Open Source Intelligence (OSINT): What It Is and How Analysts Use It
The definition, the six disciplines, the legal test, and the difference between a lookup and a finding that survives review.
- Public sources only.
- Passive by definition.
- Reference page, not a pitch.
- General information, not legal advice.
Open source intelligence is the collection and analysis of publicly available information to answer a defined question. It is defined by the source being public, not by the subject and not by the tool. The work is passive: it reads records that registries, resolvers, company registers and transparency logs already publish, without accessing any system it does not own.
What separates intelligence from browsing is the second half of that sentence. A defined question, a recorded purpose, and findings that carry the record they came from and the moment they were retrieved. Everything below expands that.
The definition that decides everything else
Open source intelligence sources: what counts as public.
Public means published without an authentication boundary and without a term of service you accepted that prohibits the collection. It is a narrower category than "anything I can see on my screen", and getting the line wrong is how lawful research becomes an unlawful act.
Public
- DNS answers from public resolvers
- RDAP and WHOIS registration records
- Certificate transparency logs
- Company registry filings
- Court records where the jurisdiction publishes them
- A public website, a public post, a published paper
- Scan indexes such as Shodan, which record scanning already performed
Not public, whatever the tool suggests
- Anything behind a login, including one anybody could create
- Data obtained by circumventing a rate limit or a technical control
- Collection prohibited by terms you accepted
- Breach corpora containing an individual's credentials, absent a lawful basis
- Anything requiring a packet sent to a system you are not authorized to test
The last item is the one people miss. Reading an index of scan results is passive. Running the scan yourself is not, and the difference decides whether you needed a signed testing agreement.
What the work is actually made of
The six disciplines of open source intelligence.
Organized by the question each answers rather than by tool category, because the question is what you are given and the tool is what you pick afterwards.
Infrastructure
What does this organization run, and who controls it? DNS, mail routing, hosting, certificates, nameserver delegation.
Registration
How old is this name, who is the registrar of record, is it locked, when does it lapse? RDAP and WHOIS.
Corporate
Is this a real legal entity? Directors, filings, charges and ownership from public company registries.
Exposure
What is reachable from the internet, and what has leaked? Scan indexes, transparency logs, domain-level breach exposure.
Content and media
What has this organization published, and what does it reveal? Sites, filings, job posts, conference material.
Human-source and social
What have people connected to this entity said in public? The discipline where lawful basis becomes decisive.
Each one is broken down further, with where it stops, on the OSINT framework page.
The question every buyer asks first
Is open source intelligence legal?
Collecting publicly available information is lawful in most jurisdictions. Legality turns on four things, and none of them is the tool you used. This is general information about how the category works and it is not legal advice.
-
1
Source
Is the information genuinely public, or is it behind an authentication boundary or a contractual restriction you accepted?
-
2
Purpose
Why are you collecting? Recorded before collection it constrains the work. Reconstructed afterwards it is a justification.
-
3
Jurisdiction
Whose law applies to the subject, to you, and to the data? Cross-border matters are where good intentions most often produce unlawful processing.
-
4
Lawful basis
If personal data is involved, what is your basis under GDPR or the equivalent regime? "It was public" is not a basis.
The boundary we publish and enforce, including the named refusals, is on social media OSINT. The FAQ answers the legality question at more length.
The part most definitions leave out
What turns a lookup into evidence.
Public records change. A DNS answer from Tuesday says nothing about Friday unless you can show it was Tuesday. That is why a screenshot is an assertion and a sourced finding is not.
Three attachments on every finding, without exception, including the ones you are certain about. They are the ones that get challenged.
A finding, in the form that survives review
A reviewer can re-run that in ten seconds and either agree or not. Anything a reviewer cannot re-run is an assertion wearing the clothes of a finding.
What you will actually use
The tools, and the point at which each one stops.
Free collection tooling
theHarvester, Amass, Recon-ng, the OSINT Framework directory. Genuinely good, and every analyst should know them.
Stops at: No scope record, no audit trail, no report.
Record lookups
DNS over HTTPS, RDAP, certificate transparency. This is where most vendor and fraud questions are actually answered.
Stops at: A wall of text you then screenshot.
Registration data
RDAP has replaced port-43 WHOIS. Dates, registrar, status codes and delegation survive redaction.
Stops at: Undated, so unverifiable later.
Graph and link analysis
Maltego. Unmatched for relationship discovery and pivoting through entities visually.
Stops at: You finish with a chart and a blank document.
Scan indexes
Shodan, Censys. Reading an index is passive, because the scanning already happened.
Stops at: Results are dated observations, not statements about now.
Case and evidence platforms
Where Osintpro sits. Scoped case in, sourced and timestamped report out.
Stops at: Not a graph tool, not a feed, and never a people search.
Do it once, on something you own
Run the first two disciplines right now.
Registration and infrastructure, on a domain you are authorized to assess. Declare the scope, tick the authorization box, run it, and hover a finding to reveal the source endpoint and the UTC retrieval time. Domains only, never a person.
Then read the practical training path for what to learn next, and the report template for the shape of the output.
Domain footprint sweep
passive collection only
Every finding will carry four things
- 1 Severity. What the record means for the decision in front of you.
- 2 The raw record. Exactly as the source returned it, unedited.
- 3 The source endpoint. The request that produced it, so it can be re-run.
- 4 The UTC retrieval time. Records change. Without this it is an assertion.
Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.
Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.
[]
Scope:
Analyst summary
More OSINT reference pages
- Attack surface management
- Best OSINT tools
- Censys alternative
- Competitive intelligence
- Cybersecurity due diligence
- DNS lookup tool
- Free OSINT tools
- Investigators
- Maltego alternative
New to the category? Start with open source intelligence, then see how a scoped case runs or read the analyst notes on the blog.
Run one scoped sweep and see what a sourced finding looks like.
The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.
- Passive collection only, from public sources.
- A domain, never a person. There is no input for one.
- Your case data stays yours. No card required.