GRC Careers

HomeResourcesOSINT (Open Source Intelligence)

CS-092 · Threat Intelligence

OSINT (Open Source Intelligence)

Gathering and analyzing publicly available information to support defensive security research.

Executive Summary

Open source intelligence, or OSINT, is the practice of collecting and analyzing information that is publicly and lawfully available to answer a security question. Sources include public websites, domain and certificate records, public code repositories, news, and social media. For defenders, OSINT reveals what an organization exposes to the outside world, supports threat research, and enriches investigations, all using only information anyone could legally access.

What It Is

OSINT is intelligence produced from publicly available information rather than from private or classified sources. In cybersecurity it is used to understand an organization's external attack surface, to research threat actors and campaigns, and to add context during incident investigations. Typical sources include public DNS and WHOIS records, TLS certificate transparency logs, search engines, public code and configuration repositories, job postings, corporate filings, and social media. The core of OSINT is not just collection but analysis: raw public data becomes intelligence only after it is verified, connected, and interpreted to answer a specific question. Done professionally, OSINT relies entirely on lawful access to information that is already public, and it is guided by a clear, authorized objective.

Why It Matters

Attackers perform reconnaissance using the same public sources before they strike, so a defender who runs OSINT on their own organization sees themselves the way an adversary would. That surfaces exposed services, leaked credentials in public repositories, forgotten subdomains, and information that could fuel a convincing phishing message, all of which can be fixed before they are exploited. OSINT also enriches threat intelligence by helping analysts research infrastructure and campaigns using open records. For professionals, OSINT skill is valuable across threat intelligence, security operations, penetration testing, and investigations, but it carries a responsibility: the same techniques must be applied ethically, within authorization and the law, and never to harass, stalk, or intrude on individuals.

How It Works

A sound OSINT process starts with a clear, authorized question, such as what does our organization expose externally. The analyst then plans which public sources are relevant, collects information from them, and, crucially, verifies it, since public data can be outdated, misattributed, or deliberately false. Verified findings are connected and analyzed to produce intelligence that answers the original question, and the result is reported to the people who can act on it. Automation and specialized tools help gather and organize large volumes of public data, but human judgment drives the analysis. Throughout, professional OSINT stays within scope and the law: it uses only publicly and lawfully available information, respects privacy, avoids any unauthorized access, and documents its methods so conclusions can be trusted and repeated.

Architecture Diagram

Define an authorized question and scopePlan relevant public sourcesCollect lawfully available informationVerify accuracy and attributionAnalyze and report actionable intelligence
OSINT moves from an authorized question through planned collection and verification into analysis and a reported result.

Visual Workflow

Define a clear, authorized objective and the boundaries of what is in scope.Plan which public and lawful sources are relevant to the question.Collect information from those sources without any unauthorized access.Verify accuracy and attribution, since public data can be stale or false.Analyze and connect the verified findings into intelligence that answers the question.Report the result to the people who can act, and document methods for repeatability.

Common Attacks

Common Mistakes

Best Practices

Quick Checklist

Recommended Tools

Search engines and advanced search operators
Locate publicly indexed information efficiently
DNS, WHOIS, and certificate transparency lookups
Reveal domains, subdomains, and infrastructure from public records
Attack surface discovery tools
Map an organization's externally reachable assets from public data
OSINT collection and mapping frameworks
Organize and link findings from many public sources

Industry Standards

MITRE ATT&CK (Reconnaissance and Resource Development)
Describes how adversaries gather public information before an attack
NIST SP 800-115
Technical guide to security testing where information gathering is a phase
CISA guidance on reducing external exposure
Defensive context for acting on OSINT findings

Career Relevance

OSINT is used by threat intelligence analysts researching actors and infrastructure, SOC analysts enriching alerts, threat hunters chasing leads, and penetration testers performing authorized reconnaissance. The ability to gather and, more importantly, verify and analyze public information is a valued and portable skill across security, and it is directly relevant to GRC and AI governance professionals assessing an organization's external exposure and the ethical limits of intelligence gathering.

Interview Questions

Related Certifications

GIAC Open Source Intelligence (GOSI) GIAC Cyber Threat Intelligence (GCTI) CompTIA CySA+

Further Reading

Key Takeaways

Download PDFDownload PNG

FAQ

Is OSINT legal?

Professional OSINT uses only information that is publicly and lawfully available, which is legal. It stops at the point of unauthorized access. Logging into systems you are not permitted to use, or bypassing controls, is not OSINT and is not lawful. Staying within scope, authorization, and privacy limits is what keeps the practice ethical.

How is OSINT different from threat intelligence?

OSINT is one method of gathering source material, specifically from public information. Threat intelligence is the broader discipline of producing analyzed, decision-ready insight, which may draw on OSINT among other sources. OSINT contributes raw material; analysis turns it into intelligence.

Why should defenders run OSINT on their own organization?

Attackers already do it. Reviewing your own public footprint shows you what an adversary sees, such as exposed services, leaked secrets in public repositories, or forgotten subdomains, so you can fix those exposures before they are used against you.

Get all 116 reference sheets
The complete AGJ Cybersecurity Professional Reference Library, print-ready PDFs and PNGs.
Browse the library

Related Careers

Related certifications

GIAC Open Source Intelligence (GOSI)GIAC Cyber Threat Intelligence (GCTI)CompTIA CySA+

Current openings

Live openings appear on the web version. Browse the job board for current GRC and security roles.
Browse all jobs

Suggested learning path

  1. Ground the basics with CS-001 Cybersecurity
  2. Study this sheet: OSINT (Open Source Intelligence)
  3. Go deeper: Indicators of Compromise (IOCs)
  4. Go deeper: Indicators of Attack (IOAs)
  5. Validate it: work toward GIAC Open Source Intelligence (GOSI)
  6. Find the role: browse current openings

Related sheets

More in Threat Intelligence

Share this LinkedIn Facebook X Email