Social media investigations
Account histories, links between profiles, archived content and documented attribution reasoning.
Social media investigations →OSINT for law enforcement works best when the agency keeps the authority and the decisions, and gets extra analytical capacity when a case needs it. We support police forces, prosecutors' investigators and regulatory enforcement units with surge research, attribution work, training and evidence-grade documentation.
OSINT for law enforcement is the lawful use of publicly and commercially available information to support investigations, intelligence and public safety work. OSINT-S adds capacity to agency teams: identifying who is behind accounts, verifying images and video, mapping companies and assets, and training officers. Every task runs on a written requirement from the agency, which keeps its own legal authorities and decisions.
Mostly four things: attribute an online identity, verify media, map a network of people and companies, and absorb a backlog when a major case lands.
Most agencies already run open-source research in-house. They call in a partner when volume or specialism exceeds what the unit can absorb:
Six of our services map directly onto investigative tasks; most agency engagements combine two or three of them.
Account histories, links between profiles, archived content and documented attribution reasoning.
Social media investigations →Where and when an image or video was captured, checked against imagery, shadows and earlier uploads.
Geolocation verification →Wallet clustering, exchange touchpoints and the people behind addresses.
Crypto investigations →Property, companies, vehicles and other holdings linked to suspects, to support restraint and confiscation work.
Asset tracing →Shell structures, nominee directors, shared addresses and cross-border registrations behind a fraud or laundering scheme.
Company investigations →Courses for analysts and investigators on search, attribution, verification, capture and research hygiene.
OSINT training →We research under your tasking; authorizations, covert activity and decisions about people remain the agency's responsibility under its own law.
In the UK, the Home Office code of practice on covert surveillance says that preliminary examination of online material is unlikely to interfere with a reasonable expectation of privacy, but where an authority is systematically collecting and recording information about a particular person or group, a directed surveillance authorization should be considered (Covert Surveillance and Property Interference Code, paras 3.10–3.17).
In the US, agencies that run federally funded criminal intelligence systems are bound by 28 CFR Part 23, which allows information on an individual to be kept only where there is reasonable suspicion of involvement in criminal conduct, and bars collecting information on political, religious or social views unless it directly relates to criminal conduct (28 CFR 23.20). The Bureau of Justice Assistance has published guidance on social media policies that addresses access, use, storage and dissemination with attention to civil liberties (BJA, 2013).
| Question | Who decides | What we do |
|---|---|---|
| Is an authorization needed for this research? | The agency | Describe the planned collection so your authorizing officer can decide |
| Can anyone interact with the subject online? | The agency, under its covert rules | Passive research only; we never engage subjects |
| Can findings be used as evidence? | Prosecutor and court | Capture, log and document method so the question can be answered |
Written tasking, confirmed legal basis, documented collection, verification, senior review, then a report and exhibit set the agency owns.
If a finding may reach court, its capture, provenance and method must survive disclosure and cross-examination, so we document as if it will.
A finding nobody can reproduce is intelligence at best. We record what was found, where, when, with which tool and by whom. Capture tools such as Hunchly automatically record the URL, timestamps and hashes of every page visited (Hunchly); we add an analyst log of the reasoning between pages.
This matters because research material is subject to disclosure. In England and Wales, the Criminal Procedure and Investigations Act 1996 sets out disclosure duties and a code on recording and retaining material obtained in an investigation (CPIA 1996). For international and atrocity-related cases, our workflow follows the stages of the Berkeley Protocol: inquiry, preliminary assessment, collection, preservation, verification and analysis (Berkeley Protocol).
No single tool covers an investigation; units need capture, link analysis, imagery, blockchain and search capability, plus the tradecraft to use them safely.
| Category | What it does | Watch-outs |
|---|---|---|
| Capture and case notes | Saves pages with timestamps and hashes, builds an audit trail | Only as good as the analyst's discipline about what is captured |
| Link analysis | Graphs relationships between people, companies, domains and accounts (Maltego is a common example) | Automated transforms can create false links; each edge needs a source |
| Selector search | Checks emails, phone numbers and usernames against public registrations and breach indexes | Breach data raises legal and ethical questions; use only lawful sources |
| Imagery and mapping | Satellite, street-level and historical imagery for geolocation | Imagery dates are often older than they look |
| Blockchain analytics | Traces flows between wallets and services | Clustering is probabilistic; label sources matter |
Training works when it uses your agency's policies and real case types, and ends with a shared standard for recording research.
Our OSINT training for police units covers search technique, attribution, image and video verification, company and asset research, capture and logging, and research hygiene so that officers do not reveal their agency to a subject. Exercises use your typical case types with fictional subjects, so research by one officer can be checked and repeated by another.
Illustrative examples of the work agencies bring, framed as typical patterns rather than specific cases.
Footage circulating after a public incident needs dating and locating within hours, and recycled clips need to be separated from new ones.
Victim reports name several websites; research links the domains, companies and promoters behind them.
Anonymous accounts post threats. Analysts document the posts and research likely attribution from public account history.
We do not monitor lawful protest, religion, journalism or political activity, do not run covert identities, and do not handle classified material.
For private-sector cases later referred to police, see our OSINT investigations and the wider range of OSINT services for public and private clients.
Send the requirement, the deadline and the legal basis you are working under. We reply with scope, timeline and a fixed quote; if we miss the agreed date, the fee goes down.
You keep control through written tasking. The officer in charge defines the questions, subjects and limits, and we research only within that scope. The report, captures and collection log become agency material, and decisions on suspects and charges stay with you. Focused tasks start from 10 business days; larger network mapping can take up to about a month.
That is a decision for your authorizing officer, not for us. The Home Office code says simple reconnaissance of public material is unlikely to engage privacy, but systematic collection and recording about a particular person or group should lead you to consider a directed surveillance authorization. We describe the planned collection in writing so your force can decide before we start.
No. Covert interaction with subjects is reserved to the agency under its own legal framework and trained undercover officers. We do passive research on publicly and commercially available information only; we do not create fake profiles, befriend subjects or access private content.
A course for that group would cover search technique, account and username research, image verification, company and property records, capture and logging, and how to research without revealing your agency. Exercises use your office's typical case types with fictional subjects, and the recording standard follows your policy or, if it is silent, published BJA guidance.
We would not monitor the protest or its organizers. Lawful protest, political and religious activity is outside our scope, and in the US, 28 CFR Part 23 restricts federally funded intelligence systems from holding information on political or social views unless it directly relates to criminal conduct. We can support a narrow public safety requirement, such as verifying a specific public threat of violence, under a written tasking your board can review.
Start with capture, because every finding you cannot document is weaker in court. A tool that records URLs, timestamps and hashes automatically is the base layer. The second purchase depends on your caseload: link analysis for fraud and organized crime, blockchain analytics for crypto-heavy work, or imagery for verification. Pair any purchase with training, and check each vendor's license terms.
Assume the defense will see the method, and plan for it. Disclosure rules, such as the Criminal Procedure and Investigations Act 1996 in England and Wales, require relevant material to be recorded and retained. Our logs include null searches, tool versions and the reasoning between steps. Reproducible method usually strengthens a finding; undocumented research is the real risk.
Sources checked 7 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.