Most organisations do not have an information shortage. They have company filings, news coverage, social posts, technical records, satellite images and commercial databases. The harder question is which parts are reliable, how they connect and what they mean for a decision.

Open-source intelligence, or OSINT, answers that question through structured collection and analysis. It can help an investor assess a target, an employer verify a candidate, a security team examine exposure or a journalist reconstruct an event. The method starts with available information, but the product is an evidence-based assessment rather than a collection of search results.

What Does OSINT Mean?

OSINT is intelligence derived exclusively from publicly or commercially available information and produced to address a defined requirement. This is the definition used in the US Intelligence Community’s 2024–2026 OSINT Strategy.

“Open source” describes how information can be accessed. It does not mean open-source software, and it does not mean that every online record may be collected or reused without restriction. A source can require registration or a paid subscription and still fall within OSINT if it is commercially available and the researcher is authorised to use it.

The requirement is just as important as the source. “Research this company” is too broad. “Establish who controls this supplier, whether its owners face sanctions exposure and whether it has undisclosed links to the buyer” gives the analyst a question that can be answered.

Information Is Not the Same as Intelligence

A registry entry, photograph, post or domain record is information. It becomes intelligence only after an analyst checks its origin, establishes context, compares it with other sources and explains its relevance.

Suppose a professional profile states that a founder worked for a certain company. That statement is a lead. An analyst might compare it with historic company records, archived team pages, conference biographies and dated media coverage. The final assessment should state whether the employment is confirmed, merely indicated or still unresolved.

This distinction prevents volume from being mistaken for certainty. Ten articles may repeat one original allegation. Several databases may reproduce the same outdated filing. Multiple search results are not independent corroboration when they share one source. These are among the intelligence mistakes businesses still make.

What Sources Does OSINT Use?

OSINT draws on online and offline material that is lawfully accessible for the task. Common source categories include:

  • corporate registers, court files, procurement records and regulatory disclosures;
  • sanctions lists, government publications and public datasets;
  • news archives, trade media, academic research, books and libraries;
  • company websites, professional profiles, forums and public social-media content;
  • photographs, video, maps, weather records and satellite imagery;
  • domain, certificate, DNS, IP and other publicly visible technical data;
  • commercial databases used under their current licence terms.

Some cases involve publicly accessible dark-web pages, leak sites or other high-risk environments. Visibility alone does not make access, possession or reuse lawful. Restricted forums, stolen credentials, illegal material and systems protected by authentication require a different assessment and may fall outside OSINT entirely.

Source coverage also varies by jurisdiction. A corporate register may publish shareholders in one country and only directors in another. Court files may be searchable online, available only in person or restricted to particular users. An empty search result therefore proves only that no record was found in that source at that time.

Who Uses OSINT?

Government departments, law-enforcement bodies, military teams, journalists, human-rights investigators, lawyers, private investigators, cybersecurity specialists and intelligence companies all work with open sources. Their mandates and evidence standards differ.

Businesses use OSINT when the cost of an unsupported assumption is material. Typical applications include:

  • checking ownership, related parties, sanctions exposure and litigation before a transaction;
  • verifying suppliers, distributors and other third parties;
  • reviewing candidate claims for senior, regulated or security-sensitive positions;
  • assessing competitors, markets, pricing signals and market-entry risks;
  • supporting cyber and information risk management by identifying exposed digital infrastructure and emerging threats;
  • reconstructing fraud, asset, reputation or information-threat networks.

For example, third-party due diligence may combine company records, sanctions sources, court documents, procurement data and local-language reporting. Pre-employment screening should instead be scoped to the role, jurisdiction and level of access the candidate would receive. The same methods do not justify the same scope in every case.

How Does OSINT Work?

Professional OSINT follows an intelligence cycle. Organisations use different labels, but five stages cover most corporate and investigative work.

1. Direction and preparation

The case owner defines the question, decision, deadline, jurisdictions and materiality threshold. The team records known identifiers, assumptions, permitted sources and legal boundaries. This stage also determines what would justify expanding, pausing or ending the work.

2. Collection

Analysts gather enough relevant and diverse material to answer the requirement. They record search terms, source URLs, access dates and identifiers. Collection should be targeted and proportionate, particularly when it involves personal or sensitive information.

3. Processing

The team organises records, normalises names and dates, translates material and separates possible matches from confirmed identities. Duplicate reports can be grouped, but the original source trail should remain intact. Automated extraction and translation need checking against the underlying material.

4. Analysis and production

Analysts test relationships, sequences and competing explanations. They may build timelines, ownership charts or geographic comparisons. The report separates confirmed facts from indicators and assumptions, assigns proportionate confidence and identifies gaps that could affect the conclusion.

5. Dissemination and feedback

The authorised recipient receives the answer in a format suited to the decision: a report, briefing, alert, timeline or evidence pack. Feedback may narrow the requirement, identify another source or trigger monitoring. It does not automatically authorise a new method or wider collection.

For a deeper explanation of how a tool directory differs from a repeatable investigative method, see our guide to the OSINT Framework. It covers source planning, evidence handling, analytical review and reporting.

Which Techniques Support OSINT?

OSINT techniques are methods for locating, testing and connecting information. Common examples include:

  • using search operators, alternative spellings and local-language queries;
  • checking official corporate, court, sanctions and procurement records;
  • reviewing public social-media activity after confirming the account owner;
  • finding earlier versions of websites through web archives;
  • using reverse-image search, metadata and visual clues to examine media;
  • comparing maps, imagery, weather and shadows for geolocation or chronolocation;
  • examining public domain-registration, DNS and certificate data;
  • mapping links among people, companies, addresses, transactions and events;
  • monitoring defined sources for changes that meet an escalation threshold.

Search engines and tools accelerate discovery, but their output is not proof. Rankings are incomplete, automated sentiment can misrepresent a population and a visualisation can make a weak link look stronger than its evidence.

For practical guidance on search operators, public records, metadata, geolocation, image verification and web archives, explore our guide to 14 OSINT techniques for verifiable online research.

Passive and Active OSINT

Passive OSINT generally means collecting information without deliberately communicating with or prompting the subject. Reading a filing, searching an archive or reviewing a public webpage may fall into this category.

Passive does not mean invisible. Websites and databases can log queries, IP addresses and account identifiers. Platforms may notify users about profile views. Third-party tools may retain searches or uploaded files. Even non-interactive collection therefore requires rules for accounts, automation, data handling and investigator exposure.

“Active OSINT” is an informal label rather than a universal legal category. It can describe following an account, reacting to content, requesting entry to a private group, submitting a form or messaging a person. These actions create interaction, may alert the subject and can alter the available evidence.

Direct engagement should be treated separately from routine open-source observation. Interviews, reference checks, controlled security testing or witness approaches require their own authority and procedures.

For authorised active research, investigators may use dedicated research personas, sometimes called research or sock-puppet accounts, rather than personal profiles. A team may maintain more than one account across relevant platforms so the persona has a consistent presence. The account should be created and managed under the organisation’s standard operating procedures and applicable platform rules, separated from the analyst’s personal identity and aligned with the environment in which it will operate. A research persona must not impersonate a real person or use another person’s photographs or identifying details. An empty profile created immediately before contact can expose the researcher and compromise the work.

Access to a private group also needs an explicit classification. Some organisations treat read-only membership as passive because the analyst does not communicate after entry. Others consider the request to join an active step or a form of undercover access. The organisation should settle this point in its SOP before the case begins rather than leave it to the individual researcher.

Group size changes operational exposure. A new account may blend into a community of 500 members more easily than into a group of 20, where administrators and participants are more likely to notice a new arrival. Size does not replace authorisation, but it affects the chance of detection and should inform the risk assessment.

Before any message, reaction, connection request or group application, the team should define the permitted identity, allowed interactions, evidence-handling rules and stop conditions. A research persona must remain within the approved mandate and must not be used to defeat technical access controls.

A Four-Part Test: Is It Really OSINT?

This test helps separate open-source intelligence from general browsing and from methods that require different authority.

  1. Access: Is the information public, commercially available or reachable through an approved research account or group-access procedure without defeating a technical control?
  2. Method: Is the collection permitted by law, organisational policy, the source’s access conditions and any applicable contract?
  3. Purpose: Does the work answer a defined and legitimate intelligence requirement rather than collect information without a boundary?
  4. Product: Has the material been evaluated, corroborated and analysed with sources, confidence and limitations made clear?

If the access or method fails, the activity is not routine OSINT. If the purpose or product fails, the result may be open-source information, but it is not yet intelligence.

Legal and Ethical Boundaries

Public availability does not cancel privacy, data-protection, copyright, database rights, confidentiality, employment, surveillance or computer-misuse rules. Platform terms and commercial licences can impose further restrictions. The relevant obligations depend on the jurisdiction, source, purpose, subject and intended use.

For UK organisations, the Information Commissioner’s Office explains that the standard legitimate interests basis requires a purpose, necessity and balancing test. Processing personal data obtained from publicly accessible sources can still trigger transparency duties and other data-subject rights, subject to applicable exceptions and exemptions.

Responsible OSINT should follow several controls:

  • define a lawful purpose and collect only what it requires;
  • minimise sensitive and unrelated personal information;
  • do not bypass authentication, exploit a vulnerability or use leaked credentials;
  • assess the safety of subjects, sources, analysts and third parties;
  • preserve provenance and the original context of material findings;
  • test alternative explanations and distinguish fact from inference;
  • restrict access, retention and dissemination to the authorised purpose;
  • stop and escalate when the next step requires new authority.

The Berkeley Protocol on Digital Open Source Investigations was developed for international criminal and human-rights work. Its principles of accountability, objectivity, competence, documentation and safety are also useful for corporate investigations. This article is general information, not legal advice or authorisation to investigate.

Benefits and Limitations of OSINT

OSINT gives analysts access to many source types without relying solely on confidential collection. It can sometimes surface events quickly, support cross-border comparison and leave an audit trail that a reviewer can inspect. Public and commercial sources can also be monitored as ownership, sanctions, litigation or threat exposure changes.

The method is not automatically cheap, immediate or transparent. Specialist databases, language skills, secure infrastructure and experienced analysts cost money. Records can lag, disappear or contain errors. Social platforms contain impersonation, coordinated activity and synthetic media. Search algorithms decide what appears first, not what is most reliable.

These limits explain why verification matters. AI-assisted OSINT workflows can help with translation, transcription, extraction and triage. They can also merge identities, omit context or generate false citations. A material conclusion still needs human review against original sources.

OSINT for Public-Interest Work

OSINT also supports humanitarian and accountability projects. Trace Labs coordinates passive research on missing-person cases and passes potential leads to law enforcement. Its rules prohibit contacting, tagging, following or otherwise engaging with the missing person’s family and friends.

Europol’s Stop Child Abuse – Trace an Object initiative publishes isolated background objects from child sexual abuse material. Members of the public can submit clues about an object’s location or origin through Europol’s official form. Europol tells users not to share recognisable images, names or other personal information online.

Both examples connect collection to a defined purpose, controlled submission channel and responsible authority. They do not invite independent contact with subjects or public speculation about individual cases.

What Should an OSINT Report Deliver?

A useful OSINT report answers the original requirement. It identifies the sources behind material findings and separates what the evidence confirms from what it merely indicates. It records confidence, contradictions, unavailable sources and other limitations.

The report should then explain the implication for the reader: proceed with a transaction, pause for another check, change a contractual control, reject an unsupported claim or begin monitoring a defined risk. A large source list without that analytical judgement remains research, not decision-ready intelligence.

The Role of OSINT in Organisational Decisions

OSINT can strengthen investigations, security assessments, market analysis, due diligence and hiring when the question and authority are clear. It can link entities, reconstruct events, test claims and identify gaps that standard databases miss.

The method does not replace judgement. Its value comes from selecting the right sources, testing what they show and stating what remains unknown. Molfar Intelligence applies that standard through business intelligence consulting, where public and commercial information is assessed against the decision the client needs to make.

Author

Former British Army officer, trained in surveillance and target acquisition, and Bain and Company engagement manager, with more than a decade of experience working in consulting, private equity and venture capital across Western Europe.

Recent posts

View all
View all
White Plus Icon
View all
View all
White Plus Icon

Related posts

View all
View all
White Plus Icon
No items found.
View all
View all
White Plus Icon
Turn Intelligence Into Action
Order a service
Order a service
Black Plus Icon

Our cases

Behind every case is a client who needed clarity in uncertainty. Browse our work to see how we uncover what others miss — and what that means in practice for businesses and decision-makers.

View all cases
View all cases
White Plus Icon
Expanded Plus Icon

Investor Due Diligence: Mitigating Reputational Risks in Defence Tech

Revealed how a high-stakes Defence Tech investment was halted after OSINT-driven due diligence uncovered a co-founder’s links to Russian-origin money laundering and a seized 2.6 billion UAH gambling enterprise, protecting a global firm from severe reputational and regulatory fallout.

Investment

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Pre-Employment Screening for a Spacecraft Manufacturing Role

Conducted a full pre-employment background investigation for a high-security aerospace role, covering court registry checks, financial record verification, ideological risk assessment, and social media OSINT analysis across relevant jurisdictions.

Space

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Sanctions Gaps — Supercam Drone Production Continues

Revealed how Russian drone manufacturers circumvent international sanctions by exploiting a critical design flaw (sanctions applied to company names rather than underlying legal entity identifiers), enabling Supercam to increase production tenfold despite being designated.

Finance

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Cybersecurity Audit and Internal Data Exposure Mitigation

Conducted a comprehensive cybersecurity audit of a long-standing European IT infrastructure, identified critical internal data leaks involving financial plans and performance reviews, and implemented high-level security protocols to mitigate regulatory and operational risks.

Cybersecurity

Learn more
Learn more
White Plus Icon
Gain the Clarity You Need to Move with Confidence

Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.