← Field Notes
Engineering·13 August 2026·9 min read

ALREADY
PUBLIC.

OSINT is the structured practice of finding your own exposure before someone with worse intentions does. AI has changed the scale — the four-stage process, and the ethical boundaries, have not.

OSINTThreat IntelligenceCompetitive IntelligenceAI SecurityAttack Surface

Information your organisation has exposed is already visible to anyone who knows how to look. Security teams call the practice of finding it OSINT: open-source intelligence. The same techniques used to monitor your own exposure are used to map a target before an attack. That dual-use reality is not a disclaimer at the end of a methodology document. It is the reason ethical and legal framing is load-bearing here, not decorative.

Key Takeaways
  • OSINT covers legally accessible public data: social media, public records, news archives, company filings, DNS/WHOIS records, technical infrastructure metadata, and breach-disclosure databases.
  • The same techniques a security team uses to find their own organisation’s exposure are what an attacker uses for reconnaissance. Dual-use is the reason ethical framing is load-bearing, not decorative.
  • The four-stage cycle (Planning, Collection, Processing/Analysis, Dissemination) exists to prevent the most common failure: skipping straight from collection to conclusion without corroboration.
  • OSINT is one of nine recognised intelligence disciplines. In business and security contexts, its primary value is as a corroboration layer for other sources, not as a standalone intelligence product.
01

WHAT OSINT ACTUALLY IS

#

Open-source intelligence is the structured practice of collecting, analysing, and interpreting publicly or commercially available information to produce actionable insight. Not covert collection, which is a different discipline and a different legal category entirely. "Open source" means legally accessible: social media, public records, news archives, company filings, DNS and WHOIS records, technical infrastructure metadata, breach-disclosure databases.

4-STAGE INTELLIGENCE PROCESS — COLLECTION TO ACTIONCOLLECTraw public datasocial media · DNS/WHOISpublic records · breach DBsPROCESSstructure + filternormalise · deduplicatetag by relevance + sourceANALYSEcorrelate + interpretcross-reference · pattern matchplace in contextDISTRIBUTEdecision-readyto whoever needs to actin a format they can useSkipping analysis — going collection → conclusion — is the most common failure mode

OSINT is a collection method, not the finished product. Threat intelligence, competitive intelligence, and due diligence are the broader disciplines that combine OSINT with proprietary data, internal context, and analytical judgment to produce something a decision-maker can act on. A raw search result is a data point. Intelligence is that data point placed in context, corroborated, and connected to a decision.

The most common way OSINT work goes wrong: skipping straight from collection to conclusion without the analysis and corroboration steps. The four-stage process exists specifically to prevent that failure mode.

02

THE NINE INTELLIGENCE DISCIPLINES

#

OSINT is one of nine recognised intelligence disciplines. In most business and security contexts, its real value is as a corroboration layer across others — validating what a human source says, cross-referencing financial records against public disclosures, confirming a threat actor's claimed infrastructure actually exists.

THE INTELLIGENCE DISCIPLINES — OSINT AND CTI ARE MOST DIRECTLY BUSINESS-RELEVANTOSINTOpen-Source Intelligencethis workbook · the foundationCTICyber Threat Intelligencebuilt directly on OSINTFININTFinancial Intelligenceheavy OSINT overlapGEOINTGeospatial Intelligencesupply chain, market analysisHUMINTHuman SourcesOSINT corroboratesTECHINTTechnical Intelligencecompetitor capabilityIMINTImagery Intelligencesubset of GEOINTSIGINTSignals Intelligencegov/mil domain onlyMASINTMeasurement & Signaturehighly specialised, gov/defOSINT cross-validates across all nine — corroborating human sources, verifying financial disclosures, confirming infrastructure claims

CTI and FININT have the most direct OSINT overlap in a business context. GEOINT is relevant for supply-chain risk and market analysis. The rest — SIGINT, MASINT — are government and defence domains. Treating OSINT findings as complete on their own, without cross-referencing, is a consistent source of false conclusions in practice.

03

HOW AI CHANGES EACH APPLICATION AREA

#

AI-assisted OSINT has matured fastest in cybersecurity and threat intelligence, but the same capability shifts are happening across every application area. The underlying change is consistent: AI handles the volume problem that made continuous monitoring impractical and surfaces relationships across disconnected sources that no single search would reveal.

SIX APPLICATION AREAS — WHAT AI SPECIFICALLY ADDS TO EACHCYBERSECURITY / CTIExposed assets · leaked creds · threat actor infrastructureAI Continuous monitoring across Pastebin, GitHub, breach forums,and deep-web disclosure sites — no manual process matches scaleCOMPETITIVE INTELSocial listening · sentiment analysis · citation trackingAI NLP across unstructured competitor and market signals at scale;AEO/GEO citation tracking is a direct instance of this disciplineFRAUD / FININTCorporate filings · ownership structures · AML case workAI Pattern detection across registries, disclosures, adverse media —correlations a human analyst would take far longer to surfaceMISINFORMATIONDeepfake detection · claim verification · media authenticationAI NLP flags likely-synthetic content at a scale manual review cannot;detection vs generation is an active, ongoing arms raceDUE DILIGENCEVendor · partner · acquisition vetting from public filingsAI Surface litigation history, adverse media, and regulatory riskfaster than manual research — feeding into vendor-review workflowsGEOSPATIALLocation-based public data · supply chain · site selectionAI Correlates disparate location signals at scale — primarily forsupply-chain risk, market analysis, and infrastructure exposureWiz · Bitsight · ShadowDragon · Web Asha Technologies — 2026 OSINT practitioner guides

One practical framing worth holding onto across all six areas: the same category of technique that a security team uses to find their own organisation's exposure is what an attacker uses for reconnaissance. The discipline is the same. The target and the intent are what differ.

04

WHAT AI ADDS, MECHANISM BY MECHANISM

#

Scale

AI-assisted crawlers and monitoring tools process volumes of public data no manual process could keep pace with. This is the single biggest practical shift — turning what used to be periodic manual searches into continuous monitoring.

Pattern discovery across disconnected sources

Link-analysis tooling surfaces relationships between entities that would not be visible from any single source. Maltego-style platforms run automated transforms across 100+ data sources to map connections between infrastructure, domains, and threat actors — work that used to be manual graph-building.

Natural-language querying

Being able to ask a plain-language question against a large corpus of scraped public content, rather than constructing complex boolean search strings, has meaningfully lowered the skill floor for getting useful results from OSINT work.

Faster verification and corroboration

What used to require manually cross-checking multiple sources can now be partially automated. The corroboration step still requires human judgment — but the volume of sources that can be checked in parallel has changed significantly.

The contamination problem

AI-generated content is now a contaminant in the public data that OSINT tools search against. Search results increasingly include AI-generated material that needs its own verification, not just the original claim. This is a genuine, growing complication that does not yet have a clean solution.

05

ETHICAL AND LEGAL BOUNDARIES

#

Every credible source in this discipline treats legal and ethical boundaries as a stated, load-bearing part of the methodology — not an optional add-on. The following five principles are consistent across the practitioner literature.

Five core principles

1. Define clear objectives before collecting anything. Know specifically what question you are trying to answer and why. Open-ended collection — "let us see what we can find on this person or company" — is where ethical and legal problems start.

2. Respect platform terms of service and applicable privacy law. What is technically accessible is not automatically legal or appropriate to collect and use. This varies by jurisdiction and by what the information will be used for.

3. Corroborate before concluding. Multiple independent sources reduce false positives. A single, unverified public data point should never be the sole basis for a real decision — a hiring decision, a partnership, an accusation.

4. Individuals are a different category from organisations and infrastructure. Public-facing corporate information, published research, infrastructure exposure, and brand mentions are the legitimate core of business OSINT. Anything that starts to look like profiling a specific private individual — their movements, relationships, habits — requires a real, specific legal and ethical basis before proceeding.

5. The same techniques serve very different purposes depending on who uses them and why. Intent, authorisation, and defined scope matter as much as the technique itself.

The information is there either way. The question is whether you look before someone else does.

Recommended Reading

Michael Bazzell · IntelTechniques

The practitioner's handbook for OSINT: search operators, metadata extraction, social graph analysis, and investigative workflows.

Kevin Mitnick · Little, Brown and Company

The world's most famous hacker explains what data you leave behind and how adversaries collect it — essential threat-model reading.

Carlini & Wagner · ACM CCS 2017

Seminal paper showing that AI-based detection systems are themselves vulnerable to targeted manipulation — directly relevant to AI-augmented OSINT.

Continue the conversation

If this changed how you think about it — or you think I'm wrong — I want to know.

Corrections, disagreements, and applications all welcome. Replies go directly to Chris.

Get in touch →
Field Notes · PodcastHost + Expert · Gemini TTS

ALREADY PUBLIC

~6-8 min

1× · Two speakers · tap to play