Open Source Signal logo
Open Source SignalСигнал відкритих джерел
Issue #117 26 September 2026 Saturday Tool Radar EN + UKR

Open Source Signal

Сигнал відкритих джерел

Saturday OSINT tools for maintained discovery, corporate filings, beneficial-ownership research, open aerial imagery, thermal-anomaly detection, aviation data and reproducible source capture.

Saturday Tool Radar #117: Bellingcat's Online Investigation Toolkit as a maintained discovery layer rather than an endorsement list; SEC EDGAR APIs for real-time company submission history and XBRL facts without an API key; Companies House Public Data API for UK company profiles, filings and persons with significant control; OpenAerialMap for imagery metadata and tiled layers; NASA FIRMS for near-real-time fire and thermal-anomaly detections; OpenSky Network for ADS-B-derived state vectors, flights and tracks with explicit rate and coverage limits; and Zotero for saving source metadata, PDFs and local webpage snapshots as part of a reproducible research notebook.

Editorial frame

What this is: A weekly tool radar for public-interest OSINT. Each item separates tool output from evidentiary conclusion and records access, provenance, coverage, privacy and reproducibility limits.

What this is not: Doxxing, stalking, credential hunting, leaked-database abuse, private-person deanonymization, live targeting, unauthorised access, penetration testing or an automated truth verdict.

Rubric map

🧰 Tool of the Week
🏢 Corporate Filings
🧾 Beneficial Ownership
🛰️ Open Imagery
🔥 Thermal Signals
✈️ Aviation Data
📚 Research Capture
🧰Tool of the WeekІнструмент тижня
#01

Bellingcat's Online Investigation Toolkit works best as a maintained discovery layer — not as automatic endorsement of every listed service

Source: Bellingcat Online Investigation Toolkit / GitHub · Toolkit checked 26 September 2026; repository updated 24 September 2026

What happened

Bellingcat's toolkit organizes open-source research services across maps and satellites, geolocation, image/video, websites, companies and finance, conflict, transport, archiving and data analysis. Entries are maintained with volunteer contributions and Bellingcat review, and many include detailed guides and caveats.

Why it matters

A maintained catalogue reduces rediscovery cost, but catalogue inclusion is not evidence that a tool is currently available, legally appropriate or suitable for a specific investigation.

How to use it

Use the toolkit to identify candidate services, then verify the provider's current documentation, terms, access model and data provenance before relying on output.

Limits

The toolkit itself states that inclusion does not imply endorsement and that some entries come with significant caveats.

Bellingcat Online Investigation Toolkit найкраще працює як підтримуваний шар пошуку — а не як автоматичне схвалення кожного сервісу в каталозі

Джерело: Bellingcat Online Investigation Toolkit / GitHub · Перевірено 26 вересня 2026; репозиторій оновлено 24 вересня 2026

Що сталося

Toolkit Bellingcat організовує сервіси для досліджень відкритих джерел за картами й супутниками, геолокацією, фото/відео, сайтами, компаніями та фінансами, конфліктами, транспортом, архівуванням і аналізом даних. Записи підтримує волонтерська спільнота з перевіркою Bellingcat; для багатьох є докладні гайди й застереження.

Чому це важливо

Підтримуваний каталог зменшує вартість повторного пошуку інструментів, але включення до нього не доводить, що сервіс зараз доступний, юридично доречний або придатний для конкретного розслідування.

Як це застосувати

Використовуйте каталог для пошуку кандидатних сервісів, а потім перевіряйте актуальну документацію постачальника, умови, модель доступу й походження даних.

Обмеження

Сам toolkit прямо зазначає, що включення не означає рекомендацію, а деякі сервіси мають суттєві застереження.

tool-of-weektool-discoverybellingcatcataloguemaintenance
🏢Corporate FilingsКорпоративні подання
#02

SEC EDGAR APIs expose company submission history and XBRL facts as keyless JSON — filings remain company disclosures, not verified ground truth

Source: U.S. Securities and Exchange Commission · Official documentation checked 26 September 2026

What happened

The SEC's data APIs provide JSON-formatted submissions history by filer and extracted XBRL data from financial statements. The APIs do not require authentication or API keys, update throughout the day, and also publish nightly bulk ZIP files.

Why it matters

CIK identifiers, filing timestamps, former names and machine-readable facts make EDGAR a strong reconciliation layer for U.S.-linked corporate research.

How to use it

Preserve accession number, filing form, filing date and source URL. Treat amended filings as new versions rather than silently replacing older disclosures.

Limits

EDGAR covers entities and disclosures within the SEC reporting system; a filed statement is not automatically independently verified.

API SEC EDGAR віддають історію корпоративних подань і XBRL-факти у JSON без ключа — подання лишаються розкриттями компаній, а не перевіреною «істиною»

Джерело: U.S. Securities and Exchange Commission · Офіційну документацію перевірено 26 вересня 2026

Що сталося

API SEC надають у JSON історію подань за емітентом і витягнуті XBRL-дані з фінансової звітності. Для доступу не потрібні автентифікація чи API-ключ; дані оновлюються протягом дня, а вночі публікуються масові ZIP-набори.

Чому це важливо

CIK-ідентифікатори, часові мітки подань, попередні назви й машинозчитувані фінансові факти роблять EDGAR сильним шаром звірки для дослідження компаній, пов'язаних зі США.

Як це застосувати

Зберігайте accession number, тип форми, дату подання й URL джерела. Виправлені подання ведіть як нові версії, а не непомітно замінюйте старі.

Обмеження

EDGAR охоплює суб'єктів і розкриття в системі SEC; факт подання не означає незалежної перевірки кожного твердження.

corporate-filingssecedgarxbrlentity-resolution
🧾Beneficial OwnershipКонтроль над компаніями
#03

Companies House API exposes UK company profiles and persons with significant control — registry statements still require context and cross-checking

Source: Companies House · Official documentation checked 26 September 2026

What happened

The Companies House Public Data API provides company records and endpoints for persons with significant control, including individual, corporate-entity and legal-person notifications. API-key authentication is required for the public API.

Why it matters

Company number is a stable identity key, while PSC records help distinguish names that merely resemble one another from formal control notifications.

How to use it

Resolve by company number first, then store filing history and PSC notifications with dates and status. Cross-check material ownership conclusions against filings and other registries.

Limits

Registry data reflects filed information and statutory disclosure rules; it is not a complete map of all economic influence or beneficial ownership.

API Companies House відкриває профілі британських компаній і осіб зі значним контролем — реєстрові записи все одно потребують контексту й перехресної перевірки

Джерело: Companies House · Офіційну документацію перевірено 26 вересня 2026

Що сталося

Public Data API Companies House надає дані про компанії та endpoints для осіб зі значним контролем, включно з фізичними особами, корпоративними структурами й юридичними особами. Для публічного API потрібен API-ключ.

Чому це важливо

Номер компанії є стабільним ідентифікатором, а записи PSC допомагають відрізняти простий збіг назв від формально заявленого контролю.

Як це застосувати

Спершу звіряйте за номером компанії, далі зберігайте історію подань і PSC-повідомлення з датами та статусами. Важливі висновки про власність перевіряйте за поданнями й іншими реєстрами.

Обмеження

Реєстрові дані відображають подану інформацію й вимоги закону; це не повна карта всього економічного впливу чи кінцевої власності.

companies-housepsccorporate-identityukregistry
🔥Thermal SignalsТеплові сигнали
#05

NASA FIRMS delivers near-real-time fire and thermal-anomaly detections — a hotspot is a lead, not proof of cause

Source: NASA LANCE FIRMS · Official service checked 26 September 2026

What happened

FIRMS distributes MODIS and VIIRS active-fire and thermal-anomaly detections, with global near-real-time data generally available within about three hours of satellite observation. Data can be viewed in maps or downloaded through multiple geospatial formats and web services.

Why it matters

Thermal detections can help bracket timing and corroborate reports of large fires, but they do not identify what burned or why.

How to use it

Store satellite/instrument, acquisition time, confidence or quality fields and coordinates, then corroborate with imagery, local reports and facility context.

Limits

Cloud, sensor resolution, revisit timing and non-fire heat sources can produce gaps or ambiguous detections.

NASA FIRMS дає майже оперативні виявлення пожеж і теплових аномалій — hotspot є зачіпкою, а не доказом причини

Джерело: NASA LANCE FIRMS · Офіційний сервіс перевірено 26 вересня 2026

Що сталося

FIRMS поширює дані MODIS і VIIRS про активні пожежі та теплові аномалії; глобальні near-real-time дані зазвичай доступні приблизно протягом трьох годин після супутникового спостереження. Дані можна переглядати на картах або завантажувати в кількох геопросторових форматах і через web services.

Чому це важливо

Теплові детекції допомагають звузити час і підтвердити повідомлення про великі пожежі, але не визначають, що саме горіло й з якої причини.

Як це застосувати

Зберігайте супутник/сенсор, час зйомки, поля якості або confidence і координати, а потім звіряйте з imagery, локальними повідомленнями та контекстом об'єкта.

Обмеження

Хмарність, роздільна здатність, частота прольотів і не-пожежні джерела тепла можуть створювати прогалини або неоднозначні сигнали.

firmsthermalsatellitefirecorroboration
✈️Aviation DataАвіаційні дані
#06

OpenSky Network exposes ADS-B-derived state vectors, flights and tracks — receiver coverage and transponder behaviour shape what you can see

Source: OpenSky Network · Official API documentation checked 26 September 2026

What happened

OpenSky provides research-oriented access to live airspace data, including state vectors, flights and tracks derived from its sensor network. The REST API documents rate limits and uses OAuth2 client credentials rather than username/password basic authentication.

Why it matters

ADS-B history is useful for candidate flight reconstruction, but missing points can reflect coverage or transponder choices rather than absence of an aircraft.

How to use it

Preserve ICAO24 identifier, timestamps, query parameters and returned track points. Cross-check with airport, operator and other flight-tracking sources.

Limits

OpenSky explicitly does not provide commercial schedule or delay data that cannot be derived from ADS-B, and API access is rate-limited.

OpenSky Network відкриває ADS-B-дані про стан, рейси й треки — те, що видно, залежить від покриття приймачів і поведінки транспондерів

Джерело: OpenSky Network · Офіційну документацію API перевірено 26 вересня 2026

Що сталося

OpenSky надає дослідницький доступ до даних повітряного простору, включно зі state vectors, рейсами й треками, отриманими з мережі сенсорів. REST API документує rate limits і використовує OAuth2 client credentials замість базової автентифікації логіном і паролем.

Чому це важливо

Історія ADS-B корисна для реконструкції кандидатних рейсів, але пропуски можуть бути наслідком покриття або роботи транспондера, а не відсутності літака.

Як це застосувати

Зберігайте ICAO24, часові мітки, параметри запиту й отримані точки треку. Перевіряйте за даними аеропортів, операторів та інших flight-tracking джерел.

Обмеження

OpenSky прямо не надає комерційні розклади чи затримки, які не можна вивести з ADS-B, а доступ до API має обмеження частоти.

aviationads-bopenskytrackscoverage
📚Research CaptureЗбереження дослідження
#07

Zotero can save source metadata, PDFs and local webpage snapshots — useful provenance, but not a forensic capture system

Source: Zotero Documentation · Official documentation checked 26 September 2026

What happened

Zotero Connector can save webpage metadata, PDFs and local snapshots. A snapshot preserves a local copy of a page in the state seen when saved, alongside title, URL and access-date metadata.

Why it matters

For long investigations, source organisation and reproducibility often fail before sophisticated verification does. Zotero offers a low-friction research log for ordinary sources.

How to use it

Save the source record and snapshot, add notes about why it matters, and independently hash or archive evidence-grade material when chain of custody matters.

Limits

A Zotero snapshot is a research convenience, not a cryptographically authenticated forensic capture and not proof that the page was true.

Zotero може зберігати метадані джерел, PDF і локальні знімки вебсторінок — це корисне походження даних, але не форензична система фіксації

Джерело: Zotero Documentation · Офіційну документацію перевірено 26 вересня 2026

Що сталося

Zotero Connector може зберігати метадані вебсторінки, PDF і локальні snapshots. Snapshot залишає локальну копію сторінки в стані на момент збереження разом із назвою, URL та датою доступу.

Чому це важливо

У довгих розслідуваннях організація джерел і відтворюваність часто ламаються раніше, ніж складна верифікація. Zotero дає простий журнал для звичайних джерел.

Як це застосувати

Зберігайте картку джерела й snapshot, додавайте нотатки про значення матеріалу, а доказово критичні об'єкти окремо хешуйте або архівуйте, якщо важливий chain of custody.

Обмеження

Snapshot Zotero — це дослідницька зручність, а не криптографічно автентифікована форензична фіксація й не доказ правдивості сторінки.

zoteroresearch-capturesnapshotsprovenancesource-management