This website uses cookies

Read our Privacy policy and Terms of use for more information.

GUIDEGDE-000
TOPICOSINT FUNDAMENTALS
DOMAINOSINT METHODOLOGY
LAST UPDATEDJULY 2026

01

What it is

OSINT is intelligence gathered from publicly available sources, such as websites, social media, public records and open data, using a defined and repeatable process rather than random searching.

The term covers a spectrum of activity, from a quick background check against public records to a multi week investigation drawing on satellite imagery, corporate filings and social media archives. What separates OSINT from casual searching is method: a defined question, a deliberate source strategy and verification before any finding is treated as fact.

Investigative journalists use OSINT to establish facts before publication. Corporate investigators use it for due diligence and fraud detection. Human rights researchers use it to document abuses from footage and metadata that would otherwise go unexamined. Law enforcement and intelligence analysts use it as one input among several, subject to the same evidentiary standards as any other source.

When to use this guide

  • Starting an investigation and needing a working definition before choosing tools
  • Explaining OSINT to a newsroom, client or colleague unfamiliar with the discipline
  • Distinguishing OSINT from hacking, social engineering or unauthorised data access
  • Building a repeatable process rather than searching ad hoc
  • Evaluating whether a finding qualifies as OSINT-derived evidence

02

How is an OSINT investigation structured?

Every OSINT investigation follows the same underlying cycle, regardless of the technique or platform involved.

The tools below are starting points for building an OSINT practice, not a technique-specific stack. Each is free and requires no registration.

OSINT Framework: A free, browser-based directory of OSINT tools organised by category, including usernames, email addresses, domains, social media and geolocation. It does not collect intelligence itself; it points to the source or tool suited to a specific question. No registration required.

Google Advanced Search: A free structured search interface for narrowing results by site, file type, date range and exact phrase. It is the basis for search operator technique, sometimes called dorking, a foundational OSINT search method. No registration required.

Wayback Machine: A free archive of historical web page snapshots, run by the Internet Archive. Used to recover deleted or altered content and to establish when a page existed in a given state. No registration required.

Before you begin

Stop at the login
All tools referenced in this guide are free and require no login. If a source encountered later in an investigation asks for registration or payment, treat that as a deliberate escalation decision, not a default step.

Legal considerations
OSINT is the legal collection of publicly available information. It stops being OSINT the moment it requires bypassing access controls, using a false identity to gain access, or acquiring breached data. Data protection law, such as GDPR and equivalent regimes, still governs how findings are stored and used, regardless of jurisdiction.

The method

01

Define the question, not just the subject

Goal · Establish a specific, answerable investigative question before opening any source.

Every OSINT investigation starts with a defined question, not a subject. “What ties company X to person Y” is a question. “Find everything about X” is not. A vague starting point produces unfocused collection and wastes time verifying material that never answers anything. Write the question down before opening a browser tab.

02

Map the likely source categories

Goal · Identify which types of public sources are likely to hold an answer, before searching.

Corporate filings, court records, social media, domain registration data, satellite imagery and archived web pages each answer different kinds of questions. Match the question to a source category first. This prevents defaulting to a general web search when a structured registry, such as a companies register or DNS record, would answer the question faster and more reliably.

03

Collect from public sources systematically

Goal · Gather material from the identified sources using a repeatable method.

Use the OSINT Framework, or an equivalent directory, to identify the specific tool or registry suited to each source category, then work through them in order. Record where each piece of material came from and when it was collected as you go, not afterwards.

04

Verify before treating an OSINT finding as fact

Goal · Corroborate every material finding with at least one independent source before relying on it.

A single source, however credible it looks, is a lead, not a fact. Cross-reference names, dates and locations against at least one independent source. Where corroboration is not possible, grade the finding by confidence rather than presenting it as established.

05

Assess confidence and gaps

Goal · State plainly what is confirmed, what is likely, and what remains unknown.

Before drawing conclusions, separate confirmed findings from inference. Note where evidence is thin, contradictory or absent. This step is what distinguishes a structured OSINT process from a loosely supported narrative.

06

Record and report with sources intact

Goal · Document the investigation so findings can be checked and reproduced by someone else.

Retain screenshots, archive captures and source URLs for every material finding. Present conclusions with their supporting evidence attached, not asserted without a trail back to source. This is the step that turns OSINT into defensible evidence rather than an unsupported claim.

03

Where OSINT investigations go wrong

Common errors and evidentiary traps that undermine an otherwise sound OSINT process.

Treating a single source as confirmation: A social media profile, WHOIS record or forum post that appears to confirm a fact is still one data point until independently corroborated. Analysts under time pressure often stop at the first plausible match.

Verifying check: At least one independent source, ideally from a different category, such as a registry alongside a social profile, supports the same finding before it is treated as established.

Confusing a directory with a technique: OSINT Framework and similar tools are indexes, not investigative methods. Citing “I used OSINT Framework” as a method statement obscures which actual source and technique produced a finding.

Verifying check: The investigation record names the specific source or tool used for each finding, not the directory that pointed to it.

Conflating OSINT with unauthorised access: Bypassing a login wall, using a false identity to join a private group, or purchasing breached data are not OSINT. Each carries legal exposure the practitioner may not have assessed.

Verifying check: Every source used was reachable without circumventing an access control, a deceptive identity or payment for stolen data.

Skipping documentation until the finding matters: Recreating a source trail from memory after the fact introduces errors and cannot be defended if challenged.

Verifying check: A capture, such as a screenshot, archive URL or file, exists for every material finding, timestamped at the point of collection.

Chain of custody: For OSINT findings to hold up under scrutiny, whether in a newsroom fact-check, a legal proceeding or an internal investigation, the collection method and evidence chain must be reconstructable by someone other than the original analyst.

  1. Capture a screenshot or full-page archive at the point of collection, not afterwards.

  2. Record the source URL, access date and collection method for every finding.

  3. Preserve the original file or capture unaltered; store edited or annotated copies separately.

  4. Hash any file-based evidence where reproducibility may be challenged.

  5. Note the confidence grade assigned to each finding alongside its source.

04

Go deeper

Guides, reference cards and tutorials for practitioners ready to apply OSINT to a specific technique.

INVESTIGATION SYSTEM

OSINT Investigator.

The six steps in this guide, defining a question through documenting sources, built out into a full system: seven investigation modes, Admiralty grading on every source, and a shared Cases spine so nothing gets lost between platforms.

Notion workspace
€129.00GET THE INVESTIGATOR →