This website uses cookies

Read our Privacy policy and Terms of use for more information.

AI-assisted content

BLOCK01 · GEO & CHRONO
TOPICWI-FI POSITIONING · GEO-IP
TOOLSWIGLE.NET · IPINFO.IO · MAXMIND GEOLITE2 · SHODAN
DIFFICULTYINTERMEDIATE

01

Network identifiers locate subjects when visual evidence fails

When footage contains no recognisable landmarks and metadata has been stripped, the network infrastructure visible in a device's environment can still place it in a neighbourhood, a building type, or a specific address range. Wi-Fi BSSID records, geo-IP mappings and passive network scans form a parallel geolocation layer that operates independently of camera angle, sun position or terrain.

Wireless access points broadcast a hardware identifier, the BSSID, that is fixed to the device and logged in crowdsourced wardrive databases. When a screenshot, a leaked config file or a background detail in video reveals a network name or partial BSSID, that string can resolve to a latitude and longitude without any active engagement with the subject. The technique is passive, legal in most jurisdictions when restricted to public databases, and repeatable.

IP geolocation works at a coarser grain: it maps an internet-routable address to an autonomous system, a city-level location and sometimes a postal district. Used alone it is rarely conclusive. Used alongside BSSID evidence, leaked device logs or corroborating imagery, it narrows a geographic hypothesis to a testable claim. Together, these two network-layer signals give investigators a location chain that is structurally independent of the visual content they are trying to verify.

In the field

In its 2018–2020 GRU officer identification series, Bellingcat and its partner The Insider identified operatives behind the Skripal poisoning and related operations. The series is the clearest public demonstration of network-layer identifiers as evidence: not the IP/ASN attribution this tutorial teaches, but the same underlying principle, that infrastructure records an adversary does not control can place them independently of what they choose to disclose.

  • Registry cross-reference. Investigators matched leaked Russian vehicle-registration and passport databases against known GRU unit addresses, identifying officers by the administrative records tied to their real identities.
  • Multi-partner corroboration. Findings were independently corroborated with partners including The Insider, Der Spiegel and CNN before publication, meeting a multi-source verification threshold.

Bellingcat and The Insider · GRU officer identification series · 2018–2020

Note: this series is documented as using leaked registration, passport and phone-metadata databases, not IP/ASN geolocation specifically. It is included for the corroboration-and-registry-cross-reference principle it demonstrates, not as a worked example of the geo-IP workflow taught below.

Learning outcomes

By the end of this tutorial you will be able to:

  • Query crowdsourced BSSID databases to resolve a network name or partial hardware identifier to a geographic coordinate

  • Interpret IP geolocation outputs at the correct grain, distinguishing ASN-level from city-level from postal-district resolution

  • Cross-reference BSSID and geo-IP evidence against imagery and open records to build a corroborated location claim

  • Document the network-layer evidence chain to evidentiary standard, noting the confidence tier of each data point

logo

This tutorial is for Signal subscribers.

Methods goes deep on a single technique each fortnight. The decision framework, the tools, the failure modes, and the evidentiary standard required to use the finding defensibly.

Join Signal

A Signal subscription gives you:

  • Full OSINT Reference Card library
  • Methods, all tradecraft tutorials in full
  • Shadow Analysis, all evidence-based reporting
  • Forensic Dossiers, full access
  • Discord access included

Keep Reading