Every Device You Own Is a Surveillance Node

▶ Watch (1:48)

Smart doorbells log motion. Smart refrigerators phone home. Navigation systems record every route. Social media accounts feed behavioral profiles to advertisers. Wilson adds data breaches as a separate layer: passwords, healthcare records, and children’s school information leaked without consent. The attack surface is not a device or an account. It is every interaction, purchase, and movement tied to your identity, aggregated into a profile no single person ever agreed to create.

The Five-Tool OSINT Counter-Surveillance Stack

▶ Watch (8:00)

Wilson’s stack uses five free tools. Spiderfoot continuously scans public sources for your email, phone number, and IP address. NTFY pushes those findings as push notifications to your phone. OpenCanary hosts honeypots, small decoys that log whoever touches them. Tailscale ties everything into a private network with DNS. Docker keeps the full stack containerized and in your possession. The VPN layer is not optional: the point of ghost mode is watching without being visible, and a publicly exposed scanner defeats that goal.

Running the Stack on a Phone

▶ Watch (9:19)

Every component runs on a phone or laptop. Spiderfoot scans in the background. NTFY delivers alerts to your notification tray in real time. Wilson treats her personal setup the same way she treats client monitoring: alerts fire, you check them, you decide whether something is real. She published the full buildout on GitHub, including deployment code and a list of alternative OSINT tools for people who want to swap components. The stack is intentionally tool-agnostic. Any combination that delivers real-time alerts from a private container works.

Baselining and Log Analysis

▶ Watch (14:00)

Log volume is the main friction point. Wilson flags baselining as the first requirement: you need to know what normal looks like before you can spot what does not fit. Normal might be data brokers running periodic lookups on your email. Anomalies are queries at unusual hours, lookups from countries where you have no presence, or access patterns that do not match your own schedule. Time-based monitoring helps: if your data is being accessed at 3am from a foreign IP while you are home asleep, that is worth investigating.

Geospatial Context and Threat Response

▶ Watch (18:00)

Geospatial correlation adds a second filter. If your data is being queried from a different country or an unfamiliar region, that location context helps separate noise from real threats. When a confirmed threat emerges, Wilson’s playbook is: isolate the device, rotate credentials, check logs, and escalate if needed. That might mean contacting law enforcement or homeland security. She also mentions Security Onion as an optional addition: routing the full alert stream through it converts the personal stack into a personal SIEM.

Q&A

Has the system held up in real-world testing? At a coffee shop, Wilson detected scanning activity against her IP in real time; no attacker made progress, but the visibility was immediate. ▶ 19:51

How is Tailscale implemented in the stack? It runs as the private network backbone with DNS configured through it, keeping all components off the public internet. ▶ 21:17

Notable Quotes

It’s really like we’re reality stars Desiree Wilson · ▶ 2:12

you’re always being watched. Desiree Wilson · ▶ 6:06

I don’t write code. Desiree Wilson · ▶ 8:09

Ghost mode is the counter to the unknown Desiree Wilson · ▶ 18:36

Key Takeaways

  • A personal OSINT counter-surveillance stack can be built free using Spiderfoot, NTFY, OpenCanary, Tailscale, and Docker.
  • Baselining normal log activity is a prerequisite; anomalies only surface against a known pattern.
  • When a confirmed threat appears, isolate devices, rotate credentials, check logs, and contact law enforcement if warranted.

About the Speaker(s)

Desiree Wilson has spent over 15 years in information security and founded Quantum Mergers, a consultancy serving MSPs and MSSPs. She has worked with Fortune 500 companies, the Department of Defense, and organizations across financial services, healthcare, telecommunications, and energy. Her practice focuses on cybersecurity architecture, cloud adoption, DFIR, and threat intelligence. She is a member of the Forbes Business Council and serves as a board advisor to several organizations, with an active focus on equitable access to security education globally.