Blog/ Intelligence/ OSINT Guide
Intelligence & OSINT

WHAT IS OSINT? THE 2026 GUIDE

DATE Jun 17, 2026 READ 8 min LEVEL Intermediate KEYWORD what is osint · 12,000/mo
// TL;DR
  • OSINT (Open Source Intelligence) is the structured collection and analysis of publicly available information to produce actionable intelligence.
  • The market grew to USD 21.06 billion in 2026 with forecast of USD 43.49B by 2031 (Mordor Intelligence), driven by corporate due diligence, threat intelligence, and investigative journalism.
  • The hidden bottleneck isn't tools — it's proxy infrastructure. Rate limits, geo-restrictions, and IP attribution mean serious OSINT depends on residential and mobile proxies as much as Maltego or Shodan.

What Is OSINT? A Clear Definition

Open Source Intelligence (OSINT) is the process of collecting, processing, and analyzing publicly available information to produce actionable intelligence. As SANS Institute defines it: "OSINT is intelligence produced by collecting, evaluating and analyzing publicly available information with the purpose of answering a specific intelligence question."

The critical word is intelligence. Saving someone's LinkedIn friend list is not OSINT — it's data hoarding. OSINT begins when raw public data is interpreted against a question: Is this supplier a shell company? Did this missile launcher cross the border? Where was this video filmed?

Public sources include surface web (news, blogs, search engines), social media (X, Instagram, LinkedIn, Telegram), government filings, DNS/WHOIS records, geospatial data (Google Earth, satellites), and deep/dark web (paste sites, Tor markets).

OSINT vs. Other Intelligence Disciplines

DisciplineWhat it collects
OSINTPublicly available info (media, internet, public records)
HUMINTInformation from human sources (interviews, espionage)
SIGINTIntercepted signals (COMINT, ELINT, FISINT)
GEOINTGeospatial + imagery intelligence (satellites, drones)
MASINTMeasurement and signature data (radar, chemical, nuclear)

OSINT is the only discipline practiced legally and at scale by civilians. SOCMINT (social media intelligence) and DARKINT (dark web intelligence) are usually treated as OSINT sub-disciplines.

Brief History

OSINT traces back to the U.S. Foreign Broadcast Monitoring Service (FBMS) in 1941, which monitored enemy radio. The 9/11 Commission led to the DNI Open Source Center in November 2005. The 2010s democratized OSINT — Eliot Higgins founded Bellingcat in 2014, kicking off a decade of open-source investigative journalism that reshaped war reporting and corporate due diligence.

The OSINT Methodology: The Intelligence Cycle

Professional OSINT follows the classic five-step intelligence cycle:

01
Planning & Direction — Define the intelligence question, scope, and legal constraints. Bad questions produce bad intelligence.
02
Collection — Gather raw data from open sources using tools, scrapers, manual research, and APIs.
03
Processing — Translate, deduplicate, normalize, and structure the data.
04
Analysis & Production — Cross-reference, verify, and turn raw data into a written or visual product.
05
Dissemination — Deliver to the decision-maker and capture feedback.

The OSINT Framework (osintframework.com) is a taxonomy organizing tools by data type: usernames, emails, domains, IPs, images, geolocation, dark web. It's a roadmap, not a tool.

Core OSINT Techniques

1. Domain and Infrastructure Reconnaissance

WHOIS, DNS enumeration, reverse IP lookups, certificate transparency, subdomain discovery. Tools: theHarvester, Amass, Recon-ng, Shodan, Censys.

2. Social Media Intelligence (SOCMINT)

Username enumeration with Sherlock or Maigret across 400+ sites, post archival, network mapping. Often the highest-value layer in fraud and disinformation investigations.

3. Geolocation and Chronolocation

Identifying where and when a photo/video was taken by reading shadows, signage, vegetation, architecture, EXIF metadata. Bellingcat's MH17 investigation used Google Earth, social media videos, and shadow analysis to trace a Russian Buk launcher to the 53rd Anti-Aircraft Missile Brigade in Kursk — confirmed by the Dutch-led Joint Investigation Team.

4. Email, Phone, and Identity OSINT

Reverse email lookup, breach-database checks (Have I Been Pwned — 993 total breaches, 17.59 billion pwned accounts as of May 2026), phone footprinting, document metadata extraction.

5. Google Dorking

Advanced search operators (site:, filetype:, intitle:) turn Google into a precision tool. Example: site:gov filetype:xlsx "budget" surfaces government spreadsheets. Equally important on Bing (retains ip: operator) and Yandex (essential for post-Soviet region).

6. Dark Web Monitoring

Searching paste sites, ransomware leak portals, Tor marketplaces for stolen credentials, exposed source code. Tools: Intelligence X, Ahmia, DarkOwl.

7. Public Records and Corporate Intelligence

Sanctions screening (OFAC, EU), beneficial ownership databases (OpenCorporates, OCCRP Aleph), court filings, real-estate registries, ADS-B/AIS for aircraft/ship tracking.

// verification is the hardest part

Bellingcat's principle: every claim must be independently corroborated by at least two open sources. Assume hostile actors are seeding disinformation.

The OSINT Tools Ecosystem

Free / Open Source

  • Maltego Community Edition — graph-based link analysis, the de facto standard for relationship mapping.
  • SpiderFoot — automated reconnaissance across 200+ data sources.
  • theHarvester — email, subdomain, and host enumeration.
  • Recon-ng — modular CLI reconnaissance framework.
  • Shodan (free tier) — the search engine for internet-connected devices; ~5 million registered users as of 2022.
  • Have I Been Pwned — Troy Hunt's breach-notification service (993 breaches, 17.59B pwned accounts).
  • Wayback Machine — historical web snapshots.
  • Google Lens / Yandex Images / PimEyes — reverse image search.

Commercial / Enterprise

  • Maltego Pro / Enterprise (~$1,000/yr) — full transform hub, paid data integrations.
  • Recorded Future, Flashpoint, ShadowDragon, Social Links, Fivecast — enterprise threat-intelligence platforms.
  • OSINT Industries, Skopenow, Sayari — investigator-focused for due diligence and identity resolution.

Why Proxies Matter for OSINT

This is the part most OSINT explainers skip. Modern OSINT collection is rate-limited by platforms that aggressively detect and block datacenter IPs, scrapers, and behavior anomalies. Without proxy infrastructure, you don't have an OSINT operation — you have a research project that breaks when it scales.

Platform Constraints (2026)

PlatformRate limitDatacenter IPs
Instagram~200 requests/hour/IPFlagged instantly
LinkedIn20–30 profiles/hour/IP"Will not work"
X (Twitter)300 searches/15 minHeavily restricted
Google SERPHardened Jan 15, 2025Strict CAPTCHA + IP limits

Three Non-Negotiable Reasons

  1. Geo-restricted content. Investigating Chinese disinformation? WeChat, Weibo, Douyin require Chinese phone numbers and IPs. Local pricing audits, regional ad verification, country-specific Google results all require IPs in the target country.
  2. Operational security (OPSEC). Personal devices and home IPs must never touch an investigation. Targets can — and do — log who's looking. Proxies, paired with antidetect browsers, separate the analyst's identity from the research.
  3. Mobile-only content. Instagram Reels, TikTok feeds behave differently for mobile carrier IPs. Mobile proxies (real 4G/5G IPs) are virtually impossible to mass-block without hitting real customers.

The Cost Math

$4–7
Residential / GB
$8–21
Mobile 4G/5G / GB
$2,500
Monthly at scale (50 cases)

For an OSINT team running 50 active investigations monthly, the difference between premium enterprise proxies at $15/GB and competitive residential/mobile at $4–7/GB is the difference between $10,000 and $2,500 in monthly infrastructure cost — with no drop in success rates.

// proxy infrastructure is now the cost-determining layer

Effective cost per investigation = (price_per_GB / requests_per_GB) / success_rate. On protected targets, mobile proxies at $8/GB with 95% success beat datacenter at $0.50/GB with 30% success.

Real-World OSINT Use Cases

  • Investigative journalism: Bellingcat used social media videos, Google Earth, Russian VKontakte profiles to identify the Buk 332 launcher and 53rd Brigade officers responsible for MH17. Their October 4, 2018 report "305 Car Registrations May Point to Massive GRU Security Breach" demonstrated OSINT's power.
  • Corporate due diligence: Verifying ownership chains, screening sanctions lists, detecting shell companies, surfacing director links to failed firms.
  • Cybersecurity / threat intelligence: Mapping exposed assets via Shodan, monitoring ransomware leak sites, detecting typosquatting domains.
  • Fraud investigation: Tracing burner emails, usernames, crypto wallets across platforms; mobile proxies access mobile-only fraud rings.
  • Legal discovery: Verifying timing of corporate disclosures, surfacing contradictory social posts.
  • Brand monitoring: Tracking competitor launches, pricing across regions (requires geo-targeted IPs), counterfeit listings.

OSINT operates in a "legal but ethically complex" zone. The general rule: public data is fair game; unauthorized access is not.

Regional Frameworks Every OSINT Practitioner Should Know

RegionLawKey Provisions
EUGDPR"Legitimate interest" basis required; 4% global revenue fines
CaliforniaCCPA/CPRARestricts commercial collection and resale
BrazilLGPD (Lei 13.709)ANPD enforcement; 2% revenue fines, R$50M cap
ArgentinaLey 25.326Habeas data rights; Res. 126/2024 tripartite sanctions
MexicoLFPDPPP (2025)Effective March 21, 2025; ~$3M max fines

Best practice: respect platform ToS, document methodology, never use fake identities for private content, minimize personal data retention.

Recommendations: Building a Defensible OSINT Capability

Starting from zero (weeks 1–4)

  1. Master the OSINT Framework as a mental map.
  2. Install Maltego Community, theHarvester, Sherlock.
  3. Learn Google + Bing + Yandex dorking syntax — this single skill outperforms half the paid tools.
  4. Subscribe to Bellingcat's gitbook toolkit and Sector035's Week in OSINT.

Scaling an operation (months 2–6)

  1. Add SpiderFoot, Shodan paid tier, Have I Been Pwned API.
  2. Invest in proxy infrastructure before another SaaS tool. Start with residential pool ($4–$7/GB) and add mobile IPs for Instagram/TikTok work.
  3. Strict OPSEC: dedicated machines, antidetect browsers, separate burner identities, documented chain of custody.

Decision thresholds

  • Single investigation >1,000 profile lookups → residential proxies needed, not VPNs.
  • Investigating subjects outside your country → geo-targeted IPs required before writing queries.
  • Analysts getting blocked/CAPTCHA'd >1x per session → infrastructure under-specified, not tooling.
// the bottom line

Serious OSINT operations are infrastructure-dependent. The limiting factor isn't the tools — it's the cost and reliability of the proxy infrastructure behind them.

← Previous
IP Rotation Guide
Next →
How to Scrape Images