CTI Academy
Log in Create account

Sock Puppet Accounts: How OSINT Analysts Build Personas

By CTI Academy Team

Sock puppet accounts are a professional research tool with a legal edge: how analysts build one, what platform detection catches, and where the law bites.

Most research accounts are not burned by clever adversaries. They are burned by the analyst who made them. A stray like, a photograph with the coordinates still in it, a login from the office network at nine in the morning. The persona survives the criminals and dies of housekeeping.

That is one of the two failures worth writing about, and the second one is quieter. Far more research accounts are created without anyone's written permission than are ever exposed, and an account made that way is not a research asset at all. It is a liability sitting on your employer's books with your name attached to it, and the moment it produces something a lawyer has to look at, the absence of that permission is the first thing anyone notices.

Most practitioners still call these sock puppet accounts, and the search traffic for the phrase reflects that even though, as the next section covers, the term itself is falling out of professional use.

This is a working guide for analysts and investigators operating with authorisation, and it stops deliberately short of anything that only serves deception: no impersonating real people, no fabricated documents, and no techniques whose only purpose is defeating a platform's fraud controls. Every value in the worked example is invented. Let me walk through why the standard advice has aged badly, the six-step method itself, and how to tell whether the account you built is actually working.

Six step vertical flow from authorisation through to retirement with the authorisation step marked as the one people skip

The research account method. Only the first step is a decision rather than a technique, and it is the one that gets skipped.

Why Research Accounts Fail, and When It Matters

The failure mode is boring, which is exactly why it keeps happening. Almost every burned persona traces back to a crossover between the analyst's real life and the operational one, or to a moment of interaction that was never supposed to happen, and neither requires the other side to be sophisticated.

What has changed is the cost of that mistake. Europol, in its 2026 Internet Organised Crime Threat Assessment, describes users migrating from legacy communities such as BreachForums and XSS towards smaller, invitation-only spaces, including closed groups on platforms like Telegram, and notes that smaller communities improve the operational security of the platform by limiting exposure and enable administrators to vet or restrict memberships.

A theatrical costume on a rail seen from behind, showing lining, raw seams, chalk marks and hanging tape

Figure 1: A persona only works from one angle. Everything that gives it away sits on the side the analyst is looking at while they work: the account they were already logged into, the file they exported with its metadata intact, the network the login came from. The costume is rarely the problem. The dressing room is.

Read that alongside the rest of the same assessment and the consequence is clear. Europol records that when forums collapse, user migration is rapid and successor forums emerge within weeks, sometimes backed by the same core actors. An analyst who loses an account loses standing in a space that has already moved on.

An account that takes three months to build is not disposable. Treat it like a source, not like a browser tab.

What the Standard Advice Gets Wrong

Almost every published guide on this subject says the same two things, and one of them has aged badly. The first is the name. Raymond James Todd, writing on osint.uk in September 2024, argues that the term sock puppet is not professionally appropriate and may introduce bias, particularly in legal settings. The phrase arrived from forum astroturfing rather than from investigation.

The second is the legal line, and this is the one to look at properly. The SANS Institute guidance, published in April 2023, states that creating fake accounts violates some platforms' terms of service but that this is not usually illegal, and tells the reader to check organizational policy for permission. That was the settled reading for years.

It is no longer the whole picture. In a paper presented at the ACM Symposium on Computer Science and Law in March 2025, Madelyne Xiao, Andrew Sellars and Sarah Scheffler name sock puppets directly in a list of research methodologies that anti-fraud law reaches, alongside penetration testing, web scraping, user studies and social engineering. Their argument is that the reduced application of the Computer Fraud and Abuse Act has led to a popular belief that most legal risks for platform research are now exclusively questions of civil liability, and that this belief is incomplete.

The place the risk actually lives, in their reading, is elsewhere in the statute book. They point to federal wire fraud and to identity fraud law rather than to computer misuse law, and note that the Supreme Court narrowed the Computer Fraud and Abuse Act in Van Buren in 2021 and the Department of Justice announced a good-faith research charging policy the year after. Neither touches fraud law. The authors describe their own study being blocked by exactly that.

There is also a route the standard advice never mentions, because it did not exist when most of that advice was written. For questions about systemic risks on large platforms, the European Commission's delegated act on researcher data access entered into force on 29 October 2025. A researcher affiliated with a research institution who commits to publishing results free of charge can now request platform data lawfully rather than collecting it by hand.

Not every question fits that route. But an analyst who has never checked whether it does is choosing the riskier method by default.

The distinction that matters is not how convincing the persona looks, it is whether it ever speaks. Todd splits covert research accounts into two kinds: passive collection accounts, which are primarily observational and collect from public profiles and open discussions without direct interaction, and active undercover accounts, which involve direct engagement with subjects, joining closed groups and participating in community activities — the same terrain covered from the collection side in what HUMINT means in a cybersecurity context.

That line is where the legal exposure changes, and in some jurisdictions it is written down. Steve Adams, describing UK police guidance in 2020, states that creating and using a false persona must only be done by someone trained to conduct Level 2 or above open source activity under the National Police Chiefs' Council scheme. Level 5 activity, he adds, is undercover work involving direct interaction with the subject of an investigation. The specific scheme is British and dated, and the shape of it is not: observing is one authorisation, talking is another.

A printed authorisation form open in a card folder on a desk, carrying a wet ink signature and a date stamp

Figure 3: Authorisation is a document, a name and a date, not a conversation someone half remembers. The value of writing it down is not bureaucratic: it fixes the scope before curiosity widens it, and it is the artefact that answers the first question anyone asks when a persona later turns up in a disclosure bundle or a complaint.

Todd frames the ethical test the same way, arguing that investigators should employ the least intrusive method that can effectively achieve their goals. Applied here, that means a passive account is the default and an active one needs a reason that survives being written down.

The professional bodies have started to catch up. The OSINT Foundation published an OSINT Policy Framework on 9 February 2026, and is explicit that it should not be considered directive for intelligence community agencies but delineates best practices relative to OSINT activities. This discipline still has guidance rather than regulation.

There is one rule that decides whether any of the rest of this matters, and it is worth stating flatly:

An account you created without written authorisation is not a research account. It is a fake account you made at work.

Reinforce it with the practical habit: no persona exists before the paperwork does.

Observing is one permission. Speaking is another.

How to Build an OSINT Persona: The Method in Six Steps

The method below is six steps, and only the first is a decision rather than a technique. The other five are craft, and craft can be redone when it goes wrong.

Authorisation. Get written permission naming the purpose, the scope and the end date before the account exists. Scope means the spaces the persona may enter and the actions it may take. An open-ended authorisation is how a narrow approval turns into a standing capability nobody reviews.

Legend. Write down who the persona is, what it plausibly wants, and where it would already be. A legend is not a backstory for entertainment; it is the thing that keeps three different analysts consistent when they take turns on the same account, and it is what stops a persona from developing interests that only make sense to an investigator. Building a plausible legend draws on the same groundwork as the psychological tactics behind social engineering: a persona that has no want, no history and no plausible reason to be present reads as fake for the same reasons a pretext call does.

Separation. Give it its own browser profile, its own email, its own phone verification path, and no crossover with anything personal. Paulo Bingue's guidance on osint.uk is blunt about the first of those, telling investigators never to use a personal email and to create a clean new address, and recommends browser containers so cookies stay separate and accounts do not cross-contaminate.

Registration. Create the account where that persona would plausibly live rather than where you happen to need it. An account whose entire history begins in the space you are investigating reads as exactly what it is, and the platform notices this long before a human does.

Ageing. Let the account exist for weeks without asking the platform for anything. Bingue's advice is to keep accounts active to avoid suspension by logging in regularly and engaging minimally, which is the balance to aim for: present enough to look ordinary, quiet enough to look uninteresting.

Observation and retirement. Collect inside the authorised scope, then retire the account before it is burned rather than after. A retired persona that was never exposed can sometimes be reused on a related matter. One that was exposed is evidence about you.

Five of those steps are things you can learn.

The first is something you have to be given.

A Worked Example: Building One for a Freight Fraud Watch

Here is the whole method run once, with every value invented. The task is a watching brief on a set of public groups where hauliers and freight brokers advertise loads, because a client believes their branding is being used to solicit deposits from drivers.

The authorisation names that purpose, limits the persona to observation in public and open groups, and expires on a fixed date. The legend follows from the task rather than the other way round: someone who reads those groups without contributing much and who would plausibly have been in them for a while already.

A four field persona legend record with the hard limits field highlighted, carrying invented sample values

Figure 2: The legend written out as a record rather than held in someone's head. The third field is the one that does the compliance work, because it converts a vague instruction to be careful into a list of specific actions the persona is not permitted to take. Every value shown is invented, and the record is drawn rather than captured, but the four fields are the ones a real legend carries.

Separation is then mechanical. A dedicated browser profile, an email created for this persona and nothing else, a phone verification path that touches nothing personal, and a note in the case file naming the machine and the network it is used from. Registration follows the legend, which here means joining general haulage groups first and reaching the groups of interest weeks later.

A dedicated corner workstation with one closed laptop, its own small router and a single labelled cable to the wall

Figure 4: Separation is easier to keep when it occupies a place rather than a policy. A second browser profile can be opened by accident on a tired afternoon, while a second desk with its own connection cannot. The labelled cable is the part that matters: it makes the boundary something a colleague can see and a supervisor can audit.

Then nothing happens for a month, on purpose. The account reads, scrolls and occasionally saves a post. It joins no closed groups, sends no messages and follows nobody connected to the matter, because the authorisation does not permit any of that.

By the time the persona is useful, the analyst who built it has done almost nothing with it.

That is what a working one looks like.

How Good Platform Detection Has Become

The assumption underneath most persona guidance is that platforms cannot really tell, and the evidence published in 2026 says otherwise. In its integrity reporting published on 27 August 2026, Meta described removing a network that included 4 Facebook accounts and 31 Instagram accounts and had amassed more than 79,000 followers.

The detail that should interest an analyst is not the size. Meta describes the operation as running sophisticated operational security, including the exclusive use of United States and Canadian proxy infrastructure and personas posing as American activists and students, and says it was able to discover the network through its own proactive internal detection and attribute it to actors in Iran.

Many identical footprints in fine sand forming a repeating rhythm that is visible only from above

Figure 5: Detection at platform scale does not look for the one mistake an analyst worries about. It looks for the rhythm underneath a set of accounts: when they are created, how they are cabled to the same infrastructure, how similarly they behave. Any single step in that pattern is ordinary, which is why an operation can be careful step by step and still be obvious in aggregate.

Consider what that means for a two-account setup run by someone with a day job. A state-linked operation with dedicated proxy infrastructure and a consistent cover story was found from the inside, without a tip-off. Nothing in an analyst's toolkit is stronger than that operation's tradecraft was.

The honest conclusion is not that personas are pointless. It is that they should be built to survive scrutiny from the people you are researching, and assumed to be legible to the platform hosting them.

The Failure Modes Practitioners Actually Hit

Five failures account for most burned accounts, and none of them involves sophistication on the other side.

Crossover. The persona and the person share something: a device, a network, a payment method, a recovery email, a phone number, a photograph taken in the same room. Almost every published account of a burned persona reduces to one of these, and they are all decisions made once and forgotten.

Interaction that was not authorised. A like, a follow, a comment left while tired. This is where the passive and active distinction stops being paperwork, because a passive account that interacts has become an active one without anyone approving it.

The account that was never authorised at all. It works fine for months, produces something useful, and then somebody asks under what authority it was created. There is no technical remedy for this at the point the question is asked.

Reuse across unrelated cases. One persona used on three matters correlates those three matters for anyone who notices, and it means a single exposure costs all of them at once rather than one.

Metadata in the output. Coordinates left in an exported image, an author name in a document, a timestamp pattern that matches an office timezone. The persona holds and the analyst leaks through what they publish about it.

Every one of those is an ordinary lapse rather than a defeat.

The counter to all five is the same, and it is a written procedure rather than a better tool.

How to Tell Whether It Worked

An account that has not been suspended is not the same as an account that is working. Suspension is the only feedback a platform gives, it arrives late, and it says nothing about whether the persona is producing intelligence or simply existing quietly.

Two people at a table comparing a printed activity log against a second stapled document, one tracing a line by hand

Figure 6: Reviewing a persona is a reading exercise done by two people, because the analyst who ran the account is the worst person to judge whether it stayed inside its scope. The second document on the table is the authorisation, and the whole review is the comparison between what it permitted and what the log shows actually happened.

Four checks tell you more than the account status does:

Run those four on a schedule rather than after an incident. A persona that fails one of them quietly is more dangerous than one that gets suspended loudly, because the second kind tells you.

Where This Fits in the Analyst's Week

For most CTI functions, the research account is not the interesting part of the work. It is plumbing, and everything downstream inherits its problems: intelligence collected outside an authorisation is awkward to use, a burned persona costs access to a space that will not readmit you, and a case built on an account nobody approved has a hole in it that appears at the worst moment.

The judgment worth building is knowing when not to make one. A passive account is the default, an active one needs a reason that survives being written down, and for some questions on large platforms there is now a lawful data-access route that removes the need for a persona entirely. Analysts who reach for a new account first, and ask what it is for second, produce more risk than intelligence. The ones who write the legend before the login tend to still have the account a year later.

This is exactly the kind of discipline CTI Academy's Hunter track builds through practice rather than memorization. If the collection workflow above is new territory, start with OSINT: the complete guide. The Open Source Intelligence (OSINT) course puts the collection workflow in front of you, so that scoping a task before opening a browser becomes the habit. Fake Social Media Accounts and Rogue Application Threats works the same material from the opposite side, teaching you to recognise inauthentic accounts, which is the fastest way to understand what makes your own legible. Read the method here, then go build the reflexes. To start, explore the Advanced OSINT Investigations learning path.

Research current as of 2026-09-02. Figures reflect the reporting periods named alongside them.

Frequently Asked Questions

What is a sock puppet account?

A sock puppet account, more properly called a covert or research account, is a fictitious online identity an investigator uses to conceal their real identity while collecting open source intelligence. SANS defines it as an online fictitious identity used to conceal the true identity of the investigator. Many practitioners avoid the term itself in professional settings.

Are sock puppet accounts legal?

It depends on jurisdiction and on what the account does. Creating one usually breaches a platform's terms of service without being a crime, but researchers at Princeton, Boston University and Carnegie Mellon argued in March 2025 that anti-fraud and identity-fraud law reaches research methods including sock puppets, so the civil-only assumption is incomplete.

What is the difference between a passive and an active research account?

A passive collection account observes only, gathering information from public profiles and open discussions without interacting. An active undercover account engages directly with subjects, joins closed groups and participates. The distinction matters because the second usually needs a higher level of authorisation, and in UK policing it maps to a different training and approval level entirely.

Do you need authorisation to create a research account?

Yes, in any professional setting. SANS tells investigators to confirm their organization's policy permits it before creating one, and UK police guidance restricts false persona use to staff trained to a specified level. Written authorisation naming the purpose, the scope and an end date is the practical standard, because it is what any later review asks for.

Can platforms detect research accounts?

Yes, more reliably than most guidance assumes. Meta reported in August 2026 that it removed a network of 4 Facebook accounts and 31 Instagram accounts with more than 79,000 followers, which used dedicated proxy infrastructure and consistent personas, and stated it found the network through its own proactive internal detection rather than an external report.

Should you use a VPN when creating a research account?

Not at the moment of creation, according to SANS guidance, because platforms commonly flag traffic from commercial VPN ranges during sign-up. The broader principle matters more than the specific tool: the account should be created and used from a network path that is consistent with the persona and completely separate from the analyst's own.

What should an OSINT research account never do?

It should never impersonate a real, identifiable person, never interact with subjects unless an authorisation specifically permits that, and never share a device, network, email, phone number or payment method with the analyst's real identity. Any of those crossovers can expose the investigator and can compromise the admissibility of what was collected.


Sources

Continue with the Advanced OSINT Investigations Learning Path

Start Learning Path

Related Articles

Read more at CTI Academy Blog