REQUEST YOUR COPY OF THE FLASH BRIEFING
OR EMAIL US AT INFO@FIVECAST.COM:
Cross-Platform Threat Detection From Iranian Telegram Activity
See how OSINT analysts extended Telegram findings into a full cross-platform investigation using Fivecast ONYX.
In this investigation, analysts moved from single-source Telegram monitoring to a comprehensive, cross-platform view of threat activity. The result was a clearer picture of how narratives, actors, and indicators tied to Iranian Telegram channels propagate across the wider information environment.
How do analysts detect threats in Iranian Telegram channels?
Analysts began by reviewing Telegram channels referencing military targets and hacking-group activity, using entity and hashtag extraction to surface key locations, accounts, and topics. The extracted data narrowed quickly to a shortlist of high-value installations, including camps in Kuwait and air bases in Jordan.
What does cross-platform threat detection reveal?
Mapping relationships between accounts showed how alleged targeting information, coordinates, and imagery were repeated and amplified beyond Telegram. One IRGC-labeled channel that posted alleged coordinates for a military hangar was also linked to a known OSINT account on another platform.
What you’ll learn
- How entity and hashtag extraction narrows Telegram noise to a prioritized shortlist of leads
- How extracted locations tie posts to specific military installations
- How relationship mapping traces alleged targeting information across accounts
- How a single Telegram channel connects to an OSINT account on another platform
- How cross-platform patterns reveal target type, location, and method of attack
Who it’s for
Built for analysts and investigators tracking threat narratives that start on Telegram and extend beyond it. Suited to national security, defense, and OSINT teams assessing whether single-platform signals reflect broader coordination.

