What OSINT Is and Is Not
Defines lawful open-source intelligence, separates information from intelligence, and establishes scope, confidence language, and responsible use boundaries.
A professional six-volume open-source intelligence reference library for people who need to search, verify, record, and report public information with discipline. The OSINT Bible gives readers a structured method for lawful research: defining scope, judging source reliability, handling evidence, mapping entities, checking images and locations, writing clear findings, redacting sensitive details, and building defensive OSINT workflows that can be used in real investigations, due diligence, fraud checks, safety reviews, and professional reporting.
Defines lawful open-source intelligence, separates information from intelligence, and establishes scope, confidence language, and responsible use boundaries.
Explains why legal access is not always ethical use, with rules for consent, proportionality, minimisation, redaction, and safe sharing.
Builds the operating habits of clear questions, controlled assumptions, source discipline, cautious confidence, and knowing when to stop.
Sets up a clean research environment for notes, evidence, screenshots, browser hygiene, file naming, and repeatable investigation structure.
Shows how to preserve what was found, where it came from, when it was captured, and how it supports or limits a finding.
Introduces deliberate search planning, query refinement, source comparison, date awareness, and avoiding tool-first wandering.
Teaches source assessment: primary versus repeated information, reliability, motive, age, context, corroboration, and uncertainty.
Introduces careful attribution, entity separation, name-match risk, and the difference between clues, relationships, and proof.
Turns the foundations into a controlled workflow covering objective, scope, exclusions, sources, risks, outputs, and stopping points.
Walks through a contained beginner investigation from question to source capture, verification, confidence statement, and short report.
Builds staged search queries and records what was searched, where it was searched, and why each result mattered.
Treats news and archives as dated snapshots, preserving context before relying on excerpts, screenshots, or old material.
Uses official registers carefully while separating legal existence, public record details, update dates, and real-world control.
Checks technical and specialist sources for authority, age, narrowness, evidence, opinion, measurement, and speculation.
Maps company and domain clues as relationships requiring corroboration across records, websites, domain data, and public statements.
Uses volatile social material cautiously, capturing visible context and avoiding identity conclusions from a single platform clue.
Treats community sources as leads requiring verification, not final proof, because rumours and repeated claims can distort context.
Sets scoped monitoring terms, review cadence, and stop rules so alerts do not become uncontrolled collection or mission creep.
Creates controlled source maps with source type, reliability, update rhythm, relevance, and reuse limits instead of loose bookmarks.
Demonstrates a repeatable search trail from question to evidence to finding, focused on discipline rather than search volume.
Starts people-related research with legitimate purpose, written scope, consent where needed, sensitivity, and a stop condition.
Treats username overlap as a clue, checking context, dates, self-declared links, and corroboration before any identity claim.
Analyses public contact clues without testing private access, sending probes, or assuming shared details prove personal identity.
Maps organisations as brands, departments, roles, domains, records, and public statements without overclaiming ownership or control.
Separates registered roles, beneficial ownership, employment, influence, and public representation when interpreting company records.
Uses job posts and public process artefacts as dated clues about workflows, tools, hiring, and exposure without treating marketing text as proof.
Describes visible interaction patterns, repeated signals, and clusters while avoiding assumptions about motive, coordination, or hidden relationships.
Preserves and compares public warning signs as indicators, not verdicts, using official channels and careful escalation.
Keeps ambiguous matches explicit, separating rejected, unclear, plausible, probable, and confirmed rather than forcing a narrative.
Shows a defensible entity investigation from scope to sources, confidence, limitations, and a cautious final finding.
Uses reverse image search as discovery, recording where an image was found, capture timing, earlier copies, and reuse context.
Handles metadata as context that may be stripped, altered, or misleading, preserving originals before analysis or sharing.
Builds geolocation through independent visible clues, separating observed facts from candidate-location inferences.
Compares map, satellite, street-level, and local-photo evidence while recognising age limits and feature mismatches.
Uses environmental clues to support time and place analysis while guarding against seasons, edits, time zones, and weak assumptions.
Reads transport, architecture, signage, scripts, and local markers as context-dependent clues requiring corroboration.
Preserves original video, extracts representative frames, and checks upload context, visual clues, audio hints, and continuity.
Matches media to the correct event, time, place, and narrative while detecting old footage, partial clips, and misleading captions.
Reports the claim, clues, comparison sources, confidence, and limitations without exposing unnecessary private-location details.
Demonstrates the trail from image to map comparison to proportionate, sourced, uncertainty-aware location finding.
Shows how a clue becomes a finding only after testing, sourcing, context, restrained wording, and separation of observation from inference.
Uses entity graphs as analytical aids with sourced nodes, labelled edges, confidence levels, and limits rather than proof by diagram.
Separates event time, publication time, and capture time so sequence, gaps, contradiction, and uncertainty are visible.
Matches wording to evidence strength so reports do not imply certainty where only possibility or probability is supported.
Actively looks for ways a conclusion could be wrong and considers benign explanations before suspicious ones.
Builds readable, sourced, proportionate reports with evidence packs that allow significant statements to be traced.
Treats redaction as part of analysis, removing unnecessary personal data while preserving original evidence securely.
Uses automation for monitoring and organisation only with logs, human review, scope limits, and stop conditions.
Checks analytical logic, citations, confidence language, redaction, sensitivity, and release readiness before sharing a report.
Combines scope, evidence, analysis, report structure, limitations, and release decision into a complete investigation example.
Uses defensive OSINT to reduce personal exposure without creating a dossier, prioritising practical risk reduction and review cycles.
Reviews household and small-business exposure with extra restraint, consent, role separation, mitigation actions, and safe reporting.
Triages suspicious claims, preserves evidence, compares official routes, avoids risky engagement, and escalates credible risk safely.
Builds recurring defensive checks for brands, domains, impersonation, change, and exposure without uncontrolled alerts or panic.
Captures and preserves incident evidence calmly before removal, with controlled redaction, escalation, and handover.
Sets scope, ownership, review, communication, evidence handling, and handover so team outputs remain traceable and safe.
Defines legal and ethical stop points when authority, necessity, proportionality, sensitivity, or safety is unclear.
Maintains tool reliability and repeatability by documenting source changes, tool changes, workflow updates, and review intervals.
Turns practice into repeatable playbooks with scope, evidence rules, review points, outputs, and stop conditions.
Brings collection, evidence, analysis, redaction, reporting, and review together for an exposure-reduction operation.