OSINT Framework: The Disciplines, Mapped to the Questions They Answer
The well-known OSINT Framework is a directory tree of links. It is a useful index and it is not a framework in the analytic sense, because it organizes by tool rather than by the question you are trying to answer.
This is the map we actually work from: six disciplines, what each is genuinely good for, and the point at which each stops being enough.
- Reference, not a pitch.
- Sources named throughout.
- Passive collection only.
- Kept current by the team.
Organize by question, not by tool.
A tool-shaped index tells you what exists. It does not tell you what to run, in what order, or when to stop, which is what a junior analyst is actually missing and what a senior one has internalised.
A question-shaped map does. Start from what you have been asked, work out which discipline answers it, and the tool choice usually collapses to one or two options. It also tells you when you have finished, which is the part nobody teaches: an investigation ends when the question is answered to the confidence the decision requires, not when the tools run out.
The six disciplines below cover essentially all of defensible, passive open source work on organizations. Four of them are what the domain footprint sweep automates.
The six disciplines and what each answers.
Infrastructure intelligence
- The question it answers
- What does this organization run, and who controls it? DNS, hosting, mail routing, certificates, nameserver delegation.
- Where it stops
- Tells you nothing about the legal entity, its finances, or the humans involved.
Registration intelligence
- The question it answers
- How old is this name, who is the registrar of record, is it locked, when does it lapse? RDAP and WHOIS.
- Where it stops
- Redaction removed most individual registrant detail. What survives is dates, registrar, status codes and nameservers.
Corporate intelligence
- The question it answers
- Is this a real legal entity? Directors, filings, charges, ownership, from public registries.
- Where it stops
- Registry data lags reality, and quality varies enormously by jurisdiction.
Exposure intelligence
- The question it answers
- What is reachable, and what has leaked? Scan indexes, certificate transparency, breach corpora at the domain level.
- Where it stops
- Index results are dated observations, not statements about now. Version banners are leads, not vulnerabilities.
Content and media intelligence
- The question it answers
- What has this organization published, and what does it reveal? Sites, filings, job posts, conference material, image metadata.
- Where it stops
- Verification is the hard part. Reposted material and generated media both mislead at scale.
Human-source and social intelligence
- The question it answers
- What have people connected to this entity said in public?
- Where it stops
- This is where lawful basis becomes decisive. See the boundary we publish.
The two flagged rows are the disciplines that most often produce wrong or unlawful conclusions, for opposite reasons: exposure data is easy to misdate, and social collection is easy to misdirect at a person.
The order that saves the most time.
-
Step 1
Write the question and the scope
One sentence for what you are being asked, one for what you are authorized to look at, one for what is out of bounds. Before any collection. This is the step that decides whether the work is defensible.
-
Step 2
Registration and infrastructure first
Cheapest, fastest, highest yield, and entirely passive. Age, registrar, locks, nameservers, mail posture. Most vendor and fraud questions are largely answered here.
-
Step 3
Corporate registry second
Confirms the entity behind the infrastructure exists and files. Cross-jurisdiction work belongs here, not later.
-
Step 4
Exposure third, and dated carefully
Certificate transparency for hostnames, scan indexes for reachable services. Record the observation date separately from your retrieval date, because they are two different events.
-
Step 5
Content and media only if the question needs it
Expensive in analyst time and the easiest place to drift. Return to your scope sentence before you start.
-
Step 6
Stop when the decision is supported
Not when the tools are exhausted. Write the confidence level and the limitations, then close the case.
Which parts of this map Osintpro performs.
Stated precisely, because a platform that implies it covers everything is not a platform you can rely on for scope.
Infrastructure: automated
DNS records, mail posture derivation, nameserver and hosting attribution, reverse records. Live in the DNS module and in the demo on this page.
Registration: automated
RDAP events, registrar of record, status code interpretation, delegation. See the WHOIS module.
Exposure, hostname surface: automated
Certificate and common-label hostname discovery, with each observation dated and sourced.
Corporate registry: analyst work
Described as a platform capability rather than demonstrated here. The demo does not query registries and does not pretend to.
Content and media: analyst work
Judgment-heavy, and we do not automate judgment.
Human-source and social: refused by design
The demo has no input that accepts a person, and monitoring an individual without a lawful basis is prohibited by our acceptable use policy.
Run the first two disciplines, right now.
Registration and infrastructure, scoped and passive, with every finding carrying its raw record, its source endpoint and its UTC retrieval time. Domains only.
-
It runs in your browser. Queries go to public DNS and RDAP endpoints, not through us.
-
Nothing reaches the subject. The domain you enter is never contacted, probed or scanned.
-
A domain, never a person. There is no input on this panel that accepts an individual.
-
Findings carry their evidence. Raw record, source endpoint and the UTC moment of retrieval.
Domain footprint sweep
passive collection only
Every finding will carry four things
- 1 Severity. What the record means for the decision in front of you.
- 2 The raw record. Exactly as the source returned it, unedited.
- 3 The source endpoint. The request that produced it, so it can be re-run.
- 4 The UTC retrieval time. Records change. Without this it is an assertion.
Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.
Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.
[]
Scope:
Analyst summary
A framework organizes collection. It does not make it defensible.
Following a good map and taking screenshots still leaves you with undated claims.
Structure helps you collect the right things in the right order. It does nothing about the two failures that actually sink investigations: nothing recorded what you were authorized to look at, and nothing recorded when each record said what it said.
Those are the two things this platform adds to the map above. If you want to build the habit by hand first, the techniques post and the report template are free and use no product.
More OSINT reference pages
- Attack surface management
- Best OSINT tools
- Censys alternative
- Competitive intelligence
- Cybersecurity due diligence
- DNS lookup tool
- Free OSINT tools
- Investigators
- Maltego alternative
New to the category? Start with open source intelligence, then see how a scoped case runs or read the analyst notes on the blog.
Run one scoped sweep and see what a sourced finding looks like.
The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.
- Passive collection only, from public sources.
- A domain, never a person. There is no input for one.
- Your case data stays yours. No card required.