Visualização normal

Antes de ontemStream principal
  • ✇bellingcat
  • Burning Forests: Tools for Tracking and Reporting Wildfire Damage Galen Reich
    If you’ve seen reports of a wildfire in your region and you’re looking for open source data, NASA’s fire-tracking tool is often the first place to start. It provides a heat signature and an approximate location. But detection is only the first step in understanding what’s happened. In this guide, we explore ways to analyse and report on the scale and severity of wildfires, including those in protected areas where ecosystems are often most fragile. We also examine how often fires recur in the sam
     

Burning Forests: Tools for Tracking and Reporting Wildfire Damage

30 de Junho de 2026, 05:25

If you’ve seen reports of a wildfire in your region and you’re looking for open source data, NASA’s fire-tracking tool is often the first place to start. It provides a heat signature and an approximate location. But detection is only the first step in understanding what’s happened. In this guide, we explore ways to analyse and report on the scale and severity of wildfires, including those in protected areas where ecosystems are often most fragile. We also examine how often fires recur in the same region over multiple seasons, helping to identify patterns in fire activity as climate change reshapes fire risk around the world

Satellite imagery from Copernicus Browser will be used to visualise the spread of the fire, and vegetation health indices to assess burn severity. The datasets will then be combined in QGIS for more in-depth analysis. At each stage, suggestions will be offered for turning the data into clear, reportable findings.

Throughout this guide, a single case study will be used: Sicily’s Zingaro Nature Reserve. In 2025, wildfires swept across the region, destroying forests, grasslands and croplands. Located on the Capo San Vito peninsula, the reserve was so severely affected that sections remain closed today. 

Visualising Scorched Earth

When investigating a wildfire, it’s important to narrow down when it occurred and where it spread. The Landsat and Sentinel-2 missions are well-suited to this task, providing regular free imagery of most of the Earth’s landmass.

Below are two sets of Sentinel-2 imagery showing conditions shortly before and after a fire on July 25, 2025, near Capo San Vito, Sicily. The top two images are true-colour, similar to what would be seen from an aeroplane window. The image on the top right shows an area of scorched earth on the eastern side of the peninsula, but the exact extent of the fire is difficult to determine because the colour of the ground has changed only slightly.

Satellite images of Capo San Vito, Sicily, showing before (left) and after (right) a fire on July 25, 2025. Top row: true-colour imagery. Bottom row: false-colour imagery highlighting fire damage in red. Source: Contains modified Copernicus Sentinel data 2025, processed with Copernicus Browser.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

The bottom two images are false-colour and highlight the difference between healthy vegetation and burned areas. Such imagery is possible because Sentinel-2 captures bands of light outside the visible range, a technique known as multispectral imaging. In these images, the near-infrared (NIR) band is coloured green, and the shortwave infrared (SWIR) band is coloured red. Healthy vegetation mainly reflects NIR light, so it appears green, while burned areas mainly reflect SWIR light, so they appear red.

These images were created with Copernicus Browser, a free browser-based tool from the European Space Agency for accessing and working with Sentinel imagery. It allows users to browse the Sentinel-2 catalogue by date and visualise different band combinations. You don’t need an account to use the browser, but signing in enables additional features.

If you’d like to try Copernicus Browser without further explanation, you can go straight to the false-colour post-fire image here

To follow along step by step, first open Copernicus Browser. Then to visualise Sentinel-2 imagery:

  1. Zoom to the desired area on the map or use the search bar (San Vito Lo Capo, north-west Sicily)
  2. Select the date of interest (‘2025-07-27’ selected below).
  3. Select the layer of interest (‘True color’ by default; SWIR selected below).

Screenshot of Copernicus Browser. Annotations by Bellingcat.

By identifying the last available image before the fire and the earliest image after it in which the full burn area is visible, it’s possible to establish the location and timeline of the fire.

This allows us to report the following finding: “Satellite imagery reveals the extent of the damage caused by wildfires across the Capo San Vito peninsula on Sicily’s northern coast between July 20 and July 27, 2025.”

Extra exercise: Look up a recent fire (e.g., wildfires near Penco, Chile in January 2026), navigate to the affected location and try to visualise the burned area using Copernicus Browser.

Quantifying the Burned Area

The visibly scorched area can be measured using the Area of Interest tool (highlighted below), which allows users to draw a polygon on the map and calculate the total area in square kilometres. (Once drawn, keep the polygon in the editor, as it will be used again later.)

Estimated burn area of 53.97 km2 using the Area of Interest tool. Screenshot of Copernicus Browser. Annotations by Bellingcat.

Reportable finding: “The wildfire that swept across Sicily’s Capo San Vito peninsula in 2025 burned more than 50 km2 of the peninsula, according to Sentinel-2 data.”

Repeatedly measuring the burned area over time allows you to follow the progression of a fire. This method was used by Bellingcat when covering the Etosha National Park wildfire in late September 2025.

Extra exercise: Replicate the analysis of the Etosha National Park fire from this Bellingcat article.

Assessing Burn Severity 

Some fires only affect surface vegetation, while others scorch the ground and cause long-lasting damage. Burn severity can be measured using an index called the Normalised Burn Ratio (NBR).

How Does the Normalised Burn Ratio (NBR) Detect Burned Areas?

The spectral response of a material describes how reflective it is to different types of light. The graph below shows the difference between healthy vegetation and bare soil in terms of the amount and types of light they reflect.

Reflectance data reproduced from the ECOSTRESS Spectral Library using Conifer for Healthy Vegetation and Black Loam for bare soil. Graphic by Bellingcat.

By focusing on the NIR and SWIR bands, where reflectivity differs significantly between healthy vegetation and bare soil left after a burn, an index can be calculated: 

NBR = (NIR – SWIR) / (NIR + SWIR) 

A high NBR indicates healthy vegetation, while a low NBR indicates burned areas.

Copernicus Browser doesn’t include a default NBR layer, but it can be added via a custom script, as shown in the screenshot below:

  1. Select ‘Custom’ in the layer selector.
  2. Switch from the ‘Composite’ to the ‘Custom’ tab.
  3. Check ‘Load script from URL’.
  4. Paste this URL: https://bellingcat-scripts.ams3.cdn.digitaloceanspaces.com/NormalizedBurnRatio.js 
  5. Load the script by clicking the green circular arrows to the right of the URL.
  6. Click ‘Apply’ (you may need to scroll down).

Alternatively, you can skip these steps and go straight to the custom NBR post-fire image here.

Screenshot of Copernicus Browser. Annotations by Bellingcat.

The NBR layer displays positive values in green (healthy vegetation) and negative values in purple (burned areas), making the boundary of the scorched area much clearer than before.

To calculate the change in NBR in Copernicus Browser, use the Statistical Information tool (a free account is required to access this feature).

  1. Within the date selector, choose a date a few weeks or months after the fire.
  2. Using the Area of Interest polygon, select the ‘Statistical Info chart’ icon.

  1. Set the maximum cloud cover to around 30% using the slider in the top right.
  2. Select a date range that captures the available data surrounding the fire (July 20-27 shown below).
  3. Identify when the fire occurred on the graph (this will be marked by a sharp drop in the NBR, as shown below).
  4. Hover over the points on the graph immediately before and after the fire to display the mean value.

Composite of screenshots from within Copernicus Browser.

In this example, the pre-fire image had an average NBR of 0.11 and the post-fire image had an average NBR of -0.18. The NBR decreased by 0.29, which represents a moderate burn.

Severity LevelChange in NBR
UnburnedLess than 0.100
Low0.100 – 0.269
Moderate0.270 – 0.659
High0.660 or greater
Burn severity table from the US Forest Service (page 38), simplified by Bellingcat.

Reportable finding: In late July, the fire, which scorched more than 50km2 of Sicily’s Capo San Vito peninsula, was deemed moderately severe according to the US Forest Service guidelines

Extra exercise: Find a custom visualisation script of interest from this repository and explore what it does.

Wildfires in Conservation Areas

By focusing on protected sites such as nature reserves and national parks, we can begin to assess how wildfires affect areas of high conservation value. Controlled burns are widely used in agriculture and land management, but unchecked fires in protected areas risk eroding fragile ecosystems.

The proportion of the Zingaro Nature Reserve that was damaged by the fire can be estimated by combining the NBR image created in Copernicus Browser with a dataset from Protected Planet, a global map of protected areas that includes nature reserves.

QGIS, a program for working with geographic data, is well-suited for this type of analysis. Download and install QGIS on your computer. For help with this step, refer to the QGIS installation guide.

To download the NBR image from Copernicus Browser:

  1. With the NBR visualisation selected, click the ‘Download’ icon. 
  2. Switch tabs at the top from ‘Basic’ to ‘Analytical’.
  3. Change the image format to ‘TIFF (32-bit float)’.
  4. Change the image resolution to ‘HIGH’.
  5. Change the coordinate system to ‘Popular Web Mercator (EPSG:3857)’.
  6. Toggle the ‘Clip extra bands’ switch to the off position (see image below).
  7. Select the ‘Custom’ layer check box (and deselect any others).
  8. Click ‘Download’.
  9. Wait. It could take several minutes for the image to be generated and downloaded.
Screenshot of Copernicus Browser. Annotations by Bellingcat.

Once the image has downloaded, rename it to NBR.tiff to make it easier to work with. 

Next, open QGIS and click ‘New Project’ in the upper left. 

Load the image from Copernicus Browser by dragging and dropping the downloaded file into QGIS.

Useful QGIS Terminology

CRS – The Coordinate Reference System describes how the world should be measured and projected. Two of the most common are:

EPSG:4326 – WGS 84, which uses latitude and longitude as the unit of measurement.

EPSG:3857 – WGS 84 / Pseudo-Mercator, which uses metres as the unit of measurement.

Raster – a type of data that uses pixels to represent information (such as satellite imagery)

Vector – a type of data that uses points, lines, and polygons to represent information (such as a burn area polygon).

Processing the NBR Image

Next, we categorise each pixel in the NBR image as burned or unburned. 

Previous analysis in Copernicus Browser showed that the Zingaro Nature Reserve’s NBR value dropped below zero only after the fire (before image: mean NBR value on July 20, 0.11; after image: mean NBR value on July 27, -0.18).

We can use this analysis to set a threshold; anything below zero will be categorised as burned.

The QGIS Raster Calculator lets us apply our threshold to the NBR image and create a new layer. 

Open the Raster Calculator by selecting ‘Raster > Raster Calculator…’ from the menu bar at the top.

Screenshot of the QGIS Raster Calculator. Annotations by Bellingcat

The Raster Calculator lists the raster bands available in the project. In this example, there are five. These bands are set by the custom script we used in Copernicus Browser and are numbered as follows:

  1. Red
  2. Green
  3. Blue
  4. Pixel validity (not used in this example)
  5. NBR index

To create a new raster layer that applies our threshold on the NBR index band:

  1. Double-click the fifth band (ending ‘@5’) to add it to the expression box at the bottom. 
  2. Add < 0 using your keyboard (shown above).
  3. Select the ‘Create on-the-fly raster instead of writing layer to disk’ checkbox.
  4. Click ‘OK’.

The expression NBR@5 < 0 tells QGIS to categorise NBR index values as burned if they are less than zero. 

The new layer shows burned areas as white (a value of 1), and unburned areas as black (a value of 0).

Screenshot of QGIS.

Extra exercise: Download an NBR image captured before the fire. Use the Raster Calculator to create a new layer that shows burn severity.

Adding Conservation Area Data

Download the Zingaro Nature Reserve dataset from Protected Planet by selecting ‘Download > File Geodatabase’.

As before, drag and drop the downloaded file into QGIS. This time, the download is a zip file and contains many PDF files as well as the geodatabase file of interest. Scroll down to the bottom of the list and select the ‘gdbtable’ file with a polygon icon on the left side (see the blue highlighted row below), then press ‘Add Layers’.

Screenshot of QGIS. Annotations by Bellingcat.

This adds the nature reserve polygon as a layer in QGIS (and gives it an arbitrary colour). The nature reserve is almost completely contained within the white burned area, indicating it was heavily affected by the wildfire.

Screenshot of QGIS.

Quantifying the Burned Area in the Nature Reserve

To measure the proportion of the nature reserve that was burned by the wildfire, we will use the Zonal Histogram tool from the QGIS Processing Toolbox to count the number of unburned and burned pixels within the reserve polygon.

Open the toolbox with ‘Processing > Toolbox’, and a pane should open to the right. In the Processing Toolbox search field, look up ‘Zonal Histogram’ and double-click the result to open the tool.

To create a new layer:

  1. Set the ‘Raster layer’ to the threshold burn area layer (NBR@5 < 0)
  2. Set the ‘Vector layer containing zones’ to the nature reserve polygon layer (should start with ‘WDPA_’).
  3. Click ‘Run’
  4. Click ‘Close’
Screenshot of QGIS. Annotations by Bellingcat.

This will create a new layer called ‘Output zones’, which is a copy of the nature reserve polygon with pixel counts added.

Select the output layer in the lower left and click ‘Attribute Table’ in the upper right. (The attribute table is a spreadsheet-like view of the data contained in a layer.) 

For the output layer, there is just one row because there is only one polygon. If the layer contained many polygons, there would be many rows.

The newly calculated counts are added to the end of the table, so scroll all the way to the right. Look for fields starting with ‘HISTO_’. Here, HISTO_0 is the count of unburned pixels (value of 0), and HISTO_1 is the count of burned pixels (value of 1).

Screenshot of QGIS. Annotations by Bellingcat.

To calculate the proportion of burned area, the number of burned pixels is divided by the total number of pixels.

Proportion = 57413 / (57413 + 2195) = 0.96318…

A value of 0.96318 means that just over 96.3% of the nature reserve burned.

Reportable finding: In late July, more than 95% of the Zingaro Nature Reserve burned in a wildfire, according to Sentinel-2 satellite imagery and Protected Planet data.

Tracking Past Wildfires

To assess the significance of an ongoing wildfire, it is important to place it in historical context. How does it compare with previous fires in the same area? Is it part of a seasonal pattern, or does it represent an unusually severe event?

With coverage dating back to 2008, the European Forest Fire Information System (EFFIS) automatically maps wildfires across Europe, North Africa, and parts of the Middle East.

Fire data can be requested directly from EFFIS using web form, with results delivered by email. For ease, you can also download Bellingcat’s archived copy of EFFIS wildfire data for Italy covering 2015–2025.

For this section, it is best to open a new QGIS project.

To view and analyse historic wildfires in the Zingaro Nature Reserve using EFFIS data:

  1. (Optional) Add the OpenStreetMap layer from the XYZ Tiles category by double-clicking it.
  2. Load the EFFIS data into QGIS. If prompted to select a coordinate transformation, click ‘OK’ to accept the default option. 
  3. Load the Protected Planet Zingaro Nature Reserve polygon as described earlier. 
  4. Open the Vector Intersection tool by selecting ‘Vector > Geoprocessing Tools > Intersection…’ from the menu bar at the top.
Screenshot of QGIS Annotations by Bellingcat.

The Intersection tool creates a new layer containing only the fires that affected the Zingaro Nature Reserve. To create the new layer:

  1. Set the ‘Input layer’ to the EFFIS fires layer.
  2. Set the ‘Overlay layer’ to the Zingaro Nature Reserve polygon layer.
  3. Click ‘Run’.
Screenshot of QGIS Annotations by Bellingcat.

QGIS functionality can be extended through plugins, including Data Plotly, which adds data visualisation tools. To install Data Plotly, open the Plugin Manager by selecting ‘Plugins > Manage and Install Plugins…’ from the menu bar, then:

  1. Search for ‘Data Plotly’ in the available list.
  2. Select the plugin from the search results.
  3. Click ‘Install Plugin’ to download and install it. 
Screenshot of QGIS Annotations by Bellingcat.

Once installed, open the Data Plotly panel with ‘View > Panels > DataPlotly’. The panel should appear on the right-hand side of the QGIS window. 

To plot a graph of historic wildfire activity within the nature reserve, configure Data Plotly as follows:

  1. For ‘Plot type’, choose ‘Bar Plot’.
  2. Set the ‘Layer’ to the newly created ‘Intersection’ layer.
  3. In ‘X field’, type “year(initialdat)”. This expression extracts the year from the fire’s approximate start date, allowing events from the same year to be grouped together. 
  4. In ‘Y field’ enter “$area/1000000”. This expression calculates the burned area within the nature reserve in square kilometres.

Note: EFFIS data provide initial and final dates for each fire, which are approximate because they depend on the availability of satellite imagery. These dates should be treated as bounds for when a fire occurred, rather than as the dates when it started and ended.

Next, switch to the Layout tab in Data Plotly:

  1. Untick ‘Show Legend’. Only do this for simple plots where a legend is not required. 
  2. Add a title and labels for the X and Y axes.
  3. Finally, click ‘Create Plot’ and wait a few seconds for the chart to be generated.
Screenshot of QGIS Annotations by Bellingcat.

The chart shows that the Zingaro Nature Reserve has experienced several significant wildfires over time. However, in 2025, the data show that the fire burned a larger area within the reserve than the major fires recorded in 2020 and 2017.

Bar chart showing the burned area of the Zingaro Nature Reserve between 2015 and 2025. 

Reportable finding: The Zingaro Nature Reserve has experienced three major wildfires since 2015. Of these, the 2025 fire burned a larger area within the reserve than those recorded in 2020 and 2017.

The tools and methods in this guide can be applied to wildfires in many other regions. By combining satellite imagery with environmental and historical datasets, it’s possible to move beyond detection and begin to quantify a fire’s impact. In doing so, you can also place individual incidents in context, revealing whether they are part of a recurring pattern or an unusually severe event.

To learn more about fire detection, see Bellingcat’s guide to NASA FIRMS.

To explore QGIS further, visit the Bellingcat toolkit entry on QGIS.


Merel Zoet and Claire Press contributed to this report.

This guide contains modified Copernicus Sentinel data (2025), processed with Copernicus Browser, as well as data from the European Forest Fire Information System (EFFIS) of the European Commission Joint Research Centre.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

The post Burning Forests: Tools for Tracking and Reporting Wildfire Damage appeared first on bellingcat.

  • ✇bellingcat
  • How to Use AI to Help Find Civilian Harm Miguel Ramalho
    Between February 2022 and September 2025, Bellingcat staff and volunteers collected, geolocated, and shared more than 2,500 incidents of civilian harm following Russia’s full-scale invasion of Ukraine.  As part of this effort, Bellingcat tested a new machine learning model intended to rank Telegram social media posts on their likelihood of containing incidents of civilian harm.  This novel methodology dramatically reduced the search and selection time required, freeing researchers to focus
     

How to Use AI to Help Find Civilian Harm

25 de Junho de 2026, 10:59

Between February 2022 and September 2025, Bellingcat staff and volunteers collected, geolocated, and shared more than 2,500 incidents of civilian harm following Russia’s full-scale invasion of Ukraine. 

As part of this effort, Bellingcat tested a new machine learning model intended to rank Telegram social media posts on their likelihood of containing incidents of civilian harm. 

This novel methodology dramatically reduced the search and selection time required, freeing researchers to focus on verifying incidents of civilian harm – not just searching for them. 

This piece documents our methodology, ethical considerations and lessons learned in the hope that others researching similar topics can benefit from our work. 

Open source research into civilian harm is still a relatively new field and it presents many challenges – one of the biggest is organising and sorting through the huge volume of user generated content being produced to find what is relevant. 

Machine learning, a form of artificial intelligence that uses algorithms to identify patterns from large amounts of data and make predictions, can make this task more efficient.

With ongoing conflicts involving large amounts of civilian harm occurring in Sudan, and much of the Middle East, this guide aims to offer those covering these conflicts an example of how machine learning can be used to help find and sort incidents. You can also access the Code Notebook for our model here.

We defined “civilian harm” not just as civilian deaths or injuries resulting from armed conflict, but also the broader and delayed effects on civilians from mental trauma, loss of livelihood, displacement, destruction of infrastructure and more. This definition was informed by the Protection of Civilians book on civilian harm

Initial Telegram Dataset 

Each Telegram post containing civilian harm which had already been manually verified by researchers was used to build an initial dataset of confirmed cases of civilian harm, which data scientists call positive instances. We collected a total of 5,848 unique URLs for these Telegram posts. For our manual collection we reviewed posts on relevant Telegram channels, working through oldest to newest posts each day. Assuming that a given post made it to our geolocated incidents list, it meant the researcher who flagged it also looked at the posts that appeared before and after it on Telegram and did not flag those ones, so we selected the 10 posts surrounding the verified civilian harm post as our additional dataset of posts that did not contain civilian harm. After excluding any deleted or duplicate posts, we ended up with 48,545 non-civilian harm posts, our negative instances

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

The choice to overrepresent negative instances aims at better reflecting the real world and increasing data available for model training. 

We enriched each URL with metadata from the Telegram API, such as the time of publication, reactions or textual content. As some of these posts had been deleted, we completed the missing data points with previously preserved versions from our Auto Archiver database, only available for the positive instances.

Feature Engineering

Training a machine learning model requires numerical data, as these models compute a prediction score based on mathematical operations.

We built these by converting raw data from our initial dataset, such as keywords signalling potential civilian harm, into numerical scores (or “features”) that the model could interpret, with the aim of increasing the model’s ability to identify patterns. This process, known as feature engineering, can significantly improve model results because it allows data scientists to suggest explicit context knowledge. 

A full list of features we used to train the model can be found in the code notebook accompanying this piece. Many features were directly inspired by researchers’ input from their experiences manually screening cases of civilian harm by sorting through a set number of Telegram channels and inspecting each post individually.

Several of the features used were directly built from the metadata contained in each Telegram post including media_type, day_of_week; or binary ones: forwarded, edited and reply_to

Other features included engagement information: views, forwards, total_reactions, and even individual features for most used emojis including the reaction_crying_face to count 😭 emoji.

Converting Text to Numbers 

To embed the experience from the manual collection process, researchers put together a list of keywords both in Ukrainian and Russian that, to them, signalled posts likely to  show civilian harm. For instance, “Шахед” and “КАБ” translated to “Shahed” and “Guided aerial bomb” respectively. We created a numerical feature to count their frequency. 

In addition, we included several generic English-language keywords which meaningfully signalled potential civilian harm, such as “injured”, “school affected” and “hospital affected” that were only used for generating semantic similarity scores. 

A semantic similarity score is a calculation used to determine the proximity in meaning between different words and phrases. To get the semantic similarity between the post text and each of our keywords, we represented each in a list of numbers via a Sentence Transformer model, which converts words into numerical representations called vectors that a computer can understand. 

We then calculated the level of similarity between each vector using cosine similarity, one of the most popular methods for measuring similarity between two pieces of text.

Due to how embeddings work, this calculation results in a figure on a scale from -1 (no semantic proximity) to 1 (same meaning). For example, the words “hurt” and “injured” would have a high similarity score, while “residential” and “injured” would have a negative score as the words are not semantically similar. 

Finally, to enable the model to identify the relevance of each post to civilian harm in Ukraine, we used a multilingual text transformer from the BERT family of language models to represent the entire post’s text as a vector of 768 numerical values. This model can efficiently represent text from many languages in a way that captures meaning: the same sentence in different languages will generate similar embeddings, and trained machine learning models can detect patterns in the embeddings. 

It is important to note that for this initial prototype of a civilian harm detection model, we did not include any features derived from media content such as photos and videos, although that would be a logical next step in attempting to improve model performance.

Selecting, Training and Evaluating Models

With 54,393 rows of 893 numerical features each, we selected four machine learning algorithms to train our predictive models. 

We chose Logistic Regression as a baseline algorithm due to its simplicity. We also selected three other “best in class” models, Random Forest, XGBoost, and LightGBM. These choices centred on the interpretability of the models and their ability to work on tabular data of this size. For example, we avoided neural networks due to a lack of interpretability and because those models work best with a larger dataset. 

To genuinely assess the performance of the trained models, we split our dataset into three parts:  

  • A training set – the data the models were trained on (60 percent of the full dataset’s rows)
  • A validation set – used for an intermediary evaluation when tuning model parameters (20 percent of all rows)
  • A test set – hidden for the final performance assessment, so the models were evaluated on unseen data (remaining 20 percent of rows)

We used a stratified split to divide the dataset instead of a random split. This method ensured the proportion of positive instances (i.e. confirmed cases of civilian harm) remained consistent across all three sets at about 11 percent.

To measure the performance of machine learning models, we ran them through the test set and measured the number of correct and incorrect predictions. Models output a likelihood between 0 and 1 that each Telegram post contains civilian harm, and we tried to find a cut-off threshold that leads to a good balance between flagging almost every post (0.1) or flagging very few (0.9). 

There are two main types of evaluation metrics to gauge a model’s prediction power. Recall asserts what fraction of positive instances (i.e. known civilian harm posts) were correctly flagged as such. Precision measures the fraction of posts flagged as civilian harm that are indeed civilian harm posts.

Walber, CC BY-SA 4.0, via Wikimedia Commons.

During the training phase, we tuned the models to maximise average precision (PR-AUC), a metric that summarises precision across all recall levels. While this method also accounts for precision, it prioritises recall, which is preferable for this use case as it steers model selection to reduce the number of civilian harm posts that are skipped. 

The following table sorts models from best to worst PR-AUC against a baseline of a coin-flip predictor. ROC-AUC and F1 are two other evaluation metrics included as sanity checks. Simply put, ROC-AUC measures the probability of ranking two instances, one negative and one positive, correctly; F1 balances precision and recall equally and its best cut-off threshold value.

Model test scores comparison, XGBoost stands out in every relevant metric evaluated. 

From these results, we selected XGBoost as our final model as it had the best scores when compared across all metrics.

Interpreting the Model

Because these models are interpretable, we can understand which features are the most useful when predicting whether a post includes civilian harm. The above table shows the top 10 features that most strongly signal the XGBoost model to make a decision:

  • semantic_keywords_similarity: the semantic proximity between the post text and manually selected keywords “casualties”, “damage” and “civilian harm”
  • bert:  the model was able to discern meaning from the text with the same strength as some of the other features in this list – there are three cases of this in the top 10
  • reaction_crying_face: reactions with crying face emojis on the post
  • group_of_messages: whether a post contains multiple media files
  • keywords_in_text: the number of custom Ukrainian or Russian keywords in the post

These results generally tally with what you might expect when selecting Telegram posts for instances of civilian harm, including that posts that generate a lot of emotional engagement and posts using keywords about civilian harm were among those most likely to contain content related to this topic. Not all models had the same top features as XGBoost. In fact, for the Random Forest model the most important feature was the number of crying face emojis present in a post, a soft pattern highlighted by researchers when this methodology was first imagined.

LLM Results and Comparison

Retroactively, we decided to run a sample of the same test dataset through different large language models (LLMs) to gauge their ability to make these same predictions. 

We aimed to include an LLM-generated score as an extra feature for our trained models, which would be captured as relevant if it correlated with the correct predictions. 

To start, we selected two local models, the 1B and 4B variants of Gemma 3 from Google DeepMind, and two cloud-hosted models, Gemini 2.5 flash and Gemini 3.5 flash. With this selection, we hoped to compare results across a wide range of models’ expected performance. 

We generated a 400-row stratified sample (preserving the same proportion of real civilian harm instances) from the test dataset used for the custom models. For each of the four LLM models, we ran two tests: one where only the Telegram post message was sent, and another including both the message and the engineered features (excluding the text embeddings, as the model had direct access to the text). In the prompt for each model, we asked for a score between 0 and 1. We then evaluated the results as we did for the custom models. 

The above table shows that LLMs can indeed extract value from the engineered features. All four LLMs surpassed the baseline Logistic Regression model in our tests, yet none of them performed better than the other custom-trained models, and XGBoost remained the one with the highest PR-AUC. 

Still, Gemini 2.5 Flash performed better than its newer version 3.5 and even achieved a slightly higher best F1 score than any other model. While this is a good result, for the flagging of civilian harm posts, the PR-AUC remains the crucial metric, as it captures the model’s ability to identify infrequent instances of civilian harm while minimising false positives.

Ethical Considerations

Introducing an instrument of automated decision-making into a process of detecting civilian harm brings inherent ethical questions. These include automation bias, or how humans tend to blindly place faith in machine-generated recommendations; algorithmic bias, or how the results of these models echo the same patterns present in the training data, including under- or over-representation of types of civilian harm. 

The decision to test an automated methodology for this particular project came from the fact that there were limited resources for both steps in the process – the detection of potential civilian harm and its actual verification. Historically, we built an enormous backlog of unverified incidents because a lot of time had to be spent on monitoring the most recent events so that potential evidence would be captured and preserved as soon as possible. 

The automation of this process also reduced the exposure of researchers to a significant amount of unpleasant and distressing visual and text content, reducing the burden of exposure to traumatic content. 

For this project, we tried to ameliorate the ethical challenges with a number of strategies including randomly flagging posts not captured by any model, monitoring which features models relied on to make decisions, and by doing historical comparisons of patterns in data. 

Additionally, as stated above, for this initial prototype of a civilian harm detection model we did not include any features derived from the media content itself. In the future, it would be a logical next step in attempting to improve the model performance, to include the media from the posts – but using AI to review actual media comes with additional ethical challenges such as model bias.

Because of the opaque ownership of many LLM companies and their generative nature, the use of LLMs for an extra feature presented additional ethical challenges including privacy and safety concerns considering the sensitive nature of the data. Our model did not rely on LLMs, though we retroactively ran a sample through it. 

How the Model Fits into the Bigger Picture 

After selecting this model, we created a user interface where researchers could view a list of Telegram posts sorted from most to least likely to contain indications of civilian harm. The user interface was designed for quick triage and integration, where a positive confirmation from researchers would instantly send the post to the Auto Archiver (Bellingcat’s tool for preserving digital content) and then transfer it to ATLOS (our internal collaborative verification platform). Bellingcat staff and volunteers could then manually verify incidents. Researcher input was constantly stored so that this data could be used to improve the model in the future. 

Preliminary feedback indicated that the AI model was useful. Not only were we able to reduce time and harm from scouring through dozens of war reporting Telegram channels, researchers also reported that the stream of new posts being added to the verification backlog were capturing real and diverse cases of civilian harm. 

We recognise this model has much room for improvement and is a work in progress. Even though it can illicit diverse civilian harm posts, further tests and improvements (such as improved feature engineering and continuous evaluation) are needed before it can confidently be deployed.

Despite the focus on civilian harm and Telegram (highly popular in Ukraine and Russia), this pipeline is generic and can be adapted to other conflict monitoring tasks. How easily this can be done does depend on how open the social media platform is and whether it is possible to scrape posts from it. Apart from that, it is easy to incorporate new features and data, and cheap to automatically retrain, test and deploy models as the system receives more human input.  

Looking forward, sorting through overwhelming amounts of data in a conflict will continue to be challenging. Hopefully, this methodology can help newsrooms, conflict monitoring organisations, and others find the balance between ethical considerations and resources in order to carry out open source investigations on civilian harm and human rights violations. 


Editor’s note: This article was updated on July 3, 2026, to include a line outlining that the model described is a work in progress.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

The post How to Use AI to Help Find Civilian Harm appeared first on bellingcat.

  • ✇bellingcat
  • Mining China’s ‘Little Red Book’ for Open Source Gold Chu Yang
    The challenges of conducting open-source research in China are well-documented. Consistently named one of the most digitally oppressive countries in the world, China blocks some of the world’s largest social media platforms, such as Facebook, Google, and YouTube. Those that are still accessible are mostly Chinese-owned, strictly regulated and monitored in real time by AI systems as well as tens of thousands of “internet police”.  But despite these strict controls, Chinese apps – which boast m
     

Mining China’s ‘Little Red Book’ for Open Source Gold

20 de Abril de 2026, 09:52

The challenges of conducting open-source research in China are well-documented. Consistently named one of the most digitally oppressive countries in the world, China blocks some of the world’s largest social media platforms, such as Facebook, Google, and YouTube. Those that are still accessible are mostly Chinese-owned, strictly regulated and monitored in real time by AI systems as well as tens of thousands of “internet police”

But despite these strict controls, Chinese apps – which boast more than a billion estimated users – remain an information goldmine for investigative journalists covering stories both within and outside China.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Since most foreign sites are banned, Chinese platforms are the largest resource available to journalists and researchers interested in what’s going on in the world’s second-most populous country. Even when a topic is being censored, patterns in the censorship can themselves serve as investigative leads: a 2020 BuzzFeed News investigation, for example, mapped out detention camps in Xinjiang by examining areas that had been blanked out on China’s Baidu Maps.

With millions of Chinese people living overseas, social media activity by members of the diaspora can also turn into global stories.

Serial rapist Zou Zhenhao, a Chinese PhD student, was jailed in London last year after one of his victims posted a warning on Xiaohongshu, also known as Little Red Book or Rednote, an app popular with young Chinese women living abroad. Another woman Zou had raped reached out to the original poster, who put her in touch with the police – leading to the conviction of a man described by police as possibly one of the worst sexual predators in British history.

Founded in 2013 as a Hong Kong shopping guide, Xiaohongshu has evolved into a lifestyle and e-commerce platform that has been compared with Instagram, Pinterest and Amazon. Last year, it reported about 300 million monthly active users, rivalling some of China’s largest social media platforms.

Xiaohongshu saw a surge in international users in January 2025 amid a threatened ban on short video app TikTok. Photo: VCG via Reuters Connect

The app’s 600 million daily searches by the end of 2024 also accounted for half of market leader Baidu’s search volume, demonstrating that it is emerging as a critical search and discovery engine, not just a social platform.

Although primarily a Chinese-language app, Xiaohongshu gained attention in the English-speaking world last year, when millions of American TikTok users flocked to the platform in anticipation of a TikTok ban under US President Donald Trump. 

Responding to the surge of international users – sparked by the #TikTokRefugees trend – Xiaohongshu rolled out an AI-powered translation feature, making the app more accessible to non-Chinese audiences. This also meant that journalists without Chinese language skills can more easily communicate on and navigate the platform.

Despite its growing popularity both within and outside China, the app is relatively new and underexplored compared to more well-established platforms such as Weibo. 

This guide aims to provide a starting point for those looking to explore Xiaohongshu for open-source investigations, including an overview of its main user demographics, potential topics to explore and strategic search methods specific to the app. 

User Demographics and Topics

According to Xiaohongshu’s official data, the platform’s demographic profile is mainly young, female and urban. As of 2024, 70 percent of its users were women, with half of all users belonging to Gen Z and living in China’s largest cities. 

As previously mentioned, the app has also gained popularity with the Chinese diaspora. Many Chinese nationals living abroad use it as a search engine for local information, posting and searching for content related to their daily lives, from restaurant recommendations and apartment hunting to navigating foreign bureaucracies and finding community resources. 

This demographic profile makes Xiaohongshu particularly well-suited for investigating stories about consumer fraud and urban livability issues. For example, Chinese outlets like Jiemian have used Xiaohongshu posts to expose the grey-market ecosystem of paid reviews and fake endorsements tied to the platform’s e-commerce model, while in 2022, International Financial News traced a mother-and-baby store scam that defrauded over 400 parents back to product recommendation posts on the platform.

Given its predominantly female user base, Xiaohongshu has also evolved into one of China’s most important spaces for feminist discourse and women’s issues. Academic researchers have used content on the platform to analyse local discussions on menstrual shaming, sexual harassment, and the controversial “divorce cooling-off period” introduced in 2021. As Rest of World reported, women have increasingly congregated on Xiaohongshu, where they outnumber male users and have found ways to trick the app’s recommendation algorithm so their posts are shown mostly to other women.

The Relevance of Censorship

Political content and current affairs about China are largely absent from the app – a result of both active censorship and platform design. 

All Chinese social media platforms, including Xiaohongshu, operate under strict content moderation requirements from the Cyberspace Administration of China. A leaked 143-page internal document published by China Digital Times in 2022 revealed how Xiaohongshu censors respond to government directives in “real-time”, blocking content related to politically sensitive topics such as criticism of the Chinese Communist Party, labour strikes and student suicides. Xiaohongshu’s commercial focus also makes it less likely that these topics would be discussed on the platform: as Rest of World reported, the platform functions less like Weibo – a public square for current events – and more like “a giant mall, where shoppers tell each other what to buy”.

Related articles by Bellingcat

The Challenges of Conducting Open Source Research on China
Resources

The Challenges of Conducting Open Source Research on China

Coverage of international affairs is also tightly controlled: only state-owned or state-controlled news organisations can obtain licences to publish original news content. However, content about life abroad, particularly stories about the cost of living, healthcare, or social problems in Western countries, circulates more freely on platforms including Xiaohongshu, and provide journalists with insight into how Chinese diaspora communities engage with local political systems. 

For example, when the 2025 Miss Finland was accused of making anti-Asian gestures, searching for “芬兰小姐” (Miss Finland) and “投诉” (complaint) on Xiaohongshu revealed a trove of collective action: users shared different complaint pathways, posted templates for filing reports, and documented various outcomes from their complaints. 

For such large-scale public events, Xiaohongshu can be both an organising platform and a rich source for tracking how diaspora communities coordinate responses to discrimination, providing journalists with insight into grassroots activism and transnational advocacy networks.

Getting Started

Xiaohongshu is available for download on both Apple’s App Store and Google Play worldwide, or can be accessed via a web browser. In international app stores, the app appears under the name “RedNote,” but this is the same application as Xiaohongshu – content and accounts are shared across both. The key difference is that RedNote users who register with overseas phone numbers are automatically tagged as international users, which affects the content the algorithm surfaces to them.

For users who download the app outside mainland China, Xiaohongshu automatically detects the device language and location. Upon first login, international users are prompted with an option to automatically translate all content into English (or their device language). If enabled, posts and comments will display with translations by default, and the algorithm will prioritise English-language content and posts created by or for international users, such as expat influencers.

For researchers and journalists seeking to observe the platform as Chinese users experience it, consider disabling automatic translation. This allows you to see content as it natively appears and helps you distinguish between posts created for international audiences versus those created for domestic users – a distinction that matters when assessing how representative your sample is for the relevant topic.

The default home feed, or the “Explore” tab, is where the algorithm surfaces content based on your engagement history, location and user profile. The feed uses a grid layout displaying post thumbnails with titles and like counts.

On the top right corner of the screen, the search bar also allows keyword searches across posts, users and topics. Results can be filtered by content type (e.g. notes, videos, users or products) and sorted by relevance or recency.

The search bar on the top right and the Explore page are some of the most relevant features for journalists and researchers on Xiaohongshu. Source: Xiaohongshu

Using the Search Bar

Xiaohongshu’s search function is relatively basic. You can search by keywords and filter by time and location, but the options are general: time filters include “past day,” “past week,” or “past six months,” while location filters offer “same city” or “nearby”. 

For example, searching “Canada” returns posts tagged with that keyword, which you can then sort by recency or proximity. 

Search results for “Canada” in English (left) show mainly travel and tourism-related content, while a search in Chinese (right) shows more content posted in Chinese by Chinese people about living in Canada. Source: Xiaohongshu

For breaking news events, try searching location names or names of individuals involved in the incident, filtering for the most recent posts to capture real-time reactions and on-the-ground accounts before they’re censored or deleted.

Xiaohongshu primarily uses algorithms to curate and push content through personalised feeds. For journalists using Xiaohongshu for investigative purposes, it can be useful to actively search for topics of interest to train your algorithm – the more you search and engage with specific content, the more relevant posts the algorithm will surface to you.

However, if you are researching the platform itself – studying what content Xiaohongshu promotes, how censorship operates, or what narratives dominate – you may want to start from a clean slate. In that case, consider periodically turning off personalised recommendations (Settings → Privacy Settings → Personalisation Options), clearing your browsing history, clearing cached data, or using a fresh account to observe what the platform shows to a “neutral” user.

Language and Lingo

During the influx of “TikTok refugees” in January 2025, Xiaohongshu launched a translation feature for users outside mainland China, enabling the automatic translation of comments and posts. 

However, this does not translate search queries. The platform’s search engine is still optimised for Chinese, though there is a “prioritise English” filter for overseas users, and searching in English will return some results.

Searching for “Canada” in English, with “EN preferred” selected, will mainly return posts in English. Source: Xiaohongshu

But the language you search in shapes far more than just your results – it determines which version of the platform you see. When you search in English or use an international account, the algorithm treats you as a foreign user and surfaces content accordingly: influencers explaining why they love living in China, comparisons showing Chinese life favourably against the West. 

This isn’t a neutral cross-section of the platform – it is a curated bubble. To access what Chinese users actually discuss among themselves, it would be more effective to search in simplified Chinese and, ideally, use a China-registered account if you have access to one. If you don’t read Chinese, you can also consider using a translation tool (Google Translate, DeepL, or an AI assistant) to convert your search terms into simplified Chinese before entering them.

Despite such tools and the in-app translation feature, it is always useful when researching using Chinese platforms to work with a native speaker familiar with the local context. They can flag when an innocuous-seeming term actually carries hidden meaning, and help identify coded conversations about a censored topic.

On Xiaohongshu specifically, this coded language extends beyond political topics to include anything the platform’s algorithm might flag as “vulgar” or promotional. For example, users substitute fruits and neutral terms for body parts or sexual content to avoid being flagged as inappropriate – the peach emoji for buttocks, or 炒菜 (“cooking”) for explicit material. They may also use abbreviations and emojis for commercial terms to evade anti-marketing filters, such as “vx” (the abbreviation of how WeChat is pronounced in Chinese) or “➕绿” (“plus green”, apparently referring to WeChat’s green logo) for WeChat, or “米” (rice) or the moneybag emoji for money.

Advanced Search Strategies

For more sophisticated searching, consider using third-party marketing analytics tools like Xinhong and Qiangu, which can show trending topics, popular posts and engagement metrics, as well as identify key content creators posting about specific subjects. 

For example, on Xinhong, when you search for “Canada” in Chinese, it also shows show trending related searches such as “加拿大总理” (Canadian Prime Minister). Clicking through these suggestions leads to recent posts—for example, posts about Mark Carney’s latest statements at Davos, along with user comments and reactions.

A search on the Xinhong platform for “Canada” in Chinese also suggests related trending topics (in green box) such as “in Canada”, “living in Canada” and “Canadian Prime Minister”. Source: Xinhong, annotation by Bellingcat

While these tools are designed for marketers, they provide journalists with valuable capabilities: tracking how topics evolve, identifying influential voices in specific communities, and discovering related hashtags or discussions that might not surface through basic platform search. These tools often require paid subscriptions but can significantly enhance research efficiency for long-term investigations.

Another valuable feature is Xiaohongshu’s group chat function, where users gather around shared keywords and topics—from city-specific communities to niche interests. These groups are often highly active and provide access to candid community discussions that don’t appear in public posts. To find relevant groups, go to MessagesGroup Square, where you can browse categories or search by keyword and request to join.

Monitoring active group chats related to relevant topics, whether that’s a specific city, industry, or issue, can help journalists and researchers stay updated on emerging issues and detect potential story leads before they become widely visible on public feeds.

Preserving the Evidence

Chinese social media content can disappear quickly and without warning due to censorship, making immediate preservation critical. 

Always take two preservation steps immediately upon discovering relevant content:

First, screenshot the entire post, including the URL, timestamp, username, like/comment counts, and location tags. These metrics establish context and authenticity. Use tools that capture full-page screenshots rather than just visible portions, as posts can be long and comments extensive. Second, archive the web page using services like archive.today or Wayback Machine. Note that these services capture only static content – comments and engagement metrics may not be fully preserved and should be screenshotted separately.

For Xiaohongshu specifically, always preserve the user’s unique ID found in their profile URL when viewed on a browser, which follows the format “user/profile/[unique ID]”. Users can change their display names, but this unique identifier remains constant, allowing you to track accounts over time even after name changes. This is critical for long-term investigations or when monitoring specific sources.

The unique ID of a user can be found in the profile URL on a browser. Source: Xiaohongshu

Xiaohongshu operates under the same legal and censorship constraints as all Chinese social media platforms, and researchers should approach it with appropriate caution. Content moderation is extensive: users who post about sensitive subjects risk having their content removed or their accounts suspended, and the platform is required to comply with government data requests. For researchers, this means the information you find represents only what has survived the censorship process.

That said, Xiaohongshu remains a remarkably rich resource for open-source research. Its strength lies precisely in its apolitical, lifestyle-oriented identity: while political discussion is suppressed, candid conversations about everyday life flourish. For journalists willing to invest in learning the platform’s rhythms, building Chinese-language search skills, and understanding its coded vocabularies, Xiaohongshu offers a window into how ordinary Chinese people talk among themselves – an area that remains largely untapped by international media.


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Mining China’s ‘Little Red Book’ for Open Source Gold appeared first on bellingcat.

  • ✇bellingcat
  • When Satellite Imagery Goes Dark: New Tool Shows Damage in Iran and the Gulf Jake Godin
    Access to open source visuals of the current Iran conflict, which has spread to many parts of the Middle East, continues to be sporadic. Videos and photos from within Iran trickle out on social media as the Iranian internet blackout hinders the flow of digital communication.  In past conflicts, satellite imagery has provided a vital overview of potential damage to both military and civilian infrastructure, especially when there are digital black spots or obstacles to on-the-ground reporting.
     

When Satellite Imagery Goes Dark: New Tool Shows Damage in Iran and the Gulf

7 de Abril de 2026, 10:35

Access to open source visuals of the current Iran conflict, which has spread to many parts of the Middle East, continues to be sporadic. Videos and photos from within Iran trickle out on social media as the Iranian internet blackout hinders the flow of digital communication. 

In past conflicts, satellite imagery has provided a vital overview of potential damage to both military and civilian infrastructure, especially when there are digital black spots or obstacles to on-the-ground reporting. But imagery from commercial providers is becoming increasingly restricted, leaving even those who have access to the most expensive imagery in the dark. 

Shortly after the war in Gaza began in 2023, Bellingcat introduced a free tool authored by University College London lecturer and Bellingcat contributor, Ollie Ballinger, that was able to estimate the number of damaged buildings in a given area. This helped monitor and map the scale of destruction across the territory as Israel’s military operation progressed. 

Bellingcat is now introducing an updated version of the open source tool — called the Iran Conflict Damage Proxy Map — focused on destruction in Iran and the wider Gulf region. 

It can be accessed here.

How it Works


The tool works by conducting a statistical test on Synthetic Aperture Radar (SAR) imagery captured by the Sentinel-1 satellite which is part of the Copernicus mission developed and operated by the European Space Agency. SAR sends pulses of microwaves at the earth’s surface and uses their echo to capture textural information about what it detects. 

The SAR data for the geographic area covered by the tool is put through the Pixel-Wise T-Test (PWTT) damage detection algorithm, which was also developed by Ollie Ballinger. It takes a reference period of one year’s worth of SAR imagery before the onset of the war and calculates a “normal” range within which 99% of the observations fall. It then conducts the same process for imagery in an inference period following the onset of the war, and compares it to the reference period. The core idea is that if a building has become damaged since the beginning of the war, then the “echo” (called backscatter) from that pixel will be consistently outside of the normal range of values for that particular area. Investigators can then further probe potential damage around this highlighted area.

The plot below shows how the process was applied to Gaza and several Syrian, Iraqi and Ukrainian cities. The bars represent the weekly total number of clashes in each place, sourced from the Armed Conflict Location Event (ACLED) dataset. The pre-war reference periods are shaded in blue, spanning one year before the onset of each conflict. The one month inference periods after the respective conflicts  began are shaded in orange. The blue and orange areas are what the tool compares. 

The plot below shows an area with a number of warehouses in Tehran’s southwest. Some of the buildings show clear damage in optical Sentinel-2 imagery (something that has to be accessed outside of the tool via the Copernicus Browser). 

Clicking on the map within the tool generates a chart displaying that pixel’s historical backscatter; the red dotted lines denote a range within which 99% of the pre-war backscatter values fall. In this example, we can see that from March 14 onwards, the backscatter values over this warehouse begin to consistently fall outside of their historical normal range. This could signal that damage has been detected in the area.

Two important aspects of this workflow are that it utilises free and fully open access satellite data, as opposed to commercial satellite services; the second is that it overcomes some key limitations of AI in this domain, the most serious of which is called overfitting. This is where a model trained in one area is deployed in a new unseen area, and fails to generalise. Because we’re only ever comparing each pixel against its own historical baseline, we don’t run into that problem. 

Accuracy


The PWTT has been published in a scientific journal after two years of review.  Its accuracy was  assessed using an original dataset of over two million building footprints labeled by the United Nations, spanning 30 cities across Gaza, Ukraine, Sudan, Syria, and Iraq. Despite being simple and lightweight, the algorithm has been recorded achieving building-level accuracy statistics (AUC=0.87 in the full sample) rivaling state of the art methods that use deep learning and high resolution imagery. The plot below compares building-level predictions from the PWTT against the UN damage annotations in Hostomel, Ukraine. True positives (PWTT and United Nations agree on damage) are shown in red, true negatives are shown in green, false positives in orange, and false negatives in purple. The graphic shows the accuracy of the tool, while also emphasising that further checks on what it highlights should be conducted to draw full conclusions.  

It is important to note that just because the tool may show a high probability of a building or buildings being damaged or destroyed, that doesn’t make it definite. 

It is best to check with any other available imagery — either open source photos and videos that’ve been geolocated by a group such as Geoconfirmed or Sentinel-2 as well as other commercial satellite imagery if it’s up-to-date for the area. At time of publication, Sentinel-2 satellite imagery still offers coverage over the area that the tool focuses on. Other commercial satellite imagery providers have limited their coverage.

What the tool excels at is highlighting and narrowing down areas so that further corroboration or further confirmation can be sought.

Testing the Tool


Using the Iran Conflict Damage Proxy Map, we can spot some of the larger areas of potential damage or destruction that have occurred since the Iran war started. 

Starting from a zoomed-out view of Tehran, there are a few spots that appear with large clusters of high damage probability. Cross-referencing these locations with open source map data from platforms like OpenStreetMap or Wikimapia, we can start finding sites that would make for likely targets – such as military sites.

One example of a potentially damaged site visible in the tool is the Valiasr Barracks in central Tehran, which was struck in the first week of the war. By going to the Copernicus Browser and reviewing the area with optical Sentinel-2 imagery, we can see clear indications of damage at the barracks.

IRGC Valiasr Barracks in Tehran:

Below: Sentinel-2 comparison of February 20 and March 17.

A large Islamic Revolutionary Guard Corps (IRGC) compound near Isfahan is another example of military infrastructure that is readily visible in both the Iran Conflict Damage Proxy Map as well as Sentinel-2 imagery. 

IRGC Ashura Garrison in Isfahan:

Below: Sentinel-2 comparison of February 20 and March 17.

Air bases have also been a frequent target for U.S.-Israeli strikes in Iran. The Fath Air Base just outside of Tehran, near the city of Karaj, shows the signature of potential damage when using the tool. Checking Sentinel-2 imagery shows damage to multiple large buildings on the northern side of the base.

Fath Air Base in Karaj:

Below: Sentinel-2 comparison of February 20 and March 17.

The U.S. has stated that destroying Iran’s “defense industrial base” is also a goal, which makes large areas like the Khojir missile production complex east of Tehran a good location to search with this tool. The tool suggests large clusters of damage on both the eastern and western sides of the complex — near areas where solid propellant is reportedly produced and where other fuel components are reportedly made.

Khojir Missile Production Complex outside of Tehran:

Below: Sentinel-2 comparison of February 20 and March 17.

Usage in the Gulf Region

While useful for providing a sense of damaged areas in Iran, the Iran Conflict Damage Proxy Map can also be used to see damage outside of Iran, particularly at sites in the region which Iran has been targeting with drones and missiles.

In the below example at Al Udeid Air Base in Qatar, which hosts U.S. Central Command’s Combined Air Operations Center, there is a notable indication of damage over a warehouse-like building at 25.115647, 51.333125. Checking the same location in Sentinel-2 imagery shows that there does appear to be damage at that warehouse — represented by a large blackened area on the white roof. According to Qatar’s Ministry of Defense, at least one Iranian ballistic missile struck the base in early March.

Al Udeid Air Base in Qatar:

Below: Sentinel-2 comparison of February 22 and March 14.

Civilian sites struck by Iranian drones or missiles are also visible in the tool — though the damage has to be fairly large in order to be picked up. Something like damage to the sides of high rise buildings from an Iranian drone attack doesn’t readily appear in the tool. Sites that do appear are places like oil refineries, such as a fuel tank at Fujairah port in the United Arab Emirates. 

Fuel tanks at Fujairah Port, UAE:

Below: Sentinel-2 comparison of March 3 and March 28.

Accessing the Tool

It’s important to keep in mind that the data for the Iran Conflict Damage Proxy Map is updated approximately one or two times per week as new satellite data is collected by the Sentinel-1 satellite, so it’s not meant to be a representation of real-time damage to buildings. 

Still, it can be useful for researchers to quickly gain an overview of damage throughout Iran and the Gulf where suspected strikes may have taken place and when there is no other open source information available.

You can access the Iran Conflict Damage Proxy Map here.

Similar tools using the same methodology to assess damage in Ukraine following Russia’s full-scale invasion and Turkey following the 2023 earthquake can be found here. The Gaza Damage Proxy Map can be found here


Bellingcat’s Logan Williams contributed to this report.

This article was updated on April 7, 2026, to note that Sentinel-1 and Sentinel-2 are part of the Copernicus mission developed and operated by the European Space Agency.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post When Satellite Imagery Goes Dark: New Tool Shows Damage in Iran and the Gulf appeared first on bellingcat.

  • ✇bellingcat
  • Explosive Misinformation: A Guide to Mushroom Clouds, ‘Sonic Weapons’ and Disintegration Trevor Ball
    Since launching the military campaign against Iran on Feb. 28, the US and Israel have dropped thousands of bombs on the country. Videos of explosions have become a source of misinformation and misunderstanding, with many of the strikes incorrectly attributed to a particular munition and many explosive effects – seen in footage and images – falsely attributed to “mystery” or illegal weapons. Take the below post that initially suggested (although it said more analysis was required) that the US
     

Explosive Misinformation: A Guide to Mushroom Clouds, ‘Sonic Weapons’ and Disintegration

30 de Março de 2026, 10:46

Since launching the military campaign against Iran on Feb. 28, the US and Israel have dropped thousands of bombs on the country. Videos of explosions have become a source of misinformation and misunderstanding, with many of the strikes incorrectly attributed to a particular munition and many explosive effects – seen in footage and images – falsely attributed to “mystery” or illegal weapons.

Take the below post that initially suggested (although it said more analysis was required) that the US may have used a nuclear weapon in Iran, an outlandish and clearly incorrect claim that experts Bellingcat spoke to had little time for.

The archived video from the post below. You can find the full post, which was set to private after we published the guide, here.

IMPORTANT UPDATE AND NOTE: The following is not a complete assessment and I require more data to verify first use. This is a surface level observation but it must be noted.

☢ The US used what appears to be, without additional details, a nuclear weapon on Iran delivered by a… pic.twitter.com/7ucJNdGyNi

— Korobochka (コロボ) 🇦🇺✝ (@cirnosad) March 11, 2026

The post, set to private after the publication of this guide, appeared to suggest that a nuclear explosion happened in Iran. Source: X/cirnosad

“The video does not show a nuclear explosion—something that I am astonished even needs to be clarified,” Dr NR Jenzen-Jones, Director of Armament Research Services, a weapons intelligence consultancy, told Bellingcat.

Mushroom clouds can form when explosions produce hot gases that quickly rise and encounter resistance from denser, colder air. (Clouds created by nuclear weapons can also vary significantly in appearance.)

Non-nuclear explosive test in Canada. Source: Defence Research and Development Canada.

“Certain types of explosive munitions, such as those working on the fuel-air explosive (FAE) and thermobaric principles, are particularly poorly understood by non-specialists. As a result, these and other types of munitions are routinely misidentified,” Jenzen-Jones said.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Often posts about explosives are incorrect or inaccurate because of a lack of knowledge about how explosives work, but in other cases misinterpretations are deliberate. Joe Dyke, director of programmes at Airwars, told Bellingcat that deliberate disinformation that shifts responsibility of a strike is the most common they see, with posts often sharing flimsy but “scientific sounding” analysis.

Better understanding explosives can make it easier to identify misinformation surrounding explosions. 

This guide explains explosives, their characteristics and the impact they have on people and infrastructure. We highlight the differences between thermobaric and Dense Inert Metal Explosives (DIME), two types of explosives that are frequently the subject of misinformation.

What Are Explosives?

Explosives are energetic materials capable of causing death and destruction through a rapid release of energy. The blast creates pressure waves emanating from the epicentre. These waves can directly kill or injure people and shatter objects into lethal fragments.

High explosives are typically used in warheads and shells; they differ from low explosives which are often used in rocket propellants. The supersonic speed of the explosive reaction- classified as detonation- also separates the two kinds of explosives. During detonation, temperatures can rise above 3,000 °C, but only briefly and very close to the reaction zone, Dr Sabrina Wahler, a Postdoctoral Scholar at the California Institute of Technology focusing on research of detonation products told Bellingcat.

Graphic showing a high explosive with a detonator (initiator or blasting cap) before and after the detonation begins. The chemical reaction zone is shown as the explosive detonates. Source: Justin Baird for Bellingcat.

The detonation creates a shockwave, which is a visible wave or bubble in high speed videos. The shockwave impacts people and objects before the sound of the blast can be heard.

Visible shockwave emanating from the blast, ahead of the fireball or blast wind, in screenshots showing a surface explosion. Source: Defense Threat Reduction Agency (DTRA) Counter-WMD Test Support Division (CXT) via Lawrence Livermore National Lab.

The shockwave is the result of the pressure pushing air away from the blast in the positive phase. When the air rushes back in the negative phase, it creates a suction effect.

Visualisation of pressure phases of an explosion. Source: Justin Baird for Bellingcat.

The shockwave arrival time, combined with a known distance, has been used to estimate the explosive weight of blasts, including the Beirut explosion in 2020.

Reactive materials, such as aluminium powder, are often added to explosives to improve performance. These metals react with the gaseous products from the detonation, resulting in increased energy output, Jacqueline Akhavan, a Professor of Explosive Chemistry at Cranfield University, told Bellingcat.

Ammonium nitrate based Tannerite exploding targets with various amounts of aluminum powder added. Exploding targets are popular and widely available in the United States. Military ordnance also uses similar aluminised explosive compositions. Source: United States Department of Agriculture.

Sometimes, reactive metals such as aluminium from the explosive composition can be seen burning outside the fireball, indicating an explosive with reactive metal.

Photo of ammonium nitrate with aluminium powder exploding. Burning aluminium powder can be seen outside the fireball. Annotation by Bellingcat to indicate some of the burning powder. Source: United States Department of Agriculture.

The size of a fireball does not necessarily indicate the blast’s power. In movies and airshows, a “Hollywood shot” involves igniting large amounts of gasoline with small amounts of explosives, creating spectacular fireballs with minimal pressure.

“Hollywood shot (‘wall of fire’) done with detonation cord and gasoline.” Source: Federal Bureau of Investigation.

Thermobaric, and dense inert metal explosives (DIME), are other types of explosive compositions where metals are added to modify specific effects.

Thermobaric Explosives

In January 2024, after an attack in Gaza, social media posts appeared claiming that thermobaric explosives “literally sucks the air out of the children’s lungs and causes them to internally explode”. According to an article by Dr Rachel Lance, a biomedical engineer specialising in patterns of injury and trauma from explosions “there is no evidence that thermobarics pull the air out of the lungs”. 

There were also claims that thermobaric weapons incinerate people. According to a report by the Armament Research Services, the effects of this type of explosion “are of the same nature as those expected from a conventional high explosive”. The only difference is that the duration of each effect is likely to be longer from a few milliseconds to tens of milliseconds and in a pressure wave with a lower peak.

This occurs because thermobaric explosives add a significant amount of fuel or reactive metals to the explosive composition. Some of the fuel burns after detonation. These munitions are effective against cave or bunker systems, as the pressure wave can travel further throughout the structure.

Graph showing the “pressure history inside the blast wave; high explosive vs.TBX and EBX detonations.” Source: W.A. Trzciński, L. Maiz Thermobaric and enhanced blast explosives – properties and testing methods (Review) via Wiley Online Library.

Visual differences can indicate the types of explosives used. Even within the same category, explosives may appear different because of variations in chemical composition, conditions where the explosion occurs, and video quality.

TÜBİTAK SAGE’den yerli termobarik patlayıcıda yeni bir adım daha!

Kapalı alanlarda yüksek darbe ve sıcaklık etkinliğine sahip yeni bir termobarik patlayıcı💥

TENDÜREK’ten sonra KOR ile geleneksel patlayıcılara göre 4 kat daha yüksek sıcaklık etkinliği 🔥🔥🔥 pic.twitter.com/N4yZ8YvMi9

— TÜBİTAK SAGE (@SageTubitak) March 5, 2020

Comparison of KOR, a thermobaric explosive, and TNT, in a test by TÜBİTAK SAGE, a Turkish Defense Research Organization. Source: X/TÜBİTAK SAGE.

Many countries, including the US, Russia, China, Ukraine, Iran and Turkey, use enhanced blast and thermobaric explosives. Russia has used them in Ukraine and Syria. Israel uses munitions that have variants featuring thermobaric warheads, but the use of thermobaric explosives has not been confirmed.

Fuel-air explosives are similar to thermobaric explosives, but function differently. Both are volumetric weapons, but fuel-air explosives disperse a cloud of fuel, then the explosion occurs.

A video showing a test of a US fuel-air explosive munition. Source: jaglavaksoldier.

Dense Inert Metal Explosives

Unsubstantiated claims of DIME munitions have regularly surfaced since 2006, when they were first alleged to have been used in Gaza. Similar claims have reappeared in Gaza since the war began on Oct. 7, 2023. 

Dense Inert Metal Explosives (DIME) are typically used in munitions intended to reduce civilian harm. Non-reactive metals, like tungsten, added to the explosives reduce the area impacted by the blast, but increase the power. Often munitions filled with DIME replace steel casing with carbon fibre to reduce fragmentation.

Photo of a Dense Inert Metal Explosive (DIME) test by the US Air Force Research Laboratory (AFRL). Non-reactive metal particulates can be seen at the edges of the fireball. Annotation by Bellingcat. Source: US AFRL, 2006.

Some sources refer to DIME as a multiphase blast explosive, a term that also covers some explosives with reactive metals. Photos from testing show mannequins near the blast coated in tungsten powder.

Mannequin coated in tungsten powder following the testing of a GBU-39 A/B FLM, a DIME filled variant of the GBU-39 bomb. Source: ITEA Journal via DTIC.

Some claims of DIME use in Gaza mention the presence of powder or microscopic shrapnel found on victims. “Peppering” and “tattooing” are mentioned (warning: graphic content) as common injuries in blast victims, where the explosion propels small debris like sand into the body, along with fragments of various sizes.

Impacts of fragments and tungsten powder on blocks of ballistic gel at different distances from three tests. Source: Latin American Journal of Solids and Structures, 2024, 21(3), e535.

The US Air Force has accepted delivery of at least 500 DIME-filled GBU-39A/B bombs, and has used at least 23 in combat. No transfers of GBU-39 A/B FLM bombs from the US to any other country, including Israel, have been reported, and a Bellingcat analysis of GBU-39 strikes in Gaza between October 2023 and January 2026 did not find any evidence of this variant being used.

There is currently no conclusive evidence that militaries aside from the US have used DIME in combat.

Clues From Clouds

Clouds, and the colours of the smoke can provide clues about the type of explosive. However, chemical composition, environmental conditions, and location can all affect how explosions appear. 

Clouds

This footage, originally posted on social media in November 2025, shows an explosion in Gaza.

The Israeli army launched thermobaric and pressure bombs, supplied by the United States, on Gaza. These bombs, which burn at a temperature of 3,500 degrees Celsius, are capable of killing thousands in seconds, leaving no trace. pic.twitter.com/pZhoIfsazP

— China pulse 🇨🇳 (@Eng_china5) February 12, 2026

Video of an explosion in Gaza, falsely attributed as a thermobaric weapon. Source: X/@Eng_china5.

The visible cloud in the video is a condensation or Wilson cloud, caused by an explosive shockwave interacting with humid air. This same effect is visible in videos of the Beirut explosion in 2020, when ammonium nitrate exploded at the port after a fire.

Another view of the explosions in Beirut pic.twitter.com/efT5VlpMkj

— Borzou Daragahi 🖊🗒 (@borzou) August 4, 2020

Video of the 2020 Beirut ammonium nitrate explosion. Source: X/Borzou Daragahi.

Smoke colours

Colours in the smoke of an explosion can help identify the gases, which in turn can help identify the explosive material, Dr Rachel Lance told Bellingcat. “Yellow, orange, and red tones each indicate the presence of specific chemicals.” 

Black smoke means “the bomb produced a lot of fire and inefficiency, because materials burned instead of detonated, and was probably a homemade or improvised explosive”. White or light grey smoke indicates “an efficient detonation, and that tells us it was a pure, high-grade material inside,” Lance said.

Left: Reddish-orange smoke after the ammonium nitrate explosion at Beirut in 2020. Centre: Fuel heavy “Hollywood shot” explosion. Right: C4 explosion. Sources: Borzou Daragahi, DVIDS/Lance Cpl. Kayla LeClaire, and DVIDS/Sgt. Tara Fajardo Arteaga.

Some munitions, like cruise or ballistic missiles, may have efficient high explosives, as well as low explosive propellants or fuel. The area targeted, such as buildings, may lead to dust or debris that obscure the gases created by the explosion. 

In some cases, multiple bright fireballs are launched into the sky, accompanied by a rapid humming or throbbing sound and bright flashes. This typically happens when solid-fuel rocket motors, like those in air defence or ballistic missiles, are burning or exploding.

Major secondary explosions after a U.S. airstrike in the vicinity of Higuerote Airport in Venezuela tonight. pic.twitter.com/NrFOVj9IfM

— OSINTtechnical (@Osinttechnical) January 3, 2026

Venezuelan Buk Air Defense System rocket motors ‘cooking off’ after being targeted by US strikes in Jan. 2026. Source: X/Osinttechnical.

Geolocation

Geolocation of the explosion site can help identify or rule out potential explanations. Large explosions can be caused by much smaller bombs hitting storage sites or production sites for ammo. The geolocation of the video below indicated that the location hit was a storage area for missiles.

Qom today looks like it was hit by a GBU 57 bunker buster.

The GBU 57 Massive Ordnance Penetrator is a 30,000 pound bunker busting bomb designed to penetrate deep underground before detonating. pic.twitter.com/d4bGJ19nQb

— Open Source Intel (@Osint613) March 11, 2026

Video shared by a user claiming this video shows the use of a GBU-57 “Massive Ordnance Penetrator”. A now-suspended user claimed the video showed the “Mother of All Bombs”. Source: Osint613.

Blast Effects on People

Misinformation regarding blast effects on people might lead to reports of harm to be wrongly dismissed or false claims about mystery weapons to spread.

In February 2026, claims of “vaporisation” or disintegration of people due to thermobaric weapon explosions appeared online. Days later, counterclaims argued that explosives can’t “disintegrate” people and thermal effects were not responsible.

According to multiple studies, even less powerful explosives can cause disintegration. When explosions occur in enclosed spaces, such as inside a building, they reflect shock waves, leading to increased blast effects.

The effects of the shock wave on some structures can be seen in the first part of this video. Source: Canadian Armed Forces.

Blast injuries are generally classified into four categories, based on what mechanism is causing the injuries.

Categories of blast injuries. Source: Justin Baird for Bellingcat.

The primary effect, the blast itself, “puts tremendous strains on human tissue, causing them to rip and tear, both internally and externally, so massive internal bleeding can occur,” Brian Castner, a weapons investigator for Amnesty International, told Bellingcat.

Primary injuries can lead to a variety of symptoms, including vertigo, vomiting blood, and bleeding from the ears. A viral post shared by the White House Press Secretary claimed to be firsthand testimony from a Venezuelan security guard following US strikes in Venezuela. The post alleged that the US used a sonic weapon without any supporting evidence, and the symptoms described are typical of primary blast injuries.

The secondary effect results from the metal fragments of the munition. Some weapons are specifically designed to break into uniform small pieces, Castner said. “Even small fragments, the size of a bullet, can break a bone, since the metal is flying through the air so quickly,” the weapons investigator explained.

Even single fragments can injure or kill people hundreds of metres away from a blast. People close to it may be largely disintegrated, often described (warning: graphic content) as “total body disruption” in Forensic Medicine.

A non-graphic video showing the destruction that explosives are capable of inflicting on various materials. Source: Ballistic High-Speed.

“Combined, these blast and fragmentary effects can do horrific damage to the human body, and if a person is close enough to a large munitions detonation, leave little trace they ever existed,” Castner told Bellingcat.

A recent Bellingcat investigation into three specific US-made munitions used in Gaza found videos showing small pieces of human bodies consistent with total body disruption, at several different strikes within the dataset.

Screenshot from a video showing one area hit by a GBU-39 bomb at Khadija School, Gaza in July 2024. A separate graphic video shows a boy in this area collecting a small part of a person. Source: X/Eye on Palestine.

Explosions can also cause burns or thermal injuries. Temperature is not the most relevant factor, because “by the time a human body is exposed to the temperatures of a burning explosive, people will have severe trauma and death,” Dr Lance told Bellingcat.

In many real-world cases “the blast pressure reaches farther than the thermal flash,” Dr Sabrina Wahler said. “The thermal danger becomes much larger and longer lasting when the explosion occurs in a confined space, when the formulation supports continued burning with air, or when the detonation triggers secondary fires that keep generating heat well after the initial blast,” she noted.

Flash burns are often seen on exposed parts of the body close to the blast (warning: graphic content). Explosions that start fires or contain incendiary materials can result in severe burns.

Are These Explosives Legal?

Misinformation often raises questions about legality, with false claims that specific weapons are inherently illegal or misrepresenting how they work. This is one of the reasons that nations conduct legal reviews of new weapons, Michael Meier, a former Senior Advisor to the Army Judge Advocate General for Law of War, and current Adjunct Professor at Georgetown University Law Center, told Bellingcat.

Subscribe to the Bellingcat newsletter

Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.

Thermobarics and DIME are legal if their use complies with specific principles of international humanitarian law (IHL) and the law of armed conflict (LOAC), such as proportionate and discriminate use, experts told Bellingcat.

“Even lawful weapons can be used in an unlawful manner”, Michael Meier said. One example is when they are directed against civilians or when they are used in a manner that breaches the principles of distinction or proportionality, he explained.

“The law’s ability to prevent harm is constrained by the compromises between military necessity and humanity made in its creation,” Dr Arthur van Coller, Professor of International Humanitarian Law at the STADIO Higher Education and a legal expert on thermobaric explosives, told Bellingcat.

“As a result, weapons that cause immense destruction may remain lawful (even nuclear weapons) if they fit within legal definitions, even when their humanitarian impact is severe,” van Coller explained.


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Explosive Misinformation: A Guide to Mushroom Clouds, ‘Sonic Weapons’ and Disintegration appeared first on bellingcat.

  • ✇bellingcat
  • Using Bellingcat’s New Open Source Tool to Explore Historical and Spatial Flight Data Logan Williams
    Flight tracking data is an important tool in open source research, but with 100,000 daily flights, it can be difficult to contextualise what a particular aircraft’s movements indicate.  Bellingcat has developed a tool called Turnstone to make it easier to visualise historical trends in flight data and spot unusual patterns. It also allows users to filter by parameters such as aircraft type or a geographic region of interest.  Source: ZUMA Press Wire via Reuters Connect; overlays of Turnsto
     

Using Bellingcat’s New Open Source Tool to Explore Historical and Spatial Flight Data

5 de Março de 2026, 11:29

Flight tracking data is an important tool in open source research, but with 100,000 daily flights, it can be difficult to contextualise what a particular aircraft’s movements indicate. 

Bellingcat has developed a tool called Turnstone to make it easier to visualise historical trends in flight data and spot unusual patterns. It also allows users to filter by parameters such as aircraft type or a geographic region of interest. 

Source: ZUMA Press Wire via Reuters Connect; overlays of Turnstone by Bellingcat

This tool primarily uses Automatic Dependent Surveillance–Broadcast (ADS-B) data, the technology that enables open source investigators and enthusiasts to track flights. 

Most aircraft are equipped with transmitters that broadcast ADS-B data to comply with global aviation regulations, though regulations vary by jurisdiction, and military aircraft might not always transmit. ADS-B data includes information about an aircraft’s identity and type, as well as its precise position, speed and altitude. 

Popular flight-tracking websites such as Flightradar24 and ADS-B Exchange typically display historical data for a particular time or aircraft. However, Turnstone aggregates ADS-B data for multiple aircraft over time, and allows users to search for flights across two areas of interest at once. These features provide additional context for open source investigators to better understand flight behaviour.

Watch the video for a demonstration of how the tool works, using the example of Black Hawk helicopter patrols near one of the borders between the US and Canada:

You can view Turnstone’s source code and information about hosting it yourself on Bellingcat’s GitHub

We also have a web-based instance of the tool that journalists and academics can access. Due to data hosting and processing costs, we can only grant access on a selective basis. If you would like to apply, please fill in this form. Priority will be given to researchers conducting open source investigations aligned with Bellingcat’s goals.

Read on for more examples of how Turnstone can be used for investigations, as well as some limitations of the tool.  

Spotting Unusually High US Tanker Activity Before Iran Strikes

The US and Israel launched joint air strikes across Iran on Feb. 28, 2026, reportedly killing more than 1,000 people, including members of the Iranian leadership, in five days.

This marked a dramatic escalation since the US and Israel bombed three Iranian nuclear sites in June 2025. 

Flight data before both the June 2025 and February 2026 strikes showed a large number of American aerial tankers leaving the US and crossing the Atlantic towards Iran. Aerial tankers such as the KC-135 and KC-46A can refuel military aircraft in-flight, making them essential for most long-range combat missions.

The 9 KC-46As that went to Ben Gurion.

All came direct from the eastern U.S. pic.twitter.com/izANyrqi4Q

— Evergreen Intel (@vcdgf555) February 27, 2026

With Turnstone, it is possible to interrogate the baseline level of movement and see how unusual this activity is.

To do this, three filters are set on the search: a geographic region of interest, set to the North Atlantic, a filter on the aircraft type, to search only for tankers, and a filter on the aircraft heading, to search only for eastbound traffic.

Filtering a search by aircraft type, region of interest, and heading range that captures eastbound traffic. Source: Turnstone/Bellingcat

[Note: For the aircraft category designations, Bellingcat used a custom-prompted large language model (LLM), Claude Sonnet 4.0, to assign a category label using aircraft type code data. There may be some inaccuracies in the classifications, as LLMs are prone to hallucinations. We discuss this further in the “Limitations of the Data” section of this piece.]

This search finds over 40,000 aircraft locations that match these filter queries. However, a look at the summary table shows that this data includes non-American tankers as well.

Results from a filtered search, showing tankers owned by the French Air Force and the United States Air Force. Source: Turnstone/Bellingcat

We can filter this data to include only aircraft associated with the US by typing “United States” into the search box in the table. Note that ownership data is not 100 percent accurate – it may be out of date, especially for privately owned aircraft, and new aircraft might not have any data at all. However, especially when comparing trends over time or searching for research leads, this data can still be useful.

The graph of matching detections over time now shows that while there is a large baseline level of transatlantic movement for American tankers, there was a notably higher number of American tankers heading eastward from the US across the North Atlantic detected in the week of June 15, 2025, as well as in the last two weeks of February 2026.

The weekly graph view on Turnstone shows a noticeable spike in eastbound American tankers crossing the North Atlantic per day from June 15 to June 21, 2025 and from Feb. 15 to Feb. 28, 2026. Source: Turnstone/Bellingcat

A week after the increased eastbound traffic in June 2025, early in the morning on June 22, the US struck several nuclear sites in Iran. And on Feb. 28, 2026, the US and Israel launched over 900 strikes against Iran.

Altering the search query to look for westbound tankers instead of eastbound tankers, we can also see a larger-than-normal number of American tankers heading in the direction of the US during the week of July 13, 2025, bookending the summer airstrikes in Iran. No such return movement is yet visible following the recent strikes.

The number of American tankers heading westward across the North Atlantic, towards the US, appeared higher than usual from July 13 to July 19, 2025. Source: Turnstone/Bellingcat

Finding Deportation Flights to Guantanamo Bay

Turnstone also allows you to search for aircraft detected across two different geographic regions of interest (ROIs). 

Shortly after US President Donald Trump announced the opening of a migrant detention centre at Guantanamo Bay in Cuba at the end of January 2025, the US military reportedly flew about 100 immigrants from El Paso, Texas, to the US naval base to await deportation. By selecting the areas around both Guantanamo Bay and El Paso, we can find flights between these cities that broadcast ADS-B data.

When you select two regions of interest, a filter for the time difference between them also appears. Source: Turnstone/Bellingcat

When two ROIs are selected, you can also enter the maximum time difference between an aircraft’s presence in the two regions. 

In the example below, we have entered 36,000 seconds (10 hours), meaning that the aircraft must have crossed through both regions within 10 hours of each other. We have also set the maximum altitude to 15,000 ft (4.57km) to look for planes landing and taking off. This limit is set relatively high as there are no ADS-B receivers at Guantanamo Bay, and only the initial approach is captured.

Search panel settings for finding aircraft that have been in both Guantanamo Bay and El Paso, Texas, with inputs under the “Maximum Altitude” and “Maximum Time Difference” fields, and selection areas drawn around both areas on the map (in blue). Source: Turnstone/Bellingcat

After five months with no tracked flights between the two locations, this search shows an uptick in flights in the few months from February 2025.

The results from Turnstone come with a bar graph that shows the average aircraft per day by week or by month, which can be further filtered by aircraft hex code (the unique identifier for specific aircraft) or the aircraft type code. Source: Turnstone/Bellingcat

Results for this search query from Jan. 26, 2026, include several passenger aircraft operated by companies known to run deportation flights from the US, such as Omni Air International and Global Crossing Airlines.

Results from a search of flights of up to 10 hours between Guantanamo Bay and El Paso, Texas, conducted on Jan. 26, 2026 show flights owned by Omni Air International and Global Crossing Airlines, both carriers known to operate deportation flights. Source: Turnstone/Bellingcat

Mapping US Customs and Border Patrol Aircraft

Turnstone also supports uploading a list of International Civil Aviation Organization (ICAO) addresses, informally referred to as aircraft “hex codes”, which are unique identifiers assigned to aircraft by ICAO member states.

For example, to explore data related to Department of Homeland Security (DHS) activity and look for patterns related to the US immigration enforcement and border security operations, we can copy and paste the hex codes from a list of US Customs and Border Patrol (CBP) aircraft (used across the DHS) into a text file, and upload that file. Now, we can search among these aircraft with any of the same filters demonstrated in the earlier case studies. Alternatively, we can also deselect all of the filters to track the most recent activity by those aircraft.

Let’s try that with the CBP list, this time with a very large number of results selected: 500,000. Note that increasing the number of results increases the search time and requires more browser memory.

With the list of hex codes provided, the search interface shows “216 hex codes loaded”. No other filters have been selected and the result limit is set to 500,000. Source: Turnstone/Bellingcat

When many points are displayed, the map is simplified, and hover features are disabled.

The results map shows a large number of CBP flights over the US without any filters, from a search of historical data on Jan. 26, 2026. Source: Turnstone/Bellingcat

By the California-Mexico border, Eurocopter AS350 (type “AS50”) can be seen on frequent patrol missions over the land border. Over the Pacific Ocean, Black Hawk helicopters (“H60”) can be seen patrolling the international waters boundary off the Mexican coast, while CBP Dash-8s (“DH8B” and “DH8C”) travel farther offshore.

Zooming in on the area near the California-Mexico border shows an obvious concentration of certain aircraft types in this search of historical data on Jan. 26. 2026. Source: Turnstone/Bellingcat

In contrast, by the Minnesota-Canada border, CBP makes more active use of one of its MQ-9 Reaper drones, as seen from the prevalence of red dots that correspond to “Q9”, the type code of these drones, in the results map.

The dots around the Minnesota-Canada border mainly show activity by MQ-9 Reaper drones in this search of historical data on Jan. 26, 2026. Source: Turnstone/Bellingcat

Let’s take a closer look at these drones by filtering the results with the text “Q9”. Now the displayed aircraft only include MQ-9 Reaper drones.

Results can be filtered by typing into the search field on the top right of the “Aircraft Summary” table. Source: Turnstone/Bellingcat

Now we can take a closer look at the patterns of drones, specifically among the search results.

Left: A very large number of MQ-9 Reaper flights south of San Angelo, Texas. They are coloured by altitude, with green symbols indicating lower flights and red showing those at higher altitudes. Right: The flight pattern of a known Aug. 13, 2025 MQ-9 Reaper mission into Mexico, as shown on Turnstone. Source: Turnstone/Bellingcat

While overall CBP flight activity was relatively stable, drone flights seem to have intensified in December 2025 and January 2026, compared with previous weeks.

The bar graph by week shows a higher average number of MQ-9 Reaper drone flights in December 2025 and January 2026 than in previous weeks. Source: Turnstone/Bellingcat

Limitations of the Data

In open source research, it is always important to be alert to the limitations of a particular data source, and ADS-B data is no exception. 

For example, some aircraft do not have ADS-B transponders and use older transponders to transmit flight information, which can result in tracking tools such as Turnstone showing inaccurate position data. 

In the previous case study of CBP aircraft, the Turnstone results appeared to show an MQ-9 Reaper drone in Canada on Jan. 20, 2026. 

Search results for CBP MQ-9 Reaper drones on Jan. 20, 2026, which appeared to show four instances (circled) of a drone in Canadian airspace. Source: Turnstone/Bellingcat

Is this evidence of covert DHS missions in Canadian airspace? Likely not: a cross-check of the drone’s hex code on that date with ADS-B Exchange shows that the aircraft’s position track is not smooth, but jumps back and forth between a line in the US and several points many kilometres away in Canada.

Screenshot from flight tracking website ADS-B Exchange, appearing to show a CBP drone flying within US airspace but jumping suddenly to the circled points in Canada, several kilometres away. Source: ADS-B Exchange; annotations by Bellingcat

This happens because when ADS-B position data is not available, flight trackers often use multilateration (MLAT), which estimates the location of the aircraft using the time differences between signals transmitted from known sites, as a substitute. The flight tracking information on ADS-B Exchange shows that the position was calculated using MLAT, which is less accurate than position data directly transmitted through ADS-B. ADSB.lol, which is the data source used by Turnstone, uses MLAT when ADS-B position data is not available.  

ADS-B data is also limited by where ground antennas are available to receive radio signals from aircraft and by when aircraft choose to transmit the data.

Other datasets which Bellingcat has used to enable the filters available on Turnstone each have their own limitations. 

There is no single source of data on aircraft ownership. ADS-B data identifies an aircraft only using its ICAO address or hex codes, but does not contain other information that directly specifies the type of aircraft or its registration.

Instead, flight-tracking websites reference aircraft registration databases, such as those maintained by the US Federal Aviation Administration, to correlate ICAO addresses with registration information. The ownership data displayed on Turnstone is from tar1090-db, a community-maintained project which has produced the most comprehensive freely available global aircraft registration database. However, since ownership data is collected from many jurisdictions, with different privacy and disclosure requirements, it may sometimes be out-of-date or misleading. 

Ownership information displayed in Turnstone or any other flight-tracking software should still be verified independently using multiple sources.

For example, one of the aircraft that came up in the search for flights between El Paso and Guantanamo Bay had a hex code of a6b0f5. This showed up in Turnstone’s results as being owned by Bank of Utah Trustee, which matches the operator listed for this flight on ADS-B Exchange. But some of the flight codes used by this aircraft, starting with “GXA”, are used by Global Crossing Airlines (GlobalX). The Bank of Utah is known to legally own aircraft under a trust relationship, while leasing the aircraft and operational control to third parties such as GlobalX.

Screenshot from Turnstone showing aircraft flying between Guantanamo Bay and El Paso, from a historical flight data search on Jan. 26, 2026.

The “Category” label and “Military” flag, which provide a convenient way to filter aircraft, are pre-generated by a custom-prompted large language model, Claude Sonnet 4.0, based on the make and model of an aircraft. 

For example, the LLM may take a type code of A321, which refers to an Airbus A321 passenger jet, as input and assign the corresponding aircraft the category of “airliner”. 

Bellingcat manually verified over 80 per cent of aircraft, corresponding to the most common aircraft types. But as we know, LLMs are prone to hallucinations, and categorisation may be inaccurate for more obscure aircraft. Additionally, some aircraft, such as the V-22 Osprey, fall between categories and are inherently ambiguous. 

To prevent errors caused by the potential miscategorisation of aircraft, you may want to search by type code, which will draw from the raw tar1090-db data, rather than category. All aircraft registration, type, and owner information should be independently verified.

Suggestions and Further Information

As we’ve seen in this guide, Turnstone searches historical ADS-B data to allow researchers to explore flight patterns over time and in specific locations. While flight-tracking data has inherent limitations, Turnstone can provide useful leads for researchers looking to incorporate flight tracking in their investigations.

If you have suggestions for improving the tool, you can submit a pull request on Bellingcat’s GitHub. More technical information can also be found in the tool’s README.

For more demos and information about the history of this tool, watch a talk that Bellingcat gave about it at the What Hackers Yearn (WHY) 2025 hacker camp:


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.

The post Using Bellingcat’s New Open Source Tool to Explore Historical and Spatial Flight Data appeared first on bellingcat.

  • ✇bellingcat
  • Identifying ‘Less-Lethal’ Weapons Used By DHS Agents in US Immigration Raids and Protests Trevor Ball
    To stay up to date on our latest investigations, join Bellingcat’s WhatsApp channel here. Federal agents have frequently used so-called “less-lethal” weapons against protesters, including impact projectiles, tear gas and pepper spray, since the Trump administration’s nationwide immigration raids began last year.  The use of less-lethal weapons (LLWs) has been controversial. While designed to incapacitate or control a person without causing death or permanent injury, they can cause serious
     

Identifying ‘Less-Lethal’ Weapons Used By DHS Agents in US Immigration Raids and Protests

27 de Janeiro de 2026, 13:04

To stay up to date on our latest investigations, join Bellingcat’s WhatsApp channel here.

Federal agents have frequently used so-called “less-lethal” weapons against protesters, including impact projectiles, tear gas and pepper spray, since the Trump administration’s nationwide immigration raids began last year

The use of less-lethal weapons (LLWs) has been controversial. While designed to incapacitate or control a person without causing death or permanent injury, they can cause serious or fatal injuries, especially when used improperly

Earlier this month, two protesters in California were reportedly blinded after US federal agents fired less-lethal rounds at their faces from close range. These incidents were part of a wave of violent clashes between agents from the Department of Homeland Security (DHS) and protesters across the country after the deadly shooting of US citizen Renee Good by an Immigration and Customs Enforcement (ICE) agent in Minneapolis. 

Federal agents armed with less-lethal weapons in Minneapolis on Friday, Jan. 9, 2026. Source: Cristina Matuozzi/Sipa USA via Reuters Connect

In protests in Minneapolis immediately following Good’s death, one Customs and Border Patrol (CBP) officer was captured on camera firing a 40mm less-lethal launcher five times in less than five minutes, with several of these shots appearing to target protesters’ faces, which is against CBP’s own use-of-force policy

A Bellingcat investigation of DHS incidents in October 2025 also found about 30 incidents that appeared to violate a temporary restraining order (TRO) issued by an Illinois judge restricting how DHS agents could use LLWs.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

It is not always obvious whether the use of a LLW is authorised or not, as DHS component agencies such as ICE and CBP have varying guidance on factors such as the level of resistance an individual needs to show before a certain type of force can be used, as well as how specific types of less-lethal weapons and munitions can be used. 

While CBP’s use-of-force policy as of January 2021 is available on its website, ICE does not include specific guidance on less-lethal weapons in its 2023 “Firearms and Use of Force” Directive, and does not appear to have any publicly available policy that outlines this guidance.

DHS did not respond by publication time to Bellingcat’s request for the most recent DHS, CBP and ICE use-of-force policies, or to questions about what less-lethal weapons were authorised for use by the department and its component agencies. 

The DHS use-of-force policy, updated in February 2023, states that the department’s law enforcement officers and agents may use force, including LLWs, “only when no reasonably effective, safe and feasible alternative appears to exist”. It also says agents may only use a level of force that is “objectively reasonable in light of the facts and circumstances” that they face at the time.

DHS has repeatedly defended its use of riot-control weapons in protests across the country, stating that it was “taking reasonable and constitutional measures to uphold the rule of law and protect [its] officers”. 

Here’s how to identify some of the less-lethal weapons that DHS agents, including those from ICE and CBP, have been seen using during recent immigration operations. 

Compressed Air Launchers or ‘PepperBall Guns’

Left: A Border Patrol Agent in Chicago carrying an orange TAC-SF series PepperBall gun in Illinois on Oct. 24, 2025. Right: Agent aiming a Pepperball gun at someone filming them in Illinois on Oct. 19, 2025. Source: Youtube / @BlockClubChicago and Tiktok / @ericcervantes25

Compressed air, or pneumatic launchers, are essentially paintball guns that fire 0.68mm balls which break on impact. Often, this releases a powdered chemical irritant such as oleoresin capsicum (OC) or PavaPowder – the same compounds typically found in pepper spray. 

Compressed air launchers can also be used with other projectiles, such as “marking” projectiles that use paint to mark an individual for later arrest, and projectiles intended to break glass.

These weapons are often referred to as “PepperBall” guns, named after the leading brand PepperBall. However, DHS agents have also been seen carrying compressed air launchers from different brands, such as the FN303, produced by FN America.

Many compressed air launchers resemble standard paintball guns, with a distinct hopper or loader, which holds the ball projectiles, mounted to the top. They also have a compressed air tank that might be mounted to the side, bottom, or inside the buttstock (or back) of the weapon.

Many compressed air launchers, and less-lethal weapons in general, have very bright colours such as orange to distinguish them from lethal weapons. 

The TAC-SF PepperBall gun features a compressed air tank and a top-mounted EL-2 hopper, which has a distinctive shape. Graphic: Justin Baird for Bellingcat
The PepperBall TAC-SA Pro’s hopper is a slightly different shape from the TAC-SF, but serves the same purpose. Graphic: Justin Baird for Bellingcat
PepperBall VKS Pro features a compressed air tank located inside the buttstock and a magazine rather than a top-mounted hopper. Graphic: Justin Baird for Bellingcat

However, some compressed air launchers require closer scrutiny to distinguish them from firearms. 

For example, federal agents have been seen carrying FN303 compressed air launchers in videos of immigration enforcement activities. This weapon may resemble a rifle or other firearm, as it is usually all-black and, unlike the TAC-SF series PepperBall guns, lacks a visible hopper. 

Left: Agent holding an FN303 in California on June 11, 2025. Right: Federal Agent aiming a FN303 compressed air launcher at someone filming them in Illinois on Oct. 7, 2025. Source: TikTok / @anthony.depice and TikTok / @krisvvec

If closer examination is possible, this weapon can be identified by its distinct features, including a circular magazine, side-mounted compressed air tank and a hose connecting the firearm to the air tank.

The FN303’s air tank is mounted on the side and connected to the firearm by a hose. Graphic: Justin Baird for Bellingcat

The January 2021 CBP Use of Force Policy places several restrictions on the use of compressed air launchers, including that they should not be used against small children, the elderly, visibly pregnant women, or people operating a vehicle. It also states that PepperBall guns should not be used within 3 feet “unless the use of deadly force is reasonable and necessary”. When using the FN303, the minimum distance is increased to 10 feet. 

The CBP Use of Force Policy says that the intentional targeting of areas where there is a “substantial risk of serious bodily injury or death is considered a use of deadly force.” Agents are instructed not to target “the head, neck, spine, or groin of the intended subject, unless the use of deadly force is reasonable”. PepperBall and FN America provide similar warnings about avoiding vital areas to prevent serious injury or death.

According to a 2021 report by the US Office of Inspector General, CBP requires its agents to recertify their training to use PepperBall guns and FN303s every year, but ICE does not.   

40mm Launchers

Left: CBP agent “EZ-17” with a B&T GL06 40mm launcher and a belt with a variety of Defense Technology 40mm less lethal munitions, including one Direct Impact OC round and two Direct Impact CS rounds in Illinois on Oct. 24, 2025. Centre: EZ-17 firing a B&T GL06 launcher at a man in Minneapolis on Jan. 7, 2026. Right: A federal agent with a B&T GL06 in Illinois on Oct. 24, 2025. Source: YouTube / Block Club Chicago, X / Dymanh, Facebook / Draco Nesquik

DHS agents also use 40mm launchers to fire “Less-Lethal Specialist Impact and Chemical Munitions (LLSI-CM)”. These launchers resemble military grenade launchers, but are used to fire less-lethal ammunition, including “sponge” rounds that can disperse chemical irritants on impact. 

Federal agents have been seen using or carrying the B&T GL06 launcher in footage of multiple incidents reviewed by Bellingcat. They have also been spotted with other 40mm launchers, including Penn Arms 40mm multi-shot launchers, which have a six-round cylinder magazine. 

The B&T GL06 (pictured) and other 40mm launchers have a visibly wider barrel than compressed air launchers or standard firearms. Graphic: Justin Baird for Bellingcat

There are various less-lethal munitions available for 40mm launchers, including those whose primary function is “pain compliance” through the force of impact, chemical irritants or a combination of both. 

Videos of clashes between Border Patrol agents and protesters show these launchers being used with combination rounds designed to hit the target for pain compliance while also delivering a chemical irritant such as OC or CS. 

Direct Impact munitions by Defense Technology have distinctive rounded sponge foam noses and colours that indicate their chemical fill. Graphic: Justin Baird for Bellingcat

Other munitions dispense chemical irritants or smoke after being launched. For example, in the protests immediately following Good’s death, a Border Patrol agent was seen firing a 40mm munition that released multiple projectiles emitting chemical irritants in a single shot, consistent with the “SKAT Shell” by Defense Technology.

The SKAT Shell by Defense Technology (left) fires multiple projectiles, while the company’s SPEDE-Heat shell launches a single projectile. Graphic: Justin Baird for Bellingcat

Defense Technology’s technical specifications for its 40mm Direct Impact Rounds, which agents have been seen armed with, state that the munitions are considered less-lethal when fired at a minimum safe range of 5 feet and at the large muscle groups of the buttocks, thigh and knees, which “provide sufficient pain stimulus, while greatly reducing serious or life-threatening injuries”.

A DHS Office of Inspector General Report in 2021 noted varying guidance on the use of 40mm launchers among the department’s component agencies: “ICE’s use of force policy indicates that the 40MM launcher is deadly force when fired at someone, while the CBP use of force policy only directs officers not to target a person’s head or neck.”

CBP’s 2021 use-of-force policy states that agents should “not intentionally target the head, neck, groin, spine, or female breast”, and that anyone in custody who has been subject to such munitions should be seen by a medical professional “as soon as practicable”.

As of publication, DHS had not replied to Bellingcat’s questions about whether the department had an internal policy or provided training to staff on the minimum safe distance for 40mm less-lethal launchers as recommended by the manufacturers.

Hand-Thrown Munitions

Top Left: Border Patrol Commander of Operations At Large Greg Bovino with two Triple-Chaser CS Grenades on his vest in Minneapolis on Jan. 8, 2026. Top Right: Person holding a used Pocket Tactical Green Smoke grenade in Minneapolis, Jan. 21, 2026. Bottom Left: Top third of a Triple-Chaser Grenade in Illinois, Oct. 25, 2025. Bottom Right: Used Riot Control CS Grenade in Minneapolis, Jan. 23, 2026. Source: Nick Sortor, Rollofthedice, Bluesky / Unraveled Press, Andrew Hazzard

DHS agents have also been seen throwing some less-lethal munitions, such as flash-bangs, smoke and “tear gas” grenades or canisters by hand. 

These munitions activate a short delay after the grenade is employed. When they activate, flash-bangs or “stun” grenades emit a bright flash of light and a loud sound that is designed to disorient targets. Both smoke grenades and tear gas (also known as “CS gas” or “OC gas”) emit thick smoke, but the former just impedes visibility, whereas the latter also contains chemical irritants that sting the eyes. 

Defense Technology offers smoke grenades with hexachloroethane smoke composition, but most of their smoke grenades use “SAF-Smoke”, a less toxic terephthalic acid smoke composition

Hexachloroethane, while toxic, is not a nerve agent, despite misinformation surrounding the deployment of green colored smoke grenades in Minnesota by DHS personnel. 

The shape and general construction, colour, and any text can help identify these munitions.

Less-lethal munitions typically feature the manufacturer’s logo, the model name of the munition, and the model or part number. The text and manufacturer logo are typically colour-coded to indicate the type of payload the munition has, with blue indicating CS, orange indicating OC, yellow indicating smoke, green indicating a marking composition and black indicating munitions with no chemical payload. 

The “Triple-Chaser” grenade by Defense Technology (left) has three distinct segments that separate after the grenade is thrown, with each emitting smoke or chemical irritants, while other chemical grenades by the same company have a single smooth body (right). Graphic: Justin Baird for Bellingcat

A 2021 analysis by Bellingcat and Newsy found that Defense Technology and Combined Tactical Systems, the two manufacturers which produce most of the less-lethal munitions used by federal agents, both list the model numbers of their products online. Publicly available price lists for Defense Technology and Combined Tactical Systems can also be used to identify specific munitions by their model numbers. 

Part numbers seen on less-lethal munitions recovered in Portland in 2020. Source: Robert Evans/Bellingcat and X / @AnalystMick

CBP’s 2021 use-of-force policy states that hand-thrown munitions are subject to the same restrictions for use as munition launcher-fired impact and chemical munitions. 

Chemical Irritant Sprays

Left: DHS agent using a chemical irritant spray on a protester in Minneapolis on Nov. 25, 2025. Centre: CBP Agent spraying Alex Pretti with what appears to be OC spray moments before he is killed in Minneapolis on Jan. 24, 2026. Right: Federal Agent with a SABRE MK-9 spray threatening to spray a journalist if they do not move back in Minneapolis on Dec. 11, 2025. Source: Reddit / I_May_Have_Weed, TikTok/ShitboxHyundai, Instagram / Status Coup

DHS agents have also been using handheld chemical irritant sprays, often colloquially referred to as “pepper spray” or “mace”.

These sprays come in a variety of sizes and concentrations containing CS, OC, or both. Sprays used by law enforcement usually have a canister size designated “MK-” followed by a number, with higher numbers indicating larger canister sizes. The concentration of chemical irritants contained in the spray is also indicated on the canister.

The .2% MK-9 OC Spray by Defense Technology (left). The MK-9 produced by various companies with various concentrations has been seen often used by federal agents on protestors (right). Graphic: Justin Baird for Bellingcat

The effectiveness of OC sprays is determined by the concentration of major capsaicinoids, which are the active compounds in OC that cause irritation. These sprays are also affected by the type of aerosol dispersion, or stream, used. Different types of streams increase or decrease the range of the spray as well as the coverage area. 

Civilian and law enforcement sprays range from 0.18 percent to 1.33 percent major capsaicinoids, according to SABRE, a producer of law enforcement and civilian sprays. Civilian sprays in the US can have the same major capsaicinoid content as law enforcement sprays, but are restricted to smaller-sized canisters

Subscribe to the Bellingcat newsletter

Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.

Defense Technology sprays have different colour bands to indicate the percentage of major capsaicinoids in the spray for OC. If the spray is CS, the CS concentration is standardised at 2 percent. The company uses a white band for .2 percent, yellow band for .4 percent, orange band for .7 percent, red band for 1.3 percent and a grey band for sprays containing either CS or a combination of OC and CS.

SABRE sells a variety of concentrations and sprays as law enforcement products, including 0.33 percent, 0.67 percent, and 1.33 percent major capsaicinoid concentrations of OC, as well as CS, and combination CS and OC sprays. The specific concentrations of SABRE sprays and the type of stream can also be identified by the text on the canister. 

One Air Force Research Laboratory study found that some sprays may pose a significant risk of severe eye damage due to pressure injuries resulting from large aerosol droplets hitting the eye. 

Defense Technology’s technical specifications recommend a minimum distance of between 3 and 6 feet, depending on the specific spray. SABRE does not publicly provide their minimum safe deployment distances, but a Mesa Police Department document lists a minimum distance of six feet for the SABRE Red MK-9. CBP’s 2021 use-of-force policy does not provide any minimum use distances. 

CBP’s 2021 use-of-force policy states that OC Spray may only be used on individuals offering “active resistance”, and that it should not be used on “small children; visibly pregnant; and operators of motor vehicles”. 

Electronic Control Weapons

Left: Federal Agent pointing an Axon Taser 10 at a bystander who was filming an arrest in Los Angeles in June 2025. Right: DHS Agent with an Axon Taser 10 during an arrest in California on June 24, 2025. Source: Instagram / @dianaluespeciales, Instagram / Joe Knows Ventura

DHS agents have also been seen using electronic control weapons (ECWs), which are colloquially called TASERs after the original weapon invented for law enforcement use, in immigration-related raids. 

ECWs can deliver a shock upon direct contact or launch probes that embed in the targeted person, incapacitating them. 

A shock on contact, or a “drive-stun” feature, delivers localised pain while in direct contact. When properly deployed, the probes send signals to the body that cause muscles to contract. A person’s body “locking up” from muscle contractions is an indicator that an ECW has been deployed. ECWs may be capable of using either or both methods.

ECWs are typically painted a combination of black and bright yellow, but this varies between models. The bright colour of parts of tasers is a common feature to help distinguish an ECW from handguns used by federal agents. When viewed from the front, a circular gun barrel is visible on handguns, while ECWs feature multiple circular probes or rectangular covers on the cartridge. ECWs also usually have flashlights and lasers, although handguns may also be equipped with these features. Some ECWs may make audible sounds when armed or deployed.

The Axon TASER 10. Graphic: Justin Baird for Bellingcat

Axon, the predominant manufacturer of ECWs, produces several models including the TASER 10 and TASER 7. Axon provides a policy guide on recommended use of its TASER models to law enforcement agencies, which recommends targeting below the neck from behind, or the lower torso from the front. It recommends avoiding sensitive areas including the head, face, throat, chest and groin. 

Axon also recommends against using ECWs against small children, the elderly, pregnant people, very thin people and individuals in positions of increased risks such as running, operating a motor vehicle, or in an elevated position “unless the situation justifies an increased risk”.

CBP’s 2021 use-of-force policy, in addition to restricting the use of ECWs against small children, the elderly, visibly pregnant women, and people operating a vehicle, states that they should not be used against someone who is running or handcuffed. However, the policy does state that there may be an exception to the rule against using ECWs on a running person if an agent has a “reasonable belief that the subject presents an imminent threat of injury” to an agent or another person. This threat, according to the policy, must “outweigh the risk of injury to the subject that might occur as a result of an uncontrolled fall while the subject is running”.


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.

The post Identifying ‘Less-Lethal’ Weapons Used By DHS Agents in US Immigration Raids and Protests appeared first on bellingcat.

❌
❌