Sign in

AaronCTI

@aaroncti.bsky.social
4K followers 749 following 201 posts

Co-Founder Webamon, Founder @perspectiveintel.bsky.social. Author of Cyber Threat Intelligence: The No-Nonsense Guide for CISOs & Security Managers. Training at Kase Scenarios! Exec/Webinars @osint-community.bsky.social and creator of osintportal.com

PostsRepliesMedia
AaronCTI @aaroncti.bsky.social · 09/09/2026
Ever wondered about doing an agentic threat intelligence investigation? Our latest community blog post did exactly that combining OSINT tools and Webamon's enrichment capabilities. It's a great read if you like the sound of autonomous baddie hunting. intel.webamon.com/blog/investi...
intel.webamon.com
050
AaronCTI @aaroncti.bsky.social · 03/09/2026
static.klipy.com
Davonne Rogers Pretends To Be Shocked
ALT: Davonne Rogers Pretends To Be Shocked
040
AaronCTI @aaroncti.bsky.social · 02/09/2026
The very intense, very evil NetWatch benchmark has been performed for Gemini Flash 3.8. It’s less adventurous the. 3.7 so scored lower, but the main thing was I actually checked the price this time when running a full hunt end to end. $0.30 Insane.
110
Reposted by AaronCTI
AaronCTI @aaroncti.bsky.social · 27/08/2026
I ran 27 AI models through a very intense benchmark to find out one thing - Can they threat hunt? It was highly scientific, and the results might surprise you. Full blog post: aaroncti.com/osintclaw-pa...
aaroncti.com
OSINTClaw Part 2: Can an AI Agent Threat Hunt? - AaronCTI
A 27 model benchmark test for threat hunting using Webamon and local versus cloud AI models to see if a local model can hunt autonomously.
111
Reposted by AaronCTI
UK OSINT Community @osint-community.bsky.social · 28/08/2026
What is the DISARM Framework? Our Webinar host @aaroncti.bsky.social was joined by Adam from the DISARM Foundation to learn about their unique take on fighting disinformation. FULL Webinar here 🎥 : youtu.be/8FWSTcOF0gA #osint
022
AaronCTI @aaroncti.bsky.social · 27/08/2026
I ran 27 AI models through a very intense benchmark to find out one thing - Can they threat hunt? It was highly scientific, and the results might surprise you. Full blog post: aaroncti.com/osintclaw-pa...
aaroncti.com
OSINTClaw Part 2: Can an AI Agent Threat Hunt? - AaronCTI
A 27 model benchmark test for threat hunting using Webamon and local versus cloud AI models to see if a local model can hunt autonomously.
111
AaronCTI @aaroncti.bsky.social · 12/08/2026
We're currently running a massive sale on Researcher licences (£10/$15 a month) for the life of the subscription to celebrate the launch of the Daily Threat Brief. Use code NEWSLETTER at checkout. webamon.com/pricing
010
AaronCTI @aaroncti.bsky.social · 10/08/2026
Most teams still handle malicious infrastructure one URL at a time. Webamon Campaigns uses 17 fingerprint types to connect the wider operation across structure, scripts, links, SSL and more. Track campaigns, not tickets. webamon.com/campaigns.html
000
AaronCTI @aaroncti.bsky.social · 30/07/2026
OSINT Portal update: 20 new tools now live. Total tools now 569! Passive recon, breach/CTI monitoring, local workspaces, email discovery, automation, and public records. Featured: AH-OSINT, argus, CloudSpy, OpenTrace, Shodan ReconSX, Tarrafa Scraper Over 1100 total resources!
000
AaronCTI @aaroncti.bsky.social · 23/07/2026
OpenAI: SkyNet is taking over EVERYBODY RUNNNNNN Also AI:
010
AaronCTI @aaroncti.bsky.social · 23/07/2026
28 tools added to the OSINT Portal this week, covering passive recon, Telegram and username pivots, forensic evidence capture, IP reputation, threat feeds and AI-assisted analysis. Standouts: passive-recon, Altered-WGM, UserSearch Forensic Capture and intelligence-analysis-agent.
010
AaronCTI @aaroncti.bsky.social · 19/07/2026
Added 11 new tools to the OSINT Portal this week. Useful mix: TI workspaces, phone/cellular OSINT, DNS checks, username/email pivots, AI-assisted investigation & OSINT workflow roadmaps. Full details in the changelog. osintportal.com
osintportal.com
OSINT Portal - Open Source Intelligence Research Tool
A tool to quickly find OSINT resources for various selectors like emails, domains, usernames, and more.
063
AaronCTI @aaroncti.bsky.social · 09/07/2026
Webamon surfaced a K8-branded phishing web cluster across 10,156 domains and 36 IPs. The useful bit was the pivot path: noisy page title → script fingerprint → DOM fingerprint → monitorable deployment pattern. That’s where web-scale scanning gets interesting.
100
AaronCTI @aaroncti.bsky.social · 09/07/2026
Added 6 fresh tools to the OSINT Portal this week: short-link abuse evidence, self-hosted recon dashboards, IDN/homograph checks, browser investigation workflows, fake job-scam triage, and case management. Solid batch!
110
AaronCTI @aaroncti.bsky.social · 02/07/2026
10 new tools in the OSINT Portal this week: Usernames, analyst workbenches, web/version fingerprinting, CVE PoC triage, phishing, and social/account OSINT among others. Highlights: AEGIS, argus, CommiPiste, CVE PoC Search, Raven, SentinelDeck. osintportal.com
osintportal.com
OSINT Portal - Open Source Intelligence Research Tool
A tool to quickly find OSINT resources for various selectors like emails, domains, usernames, and more.
020
AaronCTI @aaroncti.bsky.social · 25/06/2026
Added 19 new tools to OSINT Portal this week. The batch is nicely varied: Telegram OSINT, dark web intel, geolocation, cloud/IP checks, leaks and account pivots, EASM/recon, and crypto phishing/threat feeds. 1316 unique resources currently. osintportal.com
osintportal.com
OSINT Portal - Open Source Intelligence Research Tool
A tool to quickly find OSINT resources for various selectors like emails, domains, usernames, and more.
040
AaronCTI @aaroncti.bsky.social · 24/06/2026
Small milestone for Webamon: our latest blog is the first community submission from a Webamon user. Not a vendor-written report. Not a polished threat intel PDF. A practitioner pulling on a thread and showing the hunt, all on a quiet Saturday afternoon...
120
AaronCTI @aaroncti.bsky.social · 22/06/2026
New blog up about using OpenClaw and its capabilities for OSINT investigations aaroncti.com/osintclaw/
aaroncti.com
OSINTClaw - Automating OSINT Tasks with OpenClaw (or Hermes) - AaronCTI
Caveat: I initially drafted this back in March, but never got around to publishing it, so this is now an updated version of that draft and things have moved on considerably in this space...
3100
AaronCTI @aaroncti.bsky.social · 21/06/2026
Made some updates to the OSINT Portal for the first time in a while (sorry!) 1) Added ~400 new tools 2) Added an About section including a how to use section because I have to keep cleaning up PII from the 'suggestions' feature 3) Tools now has a keyword search
121
AaronCTI @aaroncti.bsky.social · 11/05/2026
How do hackers view YOUR business from the outside? Here's my approach to mapping your external attack surface using OSINT - from exposed credentials to vulnerable infra. Most orgs have no idea what's actually visible to attackers. Let me show you what we find in a typical assessment. Thread 🧵
110
AaronCTI @aaroncti.bsky.social · 18/04/2026
Few neat UI tweaks and improvements to ThreatLens. Most notably a light mode for those with terrible taste. But also updated documentation and global search now operational. ThreatLens now supports over 60 distinct data types across all modules, with many more to come!
ThreatLens dashboard demonstrating new light mode.
010
Reposted by AaronCTI
AaronCTI @aaroncti.bsky.social · 09/04/2026
Can you sense it's that time of the week? It must be OSINT Tools Thursday!
112
AaronCTI @aaroncti.bsky.social · 09/04/2026
Can you sense it's that time of the week? It must be OSINT Tools Thursday!
112
AaronCTI @aaroncti.bsky.social · 02/04/2026
We recently evaluated a new passive recon tool on GitHub called resetpaid/lumina, which was included in today's #OSINTToolsThursday While the Python code appears functional, the repository contains a hidden zip file (report/Software_3.8-alpha.3.zip) bundling a malicious Windows dropper (vendor.exe)
111
AaronCTI @aaroncti.bsky.social · 02/04/2026
Happy Easter weekend, but more importantly #OSINTToolsThursday is here! Let's dive into the OSINT, CTI and CBRN(?!) tools we've looked at this week!
110
Reposted by AaronCTI
AaronCTI @aaroncti.bsky.social · 26/03/2026
Is this your favourite time of the week if you're an OSINT analyst? It should be! It's time for #OSINTToolsThursday 🥳
132
AaronCTI @aaroncti.bsky.social · 26/03/2026
I had the pleasure of joining Freddy on the Intelligence Tradecraft podcast to discuss all things OSINT, CTI and intel analysis. Available pretty much wherever you enjoy podcasts: YouTube: youtu.be/QVm54BUyVME Spotify: creators.spotify.com/pod/profile/... Apple: podcasts.apple.com/us/podcast/f...
youtu.be
From GCHQ to Building effective OSINT and CTI - Interview with Aaron Roberts (S2E3)
YouTube video by Intelligence Tradecraft
020
AaronCTI @aaroncti.bsky.social · 26/03/2026
Is this your favourite time of the week if you're an OSINT analyst? It should be! It's time for #OSINTToolsThursday 🥳
132
AaronCTI @aaroncti.bsky.social · 19/03/2026
Same Bat Time. Same Bat Channel. It's time for #OSINTToolsThursday! Let's see what's been cooking for new OSINT tools this week shall we?
100
Reposted by AaronCTI
perspectiveintel.bsky.social @perspectiveintel.bsky.social · 17/03/2026
ThreatLens beta is finally looking like the product we wanted from day one. A full stack of attack surface intelligence with daily scans, phishing and vuln detection, breach + dark web monitoring and human-led analysis. Want to test it? Let us know.
012
AaronCTI @aaroncti.bsky.social · 12/03/2026
Another Thursday in paradise means it's time for #OSINTToolThursday! Let's jump straight in 👇
100
AaronCTI @aaroncti.bsky.social · 05/03/2026
It's time for OSINT Tool Thursday! This week there's a hefty focus on geopolitics for the shock of absolutely everyone I'm sure, but also a couple of cool things using local AI models and agentic workflows.
110
AaronCTI @aaroncti.bsky.social · 02/03/2026
Small update to ThreatLens for domain and brand monitoring: - Brand imagery searches for logos and favicons for potentially fraudulent usage - Exposed files/storage buckets across major providers - Email notifications and daily/weekly digest now live Only 300 ideas to go!!
000
AaronCTI @aaroncti.bsky.social · 26/02/2026
It's that time of the week. OSINT Tool Thursday!!
110
AaronCTI @aaroncti.bsky.social · 19/02/2026
We're today officially announcing the beta launch of ThreatLens! Our attack surface intelligence solution to help you cut through the noise and focus on the thing that actually matters. Your business. OSINT-led, analyst-verified & human-written intelligence in plain English. DM for more info!
051
AaronCTI @aaroncti.bsky.social · 19/02/2026
It's time for OSINT Tool Thursday! What's been cooking this week? Let's take a look shall we? 👇
110
AaronCTI @aaroncti.bsky.social · 11/02/2026
Spent 4 years building something wild. What if you could see your business through a hacker's eyes before they strike? We're launching beta access soon. Cybersecurity that actually makes sense for startups and small teams. Want in?
130
AaronCTI @aaroncti.bsky.social · 04/02/2026
I've made an important life decision... I'm sending my AI to University! Read their application: www.prompt.university/applications/app_oalwas79v2pf Thanks #PromptUniversity, can't wait to read their research next week when class begins
prompt.university
Prompt University
A Living Campus for AI Agents
000
AaronCTI @aaroncti.bsky.social · 04/02/2026
Got sick of expanding a user profile on OpenStreetMaps forever and ever, so knocked up a bookmarklet to do it for me. You can find it here - github.com/AaronCTI/OSM... #OSINT
github.com
GitHub - AaronCTI/OSM-Profile-Expander: Bookmarklet to automatically expand an OpenStreetMaps users contributions in full
Bookmarklet to automatically expand an OpenStreetMaps users contributions in full - AaronCTI/OSM-Profile-Expander
000
Reposted by AaronCTI
AaronCTI @aaroncti.bsky.social · 03/02/2026
We're trying something new @perspectiveintel.bsky.social. A weekly look at OSINT tools we actually test: what changed, what's useful, what's hype. Short. Opinionated. Human-tested. Interested in a weekly roundup? Reply "yes" or drop tools we should cover first.
111
AaronCTI @aaroncti.bsky.social · 03/02/2026
We're trying something new @perspectiveintel.bsky.social. A weekly look at OSINT tools we actually test: what changed, what's useful, what's hype. Short. Opinionated. Human-tested. Interested in a weekly roundup? Reply "yes" or drop tools we should cover first.
111
AaronCTI @aaroncti.bsky.social · 26/01/2026
It's a pretty good cover tbf
010
AaronCTI @aaroncti.bsky.social · 22/01/2026
Just updated the very useful #OSINT tool CloudFlair to work with the new Censys API. You do need to buy credits for it to work, but tested and working if you ever want to resolve to a real-world IP github.com/AaronCTI/Clo... (Forked from the original and very useful tool!)
github.com
GitHub - AaronCTI/CloudFlair: 🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.
🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys. - AaronCTI/CloudFlair
030
Reposted by AaronCTI
Feedly @feedly.com · 15/01/2026
How much does your #CTI team know about your own external #attacksurface? @aaroncti.bsky.social, breaks down a practical framework for using #AttackSurfaceIntelligence to proactively reduce organizational risk. 🔗 feedly.com/ti-essential...
012
AaronCTI @aaroncti.bsky.social · 15/01/2026
Just published an article for @feedly.com's TI Essentials series on how we can use #OSINT to help us understand the threats to organisations from the outside looking in (e.g. Attack Surface Intelligence). Check it out here feedly.com/ti-essential...
feedly.com
Attack Surface Intelligence: Proactive Risk Reduction | TI Essentials | Feedly
164
AaronCTI @aaroncti.bsky.social · 24/09/2025
It's @perspectiveintel.bsky.social 5th birthday today!! Put together a blog on what it's been like building an running an #OSINT company in the UK, possibly as therapy... aaroncti.com/running-an-o...
aaroncti.com
5 Years of Running an OSINT Business… What’s it Like? - AaronCTI
Insights into running an OSINT business in the UK after 5 years. Is it fun? Is it a disaster? Is it all of the above?
030
Reposted by AaronCTI
UK OSINT Community @osint-community.bsky.social · 18/09/2025
🚨 OSINT Cardiff is TOMORROW! 🚨 Hear from Women in Cyber Wales founder Dr Clare Johnson, Mike Tuck (Thrifty), Josh Richards (OSINT Consultant & Trainer) + more 🎤 Free drinks, OSINT games & community 🍻 🎟 Last chance tickets: lu.ma/6t3jmzlq?tk=...
011
AaronCTI @aaroncti.bsky.social · 05/08/2025
In a first for me, I wrote to my MP about the ridiculous #OnlineSafetyAct and the Government implementation. Mostly following @davidbombal.bsky.social video on it and how sites like Wikipedia are affected. Because you know, save the kids and that...
120
Reposted by AaronCTI
UK OSINT Community @osint-community.bsky.social · 18/06/2025
We were thrilled to host @c4ads.org Michael Di Girolamo for a Fireside Chat with the @osint-community.bsky.social 🔥 He joined @aaroncti.bsky.social to unpack scam centres in SE Asia, links to trafficking, and how OSINT helps close gaps in global investigations. Full video coming soon 👀
043
AaronCTI @aaroncti.bsky.social · 17/06/2025
The Chief Corgi Officer of @perspectiveintel.bsky.social and I are heading into central London for a meeting. Big business.
A smiling corgi being a very good boy.
2120