Mulberry

Mulberry · Market landscape

OSINT Landscape

A living view of which data sources open-source intelligence teams are using, from mainstream social platforms and news to dark web infrastructure and government records. Updated as the market shifts.

Updated Q3 2026·A living map, updated as the market shifts
INTEGRATEDActive Features of PlatformsIMPLEMENTINGAdding or Planned AdditionsINTERESTExploring & PlanningBUYER EXPECTATIONHighMediumLowBlueskySignalBitbucketGiteeWeChatSina WeiboTelegramDiscordGitHubGitLabRedditVKontakteHackerNewsStackOverflowX4chanWhatsAppDark Web (TOR)PastebinI2P NetworksOSINT: Leaders & MoversQ3 2026 · Sourced by Mulberry · sourced.ccDot size reflects tracked provider count in SourcedNotch = direction of movement (up-left = growing, down-right = declining)
Free to use in decks and docs with attribution intact.

Key Shifts

  1. Adversary-platform demand rising

    2025 to 2026

    Geopolitical demand keeps pulling open-source intelligence toward regional and adversary-nation platforms. VKontakte and Telegram stay central to Eastern-Europe and active-conflict monitoring, and buyer interest in them is rising, not flat.

    Read More: fivecast.com

  2. Open social web widening

    May to June 2026

    The open social web is widening the surface investigators have to map. Bluesky opened up long-form articles through the AT Protocol, and Mastodon added newsletters in version 4.6, both extending federated, self-hosted infrastructure well beyond short posts.

    Read More: techcrunch.com, techcrunch.com

  3. User-defined algorithm growth

    July 2026

    Platforms are handing feed control back to users. X retuned ranking to favor mutual connections, and Threads and Instagram shipped user-facing algorithm controls. Public feeds are increasingly personalized, so a single feed sample reads less as a representative view of the platform.

    Read More: techcrunch.com, techcrunch.com

  4. Reddit access closing

    2026

    Reddit is closing its open, machine-readable access. It moved to shut down the unauthenticated endpoints that allowed scraping for years, and as of mid-2026 old Reddit requires a login. Free anonymous collection is ending, and compliant, licensed access is becoming the only dependable path to Reddit data, which matters for any investigation that leans on Reddit as a primary source.

    Read More: reclaimthenet.org

Individual Sources

Buyer expectation and demand trend are Sourced's direct assessment.Buyer expectation and demand trend are Sourced's direct market assessment, not vendor-reported. Expectation is how broadly buyers expect the source covered; trend is its movement in demand.
IntegratedActive features of platforms
SourceBuyer ExpectationDemand TrendProviders
XHighStable18
4chanMediumStable1
WhatsAppMediumStable2
Dark Web (TOR)HighGrowing4
PastebinMediumDeclining2
I2P NetworksHighGrowing2
8kunMediumDeclining1
BitChuteMediumDeclining0
GrowingStableDecliningProviders = tracked provider count in Sourced.
ImplementingAdding or planned additions
SourceBuyer ExpectationDemand TrendProviders
Telegram

Hundreds of Telegram channels are monitored for stolen financial data alone, with standing access to extortion and hacktivist coordination channels, evidence of a platform that has become the default distribution layer for ransomware leak sites.

HighGrowing6
Discord

Discord sits among the chat services monitored for threat actor community activity, and shared server admin patterns are used to trace coordinated repost networks, making it a working intelligence surface rather than a fringe messaging app.

MediumGrowing2
GitHub

Technical collection treats code repositories as a first-class source, watching for exposed credentials and API keys the moment they're committed.

HighGrowing3
GitLab

Continuous crawls of GitLab run alongside GitHub to catch inadvertent source exposures and vulnerable public forks that never make it into GitHub's larger, more heavily monitored index.

HighGrowing0
Reddit

Reddit is flagged for suspicious activity and threat detection, and brand abuse is tracked there directly, making it a crowd-sourced early-warning layer for both fraud and outage chatter.

HighGrowing15
VKontakte

VK sits among the advanced social threat detection platforms, and it appears in public datasets built for war-crimes investigations, underscoring its role for Russian-language threat actor profiling.

LowGrowing5
HackerNews

Engineering-thread analysis on HackerNews surfaces architectural bugs and supply-chain criticism early, often before a vulnerability gets a CVE number.

MediumStable0
StackOverflow

Accidental code submissions on StackOverflow routinely expose live database credentials and cloud configuration values, which is why continuous scraping of the platform remains standard practice.

HighGrowing0
GrowingStableDecliningProviders = tracked provider count in Sourced.
InterestExploring and planning
SourceBuyer ExpectationDemand TrendProviders
Bluesky

Federation metadata extraction maps community boundaries and infrastructure, maintained as an active, searchable dataset for investigations. That's a distinct trend from the platform's consumer-side numbers: security researchers and technical analysts are migrating in, even as general listening demand elsewhere softens.

LowStable7
Signal

Signal shows up in that same social engineering workflow, though the protocol's encryption limits collection to discovery metadata rather than message content.

MediumGrowing0
Mastodon

Federation metadata mapping isn't unique to Bluesky. The same technique applies to Mastodon, and active Fediverse datasets run today, real ongoing technical utility, evidence against last quarter's declining-relevance read.

LowStable0
Bitbucket

Secret-scanning pipelines apply the same logic to Bitbucket that they apply to GitHub and GitLab, watching public developer workspaces for exposed credentials.

MediumStable0
Gitee

Gitee's regional dominance in China makes it a distinct surface for tracking script variations and localized malware forks that rarely surface on Western-hosted repositories.

MediumGrowing0
WeChat

Public security accounts on WeChat post vulnerability declarations and patch updates that don't reliably appear anywhere else, making it a primary channel for Chinese-language threat disclosure.

MediumGrowing1
Sina Weibo

Weibo functions as a regional early-warning layer, surfacing exploit reports and infrastructure chatter across Asian network hubs before they're picked up elsewhere.

MediumGrowing1
Rumble

Structured API access to Rumble runs alongside 8kun and BitChute, treating alternative video platforms as a standing dataset for tracking extremist recruitment content and coordinated information campaigns.

MediumStable2
GrowingStableDecliningProviders = tracked provider count in Sourced.

‡ Reflects Sourced's direct market assessment.

Already evaluating a provider behind one of these sources?

See how it works for you on KeyKit →

Want Mulberry to do the sourcing for you? Talk to Mulberry