🧰Tool of the WeekІнструмент тижня
#01
Web-Check 2.3.0 expands self-hosted website inspection and adds supply-chain provenance to its own release artifacts
Source: Web-Check / GitHub · 2 October 2026
What happened
Web-Check 2.3.0 was released on October 2. The release adds a tracker check, verified social statistics for websites, fixes the WHOIS OpenAPI parameter, improves self-hosting options, and attaches provenance and SBOM attestations to the published container image. The project is designed as a broad website-inspection surface rather than a single-purpose lookup tool.
Why it matters
Website research often mixes DNS, WHOIS, TLS, technology fingerprints, headers, archives and social signals. A single self-hosted interface can reduce collection friction, while attestations on the tool's own image improve confidence about what software was actually published.
How to use it
Treat each module as a separate observation layer. Preserve timestamps and raw values for DNS, certificates, redirects and trackers; do not infer common ownership from one shared infrastructure indicator alone.
Limits
Many website attributes are shared, proxied, cached or transient. A technology or infrastructure match is an investigative lead, not identity proof.
Web-Check 2.3.0 розширює self-hosted аналіз сайтів і додає supply-chain provenance до власних артефактів релізу
Джерело: Web-Check / GitHub · 2 жовтня 2026
Що сталося
Web-Check 2.3.0 вийшов 2 жовтня. Реліз додає перевірку трекерів, верифіковану соціальну статистику для сайтів, виправляє параметр WHOIS в OpenAPI, покращує self-hosting і додає provenance та SBOM attestations до опублікованого контейнерного образу. Проєкт працює як широкий інтерфейс аналізу сайту, а не як один окремний lookup-сервіс.
Чому це важливо
Дослідження сайтів часто змішує DNS, WHOIS, TLS, технологічні відбитки, headers, архіви й соціальні сигнали. Єдиний self-hosted інтерфейс зменшує тертя під час збору, а attestations для власного образу інструмента підвищують довіру до того, яке саме ПЗ було опубліковано.
Як це застосувати
Сприймайте кожен модуль як окремий шар спостереження. Зберігайте час і сирі значення для DNS, сертифікатів, редиректів і трекерів; не робіть висновок про спільного власника лише з одного спільного інфраструктурного індикатора.
Обмеження
Багато характеристик сайтів є спільними, проксованими, кешованими або тимчасовими. Збіг технології чи інфраструктури — це зачіпка, а не доказ ідентичності.
tool-of-weekweb-checkwebsite-osintself-hostedsbomprovenance
🗺️Image GeolocationГеолокація зображень
#02
Waypoint turns image geolocation into a ranked evidence pipeline instead of a single opaque guess
Source: Waypoint / GitHub · Repository checked 3 October 2026; updated 30 September 2026
What happened
Waypoint is a Windows desktop tool that estimates where an outdoor photo was taken. Its pipeline starts with coarse PLONK localization, checks sun and season plausibility, compares candidates against Mapillary, Google Street View and Panoramax imagery, then applies local-feature matching with DISK and LightGlue. The application exposes confidence, uncertainty and evidence per candidate. Most inference runs locally; imagery lookups are the main networked step.
Why it matters
The useful design choice is not that the tool predicts a location, but that it exposes intermediate evidence and lets the analyst drill into ranked candidates. This makes corroboration possible instead of hiding uncertainty behind one coordinate.
How to use it
Use the result as a candidate list. Preserve the candidate score, imagery source, visual match and sun-plausibility result, then corroborate with independent landmarks, maps, terrain or other dated imagery before publishing a location claim.
Limits
The project itself states that estimates are probabilistic, not proof. Coverage and recency of street-level imagery vary by place, and the current desktop build supports Windows rather than macOS or Linux.
Waypoint перетворює геолокацію зображень на ранжований доказовий pipeline замість одного непрозорого припущення
Джерело: Waypoint / GitHub · Репозиторій перевірено 3 жовтня 2026; оновлено 30 вересня 2026
Що сталося
Waypoint — Windows desktop-інструмент, що оцінює місце зйомки зовнішньої фотографії. Pipeline починається з грубої локалізації PLONK, перевіряє правдоподібність сонця й сезону, порівнює кандидатів із зображеннями Mapillary, Google Street View і Panoramax, а потім застосовує локальне зіставлення ознак DISK і LightGlue. Інтерфейс показує confidence, uncertainty та evidence для кожного кандидата. Більшість inference виконується локально; мережевими є насамперед запити до imagery.
Чому це важливо
Корисна особливість не в самій здатності передбачити місце, а в тому, що інструмент показує проміжні докази й дозволяє аналізувати ранжованих кандидатів. Це робить можливою звірку замість приховування невизначеності за однією координатою.
Як це застосувати
Використовуйте результат як список кандидатів. Зберігайте score кандидата, джерело imagery, візуальний match і результат sun-plausibility, а перед публікацією геолокації підтверджуйте її незалежними орієнтирами, картами, рельєфом чи іншими датованими зображеннями.
Обмеження
Сам проєкт прямо зазначає, що оцінки ймовірнісні, а не доказові. Покриття й актуальність street-level imagery різняться залежно від місця, а поточний desktop build підтримує Windows, але не macOS чи Linux.
geolocationimage-verificationwaypointstreet-viewlocal-inferencecandidate-ranking
📦Source CaptureЗбереження джерел
#03
ArchiveBox 0.9.71 provides a self-hosted layer for preserving web sources in multiple durable formats
Source: ArchiveBox / PyPI / GitHub · 28 September 2026
What happened
ArchiveBox 0.9.71 is the current stable 0.9 release line available on PyPI, with newer 0.9.72 release candidates published on September 30. ArchiveBox saves web sources into multiple local formats including HTML, screenshots, PDFs, WARC, text, metadata and other extracted outputs, and exposes a CLI, REST API and webhooks for reproducible collection workflows.
Why it matters
For investigations that may need to be audited later, a live URL is not enough. Keeping an independent local snapshot, capture time and multiple representations makes it easier to show what was actually available when a claim was researched.
How to use it
Capture important sources at first use, record the original URL and capture time, and preserve the archived object as a source artifact rather than replacing the live link. For high-value evidence, keep an external hash or backup of the archive as well.
Limits
An archived page proves that particular content was captured; it does not independently prove that the page's claims were true. Dynamic sites, authentication and anti-bot systems can also produce incomplete captures.
ArchiveBox 0.9.71 дає self-hosted шар для збереження вебджерел у кількох довговічних форматах
Джерело: ArchiveBox / PyPI / GitHub · 28 вересня 2026
Що сталося
ArchiveBox 0.9.71 — поточний стабільний реліз гілки 0.9 у PyPI; 30 вересня вже з'явилися нові release candidates 0.9.72. ArchiveBox зберігає вебджерела локально в кількох форматах, включно з HTML, screenshots, PDF, WARC, текстом, метаданими та іншими витягнутими результатами, а також має CLI, REST API й webhooks для відтворюваних collection-workflows.
Чому це важливо
Для розслідувань, які можуть перевірятися пізніше, живого URL недостатньо. Незалежний локальний snapshot, час capture і кілька представлень джерела допомагають показати, що саме було доступне в момент дослідження твердження.
Як це застосувати
Архівуйте важливі джерела під час першого використання, фіксуйте оригінальний URL і час capture та зберігайте архівний об'єкт як окремий source artifact, а не заміну живого посилання. Для цінних доказів варто мати також зовнішній hash або backup архіву.
Обмеження
Архівована сторінка доводить, що певний контент було зафіксовано; вона не доводить незалежно правдивість тверджень на цій сторінці. Динамічні сайти, автентифікація й anti-bot системи також можуть давати неповні captures.
source-capturearchiveboxweb-archivingwarcreproducibilityself-hosted
🕰️Archive ResearchАрхівні дослідження
#04
Archive Scout packages Wayback Machine discovery, download and keyword scanning into a resumable desktop workflow
Source: Archive Scout / GitHub · Project created 1 October 2026; checked 3 October 2026
What happened
Archive Scout is a newly created open-source desktop application for searching public Wayback Machine captures, downloading selected material and scanning archived content for keywords. The project describes configurable CDX parameters and resumable work, which is useful when archive queries span large result sets or unstable connections.
Why it matters
Archive research is often less about one historical page than about finding when a phrase, claim, file or site structure appeared and disappeared. A resumable search-and-scan layer can make those longitudinal checks much more reproducible.
How to use it
Record the CDX query parameters, target domain, date range, filters and exact capture URLs alongside any extracted finding. Preserve the absence of a capture as 'not found in queried archive coverage', not as proof that the material never existed.
Limits
Wayback coverage is incomplete and uneven. Robots exclusions, capture failures, missing assets and changed URLs can all create false impressions of absence or discontinuity.
Archive Scout об'єднує пошук у Wayback Machine, завантаження й keyword-scanning у відновлюваний desktop-workflow
Джерело: Archive Scout / GitHub · Проєкт створено 1 жовтня 2026; перевірено 3 жовтня 2026
Що сталося
Archive Scout — новий open-source desktop-застосунок для пошуку публічних копій Wayback Machine, завантаження вибраних матеріалів і keyword-scanning архівованого контенту. Проєкт описує configurable CDX parameters і resumable-workflow, що корисно для великих наборів результатів або нестабільних з'єднань.
Чому це важливо
Архівне дослідження часто полягає не в одній старій сторінці, а в пошуку моменту, коли фраза, твердження, файл або структура сайту з'явилися чи зникли. Відновлюваний search-and-scan шар робить такі longitudinal-перевірки значно відтворюванішими.
Як це застосувати
Зберігайте CDX query parameters, target domain, діапазон дат, filters і точні capture URLs разом із кожною знахідкою. Відсутність копії формулюйте як «не знайдено в перевіреному архівному покритті», а не як доказ того, що матеріалу ніколи не існувало.
Обмеження
Покриття Wayback неповне й нерівномірне. Robots exclusions, помилки capture, відсутні assets і змінені URL можуть створювати хибне враження відсутності або розриву.
archive-researchwayback-machinecdxarchive-scoutlongitudinalreproducibility
🔐Content ProvenanceПоходження контенту
#05
Origin reads C2PA Content Credentials in-browser and deliberately separates signer claims, integrity and trust
Source: Origin / GitHub · Project checked 3 October 2026
What happened
Origin is a small static C2PA verifier that runs entirely in the browser and uploads nothing. It reads Content Credentials, checks the cryptographic record and reports what the signer claimed. Its core rules explicitly distinguish three states: no credentials means no conclusion; claims are attributed rather than asserted; and an unrecognised certificate is not the same thing as evidence of tampering.
Why it matters
This is a useful model for evidence-aware interface design. A verifier should communicate exactly what cryptography proves, what a signer merely claims, and what remains unknown instead of collapsing everything into 'real' or 'fake'.
How to use it
Store the credential state, signer identity or certificate information, manifest claim and integrity result as separate fields. Treat a valid credential as provenance evidence, then corroborate the underlying event or depicted content independently.
Limits
C2PA cannot tell you that an unsigned image is false, and a valid signature does not automatically make the signer's description true. Trust-list status and file integrity are separate questions.
Origin читає C2PA Content Credentials у браузері й навмисно розділяє заяву підписанта, цілісність і довіру
Джерело: Origin / GitHub · Проєкт перевірено 3 жовтня 2026
Що сталося
Origin — невеликий статичний C2PA-verifier, який працює повністю в браузері й нічого не завантажує на сервер. Він читає Content Credentials, перевіряє криптографічний запис і показує, що саме заявив підписант. Базові правила проєкту чітко розділяють три стани: відсутність credentials не дає висновку; claims атрибутуються, а не проголошуються фактом; невідомий сертифікат не тотожний доказу tampering.
Чому це важливо
Це корисна модель evidence-aware інтерфейсу. Verifier має показувати, що саме доводить криптографія, що лише заявляє підписант і що лишається невідомим, замість зводити все до «справжнє» або «фейк».
Як це застосувати
Зберігайте credential state, дані підписанта або сертифіката, manifest claim і результат integrity-check як окремі поля. Валідний credential сприймайте як доказ provenance, а саму подію чи зображений зміст перевіряйте незалежно.
Обмеження
C2PA не може сказати, що непідписане зображення є фальшивим, а валідний підпис не робить автоматично правдивим опис підписанта. Trust-list status і цілісність файлу — окремі питання.
c2pacontent-credentialsprovenanceimage-verificationoriginbrowser-local