Tuesday, September 22, 2026

Inside osiris: a self-hosted real-time OSINT dashboard across flights, CCTV, sanctions and crypto

Inside osiris: a self-hosted real-time OSINT dashboard across flights, CCTV, sanctions and crypto

osiris fuses live flight, seismic, CCTV, news, sanctions and crypto-tracing feeds into one GPU-rendered MapLibre dashboard for analysts working authorized intelligence and research tasks.

Toolsimplifaisoul/osiris — open-source real-time global intelligence and OSINT dashboard built on Next.js 16 and MapLibre GL
CategoryOSINT aggregation / situational-awareness platform
Primary UseFusing public feeds (OpenSky, USGS, NASA FIRMS, OpenSanctions, NVD, Telegram previews) into a single map for analyst triage and RECON lookups
Safe UseIntended for authorized threat-intelligence work, sanctioned by operators doing compliance screening, research on public data, and lab-based analyst training; all sources are public and keyless
Telemetry NoteClient-side only by default; queries hit public APIs, so source operators see your polling. RECON scanning requires a separate backend keyed via SCANNER_KEY, and any scanning you point at third parties is logged by those targets — restrict it to assets you own

osiris positions itself as an open-source answer to commercial intelligence platforms, aggregating a strikingly broad set of public data feeds into a single WebGL map interface. The repo, simplifaisoul/osiris, is written in TypeScript 5 on Next.js 16 with MapLibre GL doing the rendering, and it carries an MIT license with roughly 9.9k stars at the time of writing. The core pitch is situational awareness: instead of juggling a dozen browser tabs for flight trackers, seismic feeds, news streams and sanctions databases, an analyst toggles data layers on one GPU-accelerated canvas. The README is unusually detailed about architecture and data provenance, which makes it easy to evaluate what the platform actually does versus what its marketing implies.

The feature matrix spans aviation (via OpenSky Network), maritime chokepoint and port data, CCTV snapshots from transport agencies including TfL, WSDOT, Caltrans and TxDOT, seismic activity from the USGS Earthquake API, fire hotspots from NASA FIRMS, severe weather via NASA EONET, space weather and satellites from NOAA SWPC and N2YO, and 23 live news streams from global broadcasters. What matters analytically is that all of this is open data: the CCTV layer, for example, consists of refreshing JPEG snapshots publicly published by their operators, catalogued largely thanks to the hand-maintained bekijkhet.nu index that the README credits prominently. Nothing here involves bypassing access controls; it is aggregation of what the operators already broadcast.

Architecturally the README lays out a clean three-tier design. The client combines the MapLibre GL map with HUD panels and a RECON toolkit; a Next.js API-route layer (/api/flights, /api/cctv, /api/earthquakes, /api/osint/* and friends) mediates every request; and the external sources sit below. This proxy pattern is the right call for an OSINT dashboard because it keeps API keys server-side, enables caching, and lets the team apply polling discipline — the README claims a 75% reduction in edge requests versus the initial release, with stable data polled only every 15–30 minutes and a layerFetchedRef guard preventing duplicate fetches. Viewport-aware loading means layers fetch only data relevant to the visible map region, which is a sensible optimization when you are rendering thousands of concurrent entities at a target of 60fps.

The RECON toolkit is the part most relevant to security practitioners, and the README is honest about its boundaries. It bundles a TCP connect port scanner with service fingerprinting, full DNS record resolution (A, AAAA, MX, NS, TXT, CNAME), WHOIS, an SSL/TLS certificate-chain inspector, IP geolocation and ASN lookup, and CVE lookup against the NVD. Critically, the scanning backend is not bundled: it requires a separate service configured through SCANNER_URL and SCANNER_KEY (a shared secret you generate with openssl rand -hex 32), and without those variables the toolkit simply returns 503. This separation means the default self-hosted instance is a passive intelligence viewer, and any active scanning you wire up is your own responsibility — which should anchor it firmly to assets you are authorized to test.

The crypto and sanctions tooling is where osiris shows the most compliance-oriented maturity. Bitcoin lookups go through blockstream.info's keyless Esplora API, Ethereum through Blockscout's public instance, and every wallet result is cross-checked against the OFAC SDN sanctioned-address list mirrored from 0xB10C/ofac-sanctioned-digital-currency-addresses, surfacing a red SANCTIONED — OFAC SDN badge when there is a hit. A standalone SANCTIONS tab does full-text search across persons, organizations, vessels and aircraft using OpenSanctions data (CC-BY 4.0, roughly 7 MB cached in memory for 24 hours). Notably, the WHOIS and IP-intelligence routes automatically cross-check registrant and ASN-owner names against the SDN list — a small but genuinely useful automation for investigations where infrastructure attribution overlaps with sanctions exposure.

The Telegram OSINT layer is a good case study in scraping public surfaces without authentication. It reads the t.me/s/<channel> web preview — no Bot API token, no MTProto client — for a default curated set of five channels covering English and Russian/Ukrainian war reporting, overridable via the OSIRIS_TELEGRAM_CHANNELS environment variable. Posts are geoparsed against a multilingual place dictionary covering English, Cyrillic and Arabic toponyms and plotted on the map as clickable dots linking back to the original posts. For an analyst tracking open-source conflict reporting, this is a legitimate aggregation of publicly published content, though the geoparsing of informal place names is inherently noisy and should be treated as lead-generation rather than verified geolocation.

Deployment is straightforward and well documented. The quick start is the standard git clone https://github.com/simplifaisoul/osiris.git, npm install, npm run dev sequence serving on localhost:3000. A Docker path is also available: cp .env.template .env followed by docker compose up -d, or pulling the prebuilt multi-stage node:22-alpine image (~220 MB, non-root) from ghcr.io/simplifaisoul/osiris:latest. The compose file even embeds CasaOS app metadata for one-click homelab installs, and OSIRIS_PORT lets you remap the published host port without editing the file. The README is explicit that most layers work with zero API keys — FIRMS_API_KEY, OPENSKY_CLIENT_ID/SECRET, N2YO_API_KEY and AIS_API_KEY are optional rate-limit upgrades, not gates.

Operationally, the interface is keyboard-driven: F toggles flight layers, E earthquakes, S satellites, D the day/night cycle, and Escape closes panels. Sixteen toggleable data layers with live entity counts make it feasible to run the dashboard as a standing watch floor display, and the conflict-zone layer — 13 severity-coded zones from active wars through elevated tensions — gives threat-intelligence teams a quick orientation view for travel-security or geopolitical monitoring use cases. The Texas CCTV integration has its own testing story worth noting: npm test runs offline checks, while RUN_LIVE_TESTS=1 npx vitest run src/app/api/cctv/texas.test.ts exercises the live public inventory, with district inventories cached independently and stale data deliberately retained during source outages — a pragmatic resilience pattern.

There are caveats a professional should weigh before adopting this. The README's footer promotes a Patreon tier with a closed 'RedTeam Console' and 'encrypted developer comms', which sits awkwardly next to an MIT-licensed 'Palantir alternative' framing and is worth watching as a signal of where the project's incentives lie. The name collision with the well-known OSIRIS kernel-verification framework may also cause confusion in search. And while the platform itself only consumes public data, the optional scanner backend means operators must self-police: pointing the port scanner or vulnerability checks at infrastructure you do not own would be neither intended by the design nor defensible in practice.

From a defensive perspective, osiris is also a useful reference for what an analyst-grade aggregation of public telemetry looks like — and by symmetry, what an adversary's initial triage of your exposed footprint looks like. Everything it displays (flight ADS-B data, public camera snapshots, certificate chains, WHOIS registrant details, wallet clustering) is information you already publish, and reviewing your own organization through the same lenses is a reasonable exposure audit. Within its stated scope — authorized intelligence analysis, compliance screening, research and training — osiris is a legitimately impressive piece of open-source engineering, and the transparency of its README about sources, caching and key handling makes it easy to audit before you trust it.

Official project repository for simplifaisoul/osiris.
Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.

Share articleFacebookXLinkedIn

Continue exploring

Browse all articles →

0 comentários:

Post a Comment

Note: Only a member of this blog may post a comment.