# OSINT Box — iMac 2011

## Hardware

Component Spec Status
———–————–
Model iMac 2011 (Sandy Bridge) ✅ On desk
CPU Originally i3 → Upgrading to i7-2600S ⏳ Ordered from China (1 week)
RAM 16GB ✅ Ready
Storage 500GB Crucial SSD ✅ Ready

## Architecture (planned)

``` iMac (Debian 12 + XFCE) ├── Tailscale (LAN mesh — remote access from kaburuaibox) ├── WireGuard client → Hetzner CX22 (clean IP exit) ├── Tor proxy (per-tool or per-VM — TBD on build) │ ├── VM A: Hetzner WireGuard (daily OSINT — scrapers, recon, browsing) ├── VM B: Tor (dark web / forums) ├── VM C: Burner (per-operation, snapshotted, rollback on shutdown) │ └── MCP: kaburu-shell-mcp-osint.py (SSH via Tailscale) ```

## Egress Paths (multi-option)

Path Speed Anonymity Best For
————-———–———-
Hetzner CX22 Fast Medium Daily ops
Tor (on iMac) Slow High Threat actor forums, dark web
Open WiFi Depends Very high Physical recon, burner ops
LoRa kbps Maximum Exfil-only, emergency signal

## OSINT Tool Baseline

Category Tools
———-——-
Recon theHarvester, Recon-ng, SpiderFoot, Amass, Sublist3r
Social/Persona Sherlock, Holehe, Maigret, Twint
Infrastructure Shodan CLI, Nmap, DNSRecon, whois, Dig
Browser Firefox + Multi-Account Containers + FoxyProxy
Threat Intel MISP light, feed-based, or OpenCTI (TBD)

## Prep (Week 1 — waiting for CPU)

- [ ] TOMORROW: Configure Agent Reach channels on kaburuaibox (gh auth, cookies, Exa MCP) - [ ] TOMORROW: Research Clay.com integration — data enrichment for OSINT workflows - [ ] TOMORROW: Set up HA voice pipeline — custom conversation agent → Hermes API - [ ] TOMORROW: RustDesk + Divi collab workflow — guide Steve through visual builds - [ ] Spin up Hetzner CX22 on separate account (€3.99/mo) — no link to kaburu.cc - [ ] Install WireGuard server on CX22 - [ ] Write Debian 12 build guide - [ ] Pre-fab `kaburu-shell-mcp-osint.py` (MCP tool for iMac management) - [ ] Wiki page (done) - [ ] Syncthing installed — desktop/laptop connect syncthing - [ ] Agent Reach installed (4/13 channels) — config pending

## Voice Pipeline (HA → Hermes)

Goal: Steve speaks to any Home Assistant voice device and I hear/respond directly.

``` Device → HA Assist (STT) → Custom Conversation Agent → Hermes API → response → TTS ```

Devices available: - Home Assistant Voice 0935ac - M5Stack Atom Echo (ESP32-S3) - Echo Show 5 (via Alexa) - Pixel 9 / Motorola Edge 20 Pro (HA companion app)

## Divi Collab (RustDesk)

Goal: Steve remotes in via RustDesk, I guide real-time design decisions. - Steve: hands — clicks, drags, places modules in Divi Builder - Gwen: brain — design logic, colour theory, layout structure, responsive fixes - : We work as a two-person team on visual builds

## Separate Hermes Instance

The iMac will run its own Hermes instance with: - Different API key - Different model - Zero access to any Kaburu MSP infrastructure - If the box is popped, it leads to a burner Hetzner account and throwaway AI key — nothing else

## Notes

- Hetzner does NOT allow Tor exit relays — Tor stays on the iMac, not on any Hetzner instance - Tor routing decision deferred — will decide per-tool vs. transparent proxy when hardware is live - Blackbeard ISP research — started 2026-06-21, needs more info to identify - 10 spare machines available — if this rig burns, next one is ready