GDE-054 |
Osiris OSINT | |||||||
Real-time situational awareness | ||||||||
September 2026 | ||||||||
01
What it is
Osiris is the practice of self-hosting the open-source Osiris dashboard, a real-time global intelligence map that fuses live flight tracking, CCTV feeds, earthquake and wildfire monitoring, conflict-zone data and network-reconnaissance tools into a single browser interface, to build situational awareness from public data sources rather than from a single lookup.
Osiris is an MIT-licensed, open-source project built by GitHub developer simplifaisoul and covered in independent tech press as a low-infrastructure alternative to commercial platforms such as Palantir. It runs client-side using WebGL and MapLibre GL, deploys free to Vercel in one click or self-hosts locally via Docker, and aggregates more than 15 public data layers, including OpenSky flight data, AIS maritime traffic, USGS earthquakes, NASA FIRMS wildfire detections, NOAA space weather and live news feeds.
It also ships a RECON toolkit built into the same interface: a TCP port scanner, DNS and WHOIS resolution, SSL inspection and a vulnerability scanner. Because it is an actively developed open-source project, several independent community forks exist with different feature sets, and there is no single official hosted instance; every deployment is self-run.
| When to use this guide
|
02
How do you deploy Osiris for OSINT?
Six steps from choosing which instance to run through to citing a live finding defensibly.
The following resources are used across the steps below.
Osiris: Free, open-source (MIT licence). The canonical repository, self-hosted via Docker or Node, or deployed to Vercel in one click.
Vercel: Free tier. The recommended one-click hosting target for a self-run Osiris instance.
OpenSky Network: Free, public flight-tracking API. The underlying data source Osiris's aviation layer depends on.
| Before you begin Stop at the login. Osiris's map view itself requires no login. Any credentials involved are your own, for an optional data-source API key or your own hosting account; nothing in this workflow logs into a service on a subject's behalf. Legal considerations. Osiris is explicitly dual-use: its RECON toolkit, including the port scanner and vulnerability scanner, is legitimate for defensive research against your own infrastructure and can violate computer-misuse law if run against a system you do not own or have not been explicitly authorised to test. Independent press coverage of the project has noted this risk directly. The CCTV layer draws only from public feeds transit authorities already publish, not a private surveillance network; represent it as such and nothing more. |
Osiris has several independent community deployments. Fork the canonical repository and deploy your own copy to Vercel in one click, or run it locally via Docker, rather than trusting a third party's live instance to stay up or unaltered.
Switch on the specific domains, such as aviation, maritime, CCTV or seismic, that the investigation needs. Running all 15-plus layers at once is slower and harder to read than a targeted subset.
Use flight, maritime or CCTV data as one additional data point in a wider investigation, not a standalone source. Note that any of the platform's underlying public feeds can lag or drop out without warning.
The built-in port scanner, DNS and WHOIS lookup and vulnerability scanner are legitimate against your own infrastructure or an explicitly authorised target. Running them against a third party without authorisation is likely unlawful in most jurisdictions.
The camera layer pulls from public traffic-authority feeds already published by transit agencies; it is not a private camera network, and should be used and cited as exactly that.
Note which fork and commit you ran and which layers were enabled at the time a finding was captured, since this is an actively developed project and a later version may show something different.
|
03
What are the pitfalls of a live dashboard like Osiris?
A community fork, a feed outage or a public camera can each be mistaken for something they are not.
A community fork mistaken for the original: multiple independent forks exist with varying feature sets and maintenance levels. Verifying check: confirm which repository and commit a finding came from before treating a feature as available or a data source as current.
A live data-feed gap mistaken for absence: a public API outage or rate limit can make a layer appear empty even though the underlying activity continues. Verifying check: cross-check a gap against the underlying source's own status before concluding nothing is happening in that domain.
Public CCTV mistaken for a private surveillance capability: the camera layer only surfaces feeds transit authorities have already made public; it cannot see anything not already published. Verifying check: confirm a camera source's publishing authority before citing it as evidence.
Chain of custody: a live dashboard's state changes constantly, and an actively developed open-source project can change behaviour between versions.
Screenshot or export the map state with a timestamp before citing it as a finding.
Record the fork, commit and enabled layers active at the time of capture.
Do not run RECON toolkit functions against any target outside your own authorisation, and do not retain scan output beyond what that authorisation covers.
Note which underlying public API each finding traces back to, so a later reviewer can independently verify it.
04
Go deeper
The broader toolkit and network-reconnaissance guides Osiris draws on.
GUIDE · GDE-008
Free OSINT tools and frameworks: 2026 toolkit guide
The wider free toolkit Osiris's own layers and RECON toolkit sit alongside.
GUIDE · GDE-061
Censys for OSINT: internet-wide host and certificate search
A dedicated internet-scanning search engine that complements Osiris's built-in RECON toolkit.
Evidentiary standard
Signal & Shadow operates to the LST-001 evidentiary standard. All claims are graded against the LST-001 v1.0.3 confidence tiers (Confirmed, Corroborated, Reported, Alleged) per the canonical voice and structural specification.
About Signal & Shadow
Signal & Shadow is an independent forensic investigation and methodology practice publishing tutorials, reference cards, and forensic dossiers for working practitioners. Founded by Derek Bowler.




