npx skills add ...
npx skills add useosint/osint-skills --skill pattern-of-life-from-socials
Deep-dive a subject's social media presence — profile metadata, follower and mutual network, content analysis, and posting-time pattern of life across Instagram, Facebook, X/Twitter, TikTok, LinkedIn, Reddit, Telegram and Discord. Use when profiling a social account, mapping someone's associates, inferring a subject's timezone or routine from their posts, or archiving a profile before it is deleted. Applies to threat assessment and executive protection, insider-threat investigation, pre-litigation research, and personal exposure audits — with explicit limits on profiling uninvolved third parties. Reference at useosint.com/skills/pattern-of-life-from-socials.
npx skills add useosint/osint-skills --skill pattern-of-life-from-socials
Pattern-of-life analysis turns scattered public posts into a model of where someone is, when, and with whom. It is the most abusable technique in this repo: the same method produces a due-diligence report and a stalking dossier. The difference is authorization and scope, not tradecraft. The beginner error is collecting posts instead of analysing them — screenshots of a feed are not intelligence. Work four layers: account metadata, network, content, temporal behaviour. The first and last are the two everyone skips, and the two the subject can't curate.
Read ../../ETHICS.md, then write down before opening a single profile:
Done when all six are recorded in the case file.
Logged-out leaks less and sees less; logged-in sees more and leaks more.
Platforms variously report story views and profile visits to the subject, and
recommendation systems surface accounts that look at each other — so merely
viewing can put your research account in the subject's suggestions. Decide the
tradeoff using investigate-without-getting-made; never browse a subject from
a personal or employer account.
Then capture before you analyse. Accounts get locked or scrubbed
mid-investigation, often because someone noticed. Archive the profile and every
post you may cite via read-deleted-pages, and pull older snapshots — they
routinely show a previous bio, link, or handle. Save media locally.
Done when the viewing identity is recorded and everything you intend to cite exists as an archive URL or a local file with a capture timestamp.
Go after what the subject never chose. Full per-platform behaviour is in the platform disclosure matrix.
Done when ID, creation date, handle history and every linked selector are recorded with sources.
A subject's OPSEC is nearly irrelevant if their relatives tag them.
Build this in graph-the-network, not as a list.
Done when the inner circle, one real-world cluster, and the third parties who leak about the subject are identified and graded.
Read past the subject of each photo to the accidental content: reflections in windows, mirrors, glasses and dark screens; laptop and phone displays in frame; paperwork such as boarding passes, parcel labels and event badges; vehicles, plates, dealer frames and parking permits. Repeated backgrounds are what upgrade a room from "somewhere" to "home" or "workplace" — count occurrences and note the date span.
Run secrets-in-file-metadata on everything you downloaded: platforms differ
in whether they strip EXIF, and the same platform may strip it from an inline
image while preserving it in a file attachment or an original-quality download.
Do the geolocation itself in geolocate-from-pixels. Sanity-check anything
that looks too convenient with is-this-photo-real.
Done when each location-bearing artefact is logged with post URL, date, and a pointer to the geolocation work.
Extract every post timestamp into a table and plot hour-of-day and day-of-week. The extraction schema is in the analytic checklist.
A contiguous gap of roughly seven to nine hours is the sleep window, and its position gives a UTC offset — enough to separate continents, not neighbours. A weekday dip through business hours suggests employment with restricted device access; the inverse suggests shift work or a job spent online. Sudden multi-day offset shifts are travel.
What wrecks this: scheduling tools post at fixed wall-clock times regardless of where the human is, so a scheduled account measures the scheduler; platforms may render timestamps in the viewer's locale; edits can carry the edit time; and cross-posting bridges or shared team accounts blend several humans into one histogram. Establish that posting is manual before reading anything into shape.
Done when both distributions exist over a stated sample window, with an explicit inferred UTC offset and its confidence.
Link accounts on evidence: the same avatar file, the same link-in-bio target,
follower-set overlap, aligned histograms. Writing style alone is a lead, not a
link. Then run write-the-intel-brief. Every claim cites a post or archive URL
and a date; every temporal conclusion states sample window and sample size.
Done when no claim lacks a citation and no inference lacks a grade.
Downgrade anything resting on an assumption you can't state in one sentence.
Objective: confirm a supplier's "EU operations lead" is in Europe, as the contract requires.
Bio says Lisbon. The numeric ID decodes to a signup years before the company existed — so the bio says nothing about the present. Four months of timestamps cluster 14:00–05:00 UTC with a dead zone 06:00–13:00: a sleep window centred near 09:00 UTC, wrong for Lisbon, consistent with the Americas. Dead end: no geotags anywhere, and the platform stripped EXIF from every download.
The network layer breaks it. Early followers cluster around one US state university, and a relative tags the subject at a named local restaurant on a date the subject publicly claimed to be in Portugal; a repeated kitchen background appears on both sides of that date. Graded probable — no authoritative record places the subject anywhere, and a histogram can't separate adjacent countries. Reported with the sample window stated.
| You now have | Take it to |
|---|---|
| Handle and variants | hunt-a-handle |
| Avatar, banner, posted photo | find-the-original-image, is-this-photo-real |
| Photo needing place or time | geolocate-from-pixels |
| Downloaded media files | secrets-in-file-metadata |
| Exposed email / phone | what-an-email-reveals, whose-number-is-this, what-leaked-about-you |
| Corroborated personal name | find-anyone |
| Employer, brand page, link-in-bio domain | x-ray-a-company, recon-a-domain-passively |
| Follower and mutual edges | graph-the-network |
| Deleted or edited posts | read-deleted-pages |
| Aircraft or vessel in posts | track-planes-and-ships |
| Wallet address or ENS name | follow-the-crypto |
Automated collection of profile and follower data breaches the terms of service of essentially every major platform and has been litigated as a computer-misuse matter in some jurisdictions; manual viewing of public content generally has not. Creating an account to view a subject is at minimum a ToS problem, and a fraud problem if you misrepresent identity to gain access.
Under GDPR and comparable regimes "publicly available" is not itself a lawful basis, and profiling a person's location and routine is high-risk processing. Political opinion, health, religion, sexuality and union membership are special categories — if they surface incidentally and aren't in scope, don't record them. And the one that matters: sustained monitoring of an individual's location and routine meets the statutory definition of stalking in many jurisdictions, and sourcing it publicly is not a defence. Authorization, a written objective and a stop condition are what make this work lawful.