Register for our next CTO webinar! Own (Your) Data: Utilize All The Data You Have with Maltego on Thursday, March 7, 2024 at 17:00 CET. Grab your spot now! close
07 Aug 2023

Social Media Data Recommended to Build Your Criminal Case

Daphnée Aguilar

With the prevalence of social media, platforms like Facebook, Instagram, Snapchat, and TikTok are rapidly becoming indispensable reservoirs of legally admissible data for attorneys and prosecutors.

In the past five years, subpoenas to social media companies have been issued in various arenas, including:

  • Criminal investigations where law enforcement seeks information such as user account details, messages, posts, and other relevant information that could aid in solving crimes.
  • National security and intelligence where intelligence agencies monitor potential threats, identify individuals involved in terrorism or espionage, and/or track online radicalization or extremist activities.
  • Civil litigation where social media evidence is used in lawsuits related to defamation, intellectual property disputes, employment discrimination, and personal injury claims.

And many other cases involving regulatory compliance, misinformation, data privacy, and more.

In criminal cases, subpoenas compel social media companies to disclose records or information on their customers and users that are critical to building a case against a suspect or which shed light on criminal activities. This includes information such as user account details, private messages, IP addresses, and more.

While prosecutors often use a subpoena to acquire social media data, some of the information can already be obtained using open source intelligence (OSINT).

In this article, we will discuss how OSINT helps build a criminal case and provide a cheat sheet of OSINT tools and techniques you can use to gather social media intelligence.


Establishing Relevance is Key to Building Your Case đź”—︎

Subpoenas to social media companies are often under scrutiny because the disclosure of information can potentially infringe upon an individual’s right to privacy.

Specifically, there are two primary challenges that prosecutors face when building a case for subpoena:

  • Relevance
  • Information Gathering

Relevance đź”—︎

It is important to identify what is absolutely necessary to justify a subpoena request. Prosecutors must justify the scope of the subpoena and prove the relevance between the criminal case and the information requested.

For example, prosecutors must prove that the suspect in question is using a user account, perhaps through images, posts, or location pings that indicate involvement in certain criminal activities.

Information Gathering đź”—︎

Once you identify the information needed to build a subpoena request, the second challenge is finding the information in the vast ocean of online social media data. The smoking gun can easily be hidden—or worse, be deleted—from plain sight.

Use OSINT to Gather Data In Addition to Subpoenas đź”—︎

Open source intelligence (OSINT) is highly valuable for law enforcement in building subpoena cases. It provides access to a wide range of publicly available information which supports evidence collection, suspect identification, and information verification. While the use of OSINT in law enforcement faces discussions, OSINT helps investigators cross-reference and corroborate data, trace digital footprints, and proactively prevent and prosecute crimes—all in a cost-effective and efficient manner.

As a sub-discipline of OSINT, social media intelligence (SOCMINT) is especially crucial.

SOCMINT includes all social media platforms, not only social networking sites. Social networking sites, like Facebook and LinkedIn, only make up one portion of the platforms that can be used to gather data. Information can also be found on media-sharing sites like Instagram, forums like Reddit, image-sharing sites like Pinterest, video-sharing sites like YouTube, microblogging platforms like Twitter, social gaming platforms like Xbox Live, and blogs created using platforms like WordPress.

While prosecutors often use a subpoena to acquire social media data, some of the information can already be obtained using SOCMINT to make advances in the investigations and order subpoenas for the most crucial piece of the puzzle.

SOCMINT Data That Helps Build Your Case đź”—︎

Law enforcement uses subpoenas to social media company to identify suspects. However, for the subpoena requests to be approved, you must establish relevance of the subpoena with the case at hand.

Most of the information you need to build your case can be found using SOCMINT. Moreover, some of the information that normally comes from subpoenas can also already be obtained via SOCMINT.

Here’s a list of social media data that you can gather via SOCMINT to build your case:

  • User Account Details: Information such as username, alias, registration date, birth date, and other account information if available.
  • Friends and Connections: Details of inter-profile connections, friends, followers, and followings of the relevant user account(s).
  • Groups and Communities: Groups, forums, and communities on the social media platforms that the relevant user account(s) participates in.
  • Timestamps: Timestamps of relevant actions, messages, posts, and images made by or published by the relevant user account(s).
  • Location: Locations of specific posts or content published, or locations indicated by the relevant user account(s).
  • Images and Videos: Images and videos relevant to the case or as supporting evidence.
  • Posts: Content posted on social media feeds (such as a Facebook post, a Twitter Tweet, or an Instagram Story) that is relevant to the case or as supporting evidence.
  • Post Engagement: Likes, comments, and sharing of social media posts might provide insight to people related to the suspects or involved in the criminal activities.
  • Erased or Historical Online Personas: Make note of online profiles or accounts that might be deleted or outdated, which might still provide helpful data.
  • Other Digital Movements and Metadata: Additional digital activities, histories, and metadata that can support identifying accomplices.

We’ve also compiled this into a PDF that you can take with you.


Please note that these are only a few things prosecutors can ask for. The evidence required as well as the requested data will depend mainly on the type and purpose of the investigation. The approval of subpoena requests highly depends on the court’s judgment and jurisdiction. Some companies might not comply with subpoena requests due to the legislation they adhere to, the jurisdiction they are based in, or their own company policies.

Some social media companies, like WhatsApp (owned by Meta), are aware that access to certain information can prevent harm to the life or well-being of a person or a child. Other companies like Telegram, however, are not as cooperative with law enforcement.

It is advisable to research the legal and compliance guidelines of relevant social media companies when preparing for subpoena requests.


How to Gather These SOCMINT Data for Your Case đź”—︎

Knowing which data to gather is the first step. Most importantly, where can you find all the SOCMINT data above?

In social media investigations, it is important to understand:

  1. The available social media platforms and how users typically interact on those platforms: For example, users on Instagram typically share images or videos, whereas Twitter users largely stick to text.
  2. Connections between certain accounts and platforms: For example, a Google user account is also connected to Gmail and YouTube.
  3. Metadata relevant and available on those platforms: For example, we are not simply looking for a username on Facebook, but also social connections of the target to search for additional profiles or suspects.

Resources like the OSINT Framework or OSINT Dojo are great places to learn about how data is related and how you can move through an OSINT investigation knowing that you’ve explored and pivoted to all the crucial data points.

Additionally, there are a few advanced tools and techniques that you can use to gather as much social media data as possible:

  • Google Dorking: Also known as advanced Google searching, dorking involves using specialized search operators and techniques to find specific information on the internet
  • Breached Data: These databases include data like breached passwords, email addresses, usernames, and the platforms these user information connects to.
  • Reverse Image Search: Find the original source or similar images on the internet using and image as the search input.

Download the Cheat Sheet and Try Them out Now! đź”—︎

In this cheat sheet, our SOCMINT expert put together a helpful list of:

  • 13 Google Dorks
  • 3 Breach Databases
  • 2 Reverse Image Search Workflows

Download the resource

DE +49
Albania +355
Algeria +213
Andorra +376
Angola +244
Anguilla +1264
Antigua and Barbuda +1268
Argentina +54
Armenia +374
Aruba +297
Australia +61
Austria +43
Azerbaijan +994
Bahamas +1242
Bahrain +973
Bangladesh +880
Barbados +1246
Belarus +375
Belgium +32
Belize +501
Benin +229
Bermuda +1441
Bhutan +975
Bolivia +591
Bosnia Herzegovina +387
Botswana +267
Brazil +55
Brunei +673
Bulgaria +359
Burkina Faso +226
Burundi +257
Cambodia +855
Cameroon +237
Canada +1
Cape Verde Islands +238
Cayman Islands +1345
Central African Republic +236
Chile +56
China +86
CĂ´te d'Ivoire +225
Colombia +57
Comoros +269
Congo +242
Cook Islands +682
Costa Rica +506
Croatia +385
Cuba +53
Cyprus North +90392
Cyprus South +357
Czech Republic +42
Denmark +45
Djibouti +253
Dominica +1809
Dominican Republic +1809
Ecuador +593
Egypt +20
El Salvador +503
Equatorial Guinea +240
Eritrea +291
Estonia +372
Ethiopia +251
Falkland Islands +500
Faroe Islands +298
Fiji +679
Finland +358
France +33
French Guiana +594
French Polynesia +689
Gabon +241
Gambia +220
Georgia +7880
Germany +49
Ghana +233
Gibraltar +350
Greece +30
Greenland +299
Grenada +1473
Guadeloupe +590
Guam +671
Guatemala +502
Guinea +224
Guinea - Bissau +245
Guyana +592
Haiti +509
Honduras +504
Hong Kong +852
Hungary +36
Iceland +354
India +91
Indonesia +62
Iran +98
Iraq +964
Ireland +353
Israel +972
Italy +39
Jamaica +1876
Japan +81
Jordan +962
Kazakhstan +7
Kenya +254
Kiribati +686
Korea North +850
Korea South +82
Kuwait +965
Kyrgyzstan +996
Laos +856
Latvia +371
Lebanon +961
Lesotho +266
Liberia +231
Libya +218
Liechtenstein +417
Lithuania +370
Luxembourg +352
Macao +853
Macedonia +389
Madagascar +261
Malawi +265
Malaysia +60
Maldives +960
Mali +223
Malta +356
Marshall Islands +692
Martinique +596
Mauritania +222
Mayotte +269
Mexico +52
Micronesia +691
Moldova +373
Monaco +377
Mongolia +976
Montserrat +1664
Morocco +212
Mozambique +258
Myanmar +95
Namibia +264
Nauru +674
Nepal +977
Netherlands +31
New Caledonia +687
New Zealand +64
Nicaragua +505
Niger +227
Nigeria +234
Niue +683
Norfolk Islands +672
Northern Marianas +670
Norway +47
Oman +968
Pakistan +92
Palau +680
Panama +507
Papua New Guinea +675
Paraguay +595
Peru +51
Philippines +63
Poland +48
Portugal +351
Puerto Rico +1787
Qatar +974
Reunion +262
Romania +40
Russia +7
Rwanda +250
San Marino +378
Sao Tome & Principe +239
Saudi Arabia +966
Senegal +221
Serbia +381
Seychelles +248
Sierra Leone +232
Singapore +65
Slovak Republic +421
Slovenia +386
Solomon Islands +677
Somalia +252
South Africa +27
Spain +34
Sri Lanka +94
St. Helena +290
St. Kitts +1869
St. Lucia +1758
Sudan +249
Suriname +597
Swaziland +268
Sweden +46
Switzerland +41
Syria +963
Taiwan +886
Tajikstan +7
Thailand +66
Togo +228
Tonga +676
Trinidad & Tobago +1868
Tunisia +216
Turkey +90
Turkmenistan +7
Turkmenistan +993
Turks & Caicos Islands +1649
Tuvalu +688
Uganda +256
UK +44
Ukraine +380
United Arab Emirates +971
Uruguay +598
USA +1
Uzbekistan +7
Vanuatu +678
Vatican City +379
Venezuela +58
Vietnam +84
Virgin Islands - British +84
Virgin Islands - US +84
Wallis & Futuna +681
Yemen +969
Yemen +967
Zambia +260
Zimbabwe +263

By clicking on "Access", you agree to the processing of the data you entered and you allow us to contact you for the purpose selected in the form. For further information, see our Data Privacy Policy.

We hope you find this cheat sheet practical for your social media investigations by understanding how to build a relevant and comprehensive case for your subpoena request, incorporating the techniques and SOCMINT data sources mentioned above.

Don’t forget to follow us on Twitter, LinkedIn, Mastodon, and sign up to our email newsletter, so you don’t miss out on updates and news!

Happy investigating!

About the Author đź”—︎

Daphnée Aguilar

DaphnĂ©e Aguilar đź”—︎

Daphnée is a Criminologist with more than 10 years of experience as an Intelligence Officer. She specialized in developing actionable intelligence for identifying, preventing, and neutralizing threats and risks from Transnational Organized Crime. Driven by the feminist movement, her last research was on the Effects of Gender and Racial Bias on Gender-Based Violence Policies. She considers herself a professional taco taster.

By clicking on "Subscribe", you agree to the processing of the data you entered and you allow us to contact you for the purpose selected in the form. For further information, see our Data Privacy Policy.