What OSINT Is and Is Not
Defines lawful OSINT, separates raw information from intelligence, and sets the boundaries for safe public-source research.
A practical field-reference edition of the Aldermere OSINT method. This page summarises the handbook structure, chapters, and appendices for readers who want a compact, usable guide to lawful research, source checking, evidence handling, verification, reporting discipline, and defensive OSINT workflows.
Defines lawful OSINT, separates raw information from intelligence, and sets the boundaries for safe public-source research.
Explains proportionality, consent, minimisation, redaction, and why publicly visible information still needs careful handling.
Builds disciplined habits: clear questions, controlled assumptions, source records, confidence language, and stopping when the task is answered.
Outlines a clean research workspace for notes, screenshots, evidence folders, browser hygiene, and repeatable case structure.
Shows how to record source links, capture dates, screenshots, uncertainty, and evidence cards so findings remain auditable.
Introduces deliberate search planning, query refinement, date awareness, source comparison, and avoiding tool-first wandering.
Teaches how to assess source type, motive, age, repetition, corroboration, and the limits of what a source can prove.
Explains careful attribution, entity separation, name-match risk, relationship clues, and avoiding premature identity claims.
Turns objectives into a controlled plan covering scope, exclusions, sources, risks, outputs, and stopping points.
Walks through a small end-to-end investigation from question to evidence capture, confidence statement, and short report.
Builds staged search queries and records what was searched, where it was searched, and why each result mattered.
Uses news, cached pages, and archives as dated snapshots, preserving context before relying on excerpts or screenshots.
Works with official registers while separating legal existence, public record details, update dates, and real-world control.
Checks specialist material for authority, age, narrowness, measurement, evidence, opinion, and speculation.
Maps company and domain clues as relationships requiring corroboration across records, websites, domain data, and public statements.
Handles social material as volatile context and avoids identity conclusions from one platform clue.
Treats community sources as leads requiring verification because rumours, repetition, and partial context can mislead.
Sets scoped monitoring terms, review cadence, and stop rules so alerts do not become uncontrolled collection.
Creates controlled source maps with source type, reliability, update rhythm, relevance, and reuse limits.
Demonstrates a repeatable search trail from question to evidence to finding, focused on discipline rather than volume.
Starts people-related research with legitimate purpose, written scope, sensitivity, consent where needed, and a stop condition.
Treats username overlap as a clue, checking dates, context, self-declared links, and independent corroboration.
Analyses public contact clues without testing private access, sending probes, or assuming shared details prove identity.
Maps organisations as brands, roles, domains, records, departments, and public statements without overclaiming ownership or control.
Separates registered roles, beneficial ownership, employment, influence, and public representation in company records.
Uses job posts and public process artefacts as dated clues about tools, hiring, workflow, and exposure.
Describes visible interactions and repeated signals while avoiding assumptions about motive, coordination, or hidden relationships.
Preserves and compares public warning signs as indicators, not verdicts, using official routes and cautious escalation.
Keeps ambiguous matches explicit by separating rejected, unclear, plausible, probable, and confirmed claims.
Shows a defensible entity investigation from scope to sources, confidence, limitations, and cautious final finding.
Uses reverse image search as discovery while recording image source, capture timing, earlier copies, and reuse context.
Handles metadata as context that may be stripped, altered, or misleading and preserves originals before analysis.
Builds geolocation through independent visible clues, separating observed facts from candidate-location inferences.
Compares map, satellite, street-level, and local-photo evidence while recognising age and feature limitations.
Uses environmental clues to support time and place analysis while guarding against seasons, edits, and weak assumptions.
Reads vehicles, buildings, signage, scripts, and local markers as context-dependent clues requiring corroboration.
Preserves original video, extracts representative frames, and checks upload context, audio, continuity, and visual clues.
Matches media to the correct event, time, place, and narrative while detecting old footage and misleading captions.
Reports claims, clues, comparison sources, confidence, and limitations without exposing unnecessary private-location details.
Demonstrates the trail from image to map comparison to a proportionate, sourced, uncertainty-aware location finding.
Shows how clues become findings only after testing, sourcing, context, restrained wording, and separation of observation from inference.
Uses entity graphs as analytical aids with sourced nodes, labelled edges, confidence levels, and limits.
Separates event time, publication time, and capture time so sequence, gaps, contradictions, and uncertainty are visible.
Matches wording to evidence strength so reports do not imply certainty where only possibility or probability is supported.
Actively looks for ways a conclusion could be wrong and considers benign explanations before suspicious ones.
Builds readable, sourced, proportionate reports with evidence packs that allow significant claims to be traced.
Treats redaction as part of analysis, removing unnecessary personal data while preserving original evidence securely.
Uses automation for monitoring and organisation only with logs, human review, scope limits, and stop conditions.
Checks analytical logic, citations, confidence language, redaction, sensitivity, and release readiness before sharing.
Combines scope, evidence, analysis, report structure, limitations, and release decision into a complete case example.
Uses defensive OSINT to reduce personal exposure without creating a dossier, prioritising practical risk reduction.
Reviews family and small-business exposure with extra restraint, consent, role separation, mitigation, and safe reporting.
Triages suspicious claims, preserves evidence, compares official routes, avoids risky engagement, and escalates credible risk.
Builds recurring defensive checks for brands, domains, impersonation, change, and exposure without uncontrolled alerts.
Captures and preserves incident evidence calmly before removal, with controlled redaction, escalation, and handover.
Sets scope, ownership, communication, evidence handling, review, and handover so outputs remain traceable and safe.
Defines legal and ethical stop points when authority, necessity, proportionality, sensitivity, or safety is unclear.
Maintains tool reliability and repeatability by documenting source changes, tool changes, workflow updates, and intervals.
Turns practice into repeatable playbooks with scope, evidence rules, review points, outputs, and stop conditions.
Brings collection, evidence, analysis, redaction, reporting, and review together for an exposure-reduction operation.
Plain-English definitions for key OSINT, evidence, reporting, and safety terms used throughout the handbook.
A field checklist for purpose, scope, lawful sources, evidence handling, personal-data minimisation, and escalation.
A scoring guide for assessing source authority, age, corroboration, motive, and limits before relying on a source.
Suggested wording for confirmed, likely, possible, unclear, unsupported, and contradictory findings.
A release-safety checklist for masking unnecessary personal details while keeping evidence understandable.
A structured report outline for scope, sources, findings, confidence, limitations, recommendations, and evidence packs.
A non-product-specific index of tool categories for search, archives, domains, images, maps, capture, and reporting.
A quick reference to the handbook’s visual workflows, checklists, maps, and evidence-handling diagrams.
A pre-release quality check for traceability, wording, redaction, privacy, proportionality, and audience suitability.