Satellite Imagery as OSINT: Lessons from Big Bend
Bellingcat mapped 5 miles of CBP road construction in Big Bend using commercial satellite imagery. Here's what that methodology means for red teams and defenders.
Bellingcat published “Satellite Imagery Documents New Border Patrol Road Construction in Big Bend National Park” on August 20, 2026. Using commercially sourced satellite imagery — no leaked documents, no FOIA, no insiders — analysts measured and temporally sequenced more than five miles of new CBP road construction inside a federally protected park before any official acknowledgment appeared. That sequence matters: detection before disclosure. The rest of this is about what that sequence means operationally.
What the Investigation Actually Demonstrates
Bellingcat used imagery from providers like Planet Labs, Maxar, and Airbus Defence & Space to detect ground disturbance, measure road length, and assign construction dates by comparing sequential captures. The result is a documented, timestamped record of infrastructure that the owning agency had not publicly acknowledged.
The defining characteristic here: physical change on the ground is now faster to detect via satellite than it is to suppress through information control. Geographic remoteness — Big Bend is not a suburb — provided zero protection from open-source documentation. That’s the starting point for every implication below.
Implications for Offensive Security
Geospatial Reconnaissance Belongs in Pre-Engagement Workflow
If a Bellingcat team can map five miles of government road in a remote national park with commercial imagery, an adversary with equivalent access — which is to say, anyone with a credit card and a Planet or Maxar subscription — can do the same to any surface-visible infrastructure. That includes:
- Hyperscale data center expansion visible from orbit
- Unannounced government and military construction at installations
- Energy infrastructure modifications: new substations, pipeline access roads, fiber conduit trenching
- Physical security perimeter changes at high-value campuses
Red teamers who limit reconnaissance to digital surfaces are skipping an entire collection layer. Platforms like Google Earth Pro’s historical imagery, Planet’s Explorer tool, and Sentinel Hub’s EO Browser surface physical access routes, construction timelines, and facility expansion patterns that never appear in any organizational disclosure.
The Big Bend case is concrete: a new road is a new attack surface. New roads mean new vehicle access points, new sensor installations — in this case explicitly part of CBP’s documented Smart Wall architecture — and new personnel movement patterns. Each is a reconnaissance target. Free tools like NASA Worldview and the Copernicus Open Access Hub provide multi-temporal imagery sufficient to identify road construction, building footprints, and vehicle staging areas without spending anything.
Temporal Analysis Reveals Operational Tempo
Time-sequenced imagery does more than confirm that something was built. It shows how fast. If a facility consistently moves from ground break to operational status in 90 days, that cadence has adversarial value — it sets the window during which construction activity is visible and countermeasures are not yet in place. For threat modeling, construction tempo is a predictive signal, not just historical record.
Implications for Defensive Security
Your Physical Footprint Is Already an OSINT Product
If CBP — with significant operational security resources — could not prevent open-source documentation of a major construction project in a remote, restricted-access location, organizations operating in less isolated environments are more exposed, not less.
Defensive teams responsible for physical security, critical infrastructure protection, or intelligence functions need a geospatial threat model: a periodic OSINT audit of the organization’s physical footprint using the same commercial satellite tools an adversary would use. The questions that audit should answer:
- What does a time-lapse of satellite imagery over primary facilities reveal about construction, expansion, or operational patterns?
- Are vehicle staging areas, generator placements, or antenna installations interpretable from orbit?
- Does physical construction activity telegraph strategic priorities before the organization is ready to disclose them?
That last question is pointed at defense contractors, semiconductor fabs, pharmaceutical manufacturers, and data infrastructure companies — sectors where facility investment directly signals business intent.
Sensor Network Layouts Are Often Implicit in Their Infrastructure
The CBP Smart Wall integrates roads, barriers, and sensor systems. Even when sensor specifications are not published, the physical infrastructure supporting them — conduit runs, maintenance access roads, camera mast footings, antenna pads — is frequently visible and mappable from satellite imagery. Assuming physical obscurity in remote or restricted areas is a weaker control than it was ten years ago. Sensors aren’t useless because of this; the assumption that their layout is unknown to a motivated adversary is.
The Methodology, Extracted
Read the Bellingcat investigation as a methodology document and the workflow is straightforward:
- Baseline acquisition — pre-event reference imagery for the target area
- Change detection — sequential comparison to identify ground disturbance, new structures, altered access
- Measurement and georeferencing — GIS quantification (five miles is a measurement, not an estimate)
- Temporal sequencing — assigning dates to construction phases via imagery timestamps
- Cross-referencing with public records — correlating satellite findings against procurement records, environmental impact filings, or permit databases
Step five is where this connects to the broader OSINT ecosystem. SAM.gov and USASpending.gov provide a textual layer that can confirm or contextualize what imagery shows visually. A road visible in imagery that corresponds to a CBP infrastructure contract in a matching geographic area and time window is corroborated intelligence. The NATO OSINT Handbook — Allied Intelligence Publication 2.2 — documents cross-domain corroboration as foundational to producing reliable assessments from open sources. Satellite imagery confirmed by procurement records confirmed by regulatory filings is how you get from observation to assessment confidence.
The USGS Landsat program and ESA’s Sentinel-2 mission provide free, publicly accessible multi-spectral archives going back decades. This is not an experimental capability — it’s mature, institutionally supported infrastructure that most security teams haven’t touched.
One honest failure mode: change detection at free-tier resolution (10–30m per pixel for Sentinel-2 and Landsat) works well for roads, building footprints, and large ground disturbance. It fails for small-footprint installations — individual sensor masts, equipment enclosures under tree canopy, or modifications inside existing structures. For those, you need commercial high-resolution tasking, which carries real cost and lead time. Don’t let the free-tier tools create a false ceiling on what’s actually detectable by a funded adversary.
What to Do
Red team and offensive security practitioners:
- Run geospatial reconnaissance before engagement begins. Document what commercial satellite imagery reveals about the target facility — historical imagery especially.
- Use multi-temporal imagery to identify operational patterns, not just static features. Parking lot fill rates, equipment staging cycles, and construction phases are all readable.
- Treat visible infrastructure as implying non-visible infrastructure. A maintenance road implies a sensor. A sensor implies a communication path. Follow the chain.
Defensive security and intelligence teams:
- Commission a geospatial OSINT audit of your physical footprint on the same cadence you run external attack surface assessments. Use the same tools an adversary would.
- Brief physical security teams: distance from population centers no longer functions as an intelligence barrier. The remoteness assumption is dead.
- If your organization or its facilities appear in government procurement data, SAM.gov and USASpending.gov monitoring belong in your threat intelligence feeds.
- Before constructing or modifying perimeter sensor deployments, model their satellite visibility. Do it before breaking ground.
OSINT analysts:
- The Bellingcat Big Bend workflow is replicable with free tools. Document it internally and train to it.
- Build satellite imagery review into your regular collection cycle for targets where physical activity is operationally relevant.
- Practice the corroboration chain: imagery + procurement data + regulatory filings. Each layer independently weak; together, assessable.
The barrier to geospatial intelligence has collapsed for non-state actors and researchers — which means it’s collapsed for adversaries too. Geographic remoteness is not a security control. The tools are public, the data is public, and the methodology is documented. The variable is whether your program has updated its threat model to reflect that.