Sources span public websites, registries, social platforms, forums, code repositories, published documents, breach datasets circulating openly, commercial data products, and technical records such as DNS history or certificate transparency logs. “Open” describes lawful availability, not accuracy, consent to reuse, or absence of risk.
For defenders, OSINT supports threat intelligence, attack-surface discovery, brand and fraud monitoring, incident enrichment, and exposure assessment. The same methods serve attackers researching targets, so collection itself can create obligations — privacy, data-protection, employment, and platform terms all constrain what may be gathered and retained.
Key points
Collection disciplineDefine the requirement first, then collect with documented sources, timestamps, access methods, and confidence — indiscriminate hoarding creates legal exposure without analytic value.
VerificationPublic material may be staged, outdated, recycled, or fabricated; corroborate consequential findings across independent sources before acting.
Handling constraintsApply data-protection, privacy, and terms-of-service limits to collection, retention, and sharing — availability does not imply unrestricted lawful use.
Important limitationOSINT is evidence about what is publicly visible, not proof of internal state or intent. Findings may be incomplete, deliberately seeded, or legally usable only in limited ways, and “found nothing” is not evidence of absence.