Skip to content

Web browsers for OSINT investigators

  • by

Since everybody in the OSINT community knows that regular web browsers like Chrome or Firefox might not be great out-of-the-box tools for OSINT research (not unless you configure them a little), this post will focus on third party browser solutions that are actually well suited.

My first ever encounter with a dedicated OSINT browser was back in 2018 – that was still in the law enforcement days. Some of the investigators of similar vintage who read this might remember a UK-based project called Open Source Internet Research Tool (OSIRT). It was developed after the publication of a 2017 paper “Open source internet research tool (OSIRT): an investigative tool for law enforcement officials” (see abstract here). Here’s a brief overview of its functionalities at the time:

“OSIRT styles itself on the look-and-feel of a normal web browser, but provides additional functionality such as screen capturing and automated logging of webpages visited. All evidential artefacts are automatically placed into a case container, along with the date and time they were obtained and a cryptographic hash for file verification.”

An old version of the software is still knocking around, available for download (Windows only though). The OSIRT browser was very heavily focused on the data collection process and procedure, therefore it was not something intended for the wider OSINT community. Fast-forward to the present times, the OSIRT project evolved into the OSIRT platform, offering paid access to specialised digital investigation and evidence-capture tools for both private and public sector customers.

Process-driven evidence capture is still a specific niche, so in a lot of cases it’s over the top for a regular OSINT investigator, whose needs may be different. For example, if you are a private sector analyst working a lot on web investigations, you might be interested in a multi-functional, isolated browser as opposed to something predominantly focused on the chain of evidence. If your priority is a setup that favours operational security, you might want some kind of managed attribution for controls for your web traffic egress region, user agent fingerprint and language settings. 

So this is where the hands-on testing of some of the tools and their capabilities comes in. Please note that none of these vendors sponsored or in any way influenced any of the writing below – the impressions are subjective and based on my own (sometimes limited and sometimes more extensive) hands-on experience with each product.

Authentic8 Silo

Authentic8 Silo is primarily a cloud-based isolated browser. Your Silo web sessions render in a remote container and only pixels are streamed to you. You’ve got managed attribution controls that can be configured – based on an attribution network that covers several hundreds endpoints across multiple regions. You’ve got ISP, mobile, Tor / dark web options, all accessible from the same browser environment, which is very convenient. The workspaces offered by Silo are customisable and can be tailored to different policies and audit requirements. The price isn’t too bad either – about $1,500 per user per year for the basic package – which is decent and enough to get one dedicated analyst started and equipped with a daily driver environment. In terms of the cons – in the past, Silo had some latency problems and also issues with the bi-directional clipboard configuration: sometimes you couldn’t copy URLs from an external environment and paste them directly into the Silo browser tab. But this was a couple of years ago, so chances are that it’s been rectified.

Ntrepid Nfusion

Ntrepid Nfusion offers fully disposable virtual machines rather than just a browser environment. VMs are destroyed at the end of each session, which means eliminating risky files, trackers, cookies, basically all activity history accumulated during the session. Nfusion has both device and network level attribution (including mobile virtualisation), so it goes beyond what a browser-only product like Silo can emulate. Apparently they also provide physical devices, but I never had any experience of that kind. This expansive scope is both a strength and a weakness, because the trade off comes in the form of higher cost, more complex environment configuration & maintenance. The newest update includes support for AI models and agents, if that is your requirement. 

Menlo Security

Menlo Security is a tool very much focused on the isolation layer, so if opsec is your main objective, this might be your pick. By implementing the “isolate everything” philosophy, rather than classifying which websites and online resources are safe, Menlo isolates all web traffic by default. It claims to offer protection against targeted attacks that bypass traditional security tooling (I have no idea, did not test that angle). The interesting aspect is the introduction of a capability that sanitises what AI tools might have access to. Menlo is also rather affordable, but the trade off here is that you get what you (don’t) pay for – there is managed attribution, no specific OSINT tradecraft capabilities, no case containers, no Tor integration, no chain of custody or evidence capture.

Ericom Shield

Ericom Shield is a client-less remote browser isolation product, running browsers in Linux containers in the cloud. It can be deployed on-premises or in private cloud, so in this case Ericom answers the requirement of keeping everything on-premises (like some very sensitive projects, etc.), making it a good choice when regulatory compliance or commercial sensitivity are the main objectives. However, on-prem deployment effectively removes your ability to do managed attribution, unless you have ways to configure additional resources towards that area. Otherwise, note that all the isolated traffic from the isolated endpoint still leaves from the network that is attributed to you / your organisation. Ericom is definitely more of a security product rather that an OSINT product:. As with Menlo above, there is no evidence capture capability, no managed attribution and no dedicated OSINT tooling.

Kasm Workspaces

Finally, last but not least – Kasm Workspaces. It offers multiple virtual browsers, Linux desktops and individual applications inside Docker containers, streamed to any device via KasmVNC. Containers are destroyed at the end of each session, leaving no residual data, including no third-party software that you could have chosen to install. I like Kasm for various reasons, one of them being the ability to deploy Linux VMs. You get a functional Ubuntu desktop in the browser, plus spreadsheet and file-management applications, plus malware sandboxing for detonating suspicious files or links securely. Kasm is very flexible and customisable – but this can also turn against you, since you own the deployment, you are responsible for patching and the configuration. Also, the more you deploy, the quicker you run into storage limitations problems.

Leave a Reply

Your email address will not be published. Required fields are marked *