Skip to content
Osintpro

Open Source Intelligence (OSINT): What It Is and How Analysts Use It

The definition, the six disciplines, the legal test, and the difference between a lookup and a finding that survives review.

  • Public sources only.
  • Passive by definition.
  • Reference page, not a pitch.
  • General information, not legal advice.

Open source intelligence is the collection and analysis of publicly available information to answer a defined question. It is defined by the source being public, not by the subject and not by the tool. The work is passive: it reads records that registries, resolvers, company registers and transparency logs already publish, without accessing any system it does not own.

What separates intelligence from browsing is the second half of that sentence. A defined question, a recorded purpose, and findings that carry the record they came from and the moment they were retrieved. Everything below expands that.

The definition that decides everything else

Open source intelligence sources: what counts as public.

Public means published without an authentication boundary and without a term of service you accepted that prohibits the collection. It is a narrower category than "anything I can see on my screen", and getting the line wrong is how lawful research becomes an unlawful act.

Public

  • DNS answers from public resolvers
  • RDAP and WHOIS registration records
  • Certificate transparency logs
  • Company registry filings
  • Court records where the jurisdiction publishes them
  • A public website, a public post, a published paper
  • Scan indexes such as Shodan, which record scanning already performed

Not public, whatever the tool suggests

  • Anything behind a login, including one anybody could create
  • Data obtained by circumventing a rate limit or a technical control
  • Collection prohibited by terms you accepted
  • Breach corpora containing an individual's credentials, absent a lawful basis
  • Anything requiring a packet sent to a system you are not authorized to test

The last item is the one people miss. Reading an index of scan results is passive. Running the scan yourself is not, and the difference decides whether you needed a signed testing agreement.

What the work is actually made of

The six disciplines of open source intelligence.

Organized by the question each answers rather than by tool category, because the question is what you are given and the tool is what you pick afterwards.

Infrastructure

What does this organization run, and who controls it? DNS, mail routing, hosting, certificates, nameserver delegation.

Registration

How old is this name, who is the registrar of record, is it locked, when does it lapse? RDAP and WHOIS.

Corporate

Is this a real legal entity? Directors, filings, charges and ownership from public company registries.

Exposure

What is reachable from the internet, and what has leaked? Scan indexes, transparency logs, domain-level breach exposure.

Content and media

What has this organization published, and what does it reveal? Sites, filings, job posts, conference material.

Human-source and social

What have people connected to this entity said in public? The discipline where lawful basis becomes decisive.

Each one is broken down further, with where it stops, on the OSINT framework page.

The part most definitions leave out

What turns a lookup into evidence.

Public records change. A DNS answer from Tuesday says nothing about Friday unless you can show it was Tuesday. That is why a screenshot is an assertion and a sourced finding is not.

Three attachments on every finding, without exception, including the ones you are certain about. They are the ones that get challenged.

A finding, in the form that survives review

Severity High
Claim No DMARC policy is published, so SPF and DKIM are not enforced
Evidence _dmarc.example.com TXT -> no answer
Source GET dns.google/resolve?name=_dmarc.example.com&type=TXT
Retrieved 2026-09-04T09:14:33Z

A reviewer can re-run that in ten seconds and either agree or not. Anything a reviewer cannot re-run is an assertion wearing the clothes of a finding.

What you will actually use

The tools, and the point at which each one stops.

Free collection tooling

theHarvester, Amass, Recon-ng, the OSINT Framework directory. Genuinely good, and every analyst should know them.

Stops at: No scope record, no audit trail, no report.

Free OSINT tools

Record lookups

DNS over HTTPS, RDAP, certificate transparency. This is where most vendor and fraud questions are actually answered.

Stops at: A wall of text you then screenshot.

DNS lookup

Registration data

RDAP has replaced port-43 WHOIS. Dates, registrar, status codes and delegation survive redaction.

Stops at: Undated, so unverifiable later.

WHOIS lookup

Graph and link analysis

Maltego. Unmatched for relationship discovery and pivoting through entities visually.

Stops at: You finish with a chart and a blank document.

Maltego comparison

Scan indexes

Shodan, Censys. Reading an index is passive, because the scanning already happened.

Stops at: Results are dated observations, not statements about now.

Attack surface management

Case and evidence platforms

Where Osintpro sits. Scoped case in, sourced and timestamped report out.

Stops at: Not a graph tool, not a feed, and never a people search.

Full comparison

Do it once, on something you own

Run the first two disciplines right now.

Registration and infrastructure, on a domain you are authorized to assess. Declare the scope, tick the authorization box, run it, and hover a finding to reveal the source endpoint and the UTC retrieval time. Domains only, never a person.

Then read the practical training path for what to learn next, and the report template for the shape of the output.

Domain footprint sweep

passive collection only

stamped on the report
Samples:

Every finding will carry four things

  • 1 Severity. What the record means for the decision in front of you.
  • 2 The raw record. Exactly as the source returned it, unedited.
  • 3 The source endpoint. The request that produced it, so it can be re-run.
  • 4 The UTC retrieval time. Records change. Without this it is an assertion.

Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.

Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.