canonical referenceopen source intelligence

OSINT: Open Source Intelligence

Definition, methodology, sources, tools and practical workflows for turning open information into defensible intelligence.

definition

OSINT is intelligence produced by collecting, evaluating and analyzing publicly or commercially available information to answer a defined intelligence requirement or decision question.

Information is not intelligence. Open-source information is the input. OSINT is the intelligence produced when that information is verified, contextualized and analyzed against a defined requirement.

01definition

What is OSINT?

A precise definition starts with the intelligence requirement, not with the search engine or tool.

Open Source Intelligence (OSINT) is a disciplined process for collecting, evaluating, verifying and analyzing information available from public or commercially accessible sources in order to answer a defined intelligence requirement. Information becomes intelligence only when it is assessed in context and transformed into a defensible finding, judgment or decision-support product.

The defining characteristic is not simply that the source is open. A public webpage, company filing, image, DNS record or social post is still information until it is evaluated in relation to a question. OSINT begins to emerge when the investigator establishes provenance, checks reliability, connects evidence, tests explanations and communicates what the evidence means.

This requirement-driven view is consistent with the current U.S. Intelligence Community definition, which describes OSINT as intelligence derived exclusively from publicly or commercially available information that addresses specific intelligence priorities, requirements or gaps. It also aligns with professional investigation frameworks that distinguish collection from verification and analysis.

OSINT is
  • Requirement-driven
  • Source-aware and provenance-conscious
  • Verification and corroboration oriented
  • Analytical rather than purely accumulative
  • Explicit about uncertainty and limitations
  • Communicated for a user, decision or investigation
OSINT is not automatically
  • A Google search
  • A list of links
  • A scraped dataset with no analytical purpose
  • Unverified social-media content
  • Any activity simply because the target is public
  • A synonym for every other intelligence discipline
02core distinction

Open-source information is not the same as OSINT.

Finding something is retrieval. Understanding whether it matters to a defined question is intelligence work.

01

Public information

A webpage, record, image, post, dataset or technical observation.

02

Collection

Relevant material is gathered with source, timestamp and context.

03

Evaluation

The investigator checks relevance, origin, quality and potential bias.

04

Verification

Important facts are corroborated and contradictions are investigated.

05

Analysis

Evidence is connected to identify patterns, explanations and implications.

06

Intelligence

A defensible answer addresses the original requirement with confidence and limitations.

Finding information is retrieval. Establishing whether it is reliable is verification. Explaining what it means in relation to a defined question is analysis. Producing a defensible answer is intelligence.
03methodology

How does OSINT work?

A useful OSINT workflow starts with a requirement and ends with a documented intelligence product. Tools sit inside the process; they are not the process.

  1. 01

    Define the requirement

    State the decision, intelligence gap or research question that the investigation must answer.

    output · Defined question
  2. 02

    Plan collection

    Identify relevant source families, constraints, risks and collection priorities before opening tools.

    output · Collection plan
  3. 03

    Collect

    Gather relevant material while preserving URLs, timestamps, provenance and the context needed to evaluate it later.

    output · Raw information
  4. 04

    Process & resolve

    Normalize entities, remove obvious duplicates and connect material that refers to the same person, organization, asset or event.

    output · Structured evidence
  5. 05

    Verify & corroborate

    Assess provenance, reliability and consistency, and seek independent evidence for important claims.

    output · Assessed information
  6. 06

    Analyze

    Identify patterns, relationships, contradictions and explanations that matter to the original requirement.

    output · Findings
  7. 07

    Assess confidence

    Separate what is known, inferred and unknown, then record important limitations and alternative explanations.

    output · Confidence statement
  8. 08

    Disseminate

    Communicate the result in a form appropriate to the user, decision-maker or investigative record.

    output · Intelligence product
04sources

Where does OSINT come from?

OSINT can draw from many source families. The source is only one part of the assessment: access method, provenance, reliability, context and intended use matter too.

Web & archives

Websites, search engines, cached pages, historical snapshots and other publicly retrievable web material.

Public records

Company registries, court records, filings, procurement data, public notices and other official records.

News & publications

Journalism, reports, academic literature, institutional publications and specialist research.

Social platforms

Publicly accessible posts, profiles, discussions and network signals, subject to platform and legal constraints.

Technical infrastructure

DNS, RDAP, certificate transparency, IP/ASN data, repositories and other observable infrastructure metadata.

Geospatial & multimedia

Maps, satellite imagery, photographs, video, audio and associated metadata used for verification and geolocation.

Commercially available information

Datasets, databases and research services that are legitimately available through commercial access.

Code & technical artifacts

Public repositories, package registries, commits, documentation and other software-development traces.

05analysis

Collection is only the beginning.

Strong OSINT separates three jobs that are often collapsed into one: obtaining material, establishing what can be trusted, and deciding what the evidence means.

Collection

  • Find relevant material
  • Preserve source and context
  • Record time and provenance
  • Respect collection constraints

Verification

  • Check provenance
  • Assess source reliability
  • Seek independent corroboration
  • Identify manipulation or contradiction

Analysis

  • Connect facts and entities
  • Test hypotheses
  • Identify patterns and gaps
  • Assess confidence and alternatives
07collection mode

Passive and active OSINT collection

The distinction describes whether collection creates an observable interaction. It does not by itself determine whether an activity is legal, ethical or safe.

passive collection

Research that relies on information already exposed through public pages, archives, search indexes, datasets or other sources without deliberately interacting with the subject or subject-controlled infrastructure.

Search indexesWeb archivesPublic recordsExisting datasets
active collection

Research that deliberately generates an interaction that may be observable by a person, platform or target-controlled service. Active collection requires additional operational, legal and ethical consideration.

Direct requestsAccount interactionTarget-controlled servicesObservable probes
08tools

Choose OSINT tools by investigative task.

A tool is useful when it serves a defined step in the workflow. OSINT.dev classifies tools through the same live taxonomy used across the platform.

09applications

What is OSINT used for?

The same open-source methodology appears across security, journalism, research, due diligence and investigations; the requirement and evidentiary standard change by context.

Cybersecurity

Map exposed infrastructure, investigate phishing campaigns, enrich threat intelligence and understand an organization's public attack surface.

Investigative journalism

Verify people, organizations, events, media, timelines and public claims using reproducible evidence.

Due diligence

Research corporate ownership, public filings, counterparties, sanctions exposure and material public records.

Human rights

Collect, preserve and verify digital open-source information under professional evidentiary and safety standards.

Fraud investigation

Correlate identities, companies, domains, transactions and public traces to test investigative hypotheses.

Corporate intelligence

Understand markets, organizations, relationships, public capabilities and relevant changes in the external environment.

Fact-checking

Test claims against independent sources, imagery, chronology, provenance and primary documentation.

Academic & policy research

Systematically collect and analyze public evidence while documenting methods, limitations and source provenance.

10responsible practice

Publicly accessible does not mean unrestricted.

OSINT is constrained by purpose, jurisdiction, privacy, platform rules, proportionality, evidence standards and operational safety.

Accessibility is not a universal permission model.

The fact that information can be reached on the open web does not remove privacy obligations, contractual restrictions, data-protection rules, evidentiary duties or risks to people involved. The applicable standard depends on the collection method, purpose, jurisdiction and context.

Purpose

Collection should serve a legitimate, defined investigative or research requirement rather than open-ended accumulation.

Privacy & data protection

Public availability does not remove privacy, data-protection or jurisdictional obligations.

Terms & access controls

A source being technically reachable does not automatically authorize every collection method or downstream use.

Proportionality

Collect the information needed to answer the requirement and avoid unnecessary intrusion or exposure.

Sensitive information

Handle sensitive personal data, vulnerable people and high-risk contexts with additional safeguards.

Evidence integrity

Preserve provenance, timestamps, context and transformation history when findings may need to be reproduced or reviewed.

Operational safety

Consider risks to investigators, sources, bystanders and subjects before active collection or publication.

Uncertainty

Distinguish observed facts from inference and make confidence, gaps and plausible alternatives visible.

11classification

The OSINT.dev taxonomy: a live map of the catalog.

OSINT.dev already uses a shared classification backbone across tools, articles and sources. This is the operational foundation for the forthcoming open OSINT knowledge graph.

macrocategories
17

Stable top-level domains in the current catalog.

categories
60

Operational classes connected to catalog entities.

knowledge graph
planned

Next: source → task → technique → tool → risk → output.

12worked example

A reproducible OSINT workflow: investigating a domain

The objective is not to collect everything about a domain. It is to answer a scoped question using independent observations.

question

What publicly observable infrastructure is associated with example.com, and which findings can be corroborated independently?

  1. 01

    RDAP

    Establish registration and registrar-level context where available.

  2. 02

    DNS

    Resolve current records and identify infrastructure relationships.

  3. 03

    Certificate Transparency

    Find certificate observations that may reveal related hostnames.

  4. 04

    Web archives

    Compare historical public states and changes over time.

  5. 05

    Cross-validation

    Check whether observations agree across independent source families.

  6. 06

    Assessment

    Report supported findings, uncertainty and unresolved questions.

13continue

Learn OSINT through methods, not tool lists.

The supporting editorial layer expands individual parts of the workflow while the pillar remains the canonical overview.

14evidence

Primary sources and reference standards

Definitions and methodology on this page are grounded first in institutional and professional sources. Vendor explainers are not used as the primary authority for the core definition.

Primary · intelligence doctrine

Intelligence Community Open Source Intelligence Strategy 2024–2026

Office of the Director of National Intelligence

Defines OSINT as intelligence derived exclusively from publicly or commercially available information that addresses specific intelligence priorities, requirements or gaps.

Source
Primary · professional methodology

Berkeley Protocol on Digital Open Source Investigations

OHCHR & UC Berkeley Human Rights Center

A practical framework for the professional, legal and ethical collection, preservation, verification and analysis of digital open-source information.

Source
Institutional · terminology

OSINT–CLOSINT

CERT-AGID

Describes OSINT as a process of research, selection, evaluation and reporting used to satisfy a specific information need.

Source
Practitioner · methodology

What is Open-Source Intelligence?

SANS Institute

Useful practitioner explanation of the distinction between raw information and intelligence produced to answer a specific question.

Source

Global reference

The canonical version is maintained in English. Localized editions should be added only when search and user data justify sustained editorial maintenance.

Live product layer

Tools, source catalogs and taxonomy modules are resolved from the same data model used by the rest of OSINT.dev.

Open knowledge graph

Explore the versioned semantic layer connecting sources, tasks, techniques, tools, risks and intelligence outputs.

Open dataset
OSINT.dev canonical reference

Version 1.0 · Published September 19, 2026 · Last reviewed September 20, 2026