The idea is to help discover scam and impersonation infrastructure around financial brands, especially where you don’t already have a suspicious URL to start from.
At the moment I’m trying to pull together things like certificate transparency, Common Crawl, RDAP, DNS, TLS data, threat feeds, webpage analysis and whatever public social links can be found, then connect the dots between domains, phone numbers, emails, social accounts, analytics IDs, hosting, certificates, etc.
The part I’m struggling with most is discovery.
It’s fairly easy to analyse a domain once you already know about it. The harder question is: how do you find the other domains/accounts/infrastructure belonging to the same campaign?
I’m also trying to keep the project useful without needing a pile of paid APIs. Paid sources can help, but I don’t want the whole thing to fall apart if someone doesn’t have access to commercial threat intel.
The repo is here:
https://github.com/NADUPA-AFRICA-FOUNDATION-Ke/watchtower-main/tree/main
It still has the old Watchtower name in parts of the repo. I’ve been renaming it to Mnara.
I’d appreciate feedback from people who have worked on OSINT, phishing detection, fraud investigations or threat intel.
A few things I’m particularly unsure about:
- what discovery sources I’m missing
- useful pivots beyond the obvious domain/IP/email stuff
- ways of finding related scam infrastructure without creating loads of false positives
- how you’d approach social discovery without relying on brittle scraping
- whether the evidence/scoring approach makes sense
- better ways of clustering related domains and campaigns
I’m not really looking for stars or promotion. I’m more interested in someone looking at it and saying “this part makes no sense” or “you should be doing X instead”.
If you were building something like this, what would you change first?
Source: r/OSINTExperts · by /u/BrilliantOne799