OSINT Manual Part B — Core Collection Techniques · Chapter 7 of 16
Chapter 7

Geolocation & Mapping

The 7-step geolocation workflow, environmental indicators, mapping tools, and historical geolocation.

Geolocation isn't a guessing game — it's the analysis of geographic data leading to a defensible conclusion. A location isn't "found" until observable clues have been independently matched against map or imagery evidence.

7.1 Geolocation as Hypothesis Testing

Keep competing hypotheses alive. Avoid early commitment, wishful visual thinking, and single-tool confirmation. Every claim should be traceable: clue → source → match → confidence.

The 7-step workflow

StepWhat you doTypical evidence
CaptureSave the source URL, image, timestamp, platform contextOriginal post, screenshot, archive link
ObserveDescribe visible facts before searching anythingObjects, road layout, terrain, lighting
ExtractTurn visual facts into searchable cluesLanguage, signs, lane markings, architecture
ClusterGroup clues into geography, infrastructure, timeCountry/region leads, mapped features
SearchUse maps, imagery, OSM, reverse image searchCandidate locations
VerifyMatch multiple independent featuresStreet view, satellite, shadow/terrain
ReportState coordinates, confidence, evidence limitsA confidence level plus caveats

Evidence hierarchy: what counts as "strong"?

LevelWhat it means
Direct matchSame skyline/building/sign geometry; a unique landmark; an exact street-view alignment
Strong corroborationSeveral independent features match: road shape + terrain + signage + vegetation
Contextual supportRegion/country-level clues — language, road markings, plates, architecture
Weak clueA generic hill, a common storefront, similar weather, vague architecture

7.2 Which Tool Answers Which Question

ToolQuestionCaution
ExifTool / Commons metadataIs the file self-describing?Metadata can be missing, edited, or inherited from a repost
Google Lens / TinEye / YandexHas this image appeared before?Do this after observation to avoid anchoring bias
Google Maps / Earth / Street ViewDoes the candidate geography visually match?Map imagery can be older than the photo
Mapillary / KartaViewIs public street-level imagery needed where Street View is weak?Coverage is uneven
OpenStreetMap / Overpass / Bellingcat OSM SearchCan visible mapped features be queried?Useful for specific feature combos; OSM completeness varies
SunCalc / shadow toolsDoes light/shadow support the proposed time?A plausibility check only, not a single-source proof
⚠ Geolocation tools change availability and features constantly — verify before relying on a specific one.

Treat AI outputs as hypotheses, not proof

AI geolocation tools generate leads, not conclusions. Every AI-generated location output should be independently verified against at least two map or imagery sources — document which tool you used, what it said, and what independently confirmed or rejected it.

7.3 Categories of Clues

  1. Text & language: scripts, shop names, road signs, emergency numbers
  2. Transport: lane side, road markings, bollards, plates, bus stops
  3. Built environment: roof shapes, balconies, utility poles, sidewalks
  4. Physical geography: mountains, coast, rivers, slope, vegetation
  5. Temporal clues: sun angle, weather, seasonal foliage, construction stage
  6. Technical context: metadata, resolution, platform compression, upload chain

Capturing negative evidence matters too — noting what you don't see (no readable signage, say) tells you which categories of clue you can't rely on, and helps you avoid forcing a false lead.

A seventh category worth tracking explicitly, alongside the six above: uncertainty itself. Note not just what you found, but how confident you are in each clue and why — a sign you could only partially read, a road-marking color you're not fully sure you observed correctly, an architectural style you recognize but can't precisely name. Treating uncertainty as its own tracked category, rather than silently rounding an unsure observation up to a confident one, keeps a shaky clue from quietly hardening into a confirmed fact later in the same investigation.

One clarifying distinction worth internalizing here: naming a building's type is not the same as locating it. Recognizing a structure as "a chalet," for instance, tells you something about architecture and possibly climate, but chalets exist across many countries and mountain regions — the building type is a category, not a place, and it needs combining with other clues before it narrows anything down.

Asphalt, road markings, and guardrails as regional tells

Details that surprise most beginners: reddish/terracotta asphalt is associated with the Netherlands, Belgium, and some UK cycle lanes; bleached white aggregate with the Middle East and Australia (heat-reflective); dark charcoal/black with Northern Europe. Yellow center lines: US, Canada, Japan, Brazil. White center lines: most of Europe, Australia, UK. Guardrail types — W-beam (US standard), corrugated Armco steel, concrete Jersey barriers — follow regional construction norms, and even paint color on the end-treatments (orange in the US, yellow in some EU states, unpainted galvanized in Scandinavia) is a visible clue.

7.4 Mapping Tools and Layers

Satellite/temporal platforms: Copernicus Browser (full-resolution Sentinel-2 imagery for vegetation/water/coast), NASA Worldview (recent environmental context — fires, clouds, floods), USGS EarthExplorer (historical remote-sensing datasets), Google Earth historical (a fast timeline for change-detection and capture-date checks).

Layer-matching checklist: road geometry, building footprint/roof shape, coastline/river/rail alignment, terrain slope, vegetation/land-use — plus, at street level: furniture and signs, lane markings, facade colors, utility poles and shadows, camera direction. And in context: place names, administrative boundaries, date/season, historical construction, contradictions and alternatives you tested and rejected (and why).

Measuring real-world distances

Google Maps: right-click a point → "Measure distance" → click a second point → you get an exact distance in meters, and you can add more points for a running total. Google Earth Pro: Tools → Ruler → Line/Path tab → click start and end points → choose meters. For building-height estimation: measure the shadow length, note the sun angle from SunCalc, and apply tan(angle) × shadow_length = height.

7.5 From Visible Clue to Country Hypothesis

Example chain: blue pedestrian signs, right-side driving, Mediterranean vegetation, rocky hills, concrete apartment blocks → interpretation: likely Southern/Eastern Mediterranean, exact country still uncertain → verification question: which countries combine these road-sign conventions, this terrain, and this urban style?

A practical taxonomy: road system (GeoHints, Street View, Mapillary), language/scripts (Google Lens/OCR, Wiktionary), vehicles/plates (World License Plates, local transit sites), architecture (street imagery, Wikimedia Commons), terrain/vegetation (Google Earth terrain, climate maps), infrastructure (GeoHints, OSM tags), and temporal/contextual (SunCalc, weather archives).

Country/region workflow: Inventory (list visible facts before any search) → Categorize (map each clue to an indicator family) → Weight (mark each high/medium/low signal) → Hypothesize (rank likely countries, at least two competing options) → Verify (two independent confirmations).

7.6 Historical Geolocation

Reconstructing "what existed here X years ago" follows: (1) anchor the place with stable landmarks and road geometry; (2) build a timeline from dated captures before and after the target period, keeping capture date separate from publication date; (3) cross-check street-level imagery, satellite imagery, web archives, and business records; (4) resolve conflicts by preferring directly-dated visual evidence and explaining gaps or rejected candidates.

Evidence strength ladder: High = an official record/permit tied to the exact address and date, or a dated street-level image showing the sign at the exact storefront; Medium = an archived business page matching address and phone, or OSM edit history naming a point of interest around the right period; Low = current reviews, vague blog mentions, undated photos, AI-generated map summaries.

Two more verification techniques worth adding to this workflow. First, cloud-cover matching: if a photo's claimed date is in question, check NASA Worldview's historical satellite imagery for that location and date — a claimed clear-sky day that historical imagery shows as fully overcast (or the reverse) is a hard, independently-checkable contradiction. Second, a physical-world analog to the domain-registration-date check from Chapter 9: verifying when a specific storefront or business at an address actually opened — through a dated street-level image showing the sign, an archived local business directory entry, or a permit filing — can directly contradict a claim about what existed at a location on a given date, in exactly the way a domain's registration date can contradict a company's claimed founding date.

7.7 Case Study: Real-Time Monitoring — Chernobyl 2022

The Centre for Information Resilience (CIR) — Eyes on Russia project tracked military movement before and during the Russian invasion of Ukraine (February 2022). Comparing satellite imagery over several weeks in early-to-mid March documented a camp appearing near Chernobyl's Reactor #4, with extensive digging and temporary shelters visible across the comparison period. Later satellite imagery confirmed a large fire at the camp; video reportedly showed a supply route running from Belarus into northern Ukraine near the camp; open-source reporting later cited elevated radiation readings on-site. This shows how imagery, satellite data, video, and on-the-ground verification combine in real time, on stakes that include lives — and why speed without sacrificing rigor matters so much in that kind of situation.

⚠ The specific sequence and dates in this case are presented from general recollection of public reporting on this project — verify against CIR's own published output before citing specific dates.

🧪 Practical Exercises

  1. Find a photo online (a news photo or a travel blog image) that doesn't state its location. Without searching for the caption or article title, list at least 6 visible clues, grouped into: text/language, road/transport, architecture, terrain/vegetation, lighting/time. Form 2-3 broad hypotheses (country/region level, not exact coordinates).
  2. Pick a landmark you know well from photos alone (not one you've visited) and try to identify its exact Street View viewpoint using only Google Maps/Street View.
  3. Estimate a building's height from a photo with a visible shadow: note the apparent shadow length, look up the sun's altitude for a plausible date/location on SunCalc, and apply the shadow-height formula.
  4. After completing exercise 1, write one more sentence naming the single most decisive clue among everything you listed — the one that, if it turned out to be wrong or misread, would most change your hypothesis. This forces you to weight your evidence instead of treating every clue as equally load-bearing.
  5. Pick a landmark and identify three candidate coordinates within a few hundred meters of each other, all superficially plausible from a distant satellite view. Practice choosing between them using only close-in evidence — building footprint shape, road curvature, a specific tree or utility pole — rather than defaulting to whichever pin looks "close enough."

💡 Suggested Approach / Notes

In exercise 1, resist the urge to jump straight to an exact city — the exercise is deliberately scoped to country/region level to build the discipline of ranking hypotheses before verifying. In exercise 3, treat your final number as an estimate with a wide error margin, not a precise measurement — the value of the exercise is understanding the method, not producing a lab-grade result. In exercise 5, if you find you can't confidently rule out two of the three candidates using close-in evidence alone, that's the realistic and useful outcome — it's the same discipline as Chapter 15's confidence scoring, applied to a map instead of a written finding.