# OSINT Box — iMac 2011 ## Hardware | Component | Spec | Status | |-----------|------|--------| | Model | iMac 2011 (Sandy Bridge) | ✅ On desk | | CPU | Originally i3 → Upgrading to i7-2600S | ⏳ Ordered from China (1 week) | | RAM | 16GB | ✅ Ready | | Storage | 500GB Crucial SSD | ✅ Ready | ## Architecture (planned) ``` iMac (Debian 12 + XFCE) ├── Tailscale (LAN mesh — remote access from kaburuaibox) ├── WireGuard client → Hetzner CX22 (clean IP exit) ├── Tor proxy (per-tool or per-VM — TBD on build) │ ├── VM A: Hetzner WireGuard (daily OSINT — scrapers, recon, browsing) ├── VM B: Tor (dark web / forums) ├── VM C: Burner (per-operation, snapshotted, rollback on shutdown) │ └── MCP: kaburu-shell-mcp-osint.py (SSH via Tailscale) ``` ## Egress Paths (multi-option) | Path | Speed | Anonymity | Best For | |------|-------|-----------|----------| | Hetzner CX22 | Fast | Medium | Daily ops | | Tor (on iMac) | Slow | High | Threat actor forums, dark web | | Open WiFi | Depends | Very high | Physical recon, burner ops | | LoRa | kbps | Maximum | Exfil-only, emergency signal | ## OSINT Tool Baseline | Category | Tools | |----------|-------| | Recon | theHarvester, Recon-ng, SpiderFoot, Amass, Sublist3r | | Social/Persona | Sherlock, Holehe, Maigret, Twint | | Infrastructure | Shodan CLI, Nmap, DNSRecon, whois, Dig | | Browser | Firefox + Multi-Account Containers + FoxyProxy | | Threat Intel | MISP light, feed-based, or OpenCTI (TBD) | ## Prep (Week 1 — waiting for CPU) - [ ] **TOMORROW:** Configure Agent Reach channels on kaburuaibox (gh auth, cookies, Exa MCP) - [ ] **TOMORROW:** Research Clay.com integration — data enrichment for OSINT workflows - [ ] **TOMORROW:** Set up HA voice pipeline — custom conversation agent → Hermes API - [ ] **TOMORROW:** RustDesk + Divi collab workflow — guide Steve through visual builds - [ ] Spin up Hetzner CX22 on **separate account** (€3.99/mo) — no link to kaburu.cc - [ ] Install WireGuard server on CX22 - [ ] Write Debian 12 build guide - [ ] Pre-fab `kaburu-shell-mcp-osint.py` (MCP tool for iMac management) - [ ] Wiki page (done) - [ ] Syncthing installed — desktop/laptop connect [[syncthing]] - [ ] Agent Reach installed (4/13 channels) — config pending ## Voice Pipeline (HA → Hermes) Goal: Steve speaks to any Home Assistant voice device and I hear/respond directly. ``` Device → HA Assist (STT) → Custom Conversation Agent → Hermes API → response → TTS ``` Devices available: - Home Assistant Voice 0935ac - M5Stack Atom Echo (ESP32-S3) - Echo Show 5 (via Alexa) - Pixel 9 / Motorola Edge 20 Pro (HA companion app) ## Divi Collab (RustDesk) Goal: Steve remotes in via RustDesk, I guide real-time design decisions. - **Steve:** hands — clicks, drags, places modules in Divi Builder - **Gwen:** brain — design logic, colour theory, layout structure, responsive fixes - : We work as a two-person team on visual builds ## Separate Hermes Instance The iMac will run its own Hermes instance with: - Different API key - Different model - Zero access to any Kaburu MSP infrastructure - If the box is popped, it leads to a burner Hetzner account and throwaway AI key — nothing else ## Notes - **Hetzner does NOT allow Tor exit relays** — Tor stays on the iMac, not on any Hetzner instance - **Tor routing decision deferred** — will decide per-tool vs. transparent proxy when hardware is live - **Blackbeard ISP research** — started 2026-06-21, needs more info to identify - **10 spare machines available** — if this rig burns, next one is ready