In late May, a website that looked exactly like news site Haaretz published a story claiming Ukraine had asked Israel to help locate a private aircraft filled with gold that belonged to an associate of President Volodymyr Zelenskyy.
The site used a spoof domain name — haaretz24[.]com instead of the legit haaretz.com — and copied Haaretz's design and layout, according to an article about the hoax by the real Haaretz. The article and site were likely part of a long-running Russian disinformation effort known as Doppelganger.
One of the most interesting details about the spoof site was its domain registration record. It listed Leonid Nevzlin as the administrator. Nevzlin is a shareholder in Haaretz. Listing his name in the fake site’s whois record added a layer of credibility. It could have tripped up a person who knew enough to run a whois search but wasn’t aware that you can register a domain and put whatever name you want in the admin/registrant fields.
The people behind the spoof site apparently understood this and exploited it.
This is a nuance you must learn and factor into analysis of a whois record. Investigators may collect dozens of such digital indicators in the course of research. Each has its own strengths and weaknesses — and potential pitfalls.
But there isn’t a single resource that investigators can consult to understand indicators, or a framework to evaluate them. I’m hoping to change that with the Indicator Framework. This first version, which I hope you’ll help me refine, has three elements:
A two-part method for classifying an indicator (Fidelity + Specificity)
A matrix for plotting indicators to help visualize the strength of your evidence
Guidance for evaluating how indicators interact with each other (Independence vs. Dependence) in the analysis and attribution phase
I also created tables that list more than 70 indicators commonly gathered in OSINT, show how each one is classified under the framework, and flag caveats related to attribution or analysis. It’s a resource you can consult to learn about an indicator that you might be unfamiliar with.
The method is free to read, as I’m hoping to get feedback from the community to help refine it. The matrix and tables of indicators are only available for Indicator members.
If you’d like to support this work and get access to the additional framework materials — plus our OSINT guides, a monthly workshop, and our investigations — please become a member.

Generated with Claude Design
Understanding indicators
An indicator is a single, observable digital attribute pointing to a particular actor, activity or entity. Indicators include things like an IP address, profile photo, email, or phone number. They’re the raw materials that investigators collect, enrich, pivot on, and analyze in order to make connections and confirm or refute a hypothesis.
Indicators are something of an obsession for me. After all, we named our publication and company for them. They’re the rare earths of OSINT. Like rare earths, the value isn't just in finding them — it's in what you use them for.
Indicators are everywhere: across internet infrastructure, social media, the dark web, and beyond. Their abundance is the opportunity and the trap. It’s relatively easy to gather a trove of emails, IP addresses, Telegram posts, domains, and other indicators. But what do they actually tell you? How do you interpret the connections, or lack thereof, among your indicators and account for their relative strengths and weaknesses? If you overestimate or misunderstand what an indicator reveals, and how it connects with others, you risk coming to an inaccurate conclusion.
One of the dangers of OSINT is overcollection combined with weak analysis. As Nico Dekens wrote, "We are collecting more than ever and thinking less than ever.”
One of the things I emphasize in workshops and try to practice in my work is that you need to collect and stack indicators in order to build towards attribution and conclusions. A single, strong indicator is useful but rarely enough on its own. The challenge is to know how to assess each indicator’s validity, to understand how strong a signal it is in the context of how you collected it, and to analyze the stack of indicators to properly conclude what you have (or don’t). The goal is often to be able to say that the indicators point to a single conclusion or attribution. This person did this. This group ran the operation.
Total certainty can be elusive. Overreach or incorrect attribution is a serious risk. Digital indicators are a key means by which we can support or refute a hypothesis. Or understand how little we have. (Digital indicators are, of course, just one type of evidence and information you can and should collect in an investigation.)
This framework helps investigators — journalists, researchers, analysts, PIs — think about and assess indicators to enhance analysis and, hopefully, avoid mistakes. It can also help you understand how to work with indicators that you may be unfamiliar with.
Where It Fits: ACH, the Admiralty Code, and the Pyramid of Pain
I believe this framework is a useful addition to existing methodologies such as Analysis of Competing Hypotheses and the Admiralty Code.
ACH is a valuable method for comparing how indicators and other source material support or refute a given hypothesis. The Admiralty Code is a system for analyzing information. But both operate one level above the analysis of individual digital indicators. You can’t list an indicator in an ACH matrix unless you understand its strengths and weaknesses and whether it exists as a unique asset or as part of a chain of dependent indicators. The Admiralty Code relies on rating the source and the information separately. But digital indicators don't always fit this framework, which is better suited to information from human sources.
Threat intelligence has its own well-known model for ranking indicators: David J. Bianco's Pyramid of Pain (2013). It orders indicator types — hash values, IP addresses, domain names, artifacts, tools, TTPs — by how much it costs an adversary when defenders detect and deny them. Swapping an IP is trivial; changing behavior is painful.
Our frameworks align because the indicators that are cheapest to change or most widely shared tend to be the weakest signals. The difference is that the Pyramid answers a defender's question: what should I detect to hurt the adversary most? The Indicator Framework answers an investigator's question: how much can I trust this indicator, and does it genuinely connect to my target? A file hash sits at the bottom of Bianco's pyramid because it's easy to change. Yet it's also unique to one file and a powerful pivot, so this framework treats it as a lead worth working, not a throwaway.
I believe that the Indicator Framework provides a missing first step that can strengthen subsequent analysis and methodologies. It also builds on foundational methodologies for digital verification. The original Verification Handbook (2014) I edited for the European Journalism Centre outlined approaches for verifying what was then referred to as user-generated content, including:
Provenance: Is this the original piece of content?
Source: Who uploaded the content?
Date: When was the content created?
Location: Where was the content created?
The subsequent Verification Handbook for Disinformation and Media Manipulation (2020) and work by First Draft and other people and organizations built out the practice of gathering and verifying indicators such as images, video, social media interactions and content, domain names, analytics and advertising IDs, and more.
I see the Framework as a way to help guide investigators through the process of verification and evaluation of indicators, incorporating best practices along the way and ultimately making the final analysis stronger.
As previously noted, this is the first version. I welcome feedback about the overall concept and how I’ve classified specific indicators. What did I miss? Where does the framework fall apart? I’m grateful for every piece of constructive criticism. Email me with your thoughts. I will credit people who help me improve the framework (though I’m happy to keep you anonymous if you prefer).
The Framework: Fidelity + Specificity x Independence
The framework uses three elements to assess the value of an indicator on its own and in concert with others that you collect.
First, you assess an indicator on its own according to its Fidelity and Specificity:
Fidelity: confidence the indicator is authentic as collected. You rate it by tracing its provenance: the chain of steps between the original source and you. Could any step have faked or altered it? Can I check every step back to the original source? This is where verification comes in: if it wasn’t collected from the original source, you need to work to find it, applying the approaches outlined by the Verification Handbooks and First Draft.
Specificity: how strongly the indicator can tie to a single actor and whether it can be used as a pivot point to identify other assets. There are two elements to specificity:
Could it have been planted?
Is it unique or widely shared?
Fidelity and Specificity help you assess an indicator in the context of where you discovered it and how much confidence you can have in its authenticity and usefulness as a pivot point. After you go through this for each indicator, you’re on stronger footing to assess connections and to begin to evaluate hypotheses. That’s where Independence comes in:
Independence: Is this indicator a genuinely separate line of evidence or does it flow from the same root as other indicators I've collected? Three DNS indicators that all stem from one hosting choice are dependent indicators. They’re one piece of evidence, not three.
Independence shifts your focus onto how indicators align (or don’t) with each other. Ultimately, this all comes down to confidence: how confident can you be in each indicator and how confident can you be that the indicators you’ve collected support a particular hypothesis or attribution.
The framework uses a High, Medium, Low scale for assessing Fidelity and Specificity. As noted, these are measures of confidence. Assessments are rarely absolute; caveats and context often complicate the evaluation.
The point of the framework isn’t to provide perfect answers and ratings; it’s to create a repeatable method investigators can use to think through what you’ve collected and what you really have.
As an example, the name listed in the domain registration record for haaretz24[.]com would be rated High Fidelity/Medium Specificity:
High Fidelity: By running a domain search that pulls from whois records, you can have high confidence that whoever bought/controlled the domain entered the name “Leonid Nevzlin” in the registration record. This is because a person needs access to the account in order to add a name, email, address or other information. And a whois search draws the information directly from the registry. The chain is checkable. The main risk of manipulation is a hacked account, which is uncommon.
Medium Specificity: Nothing prevents someone from entering whatever name they want in a domain registration. Registrars don't check it against government ID or any other verification. I could buy a domain and enter "Donald Trump" in the admin field. So the name is not evidence of anything yet. But it's a testable lead: it names a specific person, and you can research whether Nevzlin has any real connection to the site and contact him for more information. That test is what earns it a Medium instead of a Low. Compare that to the site's IP address, which genuinely comes from the source (DNS records) but was shared by dozens of unrelated sites. There isn’t a valid pivot path. Low Specificity.
High Fidelity tells you the entry is real: the person behind the domain almost certainly typed that name. Medium Specificity tells you the name is a lead to work, but not verified as having been entered by them. The assignment is to check whether the name is genuinely connected before you assert it as a fact. That's what prevents the misinterpretation the spoofers were counting on.
The key is that High Fidelity/Medium Specificity is the starting rating for every registrant name in a domain registration record. The starting rating is tied to the indicator type, which is what makes the framework repeatable: pulling a record from the registry makes the chain checkable (High Fidelity), while a personal name remains a testable lead that may have been planted (Medium Specificity). The current rating is situational by design — it reflects what your collection and verification have done to move it.
The rating only moves when your investigation moves it. Collect the same record as a screenshot from a source and Fidelity drops. Confirm the named person actually controls the site and Specificity rises to High.
One caution on the "personal name" part: a privacy service's name in the registrant field is a registrant name, too; but there's nothing to research about "Domains By Proxy, LLC" — it rates Low. This is what the Table of Indicators gives you for dozens of common indicators: the starting rating, which your collection and verification can then move (or not).
If you’re investigating haaretz24[.]com, you’d collect other indicators to assist with your analysis and perform the same assessment. For example:
The content of the article on the site (High Fidelity/Medium Specificity): the content was definitely published at that domain. However, the site owner can fabricate any content and publish it there. The text itself is testable: search for it elsewhere online and it becomes a pivot.
The byline on the article (High Fidelity/Medium Specificity): you can easily visit the site and confirm the name on the article (High Fidelity). A site’s owner(s) can put any name on an article, but a name is searchable. Unverified but testable = Medium Specificity.
The website’s IP address (High Fidelity/Low Specificity): the IP is genuinely connected to the site, but it was shared by dozens of other sites with different owners, and no amount of research makes a shared IP point to one actor. Not a useful pivot point = Low Specificity.
The website exhibits multiple indicators that suggest spoofing or manipulation is a possibility. You can test multiple indicators to improve your analysis: the name in the whois entry, the byline, the article text. The ratings give you a path forward for the investigation and help prevent unfounded assumptions. If your research uncovers new information, you can reapply the rating, which will help when you’re trying to assess the strength of your evidence and plot it on the matrix (which I detail below).
Important note: Always rate Fidelity first. This reinforces foundational digital verification practices. Always work to gather an indicator from its original source, or as close to it as possible. You can still rate specificity to see if it’s a worthwhile pivot, but pivoting on a potentially spoofed or manipulated indicator is risky.
Indicator Fidelity

Generated with Claude Design
What it measures: confidence the artifact is authentic, not spoofed, doctored, or forged. You rate it by tracing its provenance: the chain of steps between the original source and you.
Fidelity Scale
High: The indicator is directly from the source, or you can verify every step between you and the source. A whois record from a lookup tool counts — you can verify it against the registry. Or an image directly from a satellite provider or a tool like Google Earth that has direct access to the source material. Steps you can verify don't count against the chain — an authoritative lookup is effectively direct.
Medium: There's an unverified step in the chain, but the doubt is closable. You could re-collect from the source, or the step is unlikely to have been tampered with. For example: image metadata is editable, but it’s not a widespread tactic. Still, you have to be aware of the possibility and not overvalue what you have.
Low: The chain has a step (or more) you can't verify and can't close: no provenance, or an easily doctored artifact with no path back to the origin. Unknown provenance is Low until you establish it; unknown isn't neutral, it's an unverified link. Example: a satellite image shared on a social media platform has unknown provenance until you can pull the same image directly from a source like Planet Labs or Google Earth.
Fidelity is essential to consider in a digital environment where it's often easy to fake, copy, or manipulate a digital asset. A screenshot can be doctored in seconds. An email's "From" field can be spoofed. AI can generate a convincing satellite image, product photo, or CCTV clip. When an indicator reaches you, the first question is whether the thing itself is genuine — or whether it was altered or fabricated somewhere between its origin and your screen.
At the other end of the spectrum, a blockchain transaction record is high fidelity because it's mathematically verifiable and immutable.
Fidelity is not about who you're investigating — that's the job of the second axis, Specificity. It's tied to the specific indicator in your hands, including how and when you collected it. This is critical today where we are seeing people use AI to create fake satellite images or generate fake CCTV footage. If you collect an image from a satellite provider or from a person who delivers the camera original file with metadata, then it’s high fidelity. If you come across a satellite image or photo on social media, it’s low fidelity.
Fidelity rests on the chain between the source and you. An IP address you resolve yourself: no steps to doubt. A whois record from a lookup tool: one step, and you can check it against the registry in a wide variety of places. A screenshot of that same whois record, sent to you by a stranger: now there's a step you can't verify. Anyone can doctor a screenshot, even when the value inside it is a "plain" one. A photo inside a social media post adds a different kind of step: you can verify that the account posted it by finding the live posts; but the photo itself could be doctored or AI-generated. A real account can post a fake photo.
This is also how you raise fidelity: remove links by getting closer to the source. Find where the photo originated instead of trusting the screenshot. Get the original file from the provider instead of the copy on social media. Each step closer to the origin closes off a way it could have been faked.
If you can't establish provenance at all, treat fidelity as Low until you can.
One important takeaway is that it’s possible to improve the fidelity of an indicator by working with human sources and applying verification and reporting. If I discover a photo on social media, I have to treat it as Low Fidelity. But I could contact the person running the account and ask them if they took the photo and if they could send the file from their phone or camera. If they can corroborate that they were there at the time and the image contains metadata that aligns with the details, the image could now be considered High, or at least Medium-to-High Fidelity.
Indicator Specificity

Generated with Claude Design
What it measures: confidence that the indicator genuinely ties to the asset or actor and can be used as a pivot path. Is it generic (too many could share it) or could it have been planted (put there without being theirs)?
Specificity Scale
High: Verified and pivotable. The indicator is unique to one actor or asset, and you've confirmed it's genuinely theirs. Control or benefit is established, or a platform has verified it. Highly useful for pivoting across surfaces/tools to find other assets with the same indicator.
Medium: Unverified but pivotable. There's a concrete check that could settle the connection. The indicator is unique enough to research but could have been planted, or it's shared by a population small enough to work through.
Low: No pivot. There's no meaningful connection to an actor to test, even if the indicator is completely genuine. It's shared by a population too large to narrow — an IP behind a CDN, a TLD, a "Powered by WordPress" footer — or there's nothing about it you can research further.
Fidelity asks whether the indicator is real. Specificity evaluates how useful the indicator could be in helping establish its connection to an actor or target. An indicator can be completely genuine and still tell you almost nothing because it’s widely shared or because it could have been planted.
You assess specificity by asking two questions of an indicator:
Could it have been planted? A name in a whois record, a wallet pasted on a page, a linked social account: even when they're unique, anyone can display them to point at someone they don't belong to. I could copy someone’s Bitcoin address and put it on a site I own to send a false signal.
Is it unique? A shared IP, a common registrar, a "Powered by WordPress" footer: genuine, but so common they can't single out anyone. The more unique the attribute, the more useful it is for pivoting.
An example could be the IP address of a website. Pulling the IP address from DNS records gives you a High Fidelity record. But if the IP address is shared by tens of thousands of other sites, it’s Low Specificity because it is not specific to the person or entity behind the site.
An indicator scores high in specificity only if it is unique and genuinely tied to the actor. This is where investigators get burned, because a value can ace one test and fail the other. The "Leonid Nevzlin" name on haaretz24[.]com is the perfect example: it could have been planted but is unique and useful as a pivot. That’s why it’s Medium Specificity.
A shared IP fails the uniqueness test, and that failure is final: there is no pivot path, which makes it Low. You collect it but have to set it aside for now. The question that separates a Medium from a Low isn't how many tests it passes; it's whether you can use it to pivot and close the uncertainty gap. Low is typically a dead end. Medium and High give you a path forward.
Some indicators contain multitudes
Here's where things can get complicated: some Indicators actually contain multiple elements, each with their own level of fidelity and specificity. I’ll stick with the domain registration example, as it’s one of the most common. A whois record contains:
Registration date: High Fidelity/Low Specificity. The date is a technical record that's hard to falsify. You can be confident the domain really was registered that day. But a registration date alone is difficult to pivot on: thousands (or more) of unrelated domains were registered the same day. Where dates earn their keep is the pattern layer: a batch of suspect sites all registered within days of each other is a signal you build later, not a property of the single indicator.
Registrant/admin name, company, address: High Fidelity/Medium Specificity. This rating assumes that the field holds a real value you can research. A person's name, a company name, a street address. They are genuinely in the record, possibly planted, but each is a testable lead. When the field holds a privacy service's information or a generic placeholder, it drops to Low. There's nothing to research about "Domains By Proxy, LLC" and the like.
Country/state of registration: High Fidelity/Low Specificity. The country field is linked to the domain. But it could be an incorrect location entered by the domain’s owner, or it could belong to the privacy service they used to obscure their information. The reason the country is worth looking at separately is that sometimes the other registrant/admin information is blank but the country is filled in. This could be a clue to the location of the owner. As with registration date, a batch of sites all listing the same country/state could be a signal you build later, not a property of the single indicator.
Registrant/admin email: High Fidelity/Medium Specificity. There are times when someone enters incorrect information in the registrant/admin fields (or nothing at all) but uses a real email address. It could be a burner, but it still goes to the owner. Email addresses are always worth looking into because the domain owner uses it to get notifications from the registrar about renewals and other account matters. If they don’t pay for privacy, an email is an interesting clue and often more accurate than name, company, etc. Of course, the email address can also be fake/planted.
The same is true of a social media profile. All of the metadata that you see on the profile is high fidelity, in that you can be confident that it actually appeared on the platform. But things get complicated from there. It’s easy to create a profile in someone else’s name, to upload whatever profile photo you want, to follow a public profile.
Profile photo: High Fidelity/Medium Specificity. A distinctive photo is a reverse-image pivot. Using this verification best practice can help you with testing specificity. For example, the use of a stock image shows the photo doesn't belong to the account owner.
Bio: High Fidelity/Medium Specificity. Distinctive bio text is searchable, same as website text. But it’s also easily copied from elsewhere, so unclear if it really ties to your actor.
Join date (if available): High Fidelity/Low Specificity. The join date on an X or Facebook account is set by the platform and almost certainly accurate. But it’s not a useful pivot point. Millions of accounts may have joined the same month, and a date can't be researched into a tie. Like whois registration dates, join dates matter at the pattern level: a cluster of accounts created the same week is a signal about the set, not about any one account.
Friends/Followers: High Fidelity/Medium-to-High Specificity. The full list of an account’s friends and/or followers can be a useful signal to build out a network and to potentially find other accounts with highly similar friend/followers networks. But there are nuances by platform: in order for someone to be listed as a friend on Facebook, both parties need to agree to connect. But anyone can follow a public profile across platforms. This, again, is a set or pattern-level signal.
Posts: High Fidelity/Medium Specificity. Individual posts could be copypasta or otherwise copied. As long as it’s not a retweet, reshare, or repin, it was posted by the account owner, and its text can be searched elsewhere.
Interactions (likes, shares, etc.): High Fidelity/Medium-to-High Specificity. Interaction patterns can connect accounts, but any public account can like or share anything.
Verification tick: High Fidelity/High Specificity (unless on X). A verified check mark on an Instagram account means you can be confident that the profile name does belong to the owner of the account, and that the account is likely operated by that individual (or their team). But without the tick, an account name is low specificity due to the ease of spoofing. (We also have to factor in the possibility that a verified account can be hacked…)
The Independence test: how many ways do you actually know this?

Generated with Claude Design
Once you’ve gathered your indicators, you can perform an overall assessment that helps inform how strong your evidence is. The next step is to apply a simple test: independence versus dependence. The goal is to determine which indicators are truly independent and which all trace back to the same decision taken by the actor or target.
The question for your whole collection is: how many separate ways of knowing do you actually have?
For example: everything you discover on a social media profile is rooted in the decision made by the person or people who have had access to it. The profile photo and bio are each indicators, but they stem from the same source. If you find that 15 websites have the same IP address, mail server, and name server, do you count those as three separate indicators of connection? Or are they actually just one, due to the fact that all three are a result of the hosting infrastructure chosen by the site owner?
Every indicator is the result of a decision someone made: choosing a host, registering a domain, creating a social media profile, getting paid via crypto, running ads on Facebook, etc. Group your indicators by the decision that created them. Everything from one decision collapses to one leg — no matter how many artifacts it left. (A good related question to ask: could these indicators have diverged if my hypothesis were wrong? Dependent indicators always align with each other, regardless of the hypothesis.)
One thing to be careful about is website content. If a site links to social media accounts, a Patreon, an email address, and other outside services that belong to a person or entity, you have to entertain the possibility that they were added to make the site look connected to that person or entity. Same for a social media profile. Every one of those links exists because of a single decision — whoever has access to the webpage or account put them there. That means they're one leg, not five. And if the site or profile is trying to frame someone, they're all planted at once: it's the fruit of the poisoned tree.
Solid conclusions arise from independent indicators that rate high in fidelity and specificity. Quality beats quantity. Three independent indicators beat twelve dependent ones.
Upgrade to read the rest
Become a paying member of Indicator to access all of our content and our monthly members-only workshop. Support independent media while building your skills.
UpgradeA membership gets you:
- Everything we publish, plus archival content, including the Academic Library
- Detailed resources like, "The Indicator Guide to connecting websites together using OSINT tools and methods"
- Live monthly workshops and access to all recordings and transcripts


