OSINT Blog: Analyst Notes on Defensible Investigation
No tool tours and no link dumps. These are the sources, techniques and reporting habits that decide whether an investigation survives the first person who challenges it.
Start with what open source intelligence is, or run the domain footprint sweep and see the output form first.
- 9 posts.
- Sources, techniques and reporting.
- Every claim traceable to a record.
Newest first
Every post.
-
Pricing 8 min
Maltego Pricing and Maltego Cost: Every Plan, the Per-Seat Math and the Enterprise Price
Maltego publishes more of its pricing than most of the category, and still leaves the number that matters to a team for you to work out. Here is every plan as Maltego lists it, what the credits pay for, and what three or five analysts actually cost before you talk to sales.
Read the post
-
Pricing 8 min
Cybersecurity Risk Assessment Cost: What US Providers Charge in 2026, by Assessment Type
Three US providers publish their rates. They do not agree, and the disagreement is the useful part: it tells you the number is set by scope definition rather than by your headcount. Here is what is published, and how to turn it into a quote you can actually compare.
Read the post
-
Landscape 8 min
Attack Surface Management Vendors: How to Shortlist EASM Tools and What They Actually Cost
Every roundup of attack surface management vendors names the same twelve products and none of them tells you what any of it costs. Here is the shortlisting method that survives contact with procurement, and the question worth answering before you take a single demo.
Read the post
-
Sources 9 min
Open Source Intelligence Websites Analysts Actually Use
Most OSINT link lists are inventories. This one is shorter on purpose: these are the sites that answer a question a case actually asks, grouped by the question rather than by category.
Read the post
-
Practice 11 min
Open Source Intelligence Training: A Practical Path
Most people learning OSINT start by collecting tools. That is the slowest possible route. Skill in this discipline is mostly reasoning, and the reasoning can be practised on your own infrastructure from day one.
Read the post
-
Technique 10 min
Shodan OSINT: Finding Exposed Infrastructure You Own
Shodan is an index of scan results, not a scanner you are pointing at anyone. That distinction is what makes it usable in a defensible investigation, and it is also why the scope you declare matters more than the queries you run.
Read the post
-
Technique 10 min
Open Source Intelligence Techniques for Defensible Collection
The techniques that separate a competent investigation from a folder of screenshots are not exotic. They are pivoting, corroboration, honest negative findings, and a retrieval discipline applied without exception.
Read the post
-
Landscape 9 min
Cyber Threat Intelligence Software vs OSINT: What the Difference Buys You
One is feed-shaped and answers what is happening globally. The other is case-shaped and answers what is true about this entity. Buying the wrong shape is expensive and extremely common.
Read the post
-
Reporting 11 min
OSINT Report Template for a Defensible Investigation
A report is not a transcript of what you did. It is a document somebody acts on and somebody else checks. Here is the structure that satisfies both, section by section, with the reasoning for each part.
Read the post
Related reference pages: open source intelligence, the OSINT framework, best OSINT tools, free OSINT tools and the maintained tools list.
Run one scoped sweep and see what a sourced finding looks like.
The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.
- Passive collection only, from public sources.
- A domain, never a person. There is no input for one.
- Your case data stays yours. No card required.