OSINT: Open Source Intelligence
Definition, methodology, sources, tools and practical workflows for turning open information into defensible intelligence.
OSINT is intelligence produced by collecting, evaluating and analyzing publicly or commercially available information to answer a defined intelligence requirement or decision question.
Information is not intelligence. Open-source information is the input. OSINT is the intelligence produced when that information is verified, contextualized and analyzed against a defined requirement.
What is OSINT?
A precise definition starts with the intelligence requirement, not with the search engine or tool.
Open Source Intelligence (OSINT) is a disciplined process for collecting, evaluating, verifying and analyzing information available from public or commercially accessible sources in order to answer a defined intelligence requirement. Information becomes intelligence only when it is assessed in context and transformed into a defensible finding, judgment or decision-support product.
The defining characteristic is not simply that the source is open. A public webpage, company filing, image, DNS record or social post is still information until it is evaluated in relation to a question. OSINT begins to emerge when the investigator establishes provenance, checks reliability, connects evidence, tests explanations and communicates what the evidence means.
This requirement-driven view is consistent with the current U.S. Intelligence Community definition, which describes OSINT as intelligence derived exclusively from publicly or commercially available information that addresses specific intelligence priorities, requirements or gaps. It also aligns with professional investigation frameworks that distinguish collection from verification and analysis.
- Requirement-driven
- Source-aware and provenance-conscious
- Verification and corroboration oriented
- Analytical rather than purely accumulative
- Explicit about uncertainty and limitations
- Communicated for a user, decision or investigation
- A Google search
- A list of links
- A scraped dataset with no analytical purpose
- Unverified social-media content
- Any activity simply because the target is public
- A synonym for every other intelligence discipline
Open-source information is not the same as OSINT.
Finding something is retrieval. Understanding whether it matters to a defined question is intelligence work.
Public information
A webpage, record, image, post, dataset or technical observation.
Collection
Relevant material is gathered with source, timestamp and context.
Evaluation
The investigator checks relevance, origin, quality and potential bias.
Verification
Important facts are corroborated and contradictions are investigated.
Analysis
Evidence is connected to identify patterns, explanations and implications.
Intelligence
A defensible answer addresses the original requirement with confidence and limitations.
Finding information is retrieval. Establishing whether it is reliable is verification. Explaining what it means in relation to a defined question is analysis. Producing a defensible answer is intelligence.
How does OSINT work?
A useful OSINT workflow starts with a requirement and ends with a documented intelligence product. Tools sit inside the process; they are not the process.
- 01
Define the requirement
State the decision, intelligence gap or research question that the investigation must answer.
output · Defined question - 02
Plan collection
Identify relevant source families, constraints, risks and collection priorities before opening tools.
output · Collection plan - 03
Collect
Gather relevant material while preserving URLs, timestamps, provenance and the context needed to evaluate it later.
output · Raw information - 04
Process & resolve
Normalize entities, remove obvious duplicates and connect material that refers to the same person, organization, asset or event.
output · Structured evidence - 05
Verify & corroborate
Assess provenance, reliability and consistency, and seek independent evidence for important claims.
output · Assessed information - 06
Analyze
Identify patterns, relationships, contradictions and explanations that matter to the original requirement.
output · Findings - 07
Assess confidence
Separate what is known, inferred and unknown, then record important limitations and alternative explanations.
output · Confidence statement - 08
Disseminate
Communicate the result in a form appropriate to the user, decision-maker or investigative record.
output · Intelligence product
Where does OSINT come from?
OSINT can draw from many source families. The source is only one part of the assessment: access method, provenance, reliability, context and intended use matter too.
Web & archives
Websites, search engines, cached pages, historical snapshots and other publicly retrievable web material.
Public records
Company registries, court records, filings, procurement data, public notices and other official records.
News & publications
Journalism, reports, academic literature, institutional publications and specialist research.
Social platforms
Publicly accessible posts, profiles, discussions and network signals, subject to platform and legal constraints.
Technical infrastructure
DNS, RDAP, certificate transparency, IP/ASN data, repositories and other observable infrastructure metadata.
Geospatial & multimedia
Maps, satellite imagery, photographs, video, audio and associated metadata used for verification and geolocation.
Commercially available information
Datasets, databases and research services that are legitimately available through commercial access.
Code & technical artifacts
Public repositories, package registries, commits, documentation and other software-development traces.
Source categories currently represented in the catalog
Collection is only the beginning.
Strong OSINT separates three jobs that are often collapsed into one: obtaining material, establishing what can be trusted, and deciding what the evidence means.
Collection
- Find relevant material
- Preserve source and context
- Record time and provenance
- Respect collection constraints
Verification
- Check provenance
- Assess source reliability
- Seek independent corroboration
- Identify manipulation or contradiction
Analysis
- Connect facts and entities
- Test hypotheses
- Identify patterns and gaps
- Assess confidence and alternatives
Passive and active OSINT collection
The distinction describes whether collection creates an observable interaction. It does not by itself determine whether an activity is legal, ethical or safe.
Research that relies on information already exposed through public pages, archives, search indexes, datasets or other sources without deliberately interacting with the subject or subject-controlled infrastructure.
Research that deliberately generates an interaction that may be observable by a person, platform or target-controlled service. Active collection requires additional operational, legal and ethical consideration.
Choose OSINT tools by investigative task.
A tool is useful when it serves a defined step in the workflow. OSINT.dev classifies tools through the same live taxonomy used across the platform.
Security Headers Checker
Inspect HTTP security headers on any public URL.
DNS / MX / SPF / DMARC Inspector
Resolve DNS, mail-routing and email-authentication posture for a domain, including deep SPF/DMARC analysis.
Robots.txt + Sitemap + Meta Analyzer
Inspect robots.txt, sitemap discovery and head meta of a page.
Redirect Chain & Response Inspector
Follow every hop of a URL and report the response chain.
Tech Stack Snapshot
Lightweight tech-stack fingerprint for a public URL.
OpenCorporates
Search company records across many official registries in one place.
What is OSINT used for?
The same open-source methodology appears across security, journalism, research, due diligence and investigations; the requirement and evidentiary standard change by context.
Cybersecurity
Map exposed infrastructure, investigate phishing campaigns, enrich threat intelligence and understand an organization's public attack surface.
Investigative journalism
Verify people, organizations, events, media, timelines and public claims using reproducible evidence.
Due diligence
Research corporate ownership, public filings, counterparties, sanctions exposure and material public records.
Human rights
Collect, preserve and verify digital open-source information under professional evidentiary and safety standards.
Fraud investigation
Correlate identities, companies, domains, transactions and public traces to test investigative hypotheses.
Corporate intelligence
Understand markets, organizations, relationships, public capabilities and relevant changes in the external environment.
Fact-checking
Test claims against independent sources, imagery, chronology, provenance and primary documentation.
Academic & policy research
Systematically collect and analyze public evidence while documenting methods, limitations and source provenance.
Publicly accessible does not mean unrestricted.
OSINT is constrained by purpose, jurisdiction, privacy, platform rules, proportionality, evidence standards and operational safety.
Accessibility is not a universal permission model.
The fact that information can be reached on the open web does not remove privacy obligations, contractual restrictions, data-protection rules, evidentiary duties or risks to people involved. The applicable standard depends on the collection method, purpose, jurisdiction and context.
Purpose
Collection should serve a legitimate, defined investigative or research requirement rather than open-ended accumulation.
Privacy & data protection
Public availability does not remove privacy, data-protection or jurisdictional obligations.
Terms & access controls
A source being technically reachable does not automatically authorize every collection method or downstream use.
Proportionality
Collect the information needed to answer the requirement and avoid unnecessary intrusion or exposure.
Sensitive information
Handle sensitive personal data, vulnerable people and high-risk contexts with additional safeguards.
Evidence integrity
Preserve provenance, timestamps, context and transformation history when findings may need to be reproduced or reviewed.
Operational safety
Consider risks to investigators, sources, bystanders and subjects before active collection or publication.
Uncertainty
Distinguish observed facts from inference and make confidence, gaps and plausible alternatives visible.
The OSINT.dev taxonomy: a live map of the catalog.
OSINT.dev already uses a shared classification backbone across tools, articles and sources. This is the operational foundation for the forthcoming open OSINT knowledge graph.
Stable top-level domains in the current catalog.
Operational classes connected to catalog entities.
Next: source → task → technique → tool → risk → output.
Domain & Web
4 categoriesDomini, HTTP, struttura web
Email & Deliverability
3 categoriesEmail e deliverability
Security & Headers
3 categoriesHeader e sicurezza web
Metadata & Discovery
3 categoriesMetadati e discovery
Reputation & Risk
3 categoriesRischio ed esposizione
Infrastructure & DNS
4 categoriesDNS e infrastruttura
Geo & Visual
1 categoriesGeolocation and visual verification
Identity & People
3 categoriesPeople and identity
A reproducible OSINT workflow: investigating a domain
The objective is not to collect everything about a domain. It is to answer a scoped question using independent observations.
What publicly observable infrastructure is associated with example.com, and which findings can be corroborated independently?
- 01
RDAP
Establish registration and registrar-level context where available.
- 02
DNS
Resolve current records and identify infrastructure relationships.
- 03
Certificate Transparency
Find certificate observations that may reveal related hostnames.
- 04
Web archives
Compare historical public states and changes over time.
- 05
Cross-validation
Check whether observations agree across independent source families.
- 06
Assessment
Report supported findings, uncertainty and unresolved questions.
Learn OSINT through methods, not tool lists.
The supporting editorial layer expands individual parts of the workflow while the pillar remains the canonical overview.
Stop Calling Them Hackers
Calling every cyber actor a hacker collapses authorization, motive and attribution into one vague label. Better OSINT starts with language precise enough to preserve what the evidence actually says.
OSINT Is Not Just Searching
Search finds public information. OSINT begins when that information is resolved, verified, contextualized, corroborated and turned into a traceable answer to a defined question.
The Problem With Tool-Centric OSINT Education
Tool lists are useful, but training people around interfaces creates dependency. Durable OSINT education should teach questions, signal meaning, source criticism, limitations, evidence states and judgment — with tools inside the method.
Passive First: When Public Web Research Should Stay Narrow
A practical argument for staying narrow and passive as long as possible in public web research, before broader or more interaction-heavy methods start adding noise.
Primary sources and reference standards
Definitions and methodology on this page are grounded first in institutional and professional sources. Vendor explainers are not used as the primary authority for the core definition.
Intelligence Community Open Source Intelligence Strategy 2024–2026
Office of the Director of National Intelligence
Defines OSINT as intelligence derived exclusively from publicly or commercially available information that addresses specific intelligence priorities, requirements or gaps.
Berkeley Protocol on Digital Open Source Investigations
OHCHR & UC Berkeley Human Rights Center
A practical framework for the professional, legal and ethical collection, preservation, verification and analysis of digital open-source information.
OSINT–CLOSINT
CERT-AGID
Describes OSINT as a process of research, selection, evaluation and reporting used to satisfy a specific information need.
What is Open-Source Intelligence?
SANS Institute
Useful practitioner explanation of the distinction between raw information and intelligence produced to answer a specific question.
Global reference
The canonical version is maintained in English. Localized editions should be added only when search and user data justify sustained editorial maintenance.
Live product layer
Tools, source catalogs and taxonomy modules are resolved from the same data model used by the rest of OSINT.dev.
Open knowledge graph
Explore the versioned semantic layer connecting sources, tasks, techniques, tools, risks and intelligence outputs.
Open dataset