GDE-059 |
Osintgram | |||||||
Instagram account analysis | ||||||||
September 2026 | ||||||||
01
What it is
Osintgram is the practice of using the open-source Osintgram tool to run an interactive command-line analysis of a public Instagram account, extracting followers, following, captions, hashtags and photo metadata through Instagram's own API using an investigator's logged-in session.
Osintgram is a free, open-source Python tool, actively maintained on GitHub with more than 13,000 stars, that offers an interactive shell for pulling structured data from a target Instagram account by username. It authenticates using the investigator's own Instagram credentials and works through Instagram's API rather than scraping rendered pages, returning followers, following lists, captions, hashtags, photo descriptions and, where available, addresses tied to geotagged photos.
Because it logs in as a real Instagram account to make these requests, the tool's own documentation warns against using a primary personal account, since automated querying at volume risks a temporary or permanent ban.
| When to use this guide
|
02
How do you run an Osintgram analysis?
Six steps from setting up a dedicated account through to extracting and reviewing the data responsibly.
The following tools are used across the steps below.
Osintgram: Free, open-source (GPLv3 licence). The command-line tool itself, authenticating through Instagram's API.
| Before you begin Stop at the login. Osintgram requires the investigator's own Instagram account credentials to authenticate, since it queries Instagram's API as a logged-in user. The tool's own documentation recommends never using a primary personal account and disabling two-factor authentication on the account used, given the automated query volume involved. Legal considerations. Instagram's terms of service prohibit automated data collection through unofficial tools, and using Osintgram is a terms-of-service violation that can result in the querying account being suspended or permanently banned, independent of any question of the target's privacy. Extracted personal data, including follower lists, captions and any geotagged addresses, is personal data under GDPR and equivalent frameworks; document a lawful basis for the specific investigation before running an extraction and avoid collecting more than the case requires. |
Create an account used only for this and future OSINT work, with two-factor authentication disabled, per the tool's own recommendation, rather than risking a personal or organisational account.
Clone the repository, install its requirements, and run it against the target's public username. No target-side login or interaction is required, since it queries public API endpoints as the investigator's account.
Use the followers and followings commands to build a structured list of connections, useful for identifying shared contacts or a broader network around the target.
Run the caption and hashtag extraction commands to review language, location references or affiliations across many posts at once, rather than reading each post individually.
Where Osintgram surfaces an address tied to a geotagged photo, corroborate it against an independent source before treating it as confirmed, since metadata can be inaccurate or outdated.
Run only the commands relevant to the case rather than pulling every available data category by default, keeping the collected dataset proportionate to the investigation's actual scope.
|
03
What are the pitfalls of using Osintgram?
Automated extraction at volume carries both a platform-ban risk and a data-protection risk that a manual review does not.
A single extraction mistaken as risk-free: Osintgram's terms-of-service violation risk applies from the first automated query, not only at high volume. Verifying check: treat every run, however small, as carrying the platform's ban risk to the querying account.
Bulk metadata mistaken for verified fact: captions, hashtags and geotags are self-reported or automatically generated and can be inaccurate, outdated or deliberately misleading. Verifying check: corroborate any metadata central to a finding against an independent source before relying on it.
A public account mistaken as fully consent-free to extract: a public Instagram profile does not equate to blanket consent for bulk automated data collection under data-protection law. Verifying check: confirm a documented lawful basis for the specific extraction before running it, not only that the account is publicly visible.
Chain of custody: extraction happens through an unofficial method against Instagram's terms, which makes documentation of scope and necessity more important than for an official API integration.
Record which specific commands were run and on which date, not just that Osintgram was used.
Document the lawful basis and investigative necessity for each category of data extracted.
Retain extracted data only for the duration the active investigation requires.
Note the querying account used, separate from any personal account, for accountability if a ban or dispute arises.
04
Go deeper
The wider Instagram OSINT workflow this tool feeds into.
GUIDE · GDE-008
Free OSINT tools and frameworks: 2026 toolkit guide
The wider free toolkit Osintgram sits alongside.
GUIDE · GDE-004
How to verify a source: OSINT identity checks for journalists
The wider identity-verification workflow an Instagram account analysis feeds into.
Evidentiary standard
Signal & Shadow operates to the LST-001 evidentiary standard. All claims are graded against the LST-001 v1.0.3 confidence tiers (Confirmed, Corroborated, Reported, Alleged) per the canonical voice and structural specification.
About Signal & Shadow
Signal & Shadow is an independent forensic investigation and methodology practice publishing tutorials, reference cards, and forensic dossiers for working practitioners. Founded by Derek Bowler.




