OSINT Enabled Ghost Mode: Counter Surveillance for Everyday People

Desiree Wilson (Architect · Quantum Mergers)

DEF CON 33 · Day 1 · Main Stage

Overview

In an era defined by ubiquitous data collection and constant digital exposure, Desiree Wilson's DEF CON talk, "OSINT Enabled Ghost Mode: Counter Surveillance for Everyday People," presents a compelling and practical framework for individuals to reclaim their digital privacy. Wilson, an experienced information security architect, outlines a methodology leveraging open-source intelligence (OSINT) tools to build a personal, proactive counter-surveillance system. This "Ghost Mode" empowers even non-technical users to monitor who is tracking their data, where it's being accessed, and how it's being used, effectively flipping the script on the pervasive surveillance landscape.

Watch on YouTube

Visual summary for OSINT Enabled Ghost Mode: Counter Surveillance for Everyday People by Desiree Wilson
Visual summary for OSINT Enabled Ghost Mode: Counter Surveillance for Everyday People by Desiree Wilson

Key moments

  1. 0:00 Introduction to OSINT ghost mode and surveillance problem
  2. 2:00 The pervasive reality of data collection and tracking
  3. 2:27 Flipping the script: OSINT for counter-surveillance
  4. 6:08 OSINT: Free, accessible, proactive self-protection
  5. 7:05 Asking the hard questions about personal data
  6. 8:00 Introducing the personal counter-surveillance 'ghost mode' recipe

OSINT Enabled Ghost Mode: Counter Surveillance for Everyday People

Speakers: Desiree Wilson, Architect, Quantum Mergers

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=9-a4OhOChss

Overview

In an era defined by ubiquitous data collection and constant digital exposure, Desiree Wilson's DEF CON talk, "OSINT Enabled Ghost Mode: Counter Surveillance for Everyday People," presents a compelling and practical framework for individuals to reclaim their digital privacy. Wilson, an experienced information security architect, outlines a methodology leveraging open-source intelligence (OSINT) tools to build a personal, proactive counter-surveillance system. This "Ghost Mode" empowers even non-technical users to monitor who is tracking their data, where it's being accessed, and how it's being used, effectively flipping the script on the pervasive surveillance landscape.

The talk addresses the critical need for personal agency in an environment where smart devices, social media, and data breaches have made individuals unwitting "reality stars" of their own lives, without compensation or control over their digital footprint. Wilson's approach emphasizes accessibility, leveraging free and open-source tools to create a mobile and private monitoring solution. Her personal "pet project" transcends typical enterprise security concerns, focusing instead on empowering the average person to understand and defend against the constant collection and aggregation of their personal information.

This initiative is particularly relevant given the escalating rates of data aggregation and the increasing sophistication of tracking methods. By providing a clear, actionable "recipe," Wilson not only demystifies complex security concepts but also offers a tangible pathway for individuals to gain situational awareness over their personal data. The "Ghost Mode" framework is a call to action for digital self-defense, urging individuals to move beyond passive acceptance of surveillance to active monitoring and incident response for their own digital lives.

Background

▶ Watch: Introduction to OSINT ghost mode and surveillance problem (0:00)

The premise of "OSINT Enabled Ghost Mode" stems from the undeniable reality that modern life is characterized by unprecedented levels of data collection and surveillance. As Wilson starkly points out, "we are being watched," and this observation is not merely a theoretical concern but a lived experience for virtually everyone. Our digital and physical lives are inextricably linked to systems that constantly gather, process, and store personal information, often without our explicit consent or full understanding of its ultimate use.

This pervasive data collection manifests in numerous ways. Smart homes, equipped with connected appliances like cameras, doorbells, washing machines, and refrigerators, continuously monitor activities both inside and outside the home. Even without intentionally purchasing a "smart home," many households are replete with devices that act as data collectors. Similarly, smart cars track location, driving habits, and even energy consumption, accumulating a wealth of personal travel data over years of ownership. Beyond physical devices, our online activities—social media interactions, online purchases, browsing history, and engagement with digital services—all contribute to an expansive personal data profile. Every sign-up, every click, every interaction generates data that is collected and consumed at "all-time highs, unimaginable rates."

Adding to this landscape are data breaches, which frequently expose sensitive personal information such as passwords, healthcare records, and educational details, regardless of individual consent. This exposed data is then aggregated, expanded upon, and distributed across various platforms, creating a comprehensive and often immutable digital footprint. The sheer volume and interconnectedness of this data mean that "every single move you make in life is tracked," from daily commutes to global travels, blurring the lines between private and public information.

Wilson's professional background as an architect investigating security incidents for clients—understanding "what happened? How did it happen? Where did it come from?"—served as a catalyst for this personal project. She realized that while organizations invest heavily in understanding threats, individuals rarely apply the same scrutiny to their own data. This led to fundamental questions: "How long have they had my data? When did they get my data? What are they doing with my data? Can I do anything about them having my data?" The "Ghost Mode" project was born from this desire to democratize the investigative process, empowering everyday people with the tools and techniques to proactively monitor and protect their own digital existence, making it accessible from anywhere in the world.

Key Findings

▶ Watch: Flipping the script: OSINT for counter-surveillance (2:27)

The central finding of Wilson's talk is that effective counter-surveillance is not an exclusive domain for nation-states or large corporations but is achievable for "everyday people" using readily available open-source intelligence (OSINT) tools. She demonstrates that by adopting a methodical approach and leveraging specific technologies, individuals can build a robust, mobile, and private system to "watch the watchers."

The core contributions and discoveries presented are:

  1. Accessibility of OSINT for Personal Use: Wilson highlights that OSINT tools, being free and widely accessible, remove financial barriers to personal security. This empowers individuals who "aren't highly technical" to engage in proactive self-defense, requiring primarily effort rather than significant monetary investment or advanced coding skills.
  2. The "Ghost Mode" Recipe: A practical, modular framework is introduced for building a personal counter-surveillance system. This recipe includes:
  • Spiderfoot: An automated OSINT scanner that continuously collects information about specified targets (e.g., email addresses, IP addresses, phone numbers).
  • NTFY (Notify): A simple, self-hostable push notification service that delivers real-time alerts from the monitoring system directly to mobile devices or laptops.
  • Tailscale: A zero-config VPN that creates a secure, private network across devices, enabling ubiquitous, secure access to the counter-surveillance system from anywhere in the world.
  • Open Canary: A tool for deploying honeypots, which act as digital tripwires to detect and log unauthorized access attempts or information gathering activities.
  • Docker: Used for containerizing the entire setup, ensuring privacy, portability, and ease of deployment on personal infrastructure.
  1. Proactive Detection and Situational Awareness: The system is designed for continuous, automated operation, providing real-time alerts. This shifts individuals from a reactive stance (dealing with the aftermath of a breach) to a proactive one (detecting attempts at surveillance or data access as they happen). This constant monitoring fosters enhanced situational awareness regarding one's digital footprint.
  2. Importance of Privacy and Security in Monitoring: A critical finding is the necessity of conducting counter-surveillance safely. Wilson stresses using a VPN (like Tailscale) and hosting the system privately within a Docker container to prevent the "watchers" from realizing they are being watched. The goal is to remain in "ghost mode" oneself while observing others.
  3. Personalized Incident Response: Beyond mere detection, the framework emphasizes the development of a personal incident response plan. This includes the ability to set custom triggers, analyze logs for anomalies, identify malicious actors, and take decisive actions such as isolating devices, rotating credentials, or engaging law enforcement if a confirmed threat emerges.
  4. The Value of Baselining and Pattern Recognition: Effective counter-surveillance requires more than just collecting data; it necessitates understanding what constitutes "normal" activity. By establishing a baseline of expected data access patterns, individuals can more readily identify "outliers," "abnormal" practices, and "malicious" activities, including unusual time-based monitoring or suspicious geospatial intelligence (data access from unexpected locations).

In essence, Wilson's key finding is that digital self-defense is not only possible but also practical and accessible for all, provided they are willing to invest the effort in setting up and maintaining their own OSINT-driven "Ghost Mode" system.

Technical Deep Dive

▶ Watch: OSINT: Free, accessible, proactive self-protection (6:08)

The "Ghost Mode" architecture is designed for simplicity, automation, and privacy, making sophisticated counter-surveillance accessible without requiring deep development expertise. At its core, the system leverages several open-source tools orchestrated to continuously scan for personal data exposure, detect surveillance attempts, and deliver real-time alerts.

The primary components of Wilson's "recipe" are:

  1. Spiderfoot: This is the investigative engine of the "Ghost Mode" system. Spiderfoot is an open-source intelligence automation tool that integrates with over 200 data sources to gather information about specific targets. For personal counter-surveillance, it's configured to scan for an individual's identifying information—email addresses, IP addresses, phone numbers, and other unique identifiers—across public databases, dark web forums, social media, and various data leaks. Spiderfoot runs constantly, collecting new data points and identifying instances where personal information might be exposed or referenced. Its automated scanning capabilities ensure a continuous, passive surveillance of one's own digital footprint.
  1. NTFY (Notify): To make the continuous monitoring actionable, NTFY serves as the notification backbone. NTFY is a simple, highly customizable HTTP-based publish-subscribe notification service. Crucially, it can be self-hosted, ensuring that alerts are pushed privately and securely to the user's devices without relying on third-party cloud services that might compromise the goal of privacy. When Spiderfoot identifies a new exposure or Open Canary detects activity, NTFY pushes these alerts in real-time to a mobile phone or laptop. This immediate notification mechanism is vital for timely response, mirroring the real-time alerting capabilities found in enterprise security operations centers.
  1. Open Canary: This tool is used to deploy honeypots—decoy systems or data designed to attract and detect unauthorized access or information gathering. In a personal context, Open Canary can be configured to create fake files, network services, or even email addresses that appear legitimate but are specifically designed to trigger an alert if accessed. For instance, an Open Canary honeypot could be an email address that, if pinged or scraped, immediately sends an alert via NTFY, indicating that someone is actively looking for that specific piece of information. These honeypots act as digital tripwires, allowing the user to detect direct attempts at surveillance without revealing their active monitoring.
  1. Tailscale: Mobility and secure access are paramount for "Ghost Mode." Tailscale addresses this by creating a secure, private mesh network using the WireGuard protocol. It allows all components of the counter-surveillance system (e.g., the Docker container, monitoring dashboard, and the user's mobile devices) to communicate securely as if they were on the same local network, regardless of their physical location. Wilson specifically mentions using Tailscale for setting up DNS, implying custom DNS configurations that could further enhance privacy or direct traffic securely within her personal network. Tailscale's zero-configuration VPN capabilities make it ideal for non-technical users to establish a robust and geographically independent private network for their monitoring infrastructure.
  1. Docker: The entire "Ghost Mode" setup is designed to run within Docker containers. Docker provides a lightweight, portable, and isolated environment for applications. By containerizing Spiderfoot, NTFY, Open Canary, and the monitoring dashboard, Wilson ensures that the system is self-contained, private, and easily deployable on personal hardware. This isolation is critical for maintaining privacy, preventing data leakage, and ensuring that the counter-surveillance activities themselves do not inadvertently expose the user. Hosting the system in a private container means the individual retains full control over their monitoring data and infrastructure.

System Workflow and Data Management:

The system operates autonomously once configured. Spiderfoot continuously scans, and Open Canary honeypots lie in wait. Any detected activity or exposure triggers an alert, which is then pushed through NTFY to the user's devices. All activity logs from these tools are aggregated into a central UI dashboard, effectively creating a "single pane of glass" for personal security monitoring. This dashboard, also likely containerized, provides a consolidated view of all alerts and historical data.

Alert Customization and Analysis:

Users can set highly specific triggers for alerts, monitoring their own email addresses, IP addresses, mobile phone numbers, or even those of family members. The real challenge, and where "time and effort" are required, lies in the analysis of logs. Just like in enterprise security, raw log data can be overwhelming. Users must learn to:

  • Identify outliers and abnormalities: What constitutes unusual activity for their personal data?
  • Establish a baseline: What are the normal patterns of data access or mentions? This allows for the detection of deviations.
  • Time-based monitoring: Is activity occurring at unusual times (e.g., while asleep, or from a different time zone)?
  • Geospatial intelligence: Is data being accessed or sought from unexpected geographical locations (different countries, states, or cities)?

Wilson also briefly mentions the possibility of integrating the system with Security Onion, an open-source Linux distribution for threat hunting, security monitoring, and log management. This would enable users to create their own personal SIEM (Security Information and Event Management) solution, providing even more advanced correlation and analysis capabilities for their counter-surveillance data. This suggests a scalable architecture that can grow with the user's technical comfort and needs.

In essence, the "Ghost Mode" architecture is a carefully constructed blend of OSINT collection, real-time alerting, deceptive defenses, secure networking, and private hosting, all designed to empower individuals with a robust, personal intelligence gathering capability against pervasive digital surveillance.

Demo / Proof of Concept

▶ Watch: Asking the hard questions about personal data (7:05)

While a live, step-by-step technical demonstration of the "Ghost Mode" system was not performed during the talk, Desiree Wilson provided compelling anecdotal evidence and described her personal Proof of Concept (PoC) to illustrate the system's efficacy. She detailed how she built out the entire "recipe" and began using it in her daily life, specifically mentioning testing scenarios and initial findings.

Wilson recounted taking her "Ghost Mode" setup to a coffee shop, a common environment for potential surveillance and data snooping. During this test, she observed "some noise" indicating that "people trying to ping my IP at the time." While these attempts did not result in a successful compromise or data exfiltration—she noted they "weren't actually able to get anywhere"—the system successfully alerted her to the fact that active scanning and probing were occurring around her. This experience underscored the system's ability to provide real-time awareness of potential threats, highlighting that "there are people kind of watching and tracking everywhere you go."

Furthermore, Wilson shared another significant finding related to camera surveillance. Her system detected instances of "people who are trying to pull like camera information to to see what you see basically." This demonstrates the system's capability to monitor for attempts to access or exploit personal smart devices, such as home security cameras. Again, while no actual compromise was reported, the awareness of these attempts is crucial for proactive defense.

Wilson emphasized that the project was relatively new, having only been started "over the summer," but expressed excitement about its ongoing use, particularly as she plans to travel internationally. This continuous, real-world application serves as an ongoing, personal Proof of Concept, validating the system's practicality and its potential to uncover surveillance activities in various environments.

To enable others to replicate and build upon her work, Wilson has made the "entire recipe built out" available on a GitHub repository. This repository includes "all the tools that I use the code that I use to deploy it," along with descriptions of "additional OSENT tools" that users can leverage to customize their own counter-surveillance methods. This open-source sharing of the PoC build instructions is a critical component, allowing the audience to not only understand the concept but also to implement it themselves, fostering a broader adoption of personal "Ghost Mode" capabilities.

Defensive Implications

▶ Watch: Introducing the personal counter-surveillance 'ghost mode' recipe (8:00)

The "OSINT Enabled Ghost Mode" framework carries significant defensive implications, urging individuals to adopt a proactive, security-conscious mindset traditionally reserved for enterprise environments. For everyday people, understanding and implementing these defensive strategies can fundamentally alter their relationship with personal data and digital privacy.

  1. Proactive Personal Incident Response: The most crucial defensive implication is the call to develop a personal incident response plan. Just as organizations prepare for data breaches, individuals must have a pre-defined strategy for when their data is targeted or compromised. This plan should outline immediate steps such as isolating affected devices, rotating compromised credentials, checking activity logs, and, if necessary, contacting law enforcement or involving community resources. This shifts the individual from a passive victim to an active defender.
  1. Continuous Monitoring and Situational Awareness: Defenders must move beyond simply securing their devices to actively monitoring their digital footprint. By deploying tools like Spiderfoot and Open Canary, individuals can continuously scan for exposures and detect surveillance attempts. This constant vigilance fosters enhanced situational awareness, allowing them to identify patterns of reconnaissance or data access that would otherwise go unnoticed. This proactive monitoring is key to early detection, which is often the most effective form of defense.
  1. Baselining and Anomaly Detection: A fundamental defensive practice is baselining—understanding what constitutes "normal" activity for one's own data and digital interactions. By analyzing logs from their "Ghost Mode" system, individuals can establish a baseline of typical data mentions, access patterns, and geographical origins. Any deviation from this baseline—such as unexpected access times (time-based monitoring) or requests from unusual locations (geospatial intelligence)—should trigger investigation. This allows defenders to differentiate between legitimate data interactions and potentially malicious surveillance.
  1. Securing the Counter-Surveillance Infrastructure: Paradoxically, the tools used for counter-surveillance must themselves be secured. Wilson emphasizes using a VPN like Tailscale and Docker containers for private hosting. This prevents the "watchers" from detecting or compromising the very system designed to observe them, maintaining the "ghost mode" of the defender. Secure configuration of these tools is paramount to prevent self-doxing or exposure.
  1. Recognizing Common Surveillance Tactics: The "Ghost Mode" system educates individuals on how adversaries operate. By seeing log entries related to their data, users learn to recognize patterns of public source database queries, individual tracking attempts, and the geographical spread of interest in their information. This knowledge empowers them to identify potential threats more quickly and understand the nature of the surveillance they face.
  1. Community Engagement and Legal Recourse: Wilson highlights that some surveillance activities may infringe upon legal rights. If confirmed threats or malicious activities are detected, individuals should be prepared to engage with community resources, cybersecurity professionals, or even government bodies like Homeland Security. The ability to provide concrete log data and evidence from a personal monitoring system can be invaluable in such situations. The mantra "if you see something, say something" extends to personal digital security.
  1. Digital Hygiene and Credential Rotation: While not directly part of the "Ghost Mode" system's output, the awareness gained from monitoring reinforces the importance of good digital hygiene. Regular credential rotation, using strong and unique passwords, and isolating devices that show suspicious activity become more tangible and urgent when an individual can see active attempts to exploit their data.

In summary, "Ghost Mode" provides a blueprint for transforming individuals from passive data subjects into active participants in their own digital defense, equipped with tools and strategies to detect, analyze, and respond to the constant surveillance of the modern world.

Key Takeaways

  • Pervasive data collection necessitates personal counter-surveillance: From smart homes and cars to social media and data breaches, individuals are under constant, often uncompensated, surveillance, making personal digital defense a critical need.
  • OSINT tools empower accessible "Ghost Mode": Open-source intelligence tools like Spiderfoot, NTFY, Tailscale, and Open Canary are free and accessible, enabling even non-technical users to build a robust, private counter-surveillance system.
  • A robust personal system integrates key components: The "Ghost Mode" recipe combines Spiderfoot for continuous data scanning, Open Canary for honeypot traps, NTFY for real-time alerts, Tailscale for secure mobile access, and Docker for private, containerized hosting.
  • Continuous monitoring, baselining, and incident response are crucial: Effective counter-surveillance requires constant log analysis, establishing a "normal" baseline to detect anomalies (e.g., unusual time-based or geospatial access), and having a personal incident response plan to take decisive action against confirmed threats.
  • Privacy and security of the monitoring system are paramount: Utilizing VPNs and private containerization ensures that the counter-surveillance activities themselves do not expose the user, allowing them to "watch the watchers" without being detected.
  • The system fosters digital situational awareness: By actively monitoring their digital footprint, individuals gain a deeper understanding of who is accessing their data, where it's coming from, and how it's being used, moving from passive data subject to active digital defender.

About the Speaker(s)

Desiree Wilson is an accomplished information security professional with over 15 years of experience in the field. She is the founder of Quantum Mergers, a company that provides comprehensive consulting services, primarily to Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs). Her extensive background includes working with a diverse range of clients, from Fortune 500 companies to government entities such as the Department of Defense, and across critical sectors including financial, health, telecommunications, and energy, both domestically and globally.

As an architect and creator, Wilson is regularly involved in solving complex security problems and designing resilient systems. She is also a recognized contributor to the industry, serving on the Forbes Business Council and actively participating in prominent groups like OWASP, CSA (Cloud Security Alliance), and the Global Business Resilience Council. The "OSINT Enabled Ghost Mode" project, while a personal "pet project" and "playground," reflects her passion for security and her dedication to empowering individuals with practical tools to navigate the challenging landscape of digital privacy and surveillance.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent, accessible primer on personal OSINT-driven counter-surveillance that earns its place in a DEF CON community track. The tool stack is real and the use case is legitimate, but this is fundamentally a duct-tape integration tutorial, not original research — and the 'proof of concept' amounts to 'I saw some noise at a coffee shop.'

Heather Calloway (CISO) — SOLID

Wilson delivers a well-constructed, accessible personal OPSEC framework with a clear recipe and real tooling. It serves its DEF CON audience competently, but stays firmly in the individual self-help lane with no institutional, governance, or organizational risk dimension to speak of.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33