ShadowBroker OSINT Dashboard on GitHub: Review, Features and Limits

The ShadowBroker OSINT dashboard on GitHub is a free, self-hosted map that pulls dozens of public live feeds, from aircraft and ships to satellites, traffic cameras and cyber threat lists, onto one screen. This review is based on the project's repository, README and release pages, checked on 10 October 2026; we have not run it ourselves.

  • Open source, AGPL-3.0
  • Self-hosted with Docker
  • 40+ map layers
  • Third-party keys for some feeds
Short answer

ShadowBroker is an open-source OSINT dashboard on GitHub, maintained under the BigBodyCobain account, that aggregates public real-time data such as ADS-B flights, AIS ships, satellite orbits, traffic CCTV, hazards and cyber feeds on a single self-hosted map. It suits analysts and researchers who can run Docker. The software is free under AGPL-3.0; some feeds need your own API keys.

What Is the ShadowBroker OSINT Dashboard?

A self-hosted geospatial dashboard that layers public live data feeds on one map; it collects nothing new itself, it aggregates what providers already publish.

ShadowBroker describes itself as a "real-time geospatial intelligence platform" that combines feeds about aircraft, ships, satellites, conflict events, CCTV networks, GPS interference, internet-connected devices, scanner radio and breaking news into a single map interface (README). The frontend uses Next.js and MapLibre GL; the backend is Python with FastAPI. It runs on your own machine or server, and the README states the project has no accounts, product telemetry or analytics.

The README says the project "does not introduce new surveillance capabilities" and only aggregates public datasets. True of the data, but aggregation changes what one person can see at once.

The name is unrelated to The Shadow Brokers, the group that leaked hacking tools in 2016 and 2017. Search queries such as "shadowbroker osint github bigbodycobain" refer to this dashboard. It is one of several self-hosted map projects in our OSINT tools catalog.

Key Features

Toggleable live layers, a server-side recon toolkit, an entity graph, snapshot playback and an AI-agent command channel, plus an experimental messaging layer.

Map

40+ toggleable layers

Aviation, maritime, rail, space, hazard, infrastructure, cyber and news layers on one map.

Recon

Server-side recon toolkit

DNS, WHOIS, BGP, certificate and sanctions lookups plus optional Shodan, run server-side for local operators only.

Imagery

Satellite and SAR views

Sentinel-2, NASA and Esri imagery plus radar ground-change detection from public catalogs.

Analysis

Entity graph and Time Machine

Expand entities into a graph and replay recorded snapshots of the map.

AI

Agent command channel

A signed channel lets an AI agent search telemetry, run recon lookups and control the map.

Experimental

InfoNet testnet

Built-in messaging layer, labeled an experimental testnet with no privacy guarantee.

Data Sources and Coverage

Everything comes from third-party public feeds, so coverage and accuracy are only as good as each provider, and several feeds require your own key.

DomainExamples of sources named in the READMEKey needed?
AviationOpenSky Network (flights), adsb.lol (military aircraft)OpenSky credentials
Maritimeaisstream.io (AIS), Global Fishing Watch; carrier positions estimated from newsYes, for AIS and fishing data
SpaceCelesTrak orbital data, SatNOGS and TinyGS ground stationsNo
CamerasPublic traffic cameras from TfL, NYC DOT, Caltrans, WSDOT, Spain DGT, Singapore LTA and others; Windy WebcamsSome (e.g. Singapore LTA)
RadioKiwiSDR receivers, OpenMHZ police and fire scanner feeds, Meshtastic, APRSNo
HazardsUSGS earthquakes, NASA FIRMS fires, NWS alerts, NOAA space weatherNo
Cyber and reconabuse.ch, CISA KEV, crt.sh, RDAP, OpenSanctions, ShodanShodan only

The README puts the camera count at roughly 22,000 across 10 countries, with a lower figure elsewhere, so treat it as approximate (README).

Installation, License and Maintenance on GitHub

Docker Compose is the main install path; the code is AGPL-3.0 and was actively updated in 2026.

  • Install. Docker Compose pulls prebuilt images; Podman, a Helm chart and a desktop shell are also documented (README).
  • License. The repository's LICENSE file is the GNU Affero General Public License v3 (LICENSE). The README adds that the project is "for educational and personal research purposes", so read both before deploying.
  • Activity. The latest GitHub release listed was v0.9.83 on 15 June 2026 (releases), a 0.9.84 image tag followed, and the container registry showed a new "latest" build two days before our check (GHCR). The repository showed about 11,100 stars and 1,800 forks.

Pricing: Free Software, Your Own Data Keys

There is no price for ShadowBroker itself; the real costs are hosting, your time and any paid or restricted data feeds you connect.

ComponentCost or condition (checked 10 October 2026)
ShadowBroker softwareFree and open source under AGPL-3.0; no paid tier found
OpenSky flight APIOffered for "research and non-commercial purposes"; commercial users are asked to contact OpenSky (OpenSky API docs)
Shodan, AIS and other keyed feedsSet by each provider; ShadowBroker does not publish their prices
HostingYour own server, NAS or cloud instance; amd64 and arm64 images are provided

A company using the flight layer for business should check whether that use is still "non-commercial".

Who ShadowBroker Suits, and Who It Does Not

It suits technically capable researchers who want broad situational awareness; it does not suit teams that need verified, reportable conclusions.

Good fit: researchers, journalists and security analysts comfortable with Docker and API keys who want one screen for public signals during a breaking event.

Poor fit: compliance, legal and HR teams that need evidence-grade findings and someone accountable for the conclusion. A map of live dots is a starting point for questions, not an answer.

OSINT Limitations and Risks

Expect gaps, estimates and noise, and treat self-hosting and the AI agent channel as security decisions.

  • Estimates shown as positions. The README's disclaimer says carrier positions are estimates based on public reporting, and GPS jamming is inferred from aircraft accuracy values. Neither is an observation.
  • Gaps and false correlation. Transponders can be switched off and cameras go offline, so absence proves nothing; unrelated feeds side by side invite stories the data does not support.
  • Self-hosting exposure. A dashboard with recon tools and stored keys should not be exposed to the internet without authentication and network controls.
  • Agent permissions. The README says a connected AI agent gets read and write access to all layers and the recon toolkit (README).

ShadowBroker Alternatives for OSINT Monitoring

The closest alternative is another open-source map dashboard; for single tasks, specialist tools are usually more reliable.

  • Osiris: an MIT-licensed browser-based dashboard with flights, CCTV, hazards and a recon toolkit, plus a public live demo.
  • Censys and Shodan: search engines for internet-connected devices, if your interest is infrastructure exposure rather than a world map.
  • SpiderFoot: open-source automated reconnaissance for domains, IP addresses and organizations.

Need the Answer, Not the Tool?

If you need a verified assessment of an event, a route or a region rather than a live map, an analyst-led service is the better fit.

Our live event monitoring turns open-source signals into verified alerts for a specific event, site or trip, and our geopolitical risk intelligence and travel risk intelligence answer questions about regions and routes. Monitoring runs on an analyst-reviewed platform that updates hourly, with a senior analyst reviewing what reaches you. See our OSINT services for security teams, or browse more OSINT tools by task.

Want Verified Alerts Instead of Raw Feeds?

Tell us the event, site or region you care about and what decision depends on it. We scope it in writing and give you a fixed quote.

ShadowBroker OSINT Dashboard FAQ

I found the ShadowBroker OSINT dashboard on GitHub under BigBodyCobain — is that the official project, and what exactly would I be installing if I clone it?

Yes, github.com/BigBodyCobain/Shadowbroker is the project's own repository; no separate official website is listed. Cloning it gives you a self-hosted map dashboard with a Next.js frontend and a Python FastAPI backend, usually run with Docker Compose from prebuilt images. It aggregates public feeds such as flights, ships, satellites, traffic cameras, hazards and cyber threat lists. The code is licensed under AGPL-3.0 (LICENSE).

We'd like to use ShadowBroker in our corporate security operations center — is it free for commercial use, or will the data feeds create licensing problems for us?

The software is free under AGPL-3.0, but the feeds carry their own conditions. The OpenSky flight API, for example, is offered for research and non-commercial purposes, and commercial users are asked to contact OpenSky (OpenSky). Shodan, AIS and other keyed sources have their own terms. The README also describes the project as for educational and personal research purposes. Have legal review the license and each enabled feed before production use.

My manager saw a demo of ShadowBroker tracking private jets and live CCTV — is it actually legal for us to use a dashboard like that to follow specific people?

Following specific people is where legal risk starts, even though the feeds are public. Data protection law such as the GDPR still applies to publicly available personal data, and you need a lawful basis and proportionate purpose. In the US, the FAA offers aircraft owners privacy programs that limit how easily their aircraft can be identified (FAA). Watching individuals on cameras or tracking someone's movements without a lawful purpose can amount to stalking or harassment.

I'm not very technical but I want to monitor a region for security events before staff travel there — can I realistically run ShadowBroker myself, or is that the wrong approach?

You can run it if you are comfortable with Docker, environment files and API keys, but it may be the wrong approach for that goal. ShadowBroker shows raw signals; it does not tell you which matter for your staff or route. OSINT-S offers travel risk intelligence and live event monitoring, with focused work from 10 business days and urgent delivery available at a 50% surcharge.

How accurate are the ship, aircraft and GPS jamming positions in ShadowBroker if I want to cite them in a report for our board?

Treat them as leads, not evidence. Positions come from third-party feeds that can lag, drop out or be switched off at the source. The README says carrier positions are estimates based on public reporting, and GPS jamming is inferred from aircraft navigation-accuracy values rather than measured directly. Before citing anything in a board report, confirm it against the original provider and at least one independent source, and record when and where you captured it.