ALLINT Over OSINT: Combining Every Maritime Intelligence Layer
Maritime threat intelligence starts with AIS, the automatic identification system every vessel broadcasts. But AIS alone is insufficient. A ship can spoof its destination, mask its owner behind a shell company, or simply turn off its transponder. The team’s framework classifies open-source tools into three questions: where, what, and who. AIS answers where. Satellite imagery from commercial constellations answers what. Corporate registry cross-referencing answers who. Each data set is useless on its own. The intelligence cycle aligns them.
Tracing the Sea Serpent: A Sanctions-Evasion Case
The team applied this method to a real target: tanker MVC Sea Serpent, suspected of evading sanctions. AIS showed an inconsistent heading. Cross-referencing official databases exposed two facts: the vessel’s IMO number belonged to a different ship, making Sea Serpent a zombie, and its AIS signal went dark exactly when it entered a sanctioned zone. To confirm physical presence, the team used synthetic aperture radar from satellite imagery. The SAR data showed two ships meeting at the precise coordinates where Sea Serpent disappeared. The chain of evidence came entirely from public data.
A Risk Scoring Engine for Anomaly Detection
The team built a proof-of-concept risk scoring engine to scale anomaly detection. The logic assigns points to suspicious behaviors. One example: GPS jittering, a technique attackers use to flood tracking systems with noise. The engine flags it automatically. But the team is direct about a gap: red teamers know how to break systems, not run ships. A risk score means nothing without a maritime expert confirming whether a flagged zone is genuinely suspicious or just a busy tanker anchorage. Human judgment converts the tool into actionable intelligence.
The Attacker’s Playbook: Luffy’s Maritime Campaign
The team shifted to the attacker’s perspective using a fictional character, Luffy. His target: vessel ARXXSN. Luffy confirmed the departure port using leaked credentials from private dashboards, then identified the arrival port and found CVE-2025-87 in the port authority’s systems. He bought the exploit on a marketplace and gained system access. The vessel was due at night on August 12. Luffy found access to the port’s solar-powered lighting system. A second scenario placed Luffy in Africa, where he compromised a terminal operator account, then targeted the escort vessel’s commanding officer for blackmail using leaked personal data.
Notable Quotes
A deliberate act of deception. Samet Can Tasci · ▶ 4:51
it is a smoking gun Samet Can Tasci · ▶ 5:08
Let’s be honest, we are red teamers. Samet Can Tasci · ▶ 6:16
Key Takeaways
- Public AIS data is unreliable alone; cross-referencing satellite imagery exposes zombie vessels and ownership fraud.
- Synthetic aperture radar confirmed a vessel’s physical presence after AIS went dark in a sanctioned zone.
- GPS jittering floods tracking systems with noise; a risk engine flags it, but experts decide context.
- An attacker can chain leaked credentials, a bought exploit, and port infrastructure access in one campaign.
- ALLINT combines paid and free CTI, dark web data, and sector intelligence beyond open-source collection.
About the Speaker(s)
Mehmet Önder Key is a cybersecurity consultant specializing in critical infrastructure security, zero-day vulnerability analysis, and offensive security. He has advised organizations in defense, aerospace, and finance, with hands-on experience in red teaming and strategic security engineering. His work spans multiple countries and contributes to the discovery of systemic vulnerabilities. He currently provides consultancy to Burkut, Ogrit, and Ravenailabs.
Dr. Furkan Aydogan is an Assistant Professor of Computer Science at UNCW and a researcher in cybersecurity, digital forensics, and brainwave-based encryption systems. His Ph.D. focused on using EEG signals to secure IoT devices, blending neuroscience with cryptography. He is a two-time award winner for research in VANET security and cognitive encryption.
Samet Can Tasci is a Red Hat Certified Linux System Administrator with over six years of experience in securing and automating enterprise infrastructure. He specializes in system hardening, containerization, and secrets management with HashiCorp Vault, with a focus on DevOps workflows using Ansible and GitLab CI.