Instagram OSINT: collecting hashtag evidence, tool by tool
Published
Instagram OSINT is the collection and analysis of what public Instagram posts and profiles reveal, for an investigation, a news story or a piece of research. Most Instagram investigations start from one of two places: an account you want to understand, or a topic, event or place you want to see through other people's posts. The first is account work and has its own dedicated tools. The second usually starts from a hashtag, and it rewards a different method: a fixed time window, a complete and dated export, and a record of how you collected it. This guide covers that hashtag method step by step, names the tools that fit each kind of job, and says plainly where each one stops.
What Instagram OSINT can and cannot reach
Before picking a tool, it helps to know the ceiling every tool shares.
- Public content only. Posts from private profiles are out of reach for everyone. A tool that claims otherwise is not worth your trust.
- Hashtag feeds need a signed-in session. Instagram serves a hashtag's posts only to a signed-in request. Instaloader's own documentation marks its
#hashtagtarget with a plain "Requires login", and every other working tool has the same dependency. - Use a research account, never your own. Any tool reading Instagram with your session makes its requests as that account. Instagram can rate limit, challenge or disable an account that reads a lot, so use a separate account you are willing to lose.
- Posts disappear. People delete posts, archive them and make accounts private, often quickly after an event draws attention. Whatever you did not save while it was public may be gone the next time you look.
That last point is why collection method matters as much as the tool. A screenshot of one post is a lead. A dated, complete export of a hashtag over a known window is evidence you can analyse, share and defend.
Two kinds of Instagram investigation
The question you are asking decides where you start.
| Your question | Where you start | Tool shape that fits |
|---|---|---|
| Who is behind this account? | One username | Account lookup tools such as Osintgram |
| Who does this account talk to? | One username | Account lookup tools |
| What did people post about this event? | A hashtag and a date range | Hashtag collectors |
| Who was posting under this campaign or protest tag? | A hashtag | Hashtag collectors |
| What was posted at this venue? | A place | Place search (Osintgram has one) |
If your question starts from one account, a hashtag collector is the wrong tool. It will tell you who posted under a tag, which can point you at an account, but it does not look up followers, bios or contact details. If your question starts from an event or a topic, account tools only answer it one account at a time.
Instagram OSINT on a hashtag, step by step
This method works whichever collector you use. It assumes you have a research account set up and signed in.
- Write down the window. Note the start and end of the period you care about, in UTC. An event that ran from Friday evening to Sunday in one timezone spans different dates in UTC, and Instagram records post times as Unix timestamps, which are UTC.
- Search by hand first. Open the hashtag in the app and scroll the recent posts. You are not collecting yet. You are learning the vocabulary: the spelling variants, the companion tags people add, the language they post in. Our guide to searching several hashtags at once covers how to find those companions.
- List every tag you will collect. Most events have one main tag and two or three variants. Collect each separately and merge later, since each hashtag is its own feed.
- Collect into a file, with a stopping rule. Run your collector over each tag with the window from step 1 and a row limit high enough not to cut the window short. Keep the raw export exactly as it arrived, in JSON if your tool offers it.
- Record how you collected it. Note the tool, its version, the settings, the account used and the time you ran it. Then fingerprint the raw file, for example with
sha256sum export.json, and store the hash beside it. If anyone later asks whether the file was edited, the hash answers. - Check why the collection stopped. A small result can mean a quiet hashtag or a refused session. Those two look the same in a spreadsheet and mean opposite things. Find out which before you draw a conclusion from a count.
- Analyse a copy, never the original. Sort by time, count posts per hour, list the most active accounts, and pull the companion hashtags out of the captions. Then review the images themselves, which is where reverse image search and location work begin.
For the date step on its own, our guide to searching Instagram posts by date goes deeper, and building an Instagram hashtag dataset covers cleaning the export once you have it.
The tools, compared
Four ways to do hashtag collection, side by side. Tool details are as of October 2026, from each project's own documentation.
| By hand in the app | Instaloader | Osintgram 2.0 | Instagram Hashtag Scraper | |
|---|---|---|---|---|
| Built for | Small looks | Downloading posts | Account investigations | Hashtag collection |
| Hashtag posts | Yes | Yes (#hashtag target) | Yes (Hashtag search) | Yes |
| Account lookups | One at a time | Profile targets | 28 commands | No |
| Place search | In the app | %location id target | Yes | No |
| Date window | Scroll and judge | --post-filter on date_utc | No date parameter on Hashtag search | onlyPostsNewerThan and onlyPostsOlderThan |
| Needs | A research account | Python and a login | A HikerAPI key or an instagrapi login | An Apify account and a session cookie |
| Output | Your notes | Files named by UTC date | Cards, JSON and an HTML report | JSON, CSV or Excel rows |
By hand in the app
For a handful of posts, the app is enough. Copy each post's link, its date, the account and the caption into a spreadsheet as you go, and take a screenshot of anything you might cite. It costs nothing and needs no setup. It stops being practical once a tag has more posts than you can scroll in one sitting, and it leaves you with no record of what you missed.
Instaloader
Instaloader is a free, open-source Python tool that downloads posts to disk. It takes a hashtag as a target and, per its documentation, the hashtag target "Requires login". Its --post-filter option takes a Python expression, and the documented example filters on date_utc, so you can bound a collection by date. Files are named after each post's UTC timestamp by default, which suits an evidence folder. Our round-up of Instagram scraper GitHub projects covers how it behaves on large tags.
Osintgram
Osintgram is the best-known open-source Instagram OSINT tool, and its 2.0 release in September 2026 turned it into a web interface you run on your own machine. Its README opens with its purpose:
Point it at an Instagram account and find out who's behind it.
That is account work, and it does it thoroughly: profile details, followers and followings, comments, posting-time heatmaps and geotagged locations on a map. It also has two searches that need no account: Hashtag search, which returns posts published with a hashtag and who posted them, with a top or recent sort and a default limit of 30, and Place search for recent posts from a place. It needs a data backend: a HikerAPI key, which is a paid service, or a free instagrapi login using an Instagram account of your own. Its documentation says it prices a selection before running it and shows your remaining credit. It is licensed GPL-3.0.
Choose Osintgram when the investigation is about a person or an account. Its hashtag search is useful for a quick look at who is posting under a tag.
Instagram Hashtag Scraper
Instagram Hashtag Scraper does one job: it collects one hashtag's recent posts into a dataset. You give it the hashtag, a session cookie from your research account, a row limit and, optionally, a date window. The run stops when the feed reaches the start of your window, and onlyPostsOlderThan skips posts newer than the end, so the two together collect exactly one period.
Each row carries the post URL and shortcode, takenAt as a UTC timestamp, the caption, the hashtags pulled from it, the like and comment counts, the posting account's username, the media type and the image link. A count Instagram did not provide arrives as empty, never as zero, so a missing figure cannot pass for a real one. Duplicates are dropped within a run, and the run's status message names why it ended: limit reached, date reached, feed ran out or session refused. That is step 6 of the method, answered by the run itself. The output page lists every field.
It costs $0.0005 per post delivered to your dataset, with no other charge. It does not look up profiles, followers or comments, and it returns no location data. For account work, use an account tool.
Which tool for which investigation
- Profiling one account: Osintgram, or Instaloader if you only need that account's posts on disk.
- A quick look at who uses a tag: the app, or Osintgram's hashtag search.
- An event, protest or campaign over a fixed period: a hashtag collector with a date window, so the export covers the whole window and says when it stopped. Instaloader with a date filter or Instagram Hashtag Scraper both do this.
- Repeated monitoring of the same tag: a scheduled hashtag collection with a window equal to the gap between runs. Our guide to Instagram social listening sets that up.
When the manual way is enough
Skip the tools when the tag is small, the window is short and you need only a few posts to cite. Twenty posts read and screenshotted carefully beat two thousand rows nobody looks at. Reach for a collector when you need the whole window, when you need to count, or when you need to show later exactly what was there and when you saw it.
Ethics and the law
OSINT collects personal data, and the people in a hashtag feed did not post for your investigation. Keep only what the question needs, store it securely, and follow the data protection law that applies to you, such as the GDPR. Instagram's terms forbid automated collection "regardless of whether such automated access or collection is undertaken while logged-in to an Instagram account". Every signed-in tool in this guide, ours included, acts against terms the research account accepted. The usual consequence is a restricted or disabled account. Our article on whether it is legal to scrape Instagram sets out what the terms and the courts say, and where the lines are.
Summary
Instagram OSINT splits into account work and hashtag work. For accounts, Osintgram is the dedicated open-source option. For hashtags and events, the method matters most: a written UTC window, a manual pass to learn the variant tags, a complete raw export per tag, a hash and a collection note, and a check of why each collection stopped. Instaloader can do that with a date filter and some Python. Instagram Hashtag Scraper does it with a date window, an exact row limit and a stated reason for every stop.