Lesson 01
What OSINT actually is — and what it is not
Open-source intelligence is the disciplined process of collecting information that is lawfully available to the public, checking it, and turning it into something a decision-maker can act on. The important word is process. Searching someone's name is not OSINT. Searching a name, recording where each result came from, testing whether the results describe the same person, and stating how confident you are — that is OSINT.
Public means anyone can reach it without breaking an access control: search engines, company registries, court listings, land records, news archives, public social posts, public code repositories, published breach summaries, satellite and street imagery, ship and flight trackers, and the metadata attached to files people publish themselves.
It is not hacking. It is not guessing a password, using someone else's credentials, buying stolen data, scraping a site in violation of the law that applies to you, or pretending to be a police officer, a bank or a lawyer to make someone hand information over. The moment you do any of those, you are not an analyst — you are a defendant, and everything you found becomes unusable.
OSINT also is not proof by itself. It produces leads and assessments. A name on a registration record tells you a name was used, not that the person behind that name did the thing you are investigating. Good analysts hold both truths at once: the data is real, and the conclusion drawn from it is a judgement that can be wrong.
Takeaway. OSINT is public collection plus verification plus a stated confidence level. Drop any of the three and it is just internet searching.
