August 24, 2026

Oryx OSINT Equipment Losses: Intelligence Source Guide

0

Oryx publishes cumulative lists of military equipment losses in which every single entry is backed by a photograph or video, linked inline. It is the defensible floor for attrition analysis in several wars, and the rule that makes it credible – visual confirmation only – is also the source of its…

oryx-osint-equipment-losses-intelligence-source-guide

Oryx publishes cumulative lists of military equipment losses in which every single entry is backed by a photograph or video, linked inline. It is the defensible floor for attrition analysis in several wars, and the rule that makes it credible – visual confirmation only – is also the source of its bias.

At a glance

Source Oryx OSINT Equipment Losses
Category Conflict, Crime & Human Security › Military, Weapons & CBRN
Homepage https://www.oryxspioenkop.com/
Format HTML
Access Open — no account required
Disciplines Measurement & Signature Intel, Imagery Intelligence, Open Source Intelligence
Mission domains Military & Defense, Conflict & Humanitarian

Visually-confirmed equipment loss tracking. — as catalogued in the platform’s own source registry.

Oryx is a blog, not a database. It is written by Stijn Mitzer and Joost Oliemans with a rotating group of named contributors, hosted on Blogger at oryxspioenkop.com, and its best-known products are long single-page posts that enumerate the military equipment one belligerent has visibly lost in a given conflict. Each post is organised by equipment category – tanks, infantry fighting vehicles, armoured personnel carriers, engineering vehicles, self-propelled and towed artillery, multiple rocket launchers, air defence systems, radars, aircraft, helicopters, unmanned aerial vehicles, naval vessels, trucks and logistics – and within each category by specific type designation. Under each type is a numbered list, and every number is a hyperlink to the image or video that proves the loss. Alongside the number is a one-word status: destroyed, damaged, abandoned or captured, sometimes in combination. That is the whole schema. There is no API, no JSON, no export, no per-entry timestamp and no stable record identifier. What you are collecting when you collect Oryx is an HTML document, and what makes it worth collecting is that every claim in it carries its own evidence link.

The analytical job Oryx does that no other open source does at this granularity is to establish a verifiable lower bound on materiel attrition, itemised by type and by disposition. Nearly every other attrition figure in circulation – ministry of defence claims, general-staff daily tallies, press estimates – is an assertion you either accept or discard. An Oryx entry is a claim you can personally check in about ninety seconds by clicking the link and looking at the vehicle. That property is what makes it usable in IMINT and MASINT workflows: it is a corpus of dated-ish, sourced visual observations of specific equipment types in specific conditions, which can be re-examined for signature analysis, armour configuration, jamming and countermeasure fits, and field modifications, rather than merely counted. The four-way status distinction carries the second half of the analytical value. Destroyed and captured equipment leaves the opposing order of battle permanently; damaged equipment is a repair-cycle question and often returns; abandoned equipment is a morale, logistics and recovery-capability indicator that says as much about the losing force as the destruction figures do. Analysts who collapse the four categories into one number throw away most of what the source is for.

Who publishes it, and why that matters

This is a small independent research effort run by named individuals with a contributor community, not an institution. There is no government funder, no board, no data-management plan and no succession arrangement. The incentive structure is reputational: the team's standing rests entirely on the visual-confirmation rule, which is why they have historically been conservative about admitting entries and willing to remove them. That is good for reliability and bad for continuity. A blog maintained by two people plus volunteers can slow down, pause, or stop when the people running it change jobs, burn out, or lose access to the contributor networks that supply imagery. It has also expanded its conflict coverage opportunistically rather than systematically, which means coverage depth tracks contributor interest rather than analytical importance. Treat Oryx as a high-quality artisanal source with a single point of failure. If your workflow depends on it, mirror it on your own infrastructure and archive the evidence links, because neither the posts nor the images they point at are guaranteed to exist next year.

Provenance is the first question to ask of any dataset and the one most often skipped. Who collects it, what their incentive is, whether they publish a methodology, and whether they correct the record when they get something wrong all bear directly on how much weight a finding drawn from it can carry.

What a record actually contains

The fields you will be working with, what each one means, and whether it is something you can pivot on. Read the meanings carefully — more analysis is wrecked by misreading a field than by failing to find one, and a field that looks like an observation is often an inference.

Field Type What it means Pivot value
post_url string The conflict-and-belligerent-specific blog post is the unit of publication. There is no record table; a post is a single HTML document, frequently several megabytes, covering one side of one war. The sibling post covering the opposing belligerent, and the author index for other conflicts the same team tracks.
equipment_category enum The heading a loss sits under: tanks, IFVs, AFVs, APCs, infantry mobility vehicles, engineering and support vehicles, self-propelled artillery, towed artillery, MRLs, air defence, radars, aircraft, helicopters, UAVs, naval, trucks and jeeps. An order-of-battle or inventory source, which is what converts a raw count into a proportion of holdings.
type_designation string The specific model as identified by the team, written in the conventions of the operating force – GRAU indices, NATO reporting names, manufacturer designations and production-year modifiers mixed as appropriate. Manufacturer, licensed-production country and export history via arms-transfer databases; production plant via component and marking analysis.
status enum Destroyed, damaged, abandoned or captured, and combinations such as damaged and captured. This is the analytically load-bearing field and the one most often assigned on incomplete visual evidence. Repair-cycle and recovery analysis for damaged items; opposing-force inventory for captured items, which become a transfer event.
entry_index int The sequential number within a type block. It is a position in a list, not an identifier. Numbers shift when entries are inserted, merged or removed, so an index recorded today may point at a different vehicle after the next update. None. Do not use it as a key; hash the evidence URL instead.
evidence_url string The link behind the number: the photograph, video or social-media post that is the sole basis for the entry existing. This is the actual primary source and the only part of the record you can independently verify. The posting account and its history, other imagery from the same event, and where the media carries them, embedded coordinates and capture time.
evidence_host enum Which platform holds the media – social networks, image hosts, messaging channels, video sites. Determines how likely the evidence is to survive, and whether you can fetch it without an account. Host-level archival strategy; the channel or account as an entity in its own right.
belligerent enum Implied by which post the entry appears in rather than written on the entry. The post title states whose equipment is being counted. The opposing side's post, for the paired view of the same engagement.
capturing_party string Occasionally noted in free text for captured items, identifying who took the equipment. Frequently absent even when the imagery shows it. Unit identification via markings and insignia in the linked imagery; subsequent re-loss of the same captured vehicle.
geolocation string Sometimes present in the entry annotation or recoverable from the linked source, usually not. Oryx does not require a geolocation for an entry to be admitted, only an image. Coordinates for map placement and terrain analysis; nearby facilities and road networks for logistics inference.
loss_date timestamp Absent. This is the field newcomers assume exists and does not. Entries carry no date of loss, no date of imagery capture and no date of publication. The list is cumulative and unordered in time. None natively. Reconstruct from the linked media's posting time, which is an upper bound on the loss, not the loss time.
annotation string Free-text notes attached to some entries: qualifiers such as probable duplicate, possible same vehicle as an earlier entry, or clarifications about variant and configuration. The referenced sibling entry, for duplicate-resolution work.
post_last_updated timestamp Update state is expressed at post level, in prose, and not consistently. There is no per-entry revision history and corrections are made silently in place. Your own archived snapshots, which are the only reliable revision history that will exist.

Coverage — and what is not in it

Coverage is conflict-by-conflict and driven by the availability of a contributor community rather than by any coverage policy. The Russia-Ukraine war is by a wide margin the deepest treatment, with separate cumulative posts for each side and subsidiary lists covering foreign equipment supplied to Ukraine. Earlier and parallel treatments exist for the 2020 Nagorno-Karabakh war, the Syrian civil war, Libya, Yemen, the Tigray conflict in Ethiopia, the Sudan civil war and the Israel-Gaza fighting, at varying depth. The team also publishes non-loss reference material – inventory surveys of particular armed forces, arms-supply catalogues, and equipment identification write-ups – which is often more useful than the loss lists for baseline work. Update rhythm is irregular and batched. Entries appear in clusters when contributors process a backlog of imagery, not continuously, so the difference between two snapshots taken a week apart is not a week of fighting; it is a week of verification throughput. Geographically the lists are as global as the contributor base, which means they are strongest where combatants and civilians post to open platforms and weakest where they do not. Entity coverage is restricted to vehicles, systems and platforms large enough to be individually identifiable in a photograph. Personnel, small arms, ammunition, spare parts and consumables are entirely out of scope.

Known blind spots

Absence of evidence here is not evidence of absence. These are the conditions under which Oryx OSINT Equipment Losses will not show you something that is nevertheless real:

  • No imagery, no entry. Losses at night, at sea, in electronic-warfare-denied airspace, deep inside rear areas, or in any theatre where neither side posts battlefield imagery are simply absent, and their absence is indistinguishable in the data from their non-occurrence.
  • The posting asymmetry problem is structural and never resolves. Whichever side has more phones, more permissive posting culture and more incentive to publicise enemy losses generates more evidence, so the loss ratio in the lists reflects documentation behaviour at least as much as combat outcomes.
  • Equipment recovered and repaired stays counted. A damaged vehicle towed away, rebuilt and returned to service remains in the cumulative list forever, so the totals overstate permanent removal from the order of battle for any force with a functioning repair chain.
  • There is no loss date, so no time series exists natively. You cannot answer questions about tempo, seasonality or the effect of a specific offensive from Oryx alone without reconstructing dates from the linked media, which is slow and only ever yields upper bounds.
  • Naval and air losses are systematically thinner than ground losses, because ships sink where nobody photographs them and aircraft come down in areas the losing side controls or nobody controls.
  • Small unmanned systems, loitering munitions, electronic warfare kit, communications equipment, engineering stores and ammunition stockpiles are under-counted to the point of uselessness, because they are hard to identify by type in imagery and often not photographed at all.
  • Conflicts without an engaged contributor community get token coverage or none. The absence of a post about a war is a statement about Oryx, not about that war.
  • Link rot removes the evidence retroactively. An entry whose image host has purged the media becomes an unsourced assertion, and there is no mechanism inside the source that flags this.
  • The lists carry no denominator. Without a separate holdings or order-of-battle source, a loss count cannot be converted into combat-power depletion, and the most common misuse of Oryx is exactly that conversion done implicitly.

Write the blind spot into the product. A statement that something “was not observed in Oryx OSINT Equipment Losses” is defensible; a statement that it “did not happen” is not, and the difference is what survives cross-examination.

Access, licensing and what you may do with it

Access model: Open — no account required

Access is a web browser or an HTTP client, with no key, no account and no terms gate. The practical difficulty is that the major loss posts are extremely large single HTML documents with thousands of inline links, which makes naive scraping slow and makes the pages painful to render on constrained clients. Fetch each post once per collection cycle, store the raw HTML with a fetch timestamp, and do your parsing offline against the stored copy so that you can re-parse without re-fetching. There is no changelog, so change detection means diffing your stored copies. Several third-party projects parse Oryx into CSV or JSON and republish it; these are convenient and they are also an extra layer of interpretation, because each project makes its own choices about how to handle duplicate annotations, combination statuses and re-numbered entries. If you use one, record which one and which snapshot, and spot-check its output against the source post before you publish anything derived from it.

Licence

There is no machine-readable licence and no stated data licence. The posts are an ordinary copyrighted work by their authors, and the images the entries link to belong to whoever took and posted them – overwhelmingly third parties who have granted nobody anything. The practical norm in the field is citation: name the post, name the authors, and record the date you accessed it, because the content changes without notice. Extracting the factual counts for your own analysis is a different question from republishing the compiled list or the imagery, and the second is legally exposed in most jurisdictions. Redistribution of the underlying media is the sharpest edge, both for copyright and because a significant fraction of battlefield imagery contains human remains. Confirm current terms with the authors before any commercial redistribution rather than assuming that a public web page implies permission.

Rate limits and fair use

No published limits exist, which is a reason for restraint rather than an invitation. The infrastructure is a hosted blogging platform, not a data service, and the loss posts are among the heaviest documents on it. One fetch per post per collection cycle is ample; the content does not change hourly and a scraper polling on a short interval is pure waste. Set a descriptive user agent with contact details, respect the platform's robots directives, serialise your requests rather than parallelising them, and cache aggressively. Fetching the linked evidence media is a separate and much larger load that falls on third-party hosts, not on Oryx; throttle that independently and expect a meaningful proportion of failures.

Licensing changes, and it changes without warning. A dataset that was free for research this year may not be free for commercial or evidential use next year. Confirm the current terms before you build a dependency on it, and record the terms you relied on alongside the data — the licence in force at the time of collection is part of the provenance.

Collecting it

How Oryx OSINT Equipment Losses is actually pulled, in the order you would set it up. Prefer the bulk or export interface over per-item lookups wherever one exists: it is kinder to the publisher, faster for you, and gives a reproducible snapshot rather than a series of point-in-time answers you cannot reconstruct later.

Method Format Cadence Notes
Manual read of the post HTML per analytical question Still the right method for qualitative work. Reading a type block end to end, clicking through the imagery, tells you things about configuration and condition that no parsed count will.
Scheduled HTML fetch and diff HTML weekly is generous; the update rhythm is batched, not continuous The workhorse for tracking. Store raw HTML with a fetch timestamp and derive added, removed and re-numbered entries by diffing snapshots, because there is no changelog.
Structured parse to tabular form CSV after each successful fetch Parse category, type, status and evidence URL, and key on a hash of the evidence URL rather than the entry index. The index is unstable across updates.
Evidence archival bulk once per newly seen entry Fetch and store the linked media at first sight. This is the only defence against the link rot that will otherwise hollow out your historical records, and it must happen at ingest, not at report time.
Third-party derivative datasets JSON as published by the maintainer Faster to adopt and one interpretive layer further from the truth. Usable if you record the provenance and version and validate a sample against the source post.
Public web archive snapshots HTML opportunistic Useful for reconstructing what a post said before a silent correction, and for establishing what you could reasonably have known on a given date.

Ingesting it into the platform

Every step below is idempotent and cursor-based: interrupt one and it resumes from where it stopped rather than duplicating rows or losing progress. Collection is recorded per source, so a feed that quietly stops publishing shows up as a stale timestamp instead of silently thinning your coverage.

  1. Register the source with its constraints attached — Add Oryx in sources.php with the visual-confirmation rule, the absence of loss dates and the posting-asymmetry caveat recorded as collection notes, so that the limitation travels with the data rather than living in a separate methodology document nobody reads.
  2. Schedule the fetch — Configure collect.php to pull each tracked post on a weekly cadence and let cron.php own the schedule, so that a failed fetch surfaces as a job failure in the per-feed status view rather than as a silent flat line in the counts.
  3. Normalise entries into observations — Run import.php to turn each parsed entry into a discrete observation carrying category, type designation, status, belligerent and evidence URL, keyed on the evidence hash so that re-numbering upstream does not create phantom new records.
  4. Archive the evidence at first sight — Have the ingest step fetch and store the linked media immediately, recording the HTTP status and content hash. An entry whose evidence has already gone is worth flagging on arrival rather than discovering during a report review.
  5. Resolve geography where it exists — Where an annotation or the linked media yields coordinates, push them through resolve-everything.php so the observation becomes a placeable point; where it does not, leave the geography null rather than assigning a country centroid that will later be read as a location.
  6. Correlate against event data — Use correlate.php to associate loss observations with conflict events from geocoded event feeds, on location and approximate window, to give undated entries a probabilistic temporal anchor that is explicitly marked as inferred.
  7. Build the attrition view — Assemble type-level counts by status in analytics.php and place them on theater.php for the relevant conflict, always showing the four statuses separately and never as a single loss total.
  8. Carry the caveat into the product — When generating an assessment through reports.php, have the template state the collection basis and the floor-not-estimate character of the figures. The Summarise skill in copilot.php writes prose about the records that exist; it does not create, infer or attribute any loss, and assessments derived from this source should say so.

Registered sources and their last-collected state are listed in sources.php, and the scheduled chain that keeps them current is in automation.php.

How it is wrong, and how to tell

Every dataset is wrong in characteristic ways. Knowing which ways is the difference between using a source and being used by one, and it is the part of source evaluation most often skipped because it is the part that takes work.

Judged on its own terms – a floor on visually confirmed losses – Oryx is unusually reliable, and the basis for that judgement is that it is the rare open source where you can audit any individual claim yourself in under two minutes. The evidence link is the whole quality argument. Where it is weaker is in classification rather than existence. Distinguishing a mobility kill from a catastrophic kill in a low-resolution photograph is genuinely hard, variant identification of closely related armoured vehicles is harder, and the abandoned-versus-captured line often depends on context the image does not carry. The team corrects errors, but silently and without a public revision record, so your confidence in a historical figure you quoted last year cannot be reconstructed from the source. Independent academic and journalistic comparisons have generally found Oryx conservative relative to belligerent claims and consistent with other visual-confirmation efforts, which is the right shape for a floor. Treat the existence of an entry as high confidence, the type designation as good, the status as moderate, and any implied rate or ratio as an artefact of documentation behaviour until you have proved otherwise.

Characteristic false positives

  • Duplicate counting of one vehicle photographed at different times, from different angles, or after being moved. The team annotates suspected duplicates but cannot catch them all, and the risk is highest for distinctive vehicles that attract repeated photography.
  • Variant misidentification, particularly among closely related armoured vehicles and production-year upgrades whose external differences are small and often obscured by damage, mud, cope cages and improvised armour.
  • Recirculated imagery from an earlier phase of the same war entering the list as a new loss, because the posting date of a social media item is not the capture date of the photograph in it.
  • Cross-conflict contamination, where imagery from an older war involving similar equipment is posted as current and admitted before anyone recognises it. This has affected multiple conflicts and is a known failure mode of the underlying imagery ecosystem, not of Oryx specifically.
  • Side attribution errors on captured and abandoned equipment, which is exactly the material most likely to be photographed by whoever took it and least likely to carry unambiguous markings after capture.
  • Status inflation and deflation in both directions: a turret-thrown wreck logged as damaged, and a lightly damaged vehicle logged as destroyed, because the photograph shows one aspect of the hull.
  • Deliberately staged or manipulated content injected by parties with an interest in the tally. The visual-confirmation rule raises the cost of this but does not eliminate it, especially for hard-to-verify equipment classes.
  • Depot and storage losses counted alongside combat losses, so that a single strike on a vehicle park or a mass abandonment during a withdrawal enters the same running total as attrition accumulated over months of fighting.

None of these make the source unusable. They make it a source that requires corroboration before an assertion built on it goes into a product, which is true of every source and admitted by few.

Ageing

The list itself does not expire – it is cumulative, and an entry made two years ago remains as true as the day it was added. Three other things age badly. The evidence links rot, quickly and permanently, as social platforms purge accounts, image hosts expire free uploads and messaging channels are deleted, so an entry's verifiability decays even though its text does not. The totals for an active conflict are stale within days, and quoting a total without the date you read it is a reporting error rather than a rounding one. And the analytical currency of a loss decays as the force regenerates: a tank destroyed eighteen months ago tells you almost nothing about current combat power if the operator has since restored equipment from storage or received transfers. A stale record in practice looks like an entry whose evidence URL returns a 404 or a login wall, whose type designation reflects an identification convention the team has since revised, and whose contribution to a headline figure you are still quoting has silently changed because the entry above it was merged.

What this source feeds

A source is only worth what it lets you conclude. These are the disciplines that collect through it, the mission domains it serves and the data points it yields — every one is a tag, so you can follow any thread from here into the rest of the library.

Collected by these intelligence disciplines

Serves these mission domains

Yields these data points

How each sector uses Oryx OSINT Equipment Losses

The same dataset is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The records are shared — the constraints, thresholds and outputs are not.

🎖 Military and defence

For force-development and campaign-analysis staff this is the cheapest available check on attrition claims from any side, and its main value is as a materiel-signature corpus rather than a scoreboard. The imagery behind the entries shows which protective measures, jamming fits, field modifications and add-on armour packages are actually appearing on vehicles in theatre, and which of them are present on the ones that were destroyed. Use the four statuses as separate lines in any combat-power estimate, treat captured equipment as a transfer into the opposing inventory rather than a subtraction from the world, and never present an Oryx-derived count as a loss rate without a holdings denominator and an explicit statement about documentation asymmetry.

🕵 National intelligence

For all-source assessment this is a MASINT-adjacent and IMINT-adjacent collection route that is fully unclassified and fully citable, which makes it valuable precisely where a classified figure cannot be released. Its greatest use is corroboration: an Oryx floor that sits above a belligerent's admitted losses is a defensible public data point, and one that sits well below a classified estimate tells you something about the coverage of both. Analysts should treat the underlying imagery as the collection and the list as an index to it, mining the linked media for unit markings, terrain, seasonal indicators and equipment configuration rather than reading only the counts.

👮 Law enforcement

The law enforcement relevance is indirect but real and sits in two places. First, captured and abandoned military equipment is one of the pathways by which weapons and components leave state control and enter criminal and illicit markets, and a documented capture is the start of a proliferation question rather than the end of a combat one. Second, the archived imagery is potential evidence in war crimes and atrocity investigations, where the requirement is chain of custody and preservation rather than counting, and where the relevant standards are those for digital open source evidence rather than for intelligence assessment. Investigators should preserve, hash and document their acquisition of any media they may later need to rely on, and route the underlying criminal questions to the mandated authority rather than treating a blog entry as a case record.

🔍 Private investigation and corporate security

For corporate investigators and risk consultancies the practical uses are asset and claim verification. Insurers, lessors and loss adjusters dealing with equipment in or near conflict zones, and due diligence teams testing claims about defence supply chains and end use, can use the lists to test whether specific equipment types are demonstrably present in a theatre and in what condition. The discipline is the same as anywhere else in this trade: the entry is a lead, the linked image is the evidence, and neither is admissible in the form you found it. Do not attempt to identify individuals visible in battlefield imagery, and be aware that reselling analysis built on scraped content raises licensing questions the source does not answer.

📰 Journalism and OSINT media

This is one of the most quotable open sources in conflict reporting and one of the easiest to quote wrongly. The correct citation names the authors, the specific post and the date accessed, and the correct framing is a confirmed minimum rather than an estimate or a total. The two errors that recur in published work are comparing the two sides' figures as though documentation were symmetric, and reporting a cumulative figure as though it described a period. Reporters with time should click through a sample of entries before publishing, both because it is the only way to understand what the numbers are made of and because it occasionally catches a problem.

🌍 NGO, humanitarian and human rights

For humanitarian and human rights organisations the value is contamination mapping and documentation rather than attrition. A dense cluster of destroyed armour is a strong indicator of explosive remnants of war, unexploded ordnance and hazardous debris in inhabited areas, which is directly actionable for mine action planning and for advising returning populations. Documentation teams should treat the linked media as source material for incident files under the applicable open source evidence methodology, with the handling constraints that implies: preserve provenance, do not republish imagery of the dead, and be careful that pattern analysis of losses is not repurposed into anything resembling targeting support.

🎓 University and research

For quantitative conflict research Oryx is tempting and dangerous in the same measure. It is a genuine census of visually confirmed losses and a badly biased sample of actual losses, and papers that treat it as the latter are common and wrong. Used properly it is either a validation set for other attrition measures, a study object in its own right for research on documentation behaviour and open source verification, or a lower bound in a bounds-based argument. Researchers must archive the exact snapshot they used, publish it alongside the paper, and state the parsing rules they applied, because the source has no versioning and their results will otherwise be unreproducible within months.

Playbook: working Oryx OSINT Equipment Losses end to end

A repeatable sequence from first pull to finished product. Each phase states what you are trying to establish, not merely what to click — the objective is a defensible chain of reasoning, not a completed checklist.

Phase 1 — Decide whether you need attrition or documentation

The most common failure with this source happens before any data is touched. If your question is how much combat power a force has lost, Oryx is one input among several and cannot answer it alone. If your question is what equipment has been visibly present, in what configuration, and in what condition, Oryx is close to the best available answer. Write the question down before you fetch anything, because the same numbers support one and mislead the other.

Phase 2 — Snapshot before you analyse

Fetch and store the raw HTML of every post you will use, with a timestamp, before doing anything else. The source is silently mutable and has no versioning, so the snapshot is the only thing that makes your work reproducible or defensible three months later. Analysts who skip this step routinely find they cannot reconstruct a figure they published.

Phase 3 — Establish the documentation environment

Before comparing anything across belligerents, characterise how imagery flows out of each side: posting culture, device penetration, unit-level policy on phones, and whether the side controls the ground where losses occur. This determines whether a ratio in the lists means anything at all. Record your assessment explicitly, because every downstream comparison inherits it.

Phase 4 — Parse to observations, not counts

Break each post into per-entry records keyed on a hash of the evidence URL, carrying category, type, status and belligerent. Counting is a later operation on this table. Analysts who parse straight to totals lose the ability to detect duplicates, track individual entries across updates, or answer any question that was not the first one they asked.

Phase 5 — Harvest the evidence immediately

Fetch every newly seen media link at ingest, store the bytes, and record the hash and retrieval time. This is not optional infrastructure. Evidence decay is the single largest long-term threat to the value of a historical Oryx collection, and it is irreversible once it happens.

Phase 6 — Resolve identity and de-duplicate

Work through the type designations and reconcile them against a consistent naming authority of your own, because the source mixes conventions. Then look for duplicates: same distinctive damage pattern, same terrain, same markings, entries adjacent in the list. Expect to find some, expect not to find all of them, and record your de-duplication rules so a reviewer can test them.

Phase 7 — Establish temporal anchors

Since there is no loss date, derive an upper bound for each entry from the earliest posting time you can find for its media, and mark it clearly as an upper bound. Where the platform can correlate an entry with a geocoded conflict event in the same place, use that to narrow the window. Never let an inferred date be presented with the same confidence as an observed one.

Phase 8 — Build the denominator

Bring in a holdings or order-of-battle source and a transfers source so that loss counts can be expressed as proportions of something. Until this step exists, every conclusion about degradation is a guess dressed as arithmetic. Document the denominator's own uncertainty, which is usually larger than the numerator's.

Phase 9 — Separate the four statuses in every product

Carry destroyed, damaged, abandoned and captured as distinct series through every chart, table and paragraph. Captured items should also appear as additions to the capturing party's inventory. Collapsing the statuses is the fastest way to produce a number that is both defensible in its parts and wrong as a whole.

Phase 10 — Cross-check against independent observation

Test a sample of clusters against satellite imagery, geolocated conflict event data and any national or institutional reporting available. You are looking for two things: entries that other sources contradict, and losses other sources see that Oryx does not, which is how you calibrate the size of the invisible fraction.

Phase 11 — Quantify the gap, do not hide it

Produce an explicit statement of what proportion of losses you believe are documented, on what basis, and with what confidence. This can be a range and it can be poorly constrained, but it must exist, because the reader of your product will otherwise supply their own assumption and it will be a hundred percent.

Phase 12 — Publish with the collection basis attached

Every finished product should name the snapshot date, the parsing rules, the de-duplication approach and the visual-confirmation constraint, in the body rather than a footnote. This is also the point at which to say plainly that the underlying observations are human-verified imagery and that no part of the count was generated or inferred by a model.

The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.

What to pair it with

No single source carries a finding. These are the datasets that corroborate, extend or contradict this one — and a source that contradicts is worth more than one that agrees, because it is the only thing that will tell you when you are wrong.

Source Relationship What it adds
SIPRI Arms Transfers Database extends Supplies the transfer and delivery history that explains how an equipment type reached the theatre in the first place, and lets a captured or destroyed system be traced to a supplier relationship.
ACLED Conflict Events corroborates Geocoded, dated conflict events in the same theatre, which is the practical route to giving undated loss entries a temporal and spatial anchor.
UCDP corroborates Independently coded organised-violence data with a longer and more conservative time series, useful for testing whether documented loss clusters coincide with recorded fighting.
Conflict Armament Research iTrace extends Where Oryx documents that equipment was lost, CAR documents what specific items were, where they came from and how they were diverted, on the basis of physical inspection.
Bellingcat corroborates Published geolocation and verification methodology, plus independent investigations that frequently re-examine the same imagery with more rigour than a list entry allows.
GDELT extends Broad media event and tone data that helps establish when a loss became publicly known, which is a different question from when it happened and often the only date available.
Community geolocated loss projects corroborates Several volunteer efforts record equipment losses with coordinates and dates, which is exactly what Oryx omits. They typically have narrower type coverage and different admission rules, so they corroborate rather than replace.
Commercial and open satellite imagery corroborates Independent overhead observation of vehicle parks, repair depots and battle sites, which is the only practical check on whether damaged equipment was recovered and returned to service.
Institutional order-of-battle references prerequisite Holdings estimates without which loss counts have no denominator. Their own uncertainty is usually the dominant error term in any degradation estimate.

Legal, ethical and operational constraints

Three separate legal questions attach to this source and they are routinely conflated. The first is copyright: the posts belong to their authors and the linked imagery belongs to whoever created it, so extracting factual counts for internal analysis sits on much firmer ground than republishing compiled lists or media, and in most jurisdictions the second requires either permission or a specific statutory exception you should identify rather than assume. The second is the handling of imagery depicting the dead and the wounded, which engages international humanitarian law norms on the treatment of the dead, the dignity of victims and the sensibilities of families, and in practice means that operational archives should hold such material under access control and published products should not reproduce it. The third is data protection: battlefield imagery frequently contains identifiable individuals, including prisoners, and in jurisdictions with comprehensive data protection regimes the processing of that material for analysis needs a lawful basis and a proportionality assessment like any other. On top of all three sits the ordinary constraint on this kind of work: this is historical documentation of losses already taken, and any use of it that shades toward supporting the location or engagement of persons is outside what a public reference library will help with. Investigators handling potential atrocity evidence should follow the recognised methodology for digital open source investigations and refer substantive matters to the competent authority.

Operational security

Fetching a public Blogger page is one of the lower-exposure collection activities available, but it is not zero. The hosting platform sees your address, user agent and request pattern, and a sustained scraping pattern from an attributable corporate or government range is a legible signal about which conflicts you care about and when your interest changed. That signal is available to the platform operator and to anyone with lawful or unlawful access to its logs. The larger exposure is downstream: harvesting the evidence links sends requests to social networks, messaging services and image hosts, several of which are operated in or by parties with an interest in the conflict, and some of which require an account that will be far more identifying than an anonymous fetch. Route evidence harvesting through infrastructure you are willing to have associated with the interest, never use a personal or organisational account to view media on a belligerent-adjacent platform, and treat any request that triggers a login wall as a decision point rather than an obstacle to work around.

Two rules that hold regardless of jurisdiction. Collection that is lawful is not automatically proportionate, and a dataset assembled for one purpose does not carry consent for another. Where the records concern identifiable people, the question is not only whether you may hold the data but whether holding it serves the purpose you are accountable for.

Is it earning its place?

Sources accumulate. Feeds get added during an incident and are never reviewed again, and a decade later the pipeline is carrying dead weight that nobody dares remove. These are the measures that show whether Oryx OSINT Equipment Losses is contributing anything, and they are worth baselining now so the answer is available later.

  • Fetch reliability: the proportion of scheduled collections that returned a complete document, tracked over time, because a silently truncated fetch looks exactly like a week with no losses.
  • Evidence survival rate: the share of stored entries whose media link still resolves, sampled monthly. A falling curve tells you how fast your historical corpus is turning into unsourced assertions.
  • Novelty rate: new entries per collection cycle by category, which measures verification throughput rather than combat intensity and should never be presented as the latter.
  • Duplicate detection yield: how many suspected duplicates your own process finds per thousand entries, which is a direct measure of whether your de-duplication is doing anything.
  • Corroboration rate: the fraction of sampled entries that can be matched to an independently sourced event, geolocation or overhead observation, which is your empirical confidence measure.
  • Coverage gap estimate: the number of losses identified from other sources that never appear in Oryx, which is the only honest way to size the invisible fraction.
  • Analyst correction volume: how often your own reviewers overturn a type designation or status on inspection, which tells you where in the classification your product actually stands.
  • Downstream citation hygiene: the share of finished products that state a snapshot date and the four-status breakdown rather than a single total.

Beware of volume. Indicator counts rise easily and say almost nothing. Unique contribution — findings this source produced that no other source in your stack would have — is the measure that matters, and it is usually far lower than anyone expects.

Tradecraft notes

The distinctions that separate a competent analyst from a fast one:

  • The evidence link is the source; the list is an index to it. Analysts who never click through are consuming somebody else's classification decisions and will inherit every error in them without the ability to detect any.
  • Never key on the entry number. It is a list position that changes when the list changes, and building a database on it produces phantom additions and deletions on every update. Hash the evidence URL.
  • Absence of an entry is evidence about documentation, not about the world. This sentence should appear, in some form, in every product you build on this source, because your readers will not supply it themselves.
  • Captured is not the same as destroyed and abandoned is not the same as either. Captured equipment changes sides, abandoned equipment is often recovered by whoever gets there first, and treating both as attrition double-counts materiel that is still in the fight.
  • The posting time of a social media item is an upper bound on the loss and nothing more. Imagery surfaces weeks and sometimes months after the event, and the recirculation of old footage is constant.
  • Two sides' lists are not comparable without an explicit argument about documentation symmetry. If you cannot make that argument, present the two figures separately and say why you are not dividing one by the other.
  • Loss counts without a holdings denominator are numerator theatre. Getting the denominator is harder and less satisfying than getting the numerator, and it is where the actual analysis lives.
  • Silent corrections mean your archive is the revision history. If you did not snapshot it, you cannot later demonstrate what the source said when you relied on it, and in any adversarial review that is the question you will be asked.
  • Treat depot and withdrawal losses as a distinct phenomenon from sustained attrition. A hundred vehicles abandoned in one retreat and a hundred destroyed over six months describe entirely different military situations and produce the same number.

Questions analysts actually ask

Can I use Oryx figures as the total losses in a published assessment?

No. They are visually confirmed losses, which is a floor. Present them as a documented minimum, name the snapshot date, and if you need a total you must model the undocumented fraction separately and defend that model.

Why is there no date on the entries, and can I add one?

The lists are organised by equipment type and status rather than chronology, and the team does not record loss dates. You can derive an upper bound from the earliest known posting time of the linked media, and narrow it by correlating with geocoded event data, but the result is an inference and must be labelled as one.

Is one side's higher loss count in the lists evidence that they are losing?

Not on its own. It is evidence that more imagery of their losses reaches open platforms, which is a function of who holds the ground, who has cameras and who has an incentive to publish. Establish the documentation environment before comparing the numbers.

Should I use a third-party CSV of Oryx rather than parsing it myself?

You can, if you record which project and which snapshot, and validate a sample against the source post. Each derivative applies its own rules for duplicates, combination statuses and re-numbering, so two datasets both described as Oryx data will disagree.

What happens to my archive when the evidence links die?

Nothing good, unless you archived the media at ingest. Link rot is the dominant long-term degradation mode for this source and it is not recoverable after the fact, so treat evidence harvesting as part of collection rather than as an optional enrichment.

Does damaged equipment come back?

Frequently, for any force with a working recovery and repair chain. The list is cumulative and does not remove entries when equipment is repaired, so damaged counts overstate permanent removal from service by an amount that depends on the operator's maintenance capacity.

Can this source support a claim about a specific unit?

Only through the imagery, not the list. Unit-level inference comes from markings, insignia, terrain and context visible in the linked media, and it is a separate analytical exercise with its own error modes. The entry itself carries no unit field.

Is it appropriate to cite Oryx in legal or accountability work?

Cite the underlying media, not the list. For evidentiary purposes you need provenance, hashing and a documented acquisition process for each item, following the accepted methodology for digital open source investigations. The list is a finding aid that points you at material; it is not itself an evidentiary record.

How much does the platform add over reading the blog?

Continuity and correlation. Scheduled collection with snapshot retention, evidence archival at first sight, stable keys that survive upstream re-numbering, and correlation against geocoded events and transfer records. The counts themselves are the same counts, and nothing in the pipeline invents a loss.

Standards, formats and interoperability

What this source speaks natively, and what it has to be translated into before a partner can consume it. Work that arrives in a recognised format is easier to defend, easier to hand over and easier to automate against:

  • The source speaks no standard natively. It publishes prose HTML with hyperlinks, and any structure you get from it is structure you imposed, which is worth stating in the methodology section of anything you publish.
  • Equipment naming follows the conventions of the operating forces rather than a single authority, mixing GRAU indices, NATO reporting names and manufacturer designations, so a normalisation table is a prerequisite for joining to any other dataset.
  • The four-status vocabulary – destroyed, damaged, abandoned, captured – is Oryx's own and does not map cleanly onto military damage-assessment terminology, which distinguishes mobility, firepower and catastrophic kills on different criteria.
  • Geolocations, where present, should be normalised to WGS84 decimal degrees and expressed with an explicit precision, and can be rendered in MGRS for defence consumers who expect it.
  • For evidentiary handling the applicable framework is the Berkeley Protocol on Digital Open Source Investigations, which governs preservation, provenance and analyst documentation for exactly this class of material.
  • In the platform, parsed entries normalise to STIX 2.1 observed-data with the evidence link retained as an external reference, and export cleanly to MISP, CSV, JSON and JSONL.
  • Nothing here maps to indicator-style detection formats, and any attempt to express equipment loss observations as YARA, Sigma or network rules is a category error.

References

Primary documentation and authoritative references for this source. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.

  1. Oryx — Stijn Mitzer and Joost Oliemans. The source itself. Start at the index to see which conflicts are currently tracked and how recently each list was touched, because coverage is uneven and undocumented.
  2. Attack On Europe: Documenting Russian Equipment Losses — Oryx. The reference implementation of the format and the single most cited open source attrition list in the field. Read the preamble, which states the visual-confirmation rule explicitly.
  3. Attack On Europe: Documenting Ukrainian Equipment Losses — Oryx. The paired list for the opposing belligerent. Reading the two together is the fastest way to understand why the ratio between them is not a combat outcome.
  4. Bellingcat — Bellingcat. The standing reference for open source verification and geolocation method, and the place where individual pieces of conflict imagery are most often examined in depth.
  5. OHCHR publications — UN Office of the High Commissioner for Human Rights. Where the Berkeley Protocol on Digital Open Source Investigations sits. Required reading before any use of conflict imagery in accountability work.
  6. SIPRI Arms Transfers Database — Stockholm International Peace Research Institute. The supply-side counterpart. Explains how the equipment being destroyed arrived, which is often the more consequential question.
  7. ACLED — Armed Conflict Location and Event Data Project. Dated, geocoded conflict events for the same theatres, and the practical route to giving Oryx entries a temporal anchor.
  8. Uppsala Conflict Data Program — Uppsala University. Conservative, long-running organised-violence data. A useful sanity check on whether documented loss clusters coincide with independently recorded fighting.
  9. Conflict Armament Research — Conflict Armament Research. Physical documentation and tracing of weapons recovered in conflict, including material that appears in loss imagery. The methodological opposite of a photo list, and complementary for it.
  10. GICHD — Geneva International Centre for Humanitarian Demining. For readers using loss clusters as an explosive-remnants contamination signal, the reference body for how that translates into survey and clearance practice.

Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.

Put it into practice

The Quantus Intel threat intelligence platform operationalises this source: it registers each Oryx list as a scheduled collection with snapshot retention, keys every entry on its evidence link rather than its list position, archives the linked media on first sight, and carries the visually-confirmed-floor caveat through correlation into the finished assessment.. Browse the full source catalogue, or follow any tag above into the rest of the library.

Leave a Reply