What is OSINT (Open-Source Intelligence)? Definition & tools
OSINT (Open-Source Intelligence) is the collection and analysis of information from publicly available sources, such as websites, social media, public records, and metadata, to produce actionable intelligence.
OSINT is intelligence built entirely from sources anyone can legally access, no hacking required. In cybersecurity it is the foundation of reconnaissance: before attacking or defending a target, you learn everything that is already exposed about it.
What sources does OSINT use?
- Websites, job postings, and company filings.
- Social media profiles and posts.
- DNS records, WHOIS data, and certificate transparency logs.
- Code repositories, leaked credential dumps, and document metadata.
- Search engines and specialized data aggregators.
Common OSINT tools and techniques
Practitioners pivot across data points to map a target's people, infrastructure, and exposure. Common tools include theHarvester for emails and subdomains, Maltego for link analysis, Shodan for internet-connected devices, Amass for attack-surface mapping, and Google dorking for advanced search queries.
How OSINT fits into security work
OSINT feeds the reconnaissance stage of penetration testing and red teaming, supports DFIR investigations and threat intelligence, and helps defenders understand their own external attack surface. It must always be performed legally and ethically, respecting privacy and terms of service.
How to practice OSINT hands-on
On Purple Edge the osint learning hub guides you through realistic reconnaissance scenarios, where you collect and pivot on public data to profile a target the way an attacker or investigator would.
Practice this in the Learn Open-Source Intelligence (OSINT) learning path.
Put this into practice
Spin up real Kali, Ubuntu and Windows labs in your browser and learn by doing. Guided, hands-on, no setup.
Last updated: 2026-06-16