Osiris OSINT Review: The Open-Source Live Intelligence Dashboard

Osiris OSINT is an open-source, browser-based dashboard that puts live flights, satellites, public CCTV, earthquakes, fires and news on a 3D globe, with a recon toolkit and an AI forecasting module on top. This review relies on the GitHub repository, README, security policy and the public demo, checked on 10 October 2026; we have not run it ourselves.

  • MIT license
  • Live demo or self-hosted
  • 16 map layers
  • Bring your own API and AI keys
Short answer

Osiris (Open Source Intelligence and Reconnaissance Integrated System) is an MIT-licensed OSINT dashboard on GitHub by the simplifaisoul account. It maps flights, satellites, more than seventeen thousand public cameras, hazards, conflict zones and news, and adds DNS, WHOIS, port-scan, sanctions and crypto-wallet lookups. The software and demo are free; optional feeds and AI forecasts use your own keys.

What Is Osiris OSINT?

A free, open-source situational-awareness dashboard that renders public live feeds on a WebGL globe and adds a reconnaissance and forecasting toolkit.

The README describes Osiris as "a real-time global intelligence dashboard that aggregates live flight tracking, CCTV networks, earthquake monitoring, conflict zone mapping, and 24/7 news feeds into a single GPU-accelerated interface" (README). It is built with Next.js 16, TypeScript and MapLibre GL, and markets itself as an open-source "Palantir alternative". That is a headline, not a like-for-like comparison.

Searches such as "osiris osint tool flights satellites cctv" point to this project and to its demo at osirisai.live. Other repositories reuse the name, and at least one states it is built on the simplifaisoul project, so check the owner before you clone. For other map dashboards, see our catalog of OSINT tools.

Key Features

Toggleable live layers, a camera finder, a recon toolkit, crypto and sanctions checks, and an AI assistant that runs on your own model key.

Map

16 live layers

Flights, maritime chokepoints, cameras, quakes, fires, weather, space, cyber, conflict and news, loaded only for the visible area.

Cameras

Camera finder

Draw an area and Osiris lists every public camera inside it, exportable as GeoJSON, according to the README.

Recon

RECON toolkit

Port scan, DNS, WHOIS, SSL/TLS, IP intelligence and CVE lookups. It needs a separate scanner backend and returns an error without one.

Finance

Wallets and sanctions

Bitcoin and Ethereum wallet lookups and name searches, cross-checked against the US OFAC SDN list via OpenSanctions.

Social

Telegram layer

Posts from a few public channels, taken from Telegram's unauthenticated web preview and geoparsed onto the map.

AI

OI assistant and forecasts

Ask questions in plain words or run simulated forecasts on your own key from one of nine AI providers; an MCP server exposes it to agents.

Osiris Data Sources: Flights, Satellites and CCTV

Osiris relies on public agency and community feeds; several work without keys, but flights, satellites, fires and ships improve with your own credentials.

LayerSources named in the READMEKey
FlightsOpenSky Network (commercial, private and military)Optional OpenSky credentials
Satellites and space weatherN2YO, NOAA SWPCOptional N2YO key
CCTV (17k+ cameras)TfL, WSDOT, Caltrans, ODOT, MDOT, Texas TxDOT, Hong Kong, Taiwan, New Zealand and Dutch transport agencies, public webcamsNo
HazardsUSGS (M2.5+), NASA FIRMS, NASA EONETOptional FIRMS key
Maritime and conflictStatic port, chokepoint and conflict-zone data; optional AIS streamOptional AIS key
Cyber, crypto, sanctionsNVD, blockstream.info, Blockscout, OpenSanctionsScanner backend for RECON

Note that the maritime and conflict layers are static reference data, not live tracking, and the Texas cameras are refreshing snapshots rather than video (README).

License, Hosting and Maintenance

MIT-licensed, runnable from source, Docker or a prebuilt image, and updated frequently in 2026, though without formal releases.

  • License. MIT, copyright 2026 simplifaisoul (LICENSE), which permits commercial reuse of the code. Data feeds keep their own terms.
  • Hosting. Run from source with npm, with Docker Compose, or from a prebuilt image on GitHub Container Registry; the public demo runs in the browser without installation.
  • Activity. The repository showed about 10,500 stars, 2,200 forks and 329 commits, with no tagged GitHub releases. New container images were published in the days before our check (GHCR).
  • Coverage. Tech press covered the project in June 2026, including the security debate around its recon features (CloudNews).

Osiris Pricing and Hidden Costs

The software and the demo are free; costs come from hosting, optional data keys, AI model usage and any scanner backend you run.

ItemCost or condition (checked 10 October 2026)
Osiris software and live demoFree; the demo site describes it as "Free and open source" (osirisai.live)
OI assistant and forecastsBilled by your AI provider on your own key; the README shows token estimates before a run
OpenSky flight dataAPI offered for "research and non-commercial purposes" (OpenSky)
Patreon supportOptional; the README links a supporter "console" it calls "currently just a cool UI"

The repository's About text also ends with an unexplained string formatted like a cryptocurrency token address; the README does not mention any token. Treat any token promoted around the project with caution.

Who Osiris Suits, and Who It Does Not

It suits curious analysts and educators who want a fast, free overview; it does not suit work that needs verified, accountable conclusions.

Good fit: analysts, journalists, educators and students who want a quick global picture in a browser, and developers who want an MIT-licensed base to build on.

Poor fit: legal, compliance and corporate security teams that need sourced findings, chain of custody and a named analyst behind the conclusion. Osiris shows signals; it does not verify them.

OSINT Limitations and Risks

Static layers can look live, feeds drop out, and an exposed self-hosted instance with scanning enabled is a security liability.

  • Live versus static. Conflict zones and maritime chokepoints are curated reference data. Check the source before you treat a dot as current.
  • Coverage gaps. Cameras go offline and transponders can be switched off; absence on the map proves nothing.
  • Deployment. Press coverage in June 2026 warned against exposing an instance online without authentication, HTTPS and access limits, and recommended isolating the scanning backend (CloudNews).
  • Demo operator. The demo site names only the "Osiris Project" and showed no terms or privacy policy when checked, so avoid entering sensitive queries there.

Osiris Alternatives for OSINT Situational Awareness

The closest alternative is ShadowBroker; for infrastructure or recon questions, dedicated tools are deeper.

  • ShadowBroker: a self-hosted, AGPL-licensed dashboard with more layers, including ships, radio and satellite imagery, but a heavier install.
  • Censys and Shodan: search engines for exposed internet devices and services.
  • SpiderFoot: open-source automated reconnaissance for domains, IP addresses and names.
  • Maltego: link analysis for investigations that need entities and relationships rather than a map.

Need the Answer, Not the Tool?

If a decision depends on what is happening at a site, on a route or in a region, an analyst-verified answer beats a live map.

Our live event monitoring watches open sources around a specific event or site and sends verified alerts, and our geolocation and verification work confirms where and when footage or images were captured. For exposure of your own infrastructure, see threat intelligence. Every report gets a senior analyst review before it reaches you. Read more about our OSINT services and how we work.

Turn Live Signals Into Verified Answers

Send us the event, site or question you care about. We confirm scope in writing, agree a delivery date and give you a fixed quote.

Osiris OSINT FAQ

I keep seeing Osiris OSINT mentioned for tracking flights, satellites and CCTV — which GitHub project is the real one, and is it safe for me to try it?

The original project is github.com/simplifaisoul/osiris, with a public demo at osirisai.live. Other repositories use the same name, and at least one says it is built on this project, so check the owner before cloning. Trying the demo in a browser is low-risk if you avoid sensitive queries; the demo showed no terms or privacy policy when checked. Self-hosting is MIT-licensed (LICENSE), but keep the scanner backend private.

Our security team wants to use the Osiris port scanner and vulnerability lookups on a supplier's servers before we sign a contract — is that allowed?

Not without the supplier's written authorization. The Osiris security policy itself says not to scan or probe infrastructure you do not own or have explicit authorization to monitor (SECURITY.md), and unauthorized probing can breach computer-misuse laws. Passive checks such as DNS, WHOIS and certificate lookups are a different matter. For supplier risk, a passive external review or a third-party due diligence report avoids the legal problem.

I run a small corporate security team with no budget — can we use Osiris for free in our operations, or are there costs and license issues I'm missing?

The code is free under the MIT license, which allows commercial use, and the demo is free. The costs and limits sit elsewhere: your hosting, any AI model usage on your own key, and data terms. The OpenSky flight API, for example, is offered for research and non-commercial purposes, and commercial users are asked to contact OpenSky (OpenSky). Check each feed you enable.

My colleague wants to use the Osiris camera finder to keep an eye on a former employee's neighborhood — is that something we can legally do with public CCTV?

No, that is the kind of use you should refuse. Watching where a specific person lives or goes, even through public traffic cameras, can amount to stalking or harassment and engages data protection law on identifiable people. Public cameras are published for traffic and safety information. If there is a real security concern about a former employee, document it and involve legal counsel, HR and, where there is a threat, the police.

Can I rely on the Osiris AI forecasts and conflict-zone layer to brief our executives on whether to send staff to a region next month?

Not on their own. The conflict layer is static curated data, not live reporting, and the forecasts are simulations run by a language model on your key. Both can be useful prompts for questions but are not verified intelligence. For a staff travel decision, you want a dated, sourced assessment of the region and alerts during the trip. OSINT-S offers travel risk intelligence, with focused work from 10 business days and urgent delivery at a 50% surcharge.

We'd like to build our own internal dashboard on top of the Osiris code — what should we lock down before anyone in our company uses it?

Put it behind authentication and HTTPS, never expose it directly to the internet, and isolate the scanner backend with its own credentials; press coverage in June 2026 made the same recommendations (CloudNews). Keep API and AI keys out of shared browsers, log who runs recon lookups, and write a short acceptable-use policy covering authorized scanning, camera use and personal data before rollout.