Skip to content
Osintpro

OSINT Framework: The Disciplines, Mapped to the Questions They Answer

The well-known OSINT Framework is a directory tree of links. It is a useful index and it is not a framework in the analytic sense, because it organizes by tool rather than by the question you are trying to answer.

This is the map we actually work from: six disciplines, what each is genuinely good for, and the point at which each stops being enough.

See pricing
  • Reference, not a pitch.
  • Sources named throughout.
  • Passive collection only.
  • Kept current by the team.

Organize by question, not by tool.

A tool-shaped index tells you what exists. It does not tell you what to run, in what order, or when to stop, which is what a junior analyst is actually missing and what a senior one has internalised.

A question-shaped map does. Start from what you have been asked, work out which discipline answers it, and the tool choice usually collapses to one or two options. It also tells you when you have finished, which is the part nobody teaches: an investigation ends when the question is answered to the confidence the decision requires, not when the tools run out.

The six disciplines below cover essentially all of defensible, passive open source work on organizations. Four of them are what the domain footprint sweep automates.

The six disciplines and what each answers.

Infrastructure intelligence

The question it answers
What does this organization run, and who controls it? DNS, hosting, mail routing, certificates, nameserver delegation.
Where it stops
Tells you nothing about the legal entity, its finances, or the humans involved.

Registration intelligence

The question it answers
How old is this name, who is the registrar of record, is it locked, when does it lapse? RDAP and WHOIS.
Where it stops
Redaction removed most individual registrant detail. What survives is dates, registrar, status codes and nameservers.

Corporate intelligence

The question it answers
Is this a real legal entity? Directors, filings, charges, ownership, from public registries.
Where it stops
Registry data lags reality, and quality varies enormously by jurisdiction.

Exposure intelligence

The question it answers
What is reachable, and what has leaked? Scan indexes, certificate transparency, breach corpora at the domain level.
Where it stops
Index results are dated observations, not statements about now. Version banners are leads, not vulnerabilities.

Content and media intelligence

The question it answers
What has this organization published, and what does it reveal? Sites, filings, job posts, conference material, image metadata.
Where it stops
Verification is the hard part. Reposted material and generated media both mislead at scale.

Human-source and social intelligence

The question it answers
What have people connected to this entity said in public?
Where it stops
This is where lawful basis becomes decisive. See the boundary we publish.

The two flagged rows are the disciplines that most often produce wrong or unlawful conclusions, for opposite reasons: exposure data is easy to misdate, and social collection is easy to misdirect at a person.

The order that saves the most time.

  1. Step 1

    Write the question and the scope

    One sentence for what you are being asked, one for what you are authorized to look at, one for what is out of bounds. Before any collection. This is the step that decides whether the work is defensible.

  2. Step 2

    Registration and infrastructure first

    Cheapest, fastest, highest yield, and entirely passive. Age, registrar, locks, nameservers, mail posture. Most vendor and fraud questions are largely answered here.

  3. Step 3

    Corporate registry second

    Confirms the entity behind the infrastructure exists and files. Cross-jurisdiction work belongs here, not later.

  4. Step 4

    Exposure third, and dated carefully

    Certificate transparency for hostnames, scan indexes for reachable services. Record the observation date separately from your retrieval date, because they are two different events.

  5. Step 5

    Content and media only if the question needs it

    Expensive in analyst time and the easiest place to drift. Return to your scope sentence before you start.

  6. Step 6

    Stop when the decision is supported

    Not when the tools are exhausted. Write the confidence level and the limitations, then close the case.

Which parts of this map Osintpro performs.

Stated precisely, because a platform that implies it covers everything is not a platform you can rely on for scope.

Infrastructure: automated

DNS records, mail posture derivation, nameserver and hosting attribution, reverse records. Live in the DNS module and in the demo on this page.

Registration: automated

RDAP events, registrar of record, status code interpretation, delegation. See the WHOIS module.

Exposure, hostname surface: automated

Certificate and common-label hostname discovery, with each observation dated and sourced.

Corporate registry: analyst work

Described as a platform capability rather than demonstrated here. The demo does not query registries and does not pretend to.

Content and media: analyst work

Judgment-heavy, and we do not automate judgment.

Human-source and social: refused by design

The demo has no input that accepts a person, and monitoring an individual without a lawful basis is prohibited by our acceptable use policy.

Run the first two disciplines, right now.

Registration and infrastructure, scoped and passive, with every finding carrying its raw record, its source endpoint and its UTC retrieval time. Domains only.

  • It runs in your browser. Queries go to public DNS and RDAP endpoints, not through us.

  • Nothing reaches the subject. The domain you enter is never contacted, probed or scanned.

  • A domain, never a person. There is no input on this panel that accepts an individual.

  • Findings carry their evidence. Raw record, source endpoint and the UTC moment of retrieval.

Domain footprint sweep

passive collection only

stamped on the report
Samples:

Every finding will carry four things

  • 1 Severity. What the record means for the decision in front of you.
  • 2 The raw record. Exactly as the source returned it, unedited.
  • 3 The source endpoint. The request that produced it, so it can be re-run.
  • 4 The UTC retrieval time. Records change. Without this it is an assertion.

Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.

Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.

A framework organizes collection. It does not make it defensible.

Following a good map and taking screenshots still leaves you with undated claims.

Structure helps you collect the right things in the right order. It does nothing about the two failures that actually sink investigations: nothing recorded what you were authorized to look at, and nothing recorded when each record said what it said.

Those are the two things this platform adds to the map above. If you want to build the habit by hand first, the techniques post and the report template are free and use no product.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.