What Is OSINT? Open Source Intelligence Sources, Tools & Uses

OSINT turns publicly available information into intelligence. See what attackers learn from open sources, how investigations run, key tools, and legal limits.
Published on
Sunday, September 27, 2026
Updated on
September 26, 2026

Open source intelligence (OSINT) is intelligence produced by collecting, verifying, and analyzing publicly available sources to answer a specific question or solve problems. The raw material is public. The intelligence comes from the question asked and the analysis applied.

That distinction between data and intelligence matters more than any tool. A folder of screenshots about a company is data; a finding that its staging server runs an unpatched VPN appliance, reachable from a subdomain listed in a public certificate log, is intelligence.

Inside security teams, OSINT cuts both ways, since attackers and defenders read the same sources. Attackers use it to choose targets and write convincing lures, and defenders use the same sources to see their organization the way an attacker does, then close what they find.

What Counts as OSINT, and What Does Not

OSINT covers information anyone can lawfully access without breaking in, paying a criminal, or deceiving someone into sharing it.

Inside the boundary sit websites, DNS and certificate records, internet scan data, public code repositories, social media, job postings, court and company filings, news reporting, and archived versions of all of them. Some sources need a free account or a paid subscription, and they still count, because access requires registration, not bypassing a control.

Outside the boundary sits anything obtained through unauthorized access, credentials used to log in somewhere they were not meant for, and information collected by impersonating a person. Leaked breach data is the grey zone practitioners argue about: it is widely circulated, but it was stolen, so mature teams handle it under a written policy instead of treating it as ordinary open-source material.

OSINT works alongside the other intelligence disciplines, not above them. Human intelligence comes from people, signals intelligence from intercepted communications, and geospatial intelligence from imagery; OSINT supplies much of the context that makes the others readable.

What Attackers Learn About an Organization From OSINT

A capable attacker builds a detailed map of an organization in an afternoon, using nothing but public sources. A typical reconnaissance pass runs in roughly this order:

  1. Domains and infrastructure: WHOIS records, DNS, and IP allocation data reveal the organization's domains, hosting providers, and network ranges.
  2. Hidden subdomains: Certificate transparency logs list every hostname named on a publicly trusted TLS certificate, including vpn, staging, and Jenkins hosts nobody meant to advertise, and the dangling records behind a subdomain takeover.
  3. Exposed services: Internet scan data from services such as Shodan and Censys shows which ports are open on those hosts and which software versions answer.
  4. Technology stack: Job postings name the firewall vendor, EDR product, cloud platform, and ticketing system, in many listings down to the version the team runs.
  5. People and email format: Professional networking profiles map the org chart, and a handful of public addresses reveal the email naming convention for everyone else.
  6. Code and secrets: Public repositories and paste sites leak internal hostnames, configuration files, and API keys committed by mistake.
  7. Credentials: Breach compilations and infostealer logs tie those employee addresses to passwords and session cookies, the input for credential stuffing and account takeover.

Each step narrows the next. The job posting says which VPN the company runs, the certificate log shows where it lives, and the org chart names the IT staff worth targeting with a spear phishing email that references a real internal project.

Code leaks deserve particular attention because the volume keeps climbing. GitGuardian's State of Secrets Sprawl 2026 found 28.65 million new hardcoded secrets in public GitHub commits during 2025, a 34% increase over 2024.

OSINT Source Categories and What Each Reveals

OSINT sources fall into five categories, and each answers a different kind of question.

Category Typical Sources What It Reveals
Technical DNS, WHOIS, certificate logs, internet scan data, cloud IP ranges Exposed hosts, services, software versions, and infrastructure relationships
Code and Data Public repositories, paste sites, package registries, mobile app binaries Secrets, internal endpoints, configuration details, and developer habits
Human and Social Social media, professional profiles, conference talks, forums Roles, reporting lines, travel, and targets for social engineering
Organizational Company websites, filings, press releases, job postings, supplier portals Business priorities, technology choices, vendors, and acquisitions
Contextual News, government advisories, sanctions lists, geopolitical reporting Campaign timing, regional threats, and shifts in attacker motivation

Mobile applications hold more technical intelligence than most teams expect. A published Android package contains every hostname, API route, and storage bucket the app talks to, which makes it one of the richest single sources on a company's backend.

How an OSINT Investigation Runs

A disciplined OSINT investigation follows the intelligence cycle, starting from a question and ending with a decision someone can act on.

  1. Define the requirement: Write down the question, such as "which internet-facing systems belong to the subsidiary we acquired last quarter," before opening a single tool.
  2. Plan collection: Choose sources for the question and decide what stays passive, reading published data, versus active, touching the target's systems with a scan.
  3. Collect with provenance: Record the URL, timestamp, and method for every item, and capture an archived copy, since public pages change or disappear.
  4. Verify: Check each finding against an independent source, and confirm the content, the source, and the context before trusting it.
  5. Analyze: Connect verified findings into an answer, stating confidence and naming the gaps that remain.
  6. Report and act: Deliver the answer to the team that can fix, block, or investigate, in the format that team uses.
  7. Feedback: Turn new questions raised by the findings into the next collection requirements.

Verification is where amateur and professional OSINT part ways. A single social media post, a lookalike domain, or an unverified claim on a forum proves very little on its own, and investigators who skip the cross-check end up reporting fabricated or planted information as fact.

OSINT Tools Practitioners Use

Most OSINT work combines search skills with a small set of specialized tools, grouped by the job each one does.

  • Search engines and operators: Advanced search syntax, known as dorking, finds exposed documents, login pages, and directory listings by filetype, site, and URL pattern.
  • Infrastructure mapping: Certificate transparency search, passive DNS databases, and internet scan engines such as Shodan and Censys map hosts and services.
  • Subdomain enumeration: Open-source tools such as OWASP Amass and Subfinder combine dozens of passive sources into one list.
  • Code and secret search: Repository search plus secret scanners such as TruffleHog and Gitleaks surface committed credentials.
  • Mobile app intelligence: CloudSEK's free BeVigil OSINT CLI queries hostnames, URLs, parameters, and S3 buckets extracted from Android packages.
  • Link analysis: Maltego and SpiderFoot connect people, domains, and infrastructure into graphs that reveal relationships.
  • Web archives: The Wayback Machine recovers deleted pages, old staff lists, and earlier versions of exposed files.

Tool choice matters less than tradecraft. Two analysts running the same tools produce very different results, depending on how well they frame the question and verify what comes back.

Defensive OSINT Use Cases

  • Attack surface discovery: Finding forgotten domains, cloud assets, and exposed services before attackers do, the foundation of external attack surface management.
  • Secret and credential exposure: Catching keys in public code and employee credentials in breach and infostealer data, then rotating them.
  • Brand impersonation: Detecting lookalike domains through certificate logs and new registrations, plus fake social profiles and apps, a core part of brand impersonation defense.
  • Executive exposure: Reviewing what public records and social media reveal about senior staff before an attacker builds a pretext around it.
  • Threat actor tracking: Following adversary infrastructure, tooling, and chatter to inform threat intelligence and threat hunting hypotheses.
  • Third-party risk: Checking suppliers' exposed assets and leaked data, since a third-party breach reaches the organization through someone else's gap.
  • Incident investigation: Scoping an intrusion with public indicators, infrastructure history, and leak site postings.

Real-World OSINT Examples

Target: A Vendor Found in Public View

Attackers breached Target in 2013 using credentials stolen from Fazio Mechanical, a refrigeration and HVAC contractor with access to Target's supplier systems.

Post-breach reporting showed how much of Target's vendor ecosystem was publicly searchable, including supplier portal information and details of how the company worked with contractors. The lesson for defenders is that a vendor list published for convenience doubles as a target list.

WannaCry: A Kill Switch Found Through Open Analysis

When WannaCry spread in May 2017, a researcher analyzing a sample noticed it checked for an unregistered domain before encrypting. Registering that domain stopped new infections from executing the payload.

The discovery came from public samples and open sharing among researchers, and the same channels then carried indicators and patching guidance to hospitals and public agencies within hours.

APT35: An Adversary's Documents on GitHub

Defenders run OSINT against attackers, not only the reverse. CloudSEK's TRIAD team analyzed a leaked GitHub repository of internal APT35 documents, the IRGC-linked group tracked elsewhere as Charming Kitten, containing personnel rosters, timesheets, and campaign records.

The material showed separate teams for penetration testing, malware development, social engineering, and infrastructure, which gave defenders a rare view of how a state-linked operation organizes its work.

Limits, Legal Lines, and Ethics of OSINT

Public does not mean accurate, complete, or free to use in whatever way an investigator likes. Three kinds of limits shape every OSINT program.

1. Accuracy and Attribution Limits

Open sources contain stale, incomplete, and deliberately false information, including infrastructure planted to mislead researchers. Public indicators rarely prove intent or ownership on their own, so attribution based purely on OSINT carries a confidence level, not a verdict.

Coverage ends at the edge of public information, and plenty of risk lives beyond it. Internal activity, private channels, and anything behind authentication fall outside OSINT, so it complements internal telemetry and never replaces it.

2. Legal Boundaries

  • No unauthorized access: Guessing passwords, using leaked credentials to log in, or bypassing access controls moves from OSINT into computer misuse.
  • No impersonation: Pretexting a person into sharing information is social engineering, not open-source collection.
  • Platform terms: Automated scraping can breach a site's terms of service even when the data is visible.
  • Privacy law: Collecting and storing personal data triggers obligations under laws such as GDPR and India's DPDP Act, including purpose limitation and retention limits.

3. Operational Security for Investigators

Collection leaves traces. Active scans appear in the target's logs, and visiting a suspect's site or profile can reveal the investigator's organization.

Experienced teams start passive, move to active collection only when the question requires it, and keep research infrastructure separate from corporate systems.

OSINT FAQs

Is dark web data considered OSINT?

Partly. Content on openly reachable dark web forums counts as open source, while stolen data traded there raises legal and ethical issues that call for a written handling policy.

What is the difference between OSINT and threat intelligence?

OSINT is a collection discipline based on public sources. Threat intelligence is the broader product, combining OSINT with internal telemetry, commercial feeds, and human sources.

What skills does an OSINT analyst need?

Advanced search techniques, networking and DNS fundamentals, verification discipline, clear report writing, and enough scripting to automate collection and parse results.

Continuous Defensive OSINT With CloudSEK BeVigil

Running the reconnaissance pass described above once a year leaves eleven months of blind spots.

CloudSEK BeVigil runs it continuously, fingerprinting an organization's internet-facing infrastructure from public sources and scanning web applications, mobile apps, APIs, cloud, DNS, SSL, and network services for exposure.

That produces the attacker's-eye map of the organization, kept current and prioritized, so security teams close the gaps OSINT reveals before someone else uses them.

Related Posts
What is Malware Sandboxing? How It Works and Its Limits
Malware sandboxing runs suspicious files in an isolated environment to observe their behavior safely. How malware sandboxing works, its types, and evasion.
What is Google Dorking? Operators, Risks, and Defense
Google dorking uses advanced search operators to find sensitive data exposed on the web. How it works, what it exposes, and how to defend against it.
6 Best Digital Risk Protection (DRP) Platforms in 2026
CloudSEK XVigil, Recorded Future, ZeroFox, Rapid7, Group-IB, and Flare cover key DRP needs across external risk, takedown, SOC workflows, scams, and illicit monitoring.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.