Skip to content
Aynitech Group

Intelligence one click away: OSINT

Make the most of the resources the internet offers

OSINT stands for Open-Source Intelligence, and it is one of the key aspects of understanding cybersecurity as it is practised today.

OSINT is essentially information gathered from public sources, such as those we find on the internet. The term is not strictly limited to the internet: it covers every publicly available source.

The key word behind the concept of OSINT is information — above all, information that can be obtained free of charge. It may come from newspapers, blogs, websites, tweets, social networks, images, podcasts or videos, as long as it is public, free and legal.

With the right information in hand, we can gain a real advantage over the competition, or speed up any investigation into the companies or people we are responsible for.

Many people associate OSINT with cyber warfare, cyber attacks and cybersecurity, among other things. Those topics are part of it, but OSINT is much more. These examples illustrate the idea:

Asking questions in any search engine.

Researching public forums on how to do something specific.

Watching a tutorial video on YouTube.

How can I use it?

Companies and individuals use OSINT constantly — though not necessarily consciously.

Sales, marketing and product management teams also use OSINT to increase conversions, or simply to be more effective while serving the public.

In the cybersecurity field, using the right tools for an OSINT investigation can be genuinely effective when combined with critical thinking and a clear strategy.

Whether you are running a cybersecurity investigation against a company or person, or you are on the other side working to identify and mitigate future threats, practising predefined OSINT techniques with clear objectives can save you a great deal of time.

OSINT techniques and resources

There are many OSINT techniques and mechanisms, but not all of them will work for your objective. First, you have to ask yourself a few questions:

What am I looking for?

What is the main objective of my investigation?

What, or who, is my target?

How am I going to carry out my investigation?

Once you find the answers to these questions you will have completed the first step of an OSINT investigation.

These are some of the most popular OSINT techniques in cybersecurity:

Collecting employees' full names, job roles and the software they use.

Reviewing and monitoring search engine information from Google (especially using Google Dorks), Bing, Yahoo and others.

Monitoring personal and corporate blogs, and reviewing user activity in digital forums.

Identifying every social network used by the target user or company.

Reviewing the content available on social networks such as Facebook, Twitter, Google Plus or LinkedIn.

Exploring old versions of websites to reveal important information, using sites such as the Wayback Machine.

Identifying mobile phone numbers and email addresses from social networks or Google results.

Searching for photographs and videos on common photo-sharing social sites such as Flickr, Google Photos and others.

Using Google Maps and other open satellite imagery sources to retrieve images of users' geographic locations.

Running port scanners against the target company's server infrastructure to find running services.

Using tools such as Shodan to search for internet-connected devices.

Whichever you use, once you have finished an OSINT investigation you will have a great deal of data to analyse. That is the point at which you have to refine the results, look in detail for everything you actually need and discard the rest.

Where do I start?

There are many OSINT tools on the web; simply searching for the term will give you access to them. One of the best-known websites, which collects several tools for the different kinds of search described above, is OsintFramework.com. That is the way in for anyone who wants to venture out and discover the power of information on the internet.

Looking for a partner that can build, power, and protect what comes next?

Tell us what you're building—product, project, or team—and we'll propose the fastest path to outcomes.