Social media intelligence (SOCMINT)
What is social media intelligence (SOCMINT)?
Social media intelligence (SOCMINT) is the structured collection and analysis of social media-derived information, with accessibility and legal authority varying by source (e.g. profiles, posts, group memberships, and network connections), used to support investigations, threat assessments, and risk decisions.
While SOCMINT overlaps heavily with open-source intelligence (OSINT), it is not always limited to strictly open sources; for example, SOCMINT could include access-controlled groups, persona-led collection, closed communities and platform-provided data.
{{56-socmint-glossary-callout-1}}
SOCMINT treats social media as an intelligence source. It is a repeatable, documented process — usually governed by an organization's own legal and ethical guidelines — for identifying, collecting, and analyzing social signals in a way that can support a formal finding.
{{horizontal-line}}
How is SOCMINT different from OSINT and social media monitoring?
OSINT covers any intelligence drawn from publicly or lawfully available sources, including government records, news archives, corporate filings, satellite imagery, and social media. SOCMINT narrows that scope to social platforms specifically — the accounts, group chats, and posting patterns through which people actually organize and coordinate.
SOCMINT is commonly confused with social media monitoring, which tracks brand mentions and sentiment for marketing or communications teams. The two share some tooling, but not much else. Social media monitoring asks what people are saying about a brand. SOCMINT asks what narratives are spreading, which communities are amplifying them, whether behavior is coordinated, how activity is evolving over time, what the likely intent is, what real-world or cyber risk follows, who is behind a piece of activity, how they organized it, and who else is involved.
{{horizontal-line}}
How does SOCMINT work?
A SOCMINT investigation typically follows five steps:
{{horizontal-line}}
How does SOCMINT fit into all-source investigations?
No single data source tells an investigator everything, which is the premise behind all-source investigations: combining financial records, human intelligence, government data, technical signals, and open-source material into one analytic picture instead of relying on any single stream alone.
Within that model, SOCMINT supplies a behavioral and social-network layer.
A human trafficking network recruits through job postings and private messaging groups long before a victim's location or finances register anywhere else. A disinformation campaign builds a network of seemingly independent accounts before it ever touches a target's inbox. A romance or investment scam (also known as a pig butchering scam) follows the same playbook: weeks of relationship-building before the ask. In each case, financial or technical records can show that something happened; SOCMINT can expose the social relationships, behavior, and coordination that other data sources may not show.
{{horizontal-line}}
What data sources and signals does SOCMINT draw on?
Investigators typically pull from five categories of signal, usually in combination rather than relying on any one alone.
A defensible finding should show why the signals are independent enough to matter, what contradictory evidence exists, and which alternative explanations were tested.
{{horizontal-line}}
What are the limits and challenges of SOCMINT?
The most consistent failure mode is simpler than any constraint in that table: relying on a single artifact. One post, one photo, or one account rarely supports an identity attribution on its own. Defensible SOCMINT findings are corroborated across multiple signals and, where possible, checked against independent evidence such as financial records or other corroborating data.
{{horizontal-line}}
Frequently asked questions (FAQs)
1. What is the difference between SOCMINT and OSINT?
OSINT is the broader discipline: any intelligence drawn from publicly or lawfully available sources, including government records, news, and public filings. SOCMINT is a subset of OSINT focused specifically on social media platforms — the accounts, posts, and group activity where people organize and communicate.
2. What is the difference between SOCMINT and social media monitoring?
Social media monitoring tracks brand sentiment and mentions for marketing or communications purposes. SOCMINT is an investigative discipline aimed at identifying real people, mapping networks, and supporting a formal finding, which is why it follows a more rigorous collection and documentation standard.
3. Is SOCMINT-derived evidence admissible in court?
It can be, provided it's collected and documented properly. Courts generally expect a clear chain of custody, a documented collection method, and corroboration from more than one source. They're far more likely to challenge or exclude SOCMINT that was collected casually or without proper authorization.
4. How does SOCMINT relate to all-source investigations?
All-source investigations combine multiple types of evidence — financial, technical, human, and open-source — into a single analytic picture, and SOCMINT is one of those sources. It's rarely conclusive by itself, but it often supplies the connective link between a technical or financial finding and the person responsible for it.
Access our coverage of TRON, Solana and 23 other blockchains
Fill out the form to speak with our team about investigative professional services.



















