Open-Source Intelligence (OSINT) is the collection and analysis of information drawn from publicly available sources. In cyber threat intelligence it is often the first discipline analysts reach for, because so much useful context sits in the open: company websites, news and research, social media, public code repositories, domain registration records, and DNS data. OSINT turns this scattered public material into structured insight about adversaries, exposure, and context.
As a collection discipline, OSINT is defined by its source rather than its subject. Analysts use it to understand an organization's external footprint, to enrich indicators with registration and infrastructure detail, and to corroborate findings from other disciplines. Its public nature makes it broadly accessible and a natural foundation for research and attribution work. Public visibility is not the same as legal permission, however: personal data, copyrighted or database-protected material, site terms of service, and jurisdiction-specific privacy rules can all constrain what may be collected and how it may be used, so accessibility should be judged separately from lawfulness.
OSINT matters because it is inexpensive, scalable, and continuously refreshed, and it often provides the connective tissue that links other intelligence together. Its typical inputs include WHOIS and DNS records, corporate and personnel information, public forums, and media reporting. Its limits deserve respect: public data can be stale, incomplete, or deliberately misleading, and volume can overwhelm analysis. Sound OSINT practice emphasizes source evaluation and corroboration rather than treating any single public record as fact.
References#
- SANS OSINT and Cyber Threat Intelligence resources
- MITRE ATT&CK reconnaissance technique descriptions