Open-source project
simplifaisoul/osiris avatar
simplifaisoul/osiris

OSIRIS: An Open-Source OSINT Dashboard with GPU-Accelerated Map Rendering

Open Source Global Intelligence Platform - Real-Time OSINT Dashboard - A Palantir Alternative - 2nZNHm3Lr9umG3DVrzYwHgktwkuKuJRXqqRqs3ewpump

10,362 stars2,136 forksTypeScriptMIT

At a glance

What is it?
OSIRIS is a Next.js-based open-source intelligence dashboard that aggregates live flight tracking, CCTV feeds, earthquake data, conflict zone mapping, and 24/7 news streams into a WebGL-rendered map interface. It is a self-hostable alternative to commercial situational awareness platforms, with v5.0.0 released in September 2026 and an MIT license.
Who is it for?
OSIRIS is suited for security researchers, journalists, and analysts who want a self-hostable OSINT dashboard aggregating public data sources without depending on a paid platform. It is not suitable as a production intelligence system for organizations that require guaranteed data accuracy or legal assurances about data handling.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What OSIRIS Is and Who It Serves

OSIRIS (Open Source Intelligence and Reconnaissance Integrated System) is a production-grade OSINT platform described in the README as providing situational awareness across multiple intelligence domains. It aggregates public data sources, renders everything on a GPU-accelerated map through WebGL, and provides a RECON toolkit for network reconnaissance.

The platform targets security researchers, open-source intelligence practitioners, journalists covering conflict or environmental events, and developers building situational awareness tooling. Version 5.0.0 was released on 2026-09-28. The README notes that all map data is rendered via WebGL for 60 frames per second performance even with thousands of concurrent entities on-screen.

The project name refers to the Open Source Intelligence and Reconnaissance Integrated System, not the Egyptian mythological figure. The project homepage is osirisai.live.

Intelligence Domains and Data Sources

The README provides a table of the data domains OSIRIS covers. Aviation data comes from the OpenSky Network and includes commercial, private, military, and jet aircraft. Maritime data covers 39 global ports and 10 chokepoints using static naval intelligence. CCTV coverage spans 17,000 or more cameras from sources including TfL, WSDOT, Caltrans, ODOT, MDOT, the Hong Kong Transport Department, Taiwan THB, NZTA, Rijkswaterstaat, and public webcams.

Seismic data uses the USGS Earthquake API for real-time magnitude 2.5 and above events. Active fire hotspots come from NASA FIRMS. News data aggregates 24/7 live streams from 23 global broadcasters. Weather events use NASA EONET. Space data covers solar weather from NOAA SWPC and satellite tracking from N2YO. Cyber intelligence covers CVE threats from NVD and includes a vulnerability scanner. Conflict monitoring includes 13 active conflict or tension zones.

Crypto intelligence allows tracing BTC wallets via blockstream.info (Esplora API, keyless) and ETH wallets via Blockscout's public ETH instance at eth.blockscout.com, also keyless. Every wallet lookup is automatically cross-checked against the OFAC SDN sanctioned-address list mirrored from 0xB10C/ofac-sanctioned-digital-currency-addresses.

A Texas-specific CCTV integration uses TxDOT ITS snapshot cameras. The README notes that these are refreshing JPEG snapshots, not video streams, and that availability varies by district and camera. Stale data is retained during outages.

Installing OSIRIS and Starting the Dashboard

For local development, the README provides the standard Next.js workflow:

bash
git clone https://github.com/simplifaisoul/osiris.git
cd osiris
npm install
npm run dev

For Docker deployment, the docker-compose.yml in the repository defines three services: the main osiris application, an osiris-cache Nginx container on port 8080, and an osiris-intel backend on port 4000. The host port is configurable via OSIRIS_PORT in a .env file, defaulting to 3000.

The .env.example file documents which environment variables OSIRIS reads. The README states that OSIRIS works fully without any third-party API keys: aviation, maritime, satellites, fires, earthquakes, weather, news, and CVEs all use public keyless feeds. The only keys the current code actually consumes are SCANNER_URL and SCANNER_KEY, which power the RECON toolkit. Without them, the RECON features return 503 errors while all map layers continue working.

A SCANNER_KEY should be generated with:

bash
openssl rand -hex 32

The .env.example also documents optional Cloudflare Radar API keys for the Internet Outages and Attack Origins layers, but marks these as optional and enabled only when set.

The RECON Toolkit: Network and Asset Intelligence

The RECON toolkit is a separate panel within the OSIRIS interface that provides network reconnaissance capabilities. The README lists eight functions: a TCP port scanner with service fingerprinting, full DNS record resolution for A, AAAA, MX, NS, TXT, and CNAME records, WHOIS domain and IP registration data with automatic cross-checking against the OFAC SDN list, an SSL and TLS certificate chain inspector, IP intelligence covering geolocation, ASN, and threat reputation, a CVE lookup against the NVD database, a crypto wallet trace for BTC and ETH, and a full-text OFAC sanctions search across persons, organizations, vessels, and aircraft.

The RECON features depend on the osiris-intel backend service defined in docker-compose.yml. Without the backend running and the SCANNER_URL and SCANNER_KEY variables set, these features are disabled. The README says to generate a SCANNER_KEY with openssl and ensure the same key is set in both the frontend environment and the backend configuration.

For the offline test suite, the README documents: `npm test` for offline checks, and `RUN_LIVE_TESTS=1 npx vitest run src/app/api/cctv/texas.test.ts` to check the public Texas camera inventory against live TxDOT infrastructure.

Telegram OSINT and Geolocation Parsing

OSIRIS includes a Telegram OSINT layer that scrapes the unauthenticated web preview at `t.me/s/<channel>` without requiring a Bot API token or MTProto. The README specifies a default curated set of five channels covering English and Russian or Ukrainian war reporting, overridable via the `OSIRIS_TELEGRAM_CHANNELS` environment variable.

Posts from these channels are geoparsed against a multilingual place dictionary covering English, Cyrillic, and Arabic and plotted as cyan dots on the map. Clicking a dot shows the post text and links to the original on Telegram.

The README is explicit about the method: this is the public web preview, not an authenticated API. This means only public channels with a web-accessible preview endpoint are supported, and the data lag depends on how frequently the preview is cached by Telegram.

Limitations and Legal Considerations

OSIRIS aggregates public data sources, but the legality of accessing and displaying CCTV feeds, Telegram channel content, and IP intelligence data varies by jurisdiction. The README does not make legal representations about these data sources. Users deploying OSIRIS in jurisdictions with strict privacy laws, particularly the EU under GDPR, should review whether displaying public CCTV feeds from foreign infrastructure creates compliance obligations.

The RECON toolkit's port scanner and vulnerability scanner functionality is particularly sensitive. Running TCP connect scans against targets without authorization is illegal in many jurisdictions regardless of the tool used. The README does not include a legal disclaimer about this; users are responsible for ensuring they only scan infrastructure they have permission to test.

The conflict zone data and maritime chokepoint data are described as static OSINT intel in the README, meaning they reflect conditions at the time of the last update rather than live verification. The severity-coded conflict zone markers are a snapshot.

The project is MIT licensed, which permits commercial use, modification, and distribution without restriction. There is no copyleft obligation. The osiris-intel backend in the docker-compose.yml is a separate build context, and its license terms may differ from the main repository.

OSIRIS vs Commercial Alternatives: Palantir and Shodan

The README describes OSIRIS as a Palantir alternative. Palantir provides commercial data integration and analysis platforms for government and enterprise customers. It is not self-hostable, not open-source, and priced for institutional buyers. OSIRIS covers a different audience: individuals and small teams who want a public-data situational awareness dashboard they can run themselves.

Shodan is a closer technical comparison for the network intelligence features. Shodan is a commercial search engine that continuously scans the internet for devices and services, providing query access via an API. OSIRIS's RECON toolkit performs on-demand scans against specific targets rather than querying a pre-indexed database. The two tools serve different use cases: Shodan answers broad discovery questions, while OSIRIS's RECON features answer specific questions about a known target.

Editorial conclusion

OSIRIS is suited for security researchers, journalists, and analysts who want a self-hostable OSINT dashboard aggregating public data sources without depending on a paid platform. It is not suitable as a production intelligence system for organizations that require guaranteed data accuracy or legal assurances about data handling. Before deploying it, verify that the CCTV and Telegram data sources comply with applicable privacy regulations in your jurisdiction, enable the RECON features only with a properly secured SCANNER_KEY, and confirm that the AGPL-adjacent concerns do not apply since OSIRIS uses MIT. The most significant practical constraint is that the RECON vulnerability scanning features depend on a separately deployed osiris-intel backend.

Frequently asked questions

Does OSIRIS require API keys to run?

Most data layers work without any API keys. The README states that aviation, maritime, satellites, fires, earthquakes, weather, news, and CVEs all use public keyless feeds. Only the RECON toolkit features require SCANNER_URL and SCANNER_KEY; without those, RECON returns 503 but the map layers function normally.

How do you install OSIRIS with Docker?

The docker-compose.yml defines three services: the main OSIRIS app, an Nginx cache container, and the osiris-intel backend. The host port defaults to 3000 and is configurable via OSIRIS_PORT in a .env file.

What CCTV sources does OSIRIS include?

The README lists over 17,000 cameras from sources including TfL, WSDOT, Caltrans, ODOT, MDOT, the Hong Kong Transport Department, Taiwan THB, NZTA, Rijkswaterstaat, TxDOT ITS, and public webcams.

Official sources

  1. Issues
  2. License: MIT
  3. Project website
  4. README
  5. simplifaisoul/osiris on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/simplifaisoul-osiris.svg)](https://hysenlabs.com/projects/simplifaisoul-osiris)