OSINT: Reconnaissance from Open Sources
Before a single packet touches a target, a skilled adversary already knows the shape of it — the domains, the people, the leaked passwords, the software versions. Open-source intelligence turns scattered public data into a coherent picture of exposure, and doing it well is as much about discipline as it is about tooling.
Open-source intelligence — OSINT — is the practice of collecting and analysing information from publicly available sources to build knowledge about a target. In an offensive engagement it is the quiet first phase: no exploits, no alerts, just careful reading of what an organisation has, often unknowingly, left in the open. The reason it matters is simple. Attackers begin here, so defenders and testers must too. The map you build from public sources determines every decision that follows, from which subdomain to probe first to which employee makes the most plausible phishing target.
Passive by design
The defining trait of true reconnaissance from open sources is that it is passive: the collection never touches the target's own infrastructure. Querying a certificate transparency log, reading a public GitHub repository, or browsing a LinkedIn profile leaves no trace in the target's logs, because those requests go to third parties. This is what makes OSINT so attractive to an attacker and so useful to a tester modelling an external threat — a great deal of an organisation's attack surface can be mapped without ever announcing your presence.
The line matters. The moment you resolve a discovered hostname against the target's own DNS server, port-scan an IP, or authenticate to a portal, you have crossed from passive into active reconnaissance, and you may generate log entries or alerts. Knowing exactly where that line sits — and staying on the passive side until scope permits otherwise — is a core skill.
The source categories that matter
Public information falls into a handful of durable categories, each answering a different question about the target.
Infrastructure: DNS and certificates
DNS records, WHOIS data, and certificate transparency logs reveal the shape of an organisation's estate. A single wildcard certificate can leak the naming convention for an internal environment; CT logs frequently expose staging, dev, and admin subdomains that were never meant to be found. This is often the richest starting point because it is factual, structured, and continuously published.
People: social media and public records
Employees are part of the attack surface. Job titles, reporting lines, tools mentioned in posts, and conference talks all reveal how an organisation is structured and what technology it runs. A job advertisement asking for experience with a specific firewall or EDR product tells an attacker precisely what defences to expect.
Exposure: breach data and public code
Historical breach corpora expose which corporate email addresses have appeared in third-party compromises and, sometimes, the passwords associated with them — the raw material for credential-stuffing. Public code repositories are a recurring source of accidental disclosure: hard-coded API keys, internal hostnames, and connection strings committed and never fully purged from history.
Documents: metadata
Files an organisation publishes carry metadata. A PDF or Office document can embed the author's username, the internal file path, and the software version used to create it — small facts that, aggregated, reveal naming conventions and software estates.
Pivoting is where the value lives
Any single data point is usually weak. The craft of OSINT is pivoting — using one discovered fact to unlock the next, and correlating across sources until a picture emerges that no individual source contained. A username found in document metadata becomes a search term across code repositories; a matching commit exposes an internal hostname; that hostname appears in a certificate log alongside a dozen siblings; one of those siblings maps to an email format that lines up with a breach dataset. None of these facts is dramatic on its own. Chained together, they describe a credible path in.
OSINT rarely hands you a finished answer. It hands you fragments — and the discipline is in connecting them faithfully, without inventing the links you wish were there.
This is also where rigour matters most. Correlation invites false positives: two people share a name, an old record describes infrastructure long since retired, a leaked password was changed years ago. Enrichment — validating and dating each fact before it earns a place in the profile — is what separates intelligence from a pile of coincidences.
Operational security for the tester
Reconnaissance runs in both directions. While you study a target, your own activity can be observed — and a tester who is careless about operational security leaks method, intent, and sometimes identity. Searches, account interactions, and document downloads can all be attributable. Viewing a LinkedIn profile can notify its owner. Cloning a repository, downloading a file, or resolving a hostname against infrastructure you do not control may be logged by a third party who later cooperates with the target.
Good practice is to separate research identity from personal identity, to prefer sources that do not notify their subjects, and to keep meticulous notes on where each fact came from and when it was true. That provenance is not bureaucratic overhead — it is what makes the eventual report defensible and reproducible. It also keeps the engagement lawful and in-scope, which is the non-negotiable frame around all of this work.
Turning collection into defence
For a defender, the same funnel is a to-do list. Every category an attacker mines is one you can audit yourself: enumerate your own subdomains and certificates, monitor breach datasets for your domains, scan your public repositories for secrets, and strip metadata from documents before publishing. The most effective OSINT programme inside an organisation is the one that runs continuously against itself, closing exposure before an outsider finds it. Frameworks such as the reconnaissance tactics catalogued by MITRE ATT&CK give a useful checklist of what adversaries look for.
Key takeaways
- OSINT is passive by design — collection touches third parties, not the target, and leaves no trace in their logs.
- Know exactly where passive ends and active reconnaissance begins, and stay on the passive side until scope allows more.
- The value is in pivoting and correlation, not in any single source — weak signals combine into strong ones.
- Enrich and date every fact; correlation without validation produces confident nonsense.
- Mind your own operational security, and run the same funnel against yourself to shrink your exposure first.