# What is Open-Source Intelligence (OSINT)?

> Open-source intelligence is intelligence derived exclusively from publicly or commercially available information, collected and analyzed to answer specific requirements.

- Canonical URL: https://yellowcube.eu/glossary/open-source-intelligence/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Sources span public websites, registries, social platforms, forums, code repositories, published documents, breach datasets circulating openly, commercial data products, and technical records such as DNS history or certificate transparency logs. “Open” describes lawful availability, not accuracy, consent to reuse, or absence of risk.

For defenders, OSINT supports threat intelligence, attack-surface discovery, brand and fraud monitoring, incident enrichment, and exposure assessment. The same methods serve attackers researching targets, so collection itself can create obligations — privacy, data-protection, employment, and platform terms all constrain what may be gathered and retained.

### Key points

- **Collection discipline:** Define the requirement first, then collect with documented sources, timestamps, access methods, and confidence — indiscriminate hoarding creates legal exposure without analytic value.
- **Verification:** Public material may be staged, outdated, recycled, or fabricated; corroborate consequential findings across independent sources before acting.
- **Handling constraints:** Apply data-protection, privacy, and terms-of-service limits to collection, retention, and sharing — availability does not imply unrestricted lawful use.
- **Important limitation:** OSINT is evidence about what is publicly visible, not proof of internal state or intent. Findings may be incomplete, deliberately seeded, or legally usable only in limited ways, and “found nothing” is not evidence of absence.

### Related terms

[Cyber threat intelligence (CTI)](<https://yellowcube.eu/glossary/cyber-threat-intelligence/>) · [Threat intelligence platform (TIP)](<https://yellowcube.eu/glossary/threat-intelligence-platform/>) · [Threat intelligence feed](<https://yellowcube.eu/glossary/threat-intelligence-feed/>) · [Dark web](<https://yellowcube.eu/glossary/dark-web/>) · [Threat hunting](<https://yellowcube.eu/glossary/threat-hunting/>)

### Sources

[ODNI and CIA, The IC OSINT Strategy 2024–2026](https://www.dni.gov/index.php/newsroom/reports-publications/reports-publications-2024/3785-the-ic-osint-strategy-2024-2026) · [NIST SP 800-150, Guide to Cyber Threat Information Sharing](https://csrc.nist.gov/pubs/sp/800/150/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

