01 · Geolocation & Chronolocation |
Wi-Fi Positioning & Geo-IP | |||||||
Wigle.net · ipinfo.io · Maxmind GeoLite2 · Shodan | ||||||||
Intermediate | ||||||||
Network mapping with Maltego and Gephi for investigators. See also: WHOIS investigation and phone number analysis and carrier lookup for the reference-card versions of these network-identifier techniques. |
|
Wireless access points broadcast a hardware identifier, the BSSID, that is fixed to the device and logged in crowdsourced wardrive databases. When a screenshot, a leaked config file or a background detail in video reveals a network name or partial BSSID, that string can resolve to a latitude and longitude without any active engagement with the subject. The technique is passive, legal in most jurisdictions when restricted to public databases, and repeatable.
IP geolocation works at a coarser grain, mapping an internet-routable address to an autonomous system, a city-level location and sometimes a postal district. Used alone it is rarely conclusive; used alongside BSSID evidence, leaked device logs or corroborating imagery, it narrows a geographic hypothesis to a testable claim. Together, these two network-layer signals give investigators a location chain structurally independent of the visual content they are trying to verify.
In the field In its 2018–2020 GRU officer identification series, Bellingcat and The Insider identified operatives behind the Skripal poisoning and related operations. The series is the clearest public demonstration of network-layer identifiers as evidence: not the IP/ASN attribution taught here, but the same underlying principle, that infrastructure records an adversary does not control can place them independently of what they choose to disclose.
Bellingcat and The Insider · GRU officer identification series · 2018–2020 Note: this series is documented as using leaked registration, passport and phone-metadata databases, not IP/ASN geolocation specifically. Included for the corroboration-and-registry-cross-reference principle it demonstrates, not as a worked example of the workflow taught below. |
Learning outcomes
By the end of this tutorial you will be able to:
Query crowdsourced BSSID databases to resolve a network name or partial hardware identifier to a geographic coordinate
Interpret IP geolocation outputs at the correct grain, distinguishing ASN-level from city-level from postal-district resolution
Cross-reference BSSID and geo-IP evidence against imagery and open records to build a corroborated location claim
Document the network-layer evidence chain to evidentiary standard, noting the confidence tier of each data point
The rest of this tutorial is for Signal subscribers.
What remains: the decision framework, the tool configuration, the failure modes, and the evidentiary standard required to use the finding defensibly. Signal is €90 a year, or €9 a month. Students, €49 a year.
Join SignalA Signal subscription gives you:
- Full OSINT Reference Card library, 21 domains
- Methods, every tradecraft tutorial in full
- AI in OSINT, every prompt and field report
- Shadow Analysis, every forensic dossier


