Skip to main content
Glossary · Definition

OSINT (open-source intelligence)

OSINT, or open-source intelligence, is the collection and analysis of information from publicly available sources, such as news, social media, public records and websites, to answer a specific question or support a decision.

Last updated September 28, 2026

How OSINT works

OSINT is a method, not a data source. It starts with a question, for example who operates a set of accounts, whether a photo is from the event it claims, or where a rumor began. The analyst then collects material that anyone could in principle access, verifies it, and assembles it into a finding with a stated level of confidence.

Typical sources include news and broadcast coverage, social platforms, public company and property records, domain registration and hosting data, satellite and street imagery, court filings, and archived copies of web pages. The skill is less in finding any single item than in corroborating it. A claim supported by two independent public sources is treated differently from one that rests on a screenshot of unknown origin.

The standard workflow has four steps: define the question, collect from multiple sources, verify and cross-check, and report with sources and caveats. Collection at scale is done with tooling, and verification is usually done by an analyst.

Examples

A security team might use OSINT to check whether an event venue has public safety concerns before an executive travels. A comms team might trace a viral claim about the company to its first post. A threat analyst might link a set of impersonation accounts to shared infrastructure. Journalists and human-rights researchers use the same techniques to verify footage.

Why it matters to communications and risk teams

OSINT gives a team evidence it can act on and defend. Being able to say where a story began, who is spreading it and how the claim has been changing is more useful to leadership than a volume chart alone. It is also the base layer of threat intelligence and of the analysis behind information operations and coordinated inauthentic behavior reports.

Media and social coverage are a large share of the public information a comms team needs, which is why media monitoring is often the collection stage of an OSINT workflow.

Common misconceptions

Public does not mean unregulated. Privacy law, platform terms of service and ethical norms still apply, and collecting information about private individuals carries real obligations. Teams should have a policy on what they will and will not collect.

OSINT is also not the same as searching the web. Search is one collection tool. The discipline is the verification and analysis that follow, and the willingness to report that the evidence is inconclusive.

Finally, information being available does not make it accurate. Public sources include manipulated media and planted material, so verification is not optional.

Tools help with scale but not judgment. Automated collection can gather thousands of posts in minutes, yet decisions about which are relevant, which are authentic and which conclusions the evidence supports remain analytic work. Good reports record the sources used, the date each was captured, and what could not be confirmed, so that another analyst can reproduce the finding.

See how these signals show up in your own coverage on the PeakMetrics platform or run the free AI Perceptions check. Back to the glossary.

Track these signals in your own coverage.

PeakMetrics follows news, social and broadcast sources, and what AI assistants say about your organization.