Showing posts with label OSINT. Show all posts
Showing posts with label OSINT. Show all posts

September 27, 2018

You saw a ship on the news, but how do YOU find it using OSINT?

I've had some requests to walk people through, with more detail, how to look up ship-related information, and I'm not hiding any methods, the whole idea is for YOU to be able to loo up your own information for free (or for cheap), and not need to launch your own spy satellite.
(but if you have the chance, you really should - I'm looking at you Elon)

There are many, many, ways to skin this cat. I'm just going to go over one way as an example - this is by no means an exhaustive how-to. There are marine ship registries, forums, accident reports, all sorts of other resources - but I'm going to show you MarineTraffic.com and focus on AIS.

Let's take an article which was in the news and walk you through the process. The first thing is to figure out what is the subset of vessels, out of the tens of thousands presently at sea, that you're interested in. You need to scope out the breadth of your investigation. Here is a good start;

St Helena's cherished lifeline ship to return as anti-piracy armory
Joe Brock - APRIL 17, 2018 / 10:38 PM (original here)
JOHANNESBURG (Reuters) - The RMS St. Helena, Britain’s last working postal ship, was for nearly three decades the main source of contact between one of humanity’s remotest islands and the outside world.
Now the ship, cherished by the 4,500 residents of British-ruled St. Helena, will start a new life as a floating armory, packed with automatic weapons, bullet-proof jackets and night vision goggles, all stored for maritime security operatives.
Renamed the MNG Tahiti, the 340-foot ship will undergo some tweaks before sailing to the Gulf of Oman where it will be used to ferry guns and guards to passing vessels navigating stretches of water lurking with pirates, its new operator said on Tuesday.
“The ship is good to go with a few adjustments,” said Mark Gray, a former British Royal Marine and founder of floating armory firm MNG Maritime. “By the middle of the year we hope to have her operating.”
Tahiti Shipping, a subsidiary of MNG Maritime, bought the ship for an undisclosed fee on Tuesday, the St. Helena government said in a statement.
The construction last year of a commercial airport on the isolated island in the middle of the South Atlantic rendered the 156-passenger ship obsolete, prompting St. Helena authorities to put it up for sale and begin planning a gala farewell.
Before weekly flights to South Africa began in October, a five-night voyage to Cape Town on the RMS St. Helena was the only major transport route off an island made famous as the windswept outpost where French emperor Napoleon Bonaparte died.
The yellow-funnelled ship was purpose-built by the British government in 1989 to service the island and is the last of a royal mail fleet that once connected the far-flung tentacles of the old British Empire.
Its final voyage was marked with a public holiday on St. Helena, with flag-waving crowds gathering on the rocky coastline to catch one last glimpse of the ship that had delivered them everything from car parts to Christmas turkeys.
A flotilla of fishing vessels and yachts flanked the ship with those on board popping champagne corks as plumes of balloons were released into the sky to cheers from St. Helena residents, known locally as “Saints”.
“I fully appreciate the role this vessel has played in all Saints’ lives,” MNG Maritime’s Gray said. “It is not a responsibility we take on lightly. We will continue to treat her in the manner to which she has become accustomed.”
Writing by Joe Brock; Editing by Mark Heinrich (Reuters)
After reading that, do you have more questions than you started with? I sure do. First, how many ships like this does MNG Maritime and their subsidiaries have? What about other floating armouries? ...and where are they? Someone must have already made a list, hopefully with IMO or MMSI numbers which definitively identify the ships that might have duplicate names.

Web search engines like Google and Duck Duck Go will help you greatly, since none of these operations are in any way secret or covert, they are publicly discussed and licensed. These are extremely heavily armed vessels moored in strategic locations around choke points where there is high pirate activity.

Here is a fantastic resource:

"Stockpiles at Sea, Floating Armouries in the Indian Ocean"
written by Ioannis Chapsos and Paul Holtom
http://www.smallarmssurvey.org/fileadmin/docs/A-Yearbook/2015/eng/Small-Arms-Survey-2015-Chapter-08-EN.pdf

Google some more more and you'll soon find this:
https://seenthis.net/messages/688184

From those, you should have a list of a few dozen Vessels of Interest (see what I did there?)

Put all the vessel information you can find in a spreadsheet; with a little luck copy & paste works.

I'm going to use the IMO numbers because they're tied to the ship, whereas the MMSI number change with the registration and ownership. Sometimes you have access to one, or the other - always record both, and the callsign if you have it. Keeping a spreadsheet of the ships you've put information together about is essential. I recommend using Google Docs.

Now we come to the MarineTraffic.com portion of our lesson; 

Create an account, and if you're really into this, pay your yearly pound of flesh and get access to more than the free account offers.  First of all, you need a "fleet" of 50. Their basic account would provide you that. The "fleet" concept groups vessels in whatever category you would like, and allows you to control them in bulk groups easily.

Here are all the IMOs from the aforementioned floating armouries:

8112823
6524230
7027502
8965593
5278432
8107713
8107036
7313432
5427784
8701105
8129084
7406215
9606194
8131386
7412018
7624635
8413174
7353432
7709253
8206105
7911777
7115567
9050101
4908729
8410691
8912572
8333283
8301216
7932006
8003175
7319242
7636339
7392854
8333506

First, search for one of those ships, any one



Click the result, it will open up a details page on that ship


You want to make a new fleet, so click the down arrow beside "Add to default fleet" and scroll to the bottom, select "Add to new fleet". Name it something obvious, like "Floating Armouries"

Now, click the little person icon at the top right, and pull down to "My Fleets"


Select the Floating Armouries fleet you created previously. Notice the "import" line? That's what you want! That's why having a spreadsheet with the list of ships you're tracking is very handy.


Now you're presented with a big empty box for IMO or MMSI numbers; paste the whole list in that box. Any duplicates will disappear, so don't be too careful.



Import, and voila - you have a MarineTraffic fleet with all the Floating Armouries in it.



Then, you can show only the vessels in your fleet at the map view, and exclude all the others so you're not distracted.


You're ready to follow these, or other ships that match your interests, around the globe.


Did I cheat by using a pre-made list that someone else already published in a PDF? Yes. Absolutely. OSINT is all about that sort of "cheating". Use what others have already blazed the trail with, and add to that. There is no reason to start from scratch, but remember to both protect your sources, and credit them - those two things may seem at odds, because they are. I've offended people both by crediting, and not crediting them. I try to error on the side of giving credit publicly, unless someone tells me not to.

Happy hunting!

May 04, 2018

2018-05-03: Russian Air Force (RuAF) Su-30 crash off the coast of Jablah, Syria


by: ria.ru

Image available within an hour of the accident.
On May 3rd 2018 a Russian Air Force Su-30 jet crashed shortly after take-off for unknown reasons. Initial rumours suggested a bird strike on take-off, and with a full load, a loss of an engine would have been catastrophic. So where did it crash, exactly?

Let me introduce you to satellite imagery that isn't quite as crystal clear as the 30 cm resolution imagery you're used to on Google Maps. 3 meter resolution imagery is updated much more frequently, allowing the kind of coverage you simply couldn't find commercially in the past. Enter Planet Labs, and here is their image from 2018-05-03 at 10:47am local time. The crash is reported to have happened within a half hour previous to the picture. In the image we see what looks to be small boats, a small oil sheen, and possibly debris ~3 km from shore.

I'm not getting into the geopolitical aspects of the Syrian war, if the Russian air force should be there, or commenting on the loss of the two Russian pilots (which is a tragedy regardless of who's side you're on); I'm just using this as an example of how readily available satellite imagery can spot a crash site and give you information about something very quickly after such an event, before the news media has caught up on the story, or even officials are aware of what's going on. Never before have the public been able to short-circuit the dissemination of information to this extent, and bypass traditional media. I don't mean that journalism is dead, I think journalists are able to take a step back and do the deeper dive, and get more information to publish the "whole" story, while people get their fix for immediate news from primary sources like never before.


September 10, 2017

Is the US Navy, or NATO Maritime Command, watching the same ships I am?

US Navy P-8A #168440
(2016) Photo Credit to Michael Debock
This evening two plane spotters posted almost identical Tweets, drawing my attention to something I should be, but frequently forget to, keep an eye on. ADS-B transponders, from planes over the Mediterranean.



From this we know from ~1700Z to ~2200Z on September 10th 2017, US Navy Boeing P-8 Poseidon  registration #168440 was circling something off the coast of Malta, or working over an area looking for something.

Well, strangely I've been speculating there may be a Russians arms shipment going to India on (at least) two civilian ships in the area; the Ocean Fortune (MMSI 636013841) and Ocean Dream (MMSI 636016448).  Where were they between 1700Z and 2200Z?  I'm fairly certain the US Navy P-8A is outfitted with night vision capability, possibly using SAR. They may have been waiting for dark in order to inspect the ship at long range, ie without raising suspicion. However, they left their ADS-B transponder on, so they would have been very visible to anyone who was looking for them. Was this an accident? Not usually. The US Navy is usually very aware of their transponders.



I used "large" icons for the time period of the P-8A flight, but without the exact coordinates they flew, you just have to eyeball the screenshots and my map above. What do you think? It sure looks to me like the US Navy wanted a closer look at the RoRo and container ship that may be carrying S400s to India.

A bona fide "Vessel Of Interest"!

August 20, 2015

Following the Russian Navy Mod Altay class tankers

Image Credit: Ian Sturton - Mod Altay Class Tanker

Kola - Przemek / ShipSpotting.com Baltiysk, Kaliningrad 2006

Sometime last year I became interested in the Russian Naval Auxiliary ship Kola. ( Likely in part due to Tom in Lincolnshire, UK SoundCloud / Twitter ) The Kola is an oiler; a floating gas station for the Russian Navy. As I don't have my own spy satellite constellation (YET!), and the Russian Navy uses very loose terms for their deployment areas, I'm keeping an eye on a few ships of interest (like the Kola) to see where they operate, as they indicate larger operations. An oiler... oils! Well, more accurately, it ships marine diesel to ships at sea, and does alongside replenishment. If there's an oiler, there's at least one bigger boat around that's thirsty. 

Most recently the Kola returned from a Mediterranean deployment with the Russian Navy's Baltic Fleet Neustrashimyy-class (Неустрашимый) frigate RFS Yaroslav Mudry (СКР Ярослав Мудрый). The Yaroslav Mudry is the most modern Russian Navy Frigate in the fleet, being commissioned in 2009.

There were six oilers of the same class as the Kola, spread out across the fleet.  I'm uncertain which of those ships are still operating with the Russian Navy or have been decommissioned.  Specifications for the Mod Altay class tankers are as follows:

Mod Altay class (Project 160) (AOL)
Built between 1967-72 by Rauma-Repola, Finland
Displacement - full load: 7366 tonnes (7249.7 (uk) t) (8119.6 t short)) (7366000 kg)
Length - overall: 106.2 m (348.4 ft)
Beam - overall: 15.5 m (50.9 ft)
Kola - apachio / ShipSpotting.com Baltiysk, Kaliningrad 2006.12.23

Draught - hull: 6.7 m (22.0 ft)
Top speed: 14 kt (25.9 km/h) (16.1 mph)
Range: 8600 n miles (15927.2 km) (9896.7 miles) at 12 kt (22.2 km/h) (13.8 mph)
crew: 60
Cargo capacity: 4,400 tons oil fuel; 200 m3 solids
Machinery: 1 Burmeister & Wain BM550VTBN110 diesel; 3,200 hp(m) (2.35 MW); 1 shaft

August 05, 2015

Fotiy Krylov (Фотий Крылов) docks in Corinto, with a friend?

Marshal Gelovani
Photo Credit: Savitskiy Igor / ShipSpotting.com
Taken November 24, 2014 in Vladivostok
Following up on my last post about this interesting tug, the Fotiy Krylov (IMO 8613346 / MMSI 273441150) showed up at 2015-08-05 00:38Z at the Port of Corinto, Nicaragua.

The Port of Corinto is classified as a small port in the Northern Pacific, and has considerable warehousing and rail links to move cargo to/from the port.

So what?

Well, the Fotiy Krylov doesn't usually travel alone, but as a tug she usually has her AIS beacon on, unlike spy-ships or other ships of war.  So, who's she travelling with this time?

Rumour has it she's with the Project 862/II Marshal Gelovani (NATO: Yug Class) Hydrographic survey vessel. I can't find an IMO or MMSI for her, just a reference to 906O.  I also found reference that she is an AGE: General Purpose Experimental Ship (AGE = Auxiliary General Experimental).  I wonder if she's experimenting with something, and what they're up to?

The only thing I know that's going on in Nicaragua is the new canal which is being bankrolled by the Chinese, which is going to erode the American-controlled Panama canal's monopoly.  Just today they announced potential changes to the Pacific entry of the canal.  Are the Russians helping with oceanographic surveying?  Are they experimenting with new sonar?  Nicaragua is an ally of Russia, so any number of other projects could be going on, or they could have just stopped for some fuel and cigars.  I really don't know.

Title: Marshal Gelovani
Russian Navy Auxiliary
Project 862/II  |  NATO: Yug Class
Launched: 11.02.1983
Commissioned: 29.07.1983
Serving: Pacific Fleet / Vladivostok, Russia
Concept / Program (multiple sources have the ship listed differently):
  AGE: General Purpose Experimental Ship (AGE = Auxiliary General Experimental)
  General-purpose research ship
  Ekspeditsionnoye Okeanograficheskoye Sudno (EOS); Expeditionary Oceanographc Vessel
  Hydrographic survey vessel
Displacement: 1,892 tons / 2,490 tons (full)
Dimensions: 82.5 x 13.5 x 3.97 meters/270.6 x 44.3 x 13 feet
Propulsion: 2 Sulzer diesels, 2 shafts, 3,600 bhp, 15.6 knots
Crew: 46 civilian + 20 mission crew + 4 passengers/transients
Built: Poland, Stocznia Polnocna, Gdansk
  [information compiled from multiple sources]

Fotiy Krylov's last recorded position:



Corinto, Nicaragua: