Open-source intelligence (OSINT)

Table of contents
Open-source intelligence (OSINT)

What is open-source intelligence (OSINT)?

Open-source intelligence (OSINT) is the practice of collecting, evaluating, and analyzing information from publicly available information — with collection and use still subject to applicable law, policy,  and terms — to answer a specific intelligence question about a person, organization, or activity. It is one of several intelligence disciplines, alongside sources such as financial records and human intelligence, that investigators combine into a single all-source investigation.

{{55-osint-glossary-callout-1}}

OSINT draws on publicly available or commercially accessible sources, including news media, public records, social media, corporate registries, academic publications, and government databases. What separates it from casual searching is methodology. 

An OSINT process defines a specific intelligence question, collects information against that question from multiple sources, evaluates each source for reliability, and documents how each finding was obtained so another analyst could reproduce it. Multiple sources only increase confidence where they are genuinely independent. In cyber especially, the same underlying claim is frequently copied, scraped, or syndicated across many sites; so apparent multi-source corroboration can still be single-source reporting.

What makes OSINT, “open source”?

"Open" describes where the information comes from, not how easy it is to find. Intelligence.gov, the US intelligence community's public education site, defines OSINT as publicly available information appearing in print or electronic form — from newspapers and journals to commercial databases and the open internet. That definition covers a wide range of sources; most of the work in OSINT is deciding which of them are relevant, credible, and current enough to use.

A common misconception is that OSINT is equivalent to a single web search. While it’s true that a search might surface a result, the discipline lies in knowing which sources are likely to hold relevant information, searching them systematically, and weighing each result's reliability before using it to support a decision or an investigative lead.

What is the purpose of OSINT?

OSINT serves different objectives depending on who is using it. For example:

  • National security analysts use it to understand a foreign actor's capabilities and public statements
  • Law enforcement investigators use it to identify suspects and corroborate leads
  • Cyber threat intelligence and security operations teams use it to support actor/campaign attribution, map infrastructure, identify targeting and TTPs, and translate threat activity into business risk
  • Compliance and trust and safety teams use it to verify who they're doing business with and screen for bad actors on their own platforms

In every case, OSINT is one input into a larger investigative picture, not a standalone answer.

{{horizontal-line}}

How does the OSINT process work?

OSINT follows a version of the classic intelligence cycle, adapted to public sources.

Stage What happens
Planning and direction An analyst defines the specific question the investigation needs to answer and the collection priorities that follow from it
Collection Analysts gather information from relevant open sources — social media, public records, news archives, and other public data — using techniques suited to each source
Processing and evaluation Each piece of information is assessed for source reliability, information credibility, timeliness, and relevance before it's used
Analysis Analysts assess alternative hypotheses or disconfirming evidence, correlate findings across sources, test the result against the original question, and communicate how certain they are using established confidence language
Dissemination The finished analysis goes to the decision-maker, investigator, or case team that requested it, in a form they can act on

{{horizontal-line}}

How do different teams use OSINT?

Team Examples of how they use OSINT
National security and defense analysts OSINT helps assess a foreign government's capabilities, intentions, and public statements, often filling gaps between more sensitive collection methods
Law enforcement and investigators OSINT corroborates leads, identifies suspects and associates, and builds the background needed to support a warrant or a case file
Cyber threat intelligence (CTI) analysts and security operations teams Strategic analysts translate threat activity into business risk for executives, while technical and operational analysts use OSINT to drive threat hunting, detection engineering, vulnerability prioritization, credential resets, takedowns, supplier escalation, exposure remediation and changes to defensive controls
Corporate security and enterprise risk teams Security teams use OSINT to monitor threats to executives and facilities, protect brand reputation, and investigate internal incidents
Compliance and trust and safety teams Analysts use OSINT to verify beneficial ownership, screen counterparties, and investigate abuse of their own platforms and products
Journalists and researchers Investigative journalists and human rights researchers use OSINT to verify claims, geolocate images and videos, and document events that would otherwise rely on a single, unverified source

{{horizontal-line}}

What sources and techniques does OSINT rely on?

Source category Examples
Social media and forums Posts, comments, and network connections on platforms such as X, Facebook, and Reddit often reveal a person's associations, location, and activity over time
Public records and registries Corporate filings, court records, property records, and beneficial-ownership registries connect people to organizations and assets
News media and publications News archives, academic papers, and government reports provide context, history, and corroboration for a hypothesis
Geospatial and imagery data Satellite imagery, mapping tools, and metadata (note: many platforms strip EXIF and other metadata, so geolocation often relies on visual landmarks, shadows, terrain, weather, signage, imagery comparison, and other corroborating indicators) embedded in photos and videos can place an event or a person at a specific location and time
Technical and infrastructure data Registration data, certificates, hosting patterns, passive DNS and shared infrastructure can support an attribution hypothesis

{{horizontal-line}}

How does OSINT fit into all-source investigations?

No single intelligence discipline answers every investigative question on its own. All-source investigations combine OSINT with other disciplines into one investigative picture, corroborating each source against the others rather than relying on any single one alone.

Discipline What it draws on What it answers
Open-source intelligence (OSINT) Public, legally available sources Who is behind an entity or activity, and what is the surrounding context?
Financial intelligence Bank records, transaction data, corporate filings How did money move, and through which accounts or structures?
Human intelligence (HUMINT) Informants, interviews, undercover sources What do insiders know that public records don't show?
Cyber threat intelligence (CTI) Telemetry, malware analysis, vulnerability/exploit intelligence, infrastructure data, incident response findings, deep/dark web sources, proprietary reporting, OSINT What is happening, who/what is at risk, how does the adversary operate, what is the adversary likely to do next, and what defensive action should be prioritized?

Investigators cross-reference these disciplines. A Bellingcat investigation, for example, might combine satellite imagery, social media geolocation, and public flight-tracking data to place a specific vehicle or aircraft at the scene of an event — the kind of finding that only holds up when multiple independent sources agree.

{{horizontal-line}}

What are the biggest challenges in OSINT collection today?

OSINT faces practical, legal, and evidentiary limits that shape how it's used.

  • Volume and noise: The amount of public information available on any given subject keeps growing, and separating a relevant signal from irrelevant or misleading content takes real analytic effort.
  • Source reliability and disinformation: Not every public source is accurate or honest, and a single unverified post can send an investigation in the wrong direction if it isn't corroborated against other sources.
  • Legal and jurisdictional limits: Data-protection rules, platform terms of service, and cross-border information-sharing laws vary widely, and what's collectible in one jurisdiction may not be in another.

{{horizontal-line}}

How is OSINT evolving?

A few trends are reshaping OSINT work. Artificial intelligence (AI) is automating parts of collection and translation that used to require manual searching across languages and platforms, letting analysts cover more ground faster. The volume of public data keeps expanding, from satellite constellations imaging the planet daily to the growing footprint people leave across social platforms.

At the same time, privacy and data-protection regulation is tightening in many jurisdictions, narrowing what can be collected and how it can be used, even when a source is technically public. Investigators are also formalizing OSINT tradecraft: documenting methodology, verifying sources against each other, and treating OSINT with the same analytic and provenance discipline as any other intelligence discipline in an all-source investigation.

{{horizontal-line}}

Frequently asked questions (FAQs)

1. What is the difference between OSINT and classified intelligence?

OSINT is drawn entirely from sources that are publicly available, while classified intelligence comes from restricted methods such as signals interception or human sources. Analysts often use OSINT to fill gaps around classified reporting or to corroborate it without spending sensitive collection methods on a question public sources can already answer.

2. What is the difference between OSINT and cyber threat intelligence (CTI)?

Cyber threat intelligence (CTI) is intelligence specifically about cyber adversaries — their infrastructure, methods, and targets — and it can draw on both public and non-public sources, such as proprietary threat feeds. OSINT is the practice of collecting, evaluating, and analyzing information from publicly available sources, and is often one of several inputs into a CTI assessment.

3. How does OSINT fit into an all-source investigation?

OSINT supplies one category of input into an all-source investigation, alongside other disciplines such as financial intelligence, human intelligence (HUMINT), and cyber threat intelligence (CTI). Investigators corroborate findings across these disciplines rather than treating any single source as conclusive on its own.

4. Is it legal to collect and use OSINT?

OSINT relies on publicly available information, but the legality of collecting, processing, retaining, and sharing it depends on applicable law and context.

5. Can OSINT findings be used as evidence in court or a regulatory proceeding?

OSINT findings can support a legal or regulatory case when they're properly sourced, documented, and corroborated. A single, uncorroborated OSINT artifact is rarely sufficient on its own; it typically needs to be paired with other evidence or independent sources before it moves from an investigative lead to court-ready proof.

6. How is AI changing OSINT collection and analysis?

AI tools are speeding up collection and translation across languages and platforms, and helping analysts spot patterns across large volumes of public data that would be impractical to review manually. Verification remains a human responsibility, since AI tools can also make it easier to generate the kind of synthetic content OSINT analysts need to detect.

Subscribe and stay up to date with our insights

Access our coverage of TRON, Solana and 23 other blockchains

Fill out the form to speak with our team about investigative professional services.

Services of interest
Select
Transaction Monitoring/Wallet Screening
Training Services
Training Services
 
By clicking the button below, you agree to the TRM Labs Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Public information is abundant, but most of it has nothing to do with any given question. OSINT is the discipline that turns that volume of information into a specific, sourced answer: who controls an account, who owns a company, or who is connected to an event.