← Reference · Home · Print this page

Cybersecurity · Awareness

OSINT (Open-Source Intelligence)

Reference entry · last updated 20261006

Open-source intelligence (OSINT) is intelligence produced from publicly or commercially available information to answer a defined intelligence need. The U.S. Intelligence Community uses this scope in its OSINT strategy.[1]

First principles and definitions

An illustrative cyber awareness question is: which publicly visible details could help someone impersonate a colleague?

This question is an illustrative defensive use, not a reported investigation.

Open-source information is the material being examined. Intelligence is the resulting assessment tied to a question or decision. Commercial availability means that payment can be involved; open source does not mean that every source is free. The strategy also identifies provenance and validity as risks: where information came from and whether it is reliable.[1]

Source types

The following are illustrative source categories, not findings about any person or organisation.

SourceExample
Public websitesA company publishes a staff biography or contact page.
Public social postsAn account announces a conference visit.
Official publicationsAn agency releases a report or public register.
Commercial informationA licensed news database provides an article.

Collection, verification, analysis, and reporting

This is an illustrative workflow for a small defensive review, not a prescribed intelligence standard.

  1. Define the question and the authorised scope. Set a stopping point before collecting.
  2. Collect relevant material. Record its original URL, author or publisher, publication date, and retrieval date.
  3. Verify identity and context. Read the original source, check dates, and seek independent corroboration for important claims.
  4. Analyse what the evidence supports. Separate observations from inferences. Record conflicting evidence and gaps.
  5. Report the answer with its sources, limits, and confidence. Include only details needed for the decision.

For example, two articles copied from one press release would count as one origin in this workflow. An old staff biography would require a current check before treating its job title as present fact.

Public information and targeted phishing

The UK National Cyber Security Centre (NCSC) warns that attackers use website and social-media details to make targeted phishing messages more convincing. It recommends reviewing unnecessary published detail and information exposed by partners or suppliers.[2]

Illustrative example: a public event post names a supplier. A fraudulent invoice then refers to that supplier and event. Accurate background details do not establish that the payment request is authorised.

Defensive exposure checks

A digital footprint is the information about a person available online. NCSC guidance connects this exposure with identity theft and convincing phishing messages.[3]

These checks adapt NCSC social-media guidance.[3]

Access and ethical limits

The U.S. strategy calls for protections for privacy and civil liberties alongside OSINT work.[1]

For the illustrative defensive review above, the scope excludes bypassing access controls, using stolen credentials, impersonating someone to enter a private group, or publishing unnecessary personal details. Collection and reuse should follow the applicable permissions, policy, and source licence. An uncertain permission is a reason to stop and check with the responsible owner.

See also

References

  1. Office of the Director of National Intelligence, The IC OSINT Strategy 2024–2026, definition and introduction, printed pp. 1–2.
  2. National Cyber Security Centre, Phishing attacks: defending your organisation, “Reduce the information available to attackers.”
  3. National Cyber Security Centre, Social Media: how to use it safely, “Understanding your digital footprint” and “Spotting and reporting fake accounts.”