What Is OSINT? A Clear Definition
Open Source Intelligence (OSINT) is the process of collecting, processing, and analyzing publicly available information to produce actionable intelligence. As SANS Institute defines it: "OSINT is intelligence produced by collecting, evaluating and analyzing publicly available information with the purpose of answering a specific intelligence question."
The critical word is intelligence. Saving someone's LinkedIn friend list is not OSINT — it's data hoarding. OSINT begins when raw public data is interpreted against a question: Is this supplier a shell company? Did this missile launcher cross the border? Where was this video filmed?
Public sources include surface web (news, blogs, search engines), social media (X, Instagram, LinkedIn, Telegram), government filings, DNS/WHOIS records, geospatial data (Google Earth, satellites), and deep/dark web (paste sites, Tor markets).
OSINT vs. Other Intelligence Disciplines
| Discipline | What it collects |
|---|---|
| OSINT | Publicly available info (media, internet, public records) |
| HUMINT | Information from human sources (interviews, espionage) |
| SIGINT | Intercepted signals (COMINT, ELINT, FISINT) |
| GEOINT | Geospatial + imagery intelligence (satellites, drones) |
| MASINT | Measurement and signature data (radar, chemical, nuclear) |
OSINT is the only discipline practiced legally and at scale by civilians. SOCMINT (social media intelligence) and DARKINT (dark web intelligence) are usually treated as OSINT sub-disciplines.
Brief History
OSINT traces back to the U.S. Foreign Broadcast Monitoring Service (FBMS) in 1941, which monitored enemy radio. The 9/11 Commission led to the DNI Open Source Center in November 2005. The 2010s democratized OSINT — Eliot Higgins founded Bellingcat in 2014, kicking off a decade of open-source investigative journalism that reshaped war reporting and corporate due diligence.
The OSINT Methodology: The Intelligence Cycle
Professional OSINT follows the classic five-step intelligence cycle:
The OSINT Framework (osintframework.com) is a taxonomy organizing tools by data type: usernames, emails, domains, IPs, images, geolocation, dark web. It's a roadmap, not a tool.
Core OSINT Techniques
1. Domain and Infrastructure Reconnaissance
WHOIS, DNS enumeration, reverse IP lookups, certificate transparency, subdomain discovery. Tools: theHarvester, Amass, Recon-ng, Shodan, Censys.
2. Social Media Intelligence (SOCMINT)
Username enumeration with Sherlock or Maigret across 400+ sites, post archival, network mapping. Often the highest-value layer in fraud and disinformation investigations.
3. Geolocation and Chronolocation
Identifying where and when a photo/video was taken by reading shadows, signage, vegetation, architecture, EXIF metadata. Bellingcat's MH17 investigation used Google Earth, social media videos, and shadow analysis to trace a Russian Buk launcher to the 53rd Anti-Aircraft Missile Brigade in Kursk — confirmed by the Dutch-led Joint Investigation Team.
4. Email, Phone, and Identity OSINT
Reverse email lookup, breach-database checks (Have I Been Pwned — 993 total breaches, 17.59 billion pwned accounts as of May 2026), phone footprinting, document metadata extraction.
5. Google Dorking
Advanced search operators (site:, filetype:, intitle:) turn Google into a precision tool. Example: site:gov filetype:xlsx "budget" surfaces government spreadsheets. Equally important on Bing (retains ip: operator) and Yandex (essential for post-Soviet region).
6. Dark Web Monitoring
Searching paste sites, ransomware leak portals, Tor marketplaces for stolen credentials, exposed source code. Tools: Intelligence X, Ahmia, DarkOwl.
7. Public Records and Corporate Intelligence
Sanctions screening (OFAC, EU), beneficial ownership databases (OpenCorporates, OCCRP Aleph), court filings, real-estate registries, ADS-B/AIS for aircraft/ship tracking.
Bellingcat's principle: every claim must be independently corroborated by at least two open sources. Assume hostile actors are seeding disinformation.
The OSINT Tools Ecosystem
Free / Open Source
- Maltego Community Edition — graph-based link analysis, the de facto standard for relationship mapping.
- SpiderFoot — automated reconnaissance across 200+ data sources.
- theHarvester — email, subdomain, and host enumeration.
- Recon-ng — modular CLI reconnaissance framework.
- Shodan (free tier) — the search engine for internet-connected devices; ~5 million registered users as of 2022.
- Have I Been Pwned — Troy Hunt's breach-notification service (993 breaches, 17.59B pwned accounts).
- Wayback Machine — historical web snapshots.
- Google Lens / Yandex Images / PimEyes — reverse image search.
Commercial / Enterprise
- Maltego Pro / Enterprise (~$1,000/yr) — full transform hub, paid data integrations.
- Recorded Future, Flashpoint, ShadowDragon, Social Links, Fivecast — enterprise threat-intelligence platforms.
- OSINT Industries, Skopenow, Sayari — investigator-focused for due diligence and identity resolution.
Why Proxies Matter for OSINT
This is the part most OSINT explainers skip. Modern OSINT collection is rate-limited by platforms that aggressively detect and block datacenter IPs, scrapers, and behavior anomalies. Without proxy infrastructure, you don't have an OSINT operation — you have a research project that breaks when it scales.
Platform Constraints (2026)
| Platform | Rate limit | Datacenter IPs |
|---|---|---|
| ~200 requests/hour/IP | Flagged instantly | |
| 20–30 profiles/hour/IP | "Will not work" | |
| X (Twitter) | 300 searches/15 min | Heavily restricted |
| Google SERP | Hardened Jan 15, 2025 | Strict CAPTCHA + IP limits |
Three Non-Negotiable Reasons
- Geo-restricted content. Investigating Chinese disinformation? WeChat, Weibo, Douyin require Chinese phone numbers and IPs. Local pricing audits, regional ad verification, country-specific Google results all require IPs in the target country.
- Operational security (OPSEC). Personal devices and home IPs must never touch an investigation. Targets can — and do — log who's looking. Proxies, paired with antidetect browsers, separate the analyst's identity from the research.
- Mobile-only content. Instagram Reels, TikTok feeds behave differently for mobile carrier IPs. Mobile proxies (real 4G/5G IPs) are virtually impossible to mass-block without hitting real customers.
The Cost Math
For an OSINT team running 50 active investigations monthly, the difference between premium enterprise proxies at $15/GB and competitive residential/mobile at $4–7/GB is the difference between $10,000 and $2,500 in monthly infrastructure cost — with no drop in success rates.
Effective cost per investigation = (price_per_GB / requests_per_GB) / success_rate. On protected targets, mobile proxies at $8/GB with 95% success beat datacenter at $0.50/GB with 30% success.
Real-World OSINT Use Cases
- Investigative journalism: Bellingcat used social media videos, Google Earth, Russian VKontakte profiles to identify the Buk 332 launcher and 53rd Brigade officers responsible for MH17. Their October 4, 2018 report "305 Car Registrations May Point to Massive GRU Security Breach" demonstrated OSINT's power.
- Corporate due diligence: Verifying ownership chains, screening sanctions lists, detecting shell companies, surfacing director links to failed firms.
- Cybersecurity / threat intelligence: Mapping exposed assets via Shodan, monitoring ransomware leak sites, detecting typosquatting domains.
- Fraud investigation: Tracing burner emails, usernames, crypto wallets across platforms; mobile proxies access mobile-only fraud rings.
- Legal discovery: Verifying timing of corporate disclosures, surfacing contradictory social posts.
- Brand monitoring: Tracking competitor launches, pricing across regions (requires geo-targeted IPs), counterfeit listings.
Legal and Ethical Considerations
OSINT operates in a "legal but ethically complex" zone. The general rule: public data is fair game; unauthorized access is not.
Regional Frameworks Every OSINT Practitioner Should Know
| Region | Law | Key Provisions |
|---|---|---|
| EU | GDPR | "Legitimate interest" basis required; 4% global revenue fines |
| California | CCPA/CPRA | Restricts commercial collection and resale |
| Brazil | LGPD (Lei 13.709) | ANPD enforcement; 2% revenue fines, R$50M cap |
| Argentina | Ley 25.326 | Habeas data rights; Res. 126/2024 tripartite sanctions |
| Mexico | LFPDPPP (2025) | Effective March 21, 2025; ~$3M max fines |
Best practice: respect platform ToS, document methodology, never use fake identities for private content, minimize personal data retention.
Recommendations: Building a Defensible OSINT Capability
Starting from zero (weeks 1–4)
- Master the OSINT Framework as a mental map.
- Install Maltego Community, theHarvester, Sherlock.
- Learn Google + Bing + Yandex dorking syntax — this single skill outperforms half the paid tools.
- Subscribe to Bellingcat's gitbook toolkit and Sector035's Week in OSINT.
Scaling an operation (months 2–6)
- Add SpiderFoot, Shodan paid tier, Have I Been Pwned API.
- Invest in proxy infrastructure before another SaaS tool. Start with residential pool ($4–$7/GB) and add mobile IPs for Instagram/TikTok work.
- Strict OPSEC: dedicated machines, antidetect browsers, separate burner identities, documented chain of custody.
Decision thresholds
- Single investigation >1,000 profile lookups → residential proxies needed, not VPNs.
- Investigating subjects outside your country → geo-targeted IPs required before writing queries.
- Analysts getting blocked/CAPTCHA'd >1x per session → infrastructure under-specified, not tooling.
Serious OSINT operations are infrastructure-dependent. The limiting factor isn't the tools — it's the cost and reliability of the proxy infrastructure behind them.