often require switching between registries, movement history and event datasets. Vessel Viewer makes those joins inspectable in one place and is especially useful for generating candidates around identity changes, port calls, transshipments or suspicious gaps. The strongest use is comparative and historical: establish what a vessel normally does, then investigate deviations with independent records.

How to use it

Start from a stable vessel identifier such as IMO number where available. Preserve the profile URL, identity fields, registry sources, date range and exported historical data. Treat port visits, encounters and apparent fishing as event candidates to corroborate with satellite imagery, port records, company filings, sanctions lists or customs data. Record identity changes over time rather than overwriting an older flag, owner or operator.

Limits

AIS and VMS coverage is incomplete, and self-reported or registry identity information can be stale, inconsistent or manipulated. Algorithmic event labels such as apparent fishing or encounters are not proof of illegal activity. A vessel track does not establish cargo, beneficial ownership, destination intent or sanctions violation. Avoid publishing live or tactically useful vessel movements.

Vessel Viewer зводить ідентичність, історичні треки, заходи в порти та ознаки перевалки в одному записі судна

Джерело: Global Fishing Watch Vessel Viewer · Офіційна сторінка інструмента, перевірено 15 серпня 2026

Що сталося

Global Fishing Watch Vessel Viewer — відкритий інструмент історії суден і оцінювання ризиків, розроблений разом із TMT. Він дає змогу шукати серед сотень тисяч промислових риболовних і нериболовних суден та поєднує відомості про ідентичність із публічних реєстрів із даними AIS і, де вони доступні, VMS. Профілі можуть показувати історичні треки, ймовірну риболовну активність, заходи в порти, перевалки, дозволи та пов’язані судна. Після реєстрації доступні додаткові можливості пошуку, аналізу й вивантаження.

Чому це важливо

Морські розслідування часто вимагають переходити між реєстрами, історією руху та подіями. Vessel Viewer робить ці зв’язки видимими в одному місці й особливо корисний для створення кандидатів на перевірку щодо зміни ідентичності, заходів у порти, перевалок або підозрілих прогалин. Найсильніше застосування — порівняльне й історичне: спершу встановити звичну поведінку судна, а потім перевіряти відхилення іншими джерелами.

Як це застосувати

Починайте зі сталого ідентифікатора судна, наприклад номера IMO, якщо він є. Зберігайте посилання на профіль, поля ідентичності, джерела реєстрів, часовий проміжок і вивантажені історичні дані. Заходи в порти, зустрічі та ймовірну риболовну активність розглядайте як кандидати для підтвердження супутниковими знімками, портовими записами, корпоративними документами, санкційними списками або митними даними. Зміни прапора, власника чи оператора ведіть у часі, не переписуючи старий стан.

Обмеження

Покриття AIS і VMS неповне, а самозаявлені або реєстрові відомості про ідентичність можуть бути застарілими, суперечливими чи навмисно спотвореними. Алгоритмічні позначки на кшталт ймовірної риболовлі або зустрічі не доводять незаконної діяльності. Трек судна не встановлює вантаж, кінцевого власника, намір щодо пункту призначення чи порушення санкцій. Не публікуйте поточний або тактично корисний рух суден.

tool-of-weekmaritime-osintvessel-historyaispublic-registries
🗃️Offshore RecordsОфшорні реєстри
#03

ICIJ Offshore Leaks Database turns offshore entity relationships into a searchable graph without equating inclusion with wrongdoing

Source: ICIJ Offshore Leaks Database · Official database, checked 15 August 2026

What happened

The ICIJ Offshore Leaks Database exposes a searchable graph of more than 810,000 offshore companies, foundations and trusts drawn from the Offshore Leaks, Panama Papers, Bahamas Leaks, Paradise Papers and Pandora Papers investigations. Records connect entities to officers, intermediaries, addresses and jurisdictions, and the full dataset can be downloaded in CSV or Neo4j formats. ICIJ also provides a reconciliation API for matching entities from external datasets.

Why it matters

Offshore structures often appear as one layer inside a wider sanctions, corruption, asset-tracing or procurement investigation. The graph model helps researchers move from an entity to officers, intermediaries, addresses and related structures, while keeping the underlying investigation and source dataset visible. That makes it useful for generating corporate candidates and relationship hypotheses before checking current registries and transaction evidence.

How to use it

Start from a well-identified public-interest person or company, record the exact database node and investigation source, then follow relationship edges one step at a time. Preserve names, roles, dates and jurisdictions as separate fields and check current status in official corporate registries. For bulk work, use the downloadable data or reconciliation API while retaining the original match score and source node so that false positives can be reviewed.

Limits

ICIJ explicitly warns that inclusion in the database does not imply illegal or improper conduct, that legitimate offshore uses exist, that names can collide, and that data may be historical or duplicated. The records derive from journalistic leak investigations rather than a standardised current registry. Do not treat a name match as identity confirmation or republish unnecessary personal information.

ICIJ Offshore Leaks Database перетворює офшорні зв’язки на пошуковий граф, не прирівнюючи присутність у базі до правопорушення

Джерело: ICIJ Offshore Leaks Database · Офіційна база даних, перевірено 15 серпня 2026

Що сталося

ICIJ Offshore Leaks Database — пошуковий граф більш ніж 810 тисяч офшорних компаній, фондів і трастів із розслідувань Offshore Leaks, Panama Papers, Bahamas Leaks, Paradise Papers та Pandora Papers. Записи пов’язують юридичні структури з посадовцями, посередниками, адресами й юрисдикціями, а повний набір можна завантажити у форматах CSV або Neo4j. ICIJ також надає API зіставлення для зв’язування сутностей із зовнішніми наборами даних.

Чому це важливо

Офшорні структури часто є лише одним шаром у ширшому санкційному, антикорупційному, майновому чи закупівельному розслідуванні. Графова модель допомагає переходити від юридичної структури до посадовців, посередників, адрес і пов’язаних утворень, зберігаючи видимими початкове розслідування й набір джерел. Це корисно для створення кандидатів і гіпотез про зв’язки перед перевіркою актуальних реєстрів та операційних доказів.

Як це застосувати

Починайте з добре встановленої суспільно значущої особи або компанії, фіксуйте точний вузол бази та розслідування-джерело, а далі переходьте зв’язками по одному кроку. Імена, ролі, дати й юрисдикції зберігайте окремими полями та перевіряйте поточний стан в офіційних корпоративних реєстрах. Для масової роботи використовуйте завантажувані дані або API зіставлення, зберігаючи оцінку збігу й початковий вузол для перегляду можливих помилок.

Обмеження

ICIJ прямо застерігає, що присутність у базі не означає незаконної чи неналежної поведінки, офшорні структури можуть мати законне застосування, однакові імена можуть належати різним людям, а дані можуть бути історичними або дубльованими. Записи походять із журналістських розслідувань витоків, а не зі стандартизованого актуального реєстру. Не вважайте збіг імен підтвердженням особи й не публікуйте зайві персональні дані.

public-recordsoffshorecorporate-networksicijentity-resolution
🕰️Web Archive ReplayВідтворення вебархівів
#04

ReplayWeb.page lets investigators inspect preserved web evidence without depending on the original website

Source: ReplayWeb.page · Official documentation, checked 15 August 2026

What happened

ReplayWeb.page is an open-source, browser-based viewer for static web archives. It can load and render WACZ, WARC, HAR and related archive formats, search archived pages and URLs, use full-text search where extracted text is present, and incrementally load large WACZ files. Local files can be opened directly in the browser without being uploaded elsewhere, while archived content can also be loaded from remote URLs or Google Drive and embedded in other sites.

Why it matters

Preservation and replay are separate parts of evidence handling. A WARC or WACZ may contain the captured HTML, images, scripts and metadata, but investigators still need a reproducible way to see what the preserved page looked like and inspect what was actually stored. ReplayWeb.page provides that review layer without silently consulting the live website.

How to use it

Preserve the original archive file and hash before review. Record archive format, capture tool, capture time, source URL and ReplayWeb.page version or access date. During review, distinguish content contained in the archive from resources that failed to capture. For sharing, prefer WACZ where appropriate because it is indexed for on-demand loading, and keep the original evidence file unchanged alongside any exported screenshots or notes.

Limits

Replay cannot reconstruct resources that were never captured, and dynamic websites may depend on APIs, authentication or browser state absent from the archive. A visually plausible replay is not proof that every network resource was preserved. Archive viewers also do not establish who authored a page or whether its claims were true; provenance and content verification remain separate tasks.

ReplayWeb.page дає змогу переглядати збережені вебдокази без залежності від початкового сайту

Джерело: ReplayWeb.page · Офіційна документація, перевірено 15 серпня 2026

Що сталося

ReplayWeb.page — відкритий браузерний засіб для перегляду статичних вебархівів. Він відтворює WACZ, WARC, HAR та споріднені формати, дає змогу шукати сторінки й URL усередині архіву, використовувати повнотекстовий пошук за наявності витягнутого тексту та поступово завантажувати великі WACZ-файли. Локальні файли можна відкривати без надсилання на зовнішній сервер; також підтримуються віддалені посилання, Google Drive та вбудовування архівів у вебсторінки.

Чому це важливо

Збереження й відтворення — різні частини роботи з доказами. WARC або WACZ може містити захоплений HTML, зображення, скрипти й метадані, але досліднику однаково потрібен відтворюваний спосіб побачити збережену сторінку та перевірити, що саме потрапило до архіву. ReplayWeb.page дає такий шар перегляду без непомітного звернення до живого сайту.

Як це застосувати

Перед переглядом збережіть первинний архівний файл і його контрольну суму. Фіксуйте формат архіву, засіб захоплення, час, початковий URL і версію ReplayWeb.page або дату перевірки. Під час аналізу відділяйте вміст, який справді є в архіві, від ресурсів, що не були захоплені. Для поширення за потреби віддавайте перевагу WACZ із готовим індексом для вибіркового завантаження, а початковий доказовий файл тримайте незмінним поруч зі знімками екрана чи нотатками.

Обмеження

Відтворення не відновить ресурси, які ніколи не були захоплені, а динамічні сайти можуть залежати від API, автентифікації або стану оглядача, відсутніх в архіві. Візуально переконливе відтворення не доводить, що збережено всі мережеві ресурси. Переглядач архівів також не встановлює автора сторінки чи правдивість її тверджень; походження й зміст перевіряються окремо.

web-archivingreplaywaczwarcevidence-preservation
📱Mobile ForensicsМобільна криміналістика
#05

MVT turns a consented phone examination into an auditable search for traces of compromise

Source: Amnesty International Mobile Verification Toolkit · Official documentation, checked 15 August 2026

What happened

Mobile Verification Toolkit is an open-source forensic toolkit maintained by Amnesty International Security Lab and contributors for consensual analysis of Android and iOS devices. It provides command-line workflows for extracting and analysing device artefacts and for checking them against known indicators of compromise. MVT was originally released in the context of the Pegasus Project and is intended for technologists and investigators who understand mobile forensic analysis.

Why it matters

Targeted-spyware cases are unusually easy to overstate: an alert, suspicious domain, process record, backup artefact and confirmed infection are different evidence levels. MVT provides a structured way to extract artefacts and compare them with indicators while preserving the separation between a forensic hit and the broader attribution question.

How to use it

Use MVT only on a device you own or with explicit informed consent from the person whose device is being examined. Preserve device state, collection date, operating-system version, acquisition method, hashes where applicable, MVT version, indicator set and command output. Have suspicious findings reviewed by an experienced forensic analyst and preserve the distinction between malware-family evidence, infrastructure indicators, operator cluster and customer or state attribution.

Limits

Amnesty warns that these tools require technical expertise and may not detect the latest advanced spyware without additional knowledge or private indicators. A clean result is not proof that a device was never compromised, while a single indicator is not always proof of infection. MVT is not a licence to access another person’s device, communications or accounts without consent.

MVT перетворює добровільний аналіз телефона на відтворюваний пошук слідів компрометації

Джерело: Amnesty International Mobile Verification Toolkit · Офіційна документація, перевірено 15 серпня 2026

Що сталося

Mobile Verification Toolkit — відкритий криміналістичний набір, який підтримують Amnesty International Security Lab та інші учасники для добровільного аналізу пристроїв Android і iOS. Він надає командні засоби для вилучення й аналізу артефактів пристрою та їх перевірки за відомими індикаторами компрометації. MVT спочатку оприлюднили в контексті Pegasus Project; інструмент призначений для технічних фахівців і дослідників, які розуміють основи мобільної криміналістики.

Чому це важливо

Справи про цільове шпигунське програмне забезпечення особливо легко перебільшити: попередження, підозрілий домен, запис процесу, артефакт резервної копії та підтверджене зараження мають різний доказовий рівень. MVT дає структурований спосіб вилучити артефакти й зіставити їх з індикаторами, не змішуючи криміналістичний збіг із ширшим питанням атрибуції.

Як це застосувати

Використовуйте MVT лише на власному пристрої або за явної поінформованої згоди людини, чий пристрій аналізують. Фіксуйте стан пристрою, дату збирання, версію операційної системи, спосіб отримання даних, контрольні суми за можливості, версію MVT, набір індикаторів і результати команд. Підозрілі знахідки передавайте досвідченому криміналістичному фахівцеві та відділяйте докази родини шкідливого ПЗ, інфраструктурні ознаки, операторський кластер і встановлення замовника чи держави.

Обмеження

Amnesty застерігає, що ці засоби потребують технічної компетентності й можуть не виявляти найновіше складне шпигунське ПЗ без додаткових знань або закритих індикаторів. Відсутність знахідок не доводить, що пристрій ніколи не був скомпрометований, а один індикатор не завжди доводить зараження. MVT не дає дозволу доступатися до чужого пристрою, листування чи облікових записів без згоди.

mobile-forensicsmvtspywareinvestigator-opsecconsent
🛰️Damage ProxyІндикатор руйнувань
#07

The Iran Conflict Damage Proxy Map turns Sentinel-1 backscatter anomalies into locations for further verification

Source: Bellingcat Iran Conflict Damage Proxy Map · Bellingcat guide, 7 April 2026; checked 15 August 2026

What happened

Bellingcat’s Iran Conflict Damage Proxy Map applies a Pixel-Wise T-Test algorithm to open Sentinel-1 synthetic-aperture-radar imagery. For each pixel, the method builds a historical pre-war backscatter range and flags locations whose post-war observations fall consistently outside that baseline. The map is designed to highlight candidate areas of damage in Iran and the Gulf when optical or commercial imagery is sparse, and Bellingcat recommends cross-checking candidates with Sentinel-2, geolocated media or other imagery.

Why it matters

SAR can see through clouds and does not depend on daylight, but it is harder to interpret visually than optical imagery. The proxy map turns a large radar time series into a review queue: investigators can inspect anomalous areas rather than guessing where to look. The important epistemic boundary is explicit—high damage probability is a screening signal, not a confirmed destroyed building or an attribution finding.

How to use it

Use the proxy map to shortlist areas, then record the pixel or site, anomaly date range and historical baseline. Cross-check with pre- and post-event optical imagery, geolocated photos or video, official damage reports and alternative SAR dates. Preserve the distinction between algorithmic probability, visually confirmed physical damage, object identity, incident date and perpetrator attribution.

Limits

Bellingcat says the map is not real-time and is updated roughly once or twice a week as new Sentinel-1 data arrives. SAR anomalies can have causes other than conflict damage, small or facade-only damage may be missed, and a probability signal is not definitive. The tool does not determine target status, weapon, operator or legality. Sensitive current military locations should not be amplified merely because the map highlights an anomaly.

Iran Conflict Damage Proxy Map перетворює аномалії Sentinel-1 на місця-кандидати для подальшої перевірки руйнувань

Джерело: Bellingcat Iran Conflict Damage Proxy Map · Матеріал Bellingcat від 7 квітня 2026 року; перевірено 15 серпня 2026

Що сталося

Iran Conflict Damage Proxy Map від Bellingcat застосовує алгоритм Pixel-Wise T-Test до відкритих радарних знімків Sentinel-1. Для кожного пікселя метод формує історичний довоєнний діапазон зворотного розсіювання й позначає місця, де після початку війни спостереження стабільно виходять за цей базовий рівень. Карта призначена для первинного виявлення можливих зон руйнувань в Ірані та країнах Перської затоки, коли оптичних або комерційних знімків бракує; Bellingcat радить перевіряти кандидати за Sentinel-2, геолокованими матеріалами чи іншими зображеннями.

Чому це важливо

Радарні знімки не залежать від денного світла й проходять крізь хмари, але їх складніше тлумачити візуально, ніж оптичні. Карта перетворює великий часовий ряд радарних даних на чергу для перевірки: дослідник переглядає аномальні ділянки замість випадкового пошуку. Ключова межа доказу тут явна: висока ймовірність пошкодження є сигналом для первинного відбору, а не підтвердженим знищенням будівлі чи встановленням виконавця.

Як це застосувати

Використовуйте карту для створення переліку кандидатів, а потім фіксуйте ділянку, часовий проміжок аномалії та історичний базовий рівень. Звіряйте результат з оптичними знімками до і після події, геолокованими фото чи відео, офіційними повідомленнями про пошкодження та іншими датами радарного знімання. Відділяйте алгоритмічну ймовірність, візуально підтверджене фізичне пошкодження, ідентичність об’єкта, дату події та встановлення виконавця.

Обмеження

Bellingcat зазначає, що карта не працює в реальному часі й оновлюється приблизно один-два рази на тиждень із надходженням нових даних Sentinel-1. Радарні аномалії можуть мати причини, не пов’язані з бойовими руйнуваннями, а невеликі пошкодження або ураження лише фасаду можуть бути непомітними. Імовірнісний сигнал не є остаточним доказом. Інструмент не встановлює статус цілі, зброю, оператора чи правомірність удару; не слід додатково поширювати чутливі поточні військові місця лише через аномалію на карті.

satellite-imagerysarsentinel-1damage-screeningbellingcat