PILLAR · 01

    OSINT applied to security

    OSINT is not Googling. It is an intelligence method that gathers, verifies and contextualises publicly available information to anticipate risks affecting people, organisations and infrastructure. This page collects what a veteran analyst should have clear before applying it to operational security.

    01

    What OSINT is (and is not)

    OSINT (Open Source Intelligence) is the disciplined process of turning scattered public information into actionable intelligence. The raw material is within anyone's reach; value lies in method.

    It is not hacking. It does not access private systems or break authentication. It is not journalism. It does not sell narrative; it sells verified hypotheses. It is not blind mass scraping.

    03

    Four-phase methodology

    Observation. Define scope, subjects, time window and operational questions. No question, no analysis.

    Collection. Collect without polluting the trace. Primary sources before aggregators. Time-stamped capture.

    Verification. Cross-check at least two independent sources. Date every datum. Mark confidence level.

    Synthesis. Document hypotheses, indicators and gaps. Measured recommendations, not alarms.

    04

    Families of sources

    Official registries (corporate, tax, public judicial). Technical bases (DNS, certificates, ASN, geolocation). Professional networks and publications. Media and historical archive. Open institutional data. Publicly verifiable leaks consultable without unlawful access.

    Each family has a bias. Knowing the bias is part of the analysis.

    05

    OSINT audit for an organisation

    Digital footprint inventory (domains, subdomains, corporate profiles, executives, exposed suppliers). Exposure map (what can be inferred without entering). Resulting social engineering vectors. Recommendations prioritised by impact and cost of correction.

    The useful deliverable is not a long PDF: it is a decision sheet.

    06

    Application to executive protection

    Prior work to a security detail: what public information allows anticipating threats, what life patterns are visible without intent, what family and entourage exposure should be reduced.

    Well-executed OSINT reduces required physical surveillance. It does not replace it.

    07

    Common mistakes I see in the market

    Mistaking volume for value. Citing unverified sources. Mixing opinion with analysis. Selling alarm. Recycling screenshots without context. Using tools as if they were methodology.

    A responsible analyst removes noise, does not amplify it.

    08

    OSINT with AI assistance

    Models accelerate classification, translation and normalisation. They do not verify. Chain of custody and judgment remain human.

    I work with AI as support, never as a source.

    Frequently asked questions

    Is OSINT legal in Spain?+

    Yes, as long as it is limited to publicly accessible sources, respects GDPR/LOPDGDD and pursues a legitimate and proportionate purpose. Accessing non-public or protected information falls outside OSINT.

    How is OSINT different from a private investigation?+

    OSINT is an intelligence discipline based on open sources, with method and traceability. A private investigation may use OSINT as one of its techniques, alongside other regulated private-security methods.

    How long does a corporate OSINT audit take?+

    A first exposure map can be delivered in days; a full audit with cross-verification and prioritised recommendations takes weeks, depending on perimeter.

    What deliverable do I get?+

    An executive report with findings, hypotheses, confidence level and prioritised recommendations. Plus an operational decision sheet for the security lead.

    Related notebook entries

    Work with Zero101OSINT on a real case

    Every OSINT engagement is evaluated individually. If your organisation needs an exposure map or an audit with judgment, write.