Table of Contents

Author

Former British Army officer, trained in surveillance and target acquisition, and Bain and Company engagement manager, with more than a decade of experience working in consulting, private equity and venture capital across Western Europe.

Most organisations do not have an information shortage. They have company filings, news coverage, social posts, technical records, satellite images and commercial databases. The harder question is which parts are reliable, how they connect and what they mean for a decision.

Open-source intelligence, or OSINT, answers that question through structured collection and analysis. It can help an investor assess a target, an employer verify a candidate, a security team examine exposure or a journalist reconstruct an event. The method starts with available information, but the product is an evidence-based assessment rather than a collection of search results.

What Does OSINT Mean?

OSINT is intelligence derived exclusively from publicly or commercially available information and produced to address a defined requirement. This is the definition used in the US Intelligence Community’s 2024–2026 OSINT Strategy.

“Open source” describes how information can be accessed. It does not mean open-source software, and it does not mean that every online record may be collected or reused without restriction. A source can require registration or a paid subscription and still fall within OSINT if it is commercially available and the researcher is authorised to use it.

The requirement is just as important as the source. “Research this company” is too broad. “Establish who controls this supplier, whether its owners face sanctions exposure and whether it has undisclosed links to the buyer” gives the analyst a question that can be answered.

Information Is Not the Same as Intelligence

A registry entry, photograph, post or domain record is information. It becomes intelligence only after an analyst checks its origin, establishes context, compares it with other sources and explains its relevance.

Suppose a professional profile states that a founder worked for a certain company. That statement is a lead. An analyst might compare it with historic company records, archived team pages, conference biographies and dated media coverage. The final assessment should state whether the employment is confirmed, merely indicated or still unresolved.

Source evaluation should consider who originally published the information, when it was created, whether the source had direct knowledge of the event and whether independent evidence supports the claim. Analysts should also distinguish the reliability of a source from the credibility of a particular statement: even a generally trustworthy source can publish incomplete or incorrect information.

This distinction prevents volume from being mistaken for certainty. Ten articles may repeat one original allegation. Several databases may reproduce the same outdated filing. Multiple search results are not independent corroboration when they share one source. These are among the intelligence mistakes businesses still make.

What Sources Does OSINT Use?

OSINT draws on publicly or commercially available online and offline information collected through lawful, authorised methods. Common source categories include:

  • corporate registers, court files, procurement records and regulatory disclosures;
  • sanctions lists, government publications and public datasets;
  • news archives, trade media, academic research, books and libraries;
  • company websites, professional profiles, forums and public social-media content;
  • photographs, video, maps, weather records and satellite imagery;
  • domain, certificate, DNS, IP and other publicly visible technical data;
  • commercial databases used under their current licence terms.

Some cases involve publicly accessible dark-web pages, leak sites or other high-risk environments. Visibility alone does not make access, possession or reuse lawful. Restricted forums, stolen credentials, illegal material and systems protected by authentication require a different assessment and may fall outside OSINT entirely.

Source coverage also varies by jurisdiction. A corporate register may publish shareholders in one country and only directors in another. Court files may be searchable online, available only in person or restricted to particular users. An empty search result therefore proves only that no record was found in that source at that time.

Who Uses OSINT?

Government departments, law-enforcement bodies, military teams, journalists, human-rights investigators, lawyers, private investigators, cybersecurity specialists and intelligence companies all work with open sources. Their mandates and evidence standards differ.

Businesses use OSINT when the cost of an unsupported assumption is material. Typical applications include:

  • checking ownership, related parties, sanctions exposure and litigation before a transaction;
  • verifying suppliers, distributors and other third parties;
  • reviewing candidate claims for senior, regulated or security-sensitive positions;
  • assessing competitors, markets, pricing signals and market-entry risks;
  • supporting cyber and information risk management by identifying exposed digital infrastructure and emerging threats;
  • reconstructing fraud, asset, reputation or information-threat networks.

For example, third-party due diligence may combine company records, sanctions sources, court documents, procurement data and local-language reporting. Pre-employment screening should instead be scoped to the role, jurisdiction and level of access the candidate would receive. The same methods do not justify the same scope in every case.

How Does OSINT Work?

Professional OSINT follows an intelligence cycle. Organisations use different labels, but five stages cover most corporate and investigative work.

1. Direction and preparation

The case owner defines the question, decision, deadline, jurisdictions and materiality threshold. The team records known identifiers, assumptions, permitted sources and legal boundaries. This stage also determines what would justify expanding, pausing or ending the work.

2. Collection

Analysts gather enough relevant and diverse material to answer the requirement. They record search terms, source URLs, access dates and identifiers. Collection should be targeted and proportionate, particularly when it involves personal or sensitive information.

3. Processing

The team organises records, normalises names and dates, translates material and separates possible matches from confirmed identities. Duplicate reports can be grouped, but the original source trail should remain intact. Automated extraction and translation need checking against the underlying material.

4. Analysis and production

Analysts test relationships, sequences and competing explanations. They may build timelines, ownership charts or geographic comparisons. The report separates confirmed facts from indicators and assumptions, assigns proportionate confidence and identifies gaps that could affect the conclusion.

5. Dissemination and feedback

The authorised recipient receives the answer in a format suited to the decision: a report, briefing, alert, timeline or evidence pack. Feedback may narrow the requirement, identify another source or trigger monitoring. It does not automatically authorise a new method or wider collection.

For a deeper explanation of how a tool directory differs from a repeatable investigative method, see our guide to the OSINT Framework. It covers source planning, evidence handling, analytical review and reporting.

Which Techniques Support OSINT?

OSINT techniques are methods for locating, testing and connecting information. Common examples include:

  • using search operators, alternative spellings and local-language queries;
  • checking official corporate, court, sanctions and procurement records;
  • reviewing public social-media activity after confirming the account owner;
  • finding earlier versions of websites through web archives;
  • using reverse-image search, metadata and visual clues to examine media;
  • comparing maps, imagery, weather and shadows for geolocation or chronolocation;
  • examining public domain-registration, DNS and certificate data;
  • mapping links among people, companies, addresses, transactions and events;
  • monitoring defined sources for changes that meet an escalation threshold.

Search engines and tools accelerate discovery, but their output is not proof. Rankings are incomplete, automated sentiment can misrepresent a population and a visualisation can make a weak link look stronger than its evidence.

For practical guidance on search operators, public records, metadata, geolocation, image verification and web archives, explore our guide to 14 OSINT techniques for verifiable online research.

Passive and Active OSINT

Passive OSINT generally means collecting information without deliberately communicating with or prompting the subject. Reading a filing, searching an archive or reviewing a public webpage may fall into this category.

Passive does not mean invisible. Websites and databases can log queries, IP addresses and account identifiers. Platforms may notify users about profile views, while third-party tools may retain searches or uploaded files. Even non-interactive collection therefore requires appropriate rules for accounts, automation, data handling and investigator exposure.

“Active OSINT” is an informal label rather than a universal legal category. It may describe following an account, reacting to content, requesting entry to a restricted group, submitting a form or messaging a person. These actions create interaction, may alert the subject and can change the available evidence.

Direct engagement should be distinguished from routine open-source observation. Interviews, reference checks, controlled security testing and witness approaches require their own authority and procedures.

For authorised research, investigators may use dedicated research personas rather than personal profiles. Such accounts should be managed under organisational procedures and applicable platform rules, kept separate from analysts’ personal identities and used only within the approved mandate. They must not impersonate real individuals or misuse another person’s photographs or identifying details.

Access to restricted groups requires particular care. Joining a group, even without posting or messaging, may involve active engagement or access to information that is not publicly available. Organisational approval does not automatically make that material OSINT. The access method, legal basis and classification of the resulting information should be assessed before collection.

Before any message, reaction, connection request or group application, the team should define permitted interactions, evidence-handling rules and conditions for stopping or escalating the work. Research accounts must not be used to bypass authentication or other technical access controls.

A Four-Part Test: Is It Really OSINT?

This test helps distinguish open-source intelligence from general browsing and from collection methods that require separate authority.

  1. Access: Is the information publicly or commercially available, and can it be obtained through an authorised method without bypassing access controls? Material from restricted groups or private accounts requires separate classification.
  2. Method: Is the collection permitted by law, organisational policy, the source’s access conditions and any applicable contract?
  3. Purpose: Does the work answer a defined and legitimate intelligence requirement rather than collect information without a boundary?
  4. Product: Has the material been evaluated, corroborated and analysed, with sources, confidence and limitations made clear?

If the access or method fails, the activity should not be treated as routine OSINT. If the purpose or product fails, the result may be open-source information, but it is not yet intelligence.

Legal and Ethical Boundaries

Public availability does not cancel privacy, data-protection, copyright, database rights, confidentiality, employment, surveillance or computer-misuse rules. Platform terms and commercial licences can impose further restrictions. The relevant obligations depend on the jurisdiction, source, purpose, subject and intended use.

For UK organisations, the Information Commissioner’s Office explains that the standard legitimate interests basis requires a purpose, necessity and balancing test. Processing personal data obtained from publicly accessible sources can still trigger transparency duties and other data-subject rights, subject to applicable exceptions and exemptions.

Responsible OSINT should follow several controls:

  • define a lawful purpose and collect only what it requires;
  • minimise sensitive and unrelated personal information;
  • do not bypass authentication, exploit a vulnerability or use leaked credentials;
  • assess the safety of subjects, sources, analysts and third parties;
  • preserve provenance and the original context of material findings;
  • test alternative explanations and distinguish fact from inference;
  • restrict access, retention and dissemination to the authorised purpose;
  • stop and escalate when the next step requires new authority.

The Berkeley Protocol on Digital Open Source Investigations was developed for international criminal and human-rights work. Its principles of accountability, objectivity, competence, documentation and safety are also useful for corporate investigations. This article is general information, not legal advice or authorisation to investigate.

Benefits and Limitations of OSINT

OSINT gives analysts access to many source types without relying solely on confidential collection. It can sometimes surface events quickly, support cross-border comparison and leave an audit trail that a reviewer can inspect. Public and commercial sources can also be monitored as ownership, sanctions, litigation or threat exposure changes.

The method is not automatically cheap, immediate or transparent. Specialist databases, language skills, secure infrastructure and experienced analysts cost money. Records can lag, disappear or contain errors. Social platforms contain impersonation, coordinated activity and synthetic media. Search algorithms decide what appears first, not what is most reliable.

These limits explain why verification matters. AI-assisted OSINT workflows can help with translation, transcription, extraction and triage. They can also merge identities, omit context or generate false citations. A material conclusion still needs human review against original sources.

OSINT for Public-Interest Work

OSINT also supports humanitarian and accountability projects. Trace Labs coordinates passive research on missing-person cases and passes potential leads to law enforcement. Its rules prohibit contacting, tagging, following or otherwise engaging with the missing person’s family and friends.

Europol’s Stop Child Abuse – Trace an Object initiative publishes isolated background objects from child sexual abuse material. Members of the public can submit clues about an object’s location or origin through Europol’s official form. Europol tells users not to share recognisable images, names or other personal information online.

Both examples connect collection to a defined purpose, controlled submission channel and responsible authority. They do not invite independent contact with subjects or public speculation about individual cases.

What Should an OSINT Report Deliver?

A useful OSINT report answers the original requirement. It identifies the sources behind material findings and separates what the evidence confirms from what it merely indicates. It records confidence, contradictions, unavailable sources and other limitations.

The report should then explain the implication for the reader: proceed with a transaction, pause for another check, change a contractual control, reject an unsupported claim or begin monitoring a defined risk. A large source list without that analytical judgement remains research, not decision-ready intelligence.

The Role of OSINT in Organisational Decisions

OSINT can strengthen investigations, security assessments, market analysis, due diligence and hiring when the question and authority are clear. It can link entities, reconstruct events, test claims and identify gaps that standard databases miss.

The method does not replace judgement. Its value comes from selecting the right sources, testing what they show and stating what remains unknown. Molfar Intelligence applies that standard through business intelligence consulting, where public and commercial information is assessed against the decision the client needs to make.

Teams that would rather run this as a scoped engagement than build the capability in-house can review Molfar’s OSINT services.

Turn Intelligence Into Action
Order a service
Order a service
Black Plus Icon

Recent posts

View all
View all
White Plus Icon
View all
View all
White Plus Icon
Gain the Clarity You Need to Move with Confidence

Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.