Open Source Intelligence

Also known as:OSINT

Open Source Intelligence: Gathering and analyzing publicly available information for security assessments. The capability processes information regarding threats and attackers in an actionable manner. Its utility is determined by source assessment, context, timeliness, structured dissemination, and feedback into protective measures.

How it works and where it fits

Open Source Intelligence structures knowledge about potential adversaries, their objectives, capabilities, infrastructure, and observed behavior. Individual indicators are short-lived and easy to change, while behavioral patterns and technical relationships often have greater analytical value. Reporting should distinguish observed facts, assessments, and assumptions.

Practical security relevance

Practical use depends on source quality, timeliness, and relevance to the organization’s own attack surface. Information is prioritized, correlated with internal data, and converted into searches, detections, or safeguards. Investigation feedback continuously improves the assessment. Confidentiality and permitted sharing are as important as technical exchange formats.

  • ReconnaissanceReconnaissanceCollection of information regarding targets, systems, individuals, and attack surfaces.: Collection of information regarding targets, systems, individuals, and attack surfaces.
  • Cyber Threat IntelligenceCyber Threat IntelligenceProcessed information regarding threat actors, tactics, indicators, and risks.: Processed information regarding threat actors, tactics, indicators, and risks.
  • Threat ActorThreat ActorAn individual, group, or organization that intentionally carries out or supports cyberattacks.: An individual, group, or organization that intentionally carries out or supports cyberattacks.
  • External Attack Surface ManagementExternal Attack Surface ManagementIdentifies and monitors assets and risks accessible from the Internet.: Identifies and monitors assets and risks accessible from the Internet.