🚀 CloudSEK featured in the 2026 Frost Radar™!
Read more
Open source intelligence (OSINT) is intelligence produced by collecting, verifying, and analyzing publicly available sources to answer a specific question or solve problems. The raw material is public. The intelligence comes from the question asked and the analysis applied.
That distinction between data and intelligence matters more than any tool. A folder of screenshots about a company is data; a finding that its staging server runs an unpatched VPN appliance, reachable from a subdomain listed in a public certificate log, is intelligence.
Inside security teams, OSINT cuts both ways, since attackers and defenders read the same sources. Attackers use it to choose targets and write convincing lures, and defenders use the same sources to see their organization the way an attacker does, then close what they find.
OSINT covers information anyone can lawfully access without breaking in, paying a criminal, or deceiving someone into sharing it.
Inside the boundary sit websites, DNS and certificate records, internet scan data, public code repositories, social media, job postings, court and company filings, news reporting, and archived versions of all of them. Some sources need a free account or a paid subscription, and they still count, because access requires registration, not bypassing a control.
Outside the boundary sits anything obtained through unauthorized access, credentials used to log in somewhere they were not meant for, and information collected by impersonating a person. Leaked breach data is the grey zone practitioners argue about: it is widely circulated, but it was stolen, so mature teams handle it under a written policy instead of treating it as ordinary open-source material.
OSINT works alongside the other intelligence disciplines, not above them. Human intelligence comes from people, signals intelligence from intercepted communications, and geospatial intelligence from imagery; OSINT supplies much of the context that makes the others readable.
A capable attacker builds a detailed map of an organization in an afternoon, using nothing but public sources. A typical reconnaissance pass runs in roughly this order:
Each step narrows the next. The job posting says which VPN the company runs, the certificate log shows where it lives, and the org chart names the IT staff worth targeting with a spear phishing email that references a real internal project.
Code leaks deserve particular attention because the volume keeps climbing. GitGuardian's State of Secrets Sprawl 2026 found 28.65 million new hardcoded secrets in public GitHub commits during 2025, a 34% increase over 2024.
OSINT sources fall into five categories, and each answers a different kind of question.
Mobile applications hold more technical intelligence than most teams expect. A published Android package contains every hostname, API route, and storage bucket the app talks to, which makes it one of the richest single sources on a company's backend.
A disciplined OSINT investigation follows the intelligence cycle, starting from a question and ending with a decision someone can act on.
Verification is where amateur and professional OSINT part ways. A single social media post, a lookalike domain, or an unverified claim on a forum proves very little on its own, and investigators who skip the cross-check end up reporting fabricated or planted information as fact.
Most OSINT work combines search skills with a small set of specialized tools, grouped by the job each one does.
Tool choice matters less than tradecraft. Two analysts running the same tools produce very different results, depending on how well they frame the question and verify what comes back.
Attackers breached Target in 2013 using credentials stolen from Fazio Mechanical, a refrigeration and HVAC contractor with access to Target's supplier systems.
Post-breach reporting showed how much of Target's vendor ecosystem was publicly searchable, including supplier portal information and details of how the company worked with contractors. The lesson for defenders is that a vendor list published for convenience doubles as a target list.
When WannaCry spread in May 2017, a researcher analyzing a sample noticed it checked for an unregistered domain before encrypting. Registering that domain stopped new infections from executing the payload.
The discovery came from public samples and open sharing among researchers, and the same channels then carried indicators and patching guidance to hospitals and public agencies within hours.
Defenders run OSINT against attackers, not only the reverse. CloudSEK's TRIAD team analyzed a leaked GitHub repository of internal APT35 documents, the IRGC-linked group tracked elsewhere as Charming Kitten, containing personnel rosters, timesheets, and campaign records.
The material showed separate teams for penetration testing, malware development, social engineering, and infrastructure, which gave defenders a rare view of how a state-linked operation organizes its work.
Public does not mean accurate, complete, or free to use in whatever way an investigator likes. Three kinds of limits shape every OSINT program.
Open sources contain stale, incomplete, and deliberately false information, including infrastructure planted to mislead researchers. Public indicators rarely prove intent or ownership on their own, so attribution based purely on OSINT carries a confidence level, not a verdict.
Coverage ends at the edge of public information, and plenty of risk lives beyond it. Internal activity, private channels, and anything behind authentication fall outside OSINT, so it complements internal telemetry and never replaces it.
Collection leaves traces. Active scans appear in the target's logs, and visiting a suspect's site or profile can reveal the investigator's organization.
Experienced teams start passive, move to active collection only when the question requires it, and keep research infrastructure separate from corporate systems.
Partly. Content on openly reachable dark web forums counts as open source, while stolen data traded there raises legal and ethical issues that call for a written handling policy.
OSINT is a collection discipline based on public sources. Threat intelligence is the broader product, combining OSINT with internal telemetry, commercial feeds, and human sources.
Advanced search techniques, networking and DNS fundamentals, verification discipline, clear report writing, and enough scripting to automate collection and parse results.
Running the reconnaissance pass described above once a year leaves eleven months of blind spots.
CloudSEK BeVigil runs it continuously, fingerprinting an organization's internet-facing infrastructure from public sources and scanning web applications, mobile apps, APIs, cloud, DNS, SSL, and network services for exposure.
That produces the attacker's-eye map of the organization, kept current and prioritized, so security teams close the gaps OSINT reveals before someone else uses them.
