06 · Foundations & Tradecraft |
Counter-surveillance | |||||||
Whonix · Mullvad VPN · NextDNS · Tor Browser · Tails | ||||||||
Adversarial-grade | ||||||||
|
|
Investigative exposure is not limited to the moment of publication. A subject who detects surveillance activity before publication can destroy evidence, prepare legal counter-measures, shift assets or alert co-conspirators. For investigations into organised crime, corrupt officials or legally aggressive corporations, detection during the collection phase is a direct threat to the investigation and, in some contexts, to the investigator.
This tutorial walks through the operational controls that reduce your detection surface: session isolation, VPN chaining, DNS privacy, decoy query patterns and behavioural discipline. None of these controls provides absolute protection. Each one closes a specific detection vector, and together they raise the cost of detection above the effort most subjects are willing to spend.
In the field The Financial Times investigation into Wirecard, led by Dan McCrum over several years before the company collapsed into insolvency in June 2020, ran against a subject that actively watched its investigators. McCrum has described physical surveillance, hacking, electronic eavesdropping, online abuse and legal threats, and a hack-for-hire group in India with one cluster of targets tied to Wirecard.
Financial Times · CPJ interview, October 2020 · GIJN, June 2022 |
Learning outcomes
By the end of this tutorial you will be able to:
Identify the detection vectors an adversary-aware subject can use to surface investigative activity
Configure a session-isolated research environment that prevents cross-contamination with personal accounts
Apply VPN chaining and DNS-over-HTTPS to reduce IP-based and DNS-based attribution
Construct decoy query patterns that reduce your signal in a subject's access log review
Assess your own operational exposure before beginning a sensitive collection phase
The rest of this tutorial is for Signal subscribers.
What remains: the decision framework, the tool configuration, the failure modes, and the evidentiary standard required to use the finding defensibly. Signal is €90 a year, or €9 a month. Students, €49 a year.
Join SignalA Signal subscription gives you:
- Full OSINT Reference Card library, 21 domains
- Methods, every tradecraft tutorial in full
- AI in OSINT, every prompt and field report
- Shadow Analysis, every forensic dossier


