Open-source intelligence, commonly known as OSINT, is intelligence produced by collecting, verifying and analysing information that is publicly available or lawfully accessible.
That definition contains an important distinction. OSINT is not simply information found online. Search results, company records, news reports, social media posts, satellite images and vessel movements are sources of information. They become intelligence only when they are assessed in relation to a specific question and turned into findings that can support a decision.
The value of OSINT therefore lies less in finding information than in determining:
- Whether the information is authentic
- Whether it relates to the correct person, company, vessel or event
- Whether it is current and complete
- Whether independent sources corroborate it
- What conclusions the available evidence supports
- What remains unknown or uncertain
- What the findings mean for the decision at hand
A professional OSINT investigation brings these elements together through a structured, documented and proportionate process.
What does OSINT stand for?
OSINT stands for open-source intelligence.
The word “open” refers to the accessibility of the source. It does not mean that every source is free, easy to find or available through an ordinary web search.
Open sources can include:
- Government and regulatory records
- Corporate registries and statutory filings
- Court records and legal notices
- Sanctions and enforcement data
- News archives and specialist publications
- Company websites and historical web pages
- Social media and other online platforms
- Maps, satellite imagery and geospatial data
- Vessel and aircraft tracking information
- Domain registration and technical infrastructure records
- Academic research, trade publications and industry reports
- Commercial databases containing lawfully obtained information
Some sources are freely available. Others require registration, a subscription or payment of an access fee. What matters is that the investigator is entitled to access and use the information for a lawful purpose.
OSINT does not include hacking, unlawful access, impersonation, pretexting or the acquisition of information through deception. Professional investigations must operate within clear legal and ethical boundaries.
Public information is not the same as intelligence
The internet contains an enormous quantity of information, but volume should not be mistaken for insight.
A search for a company director might return hundreds of results. Some may concern another person with the same name. Others may repeat an inaccurate claim first published years earlier. Corporate databases may reproduce outdated filings. Social media accounts may be misidentified, fabricated or taken out of context.
Presenting those results as a list would amount to information collection. It would not, by itself, constitute intelligence.
To produce intelligence, an investigator must determine which information is relevant, reliable and material to the question being examined. This requires source evaluation, identity resolution, corroboration and analysis.
Consider a company conducting due diligence on a prospective business partner. A database search might identify several companies associated with one of its directors. A proper investigation would go further by asking:
- Is this the same individual?
- What role did the person hold in each company?
- When did those appointments begin and end?
- Were any of the companies dissolved, sanctioned or involved in litigation?
- Do the entities share addresses, directors, shareholders or service providers?
- Is there evidence of continuing control after a formal resignation?
- Are apparent connections meaningful, or merely administrative?
- Does the network create a material legal, financial or reputational risk?
The difference lies in the discipline applied to the evidence and the relevance of the conclusions to the client’s decision.
What can OSINT investigations be used for?
OSINT can support decisions across corporate intelligence, legal disputes, compliance, fraud, security, maritime operations and reputational risk.
Corporate due diligence
An investigation can help establish who owns, controls and operates a business. It may examine corporate history, directors, shareholders, beneficial ownership, related entities, litigation, regulatory action, adverse media and indications of undisclosed risk.
This can support decisions involving acquisitions, investments, partnerships, suppliers, distributors, customers or senior appointments.
Beneficial ownership investigations
Formal ownership records do not always reveal who exercises effective control.
Investigators may need to compare filings across several jurisdictions, identify recurring directors or addresses, trace changes in shareholding, examine trust or nominee arrangements and assess links between companies that appear separate on paper.
The objective is not merely to draw an ownership chart. It is to develop the most defensible assessment possible of who controls an entity and where uncertainty remains.
Fraud and asset investigations
Open sources can help identify corporate interests, property connections, business relationships, online activity and inconsistencies between declared circumstances and observable behaviour.
Such findings may support litigation, enforcement, recovery or internal investigations. They must be handled carefully, particularly where personal data or allegations of wrongdoing are involved.
Sanctions and supply-chain risk
Sanctions exposure does not always arise through a direct match against a sanctions list. Risk may be concealed through layered ownership, intermediaries, changes of control, opaque payment structures or entities operating on behalf of designated parties.
OSINT can help investigate these relationships, place them in context and identify areas requiring enhanced due diligence.
Maritime intelligence
Maritime investigations can combine vessel registration, ownership, management, flag history, port calls, movement data, sanctions information and corporate records.
This may help assess vessel ownership, trading patterns, deceptive shipping practices, disputed movements or potential connections to higher-risk networks.
Vessel tracking data must be treated with care. An unusual movement, transmission gap or identity change may justify further investigation, but it is not proof of misconduct. Technical limitations, poor reception, equipment problems and legitimate operational factors must also be considered.
Verification of claims, images and events
OSINT techniques can be used to assess whether an image, video, document or online claim is genuine and correctly described.
This may involve examining provenance, identifying the earliest known source, comparing visible landmarks, assessing environmental conditions, reviewing metadata where available and testing the material against independent evidence.
The objective is not simply to decide whether content “looks real”. It is to establish what can be verified, what has been inferred and what remains unresolved.
How does an OSINT investigation begin?
A strong investigation begins with a defined intelligence requirement.
This is the question the work is intended to answer. It should be specific enough to guide collection, but not so narrow that it assumes the conclusion.
“Find everything about this company” is not a useful intelligence requirement. It provides no clear standard for relevance or completion.
Better questions might include:
- Who ultimately owns and controls this company?
- Is the proposed counterparty connected to a sanctioned person or entity?
- Are the management team’s stated professional histories supported by public records?
- What evidence supports or contradicts the allegation?
- Does this vessel’s ownership and movement history indicate heightened sanctions risk?
- What material risks should be understood before entering the transaction?
The intelligence requirement determines which sources are proportionate, which jurisdictions must be examined and how findings should be presented.
It also prevents an investigation from becoming an unrestricted search for potentially damaging information. Professional OSINT should be purposeful, relevant and proportionate to the decision it supports.
The OSINT investigation process
Although every investigation is different, professional OSINT work usually follows a structured sequence.
1. Define the question
The investigator clarifies the decision, subjects, jurisdictions, timeframe and relevant risk thresholds.
Ambiguities should be identified at the outset. A trading name may refer to several legal entities. A person may have a common name or multiple transliterations. A vessel may have changed its name, flag or registered owner.
These issues affect how the investigation should be designed.
2. Establish known facts
Before searching widely, the investigator creates a baseline using reliable identifiers.
Depending on the subject, these may include:
- Full legal names
- Dates of birth
- Company registration numbers
- Registered addresses
- Previous names
- Directorship dates
- Vessel IMO numbers
- Domain names
- Email addresses
- Relevant jurisdictions
Strong identifiers reduce the risk of combining records that concern different subjects.
3. Develop a collection plan
The investigator determines which sources are most likely to answer the intelligence requirement.
Primary records usually take precedence over commentary or aggregated data. However, no single source should automatically be treated as complete or infallible.
The collection plan should account for language, jurisdiction, record availability, historical changes and the limitations of each source.
4. Collect and preserve information
Relevant records are gathered systematically and documented with their source, access date and context.
Material web pages or documents may need to be preserved because online information can be changed or removed. A clear evidence trail allows another reviewer to understand how a finding was reached.
5. Verify and corroborate
The investigator tests important findings against independent sources.
This stage may identify inconsistencies in names, dates, addresses, ownership records or reported events. Conflicts should be examined, not quietly removed from the analysis.
Corroboration is especially important when a finding could affect a person’s reputation, a transaction or a legal decision.
6. Analyse competing explanations
Evidence rarely speaks for itself. Investigators must consider what different findings could mean and whether reasonable alternative explanations exist.
For example, several companies using the same address might indicate common control. It might also reflect the use of a large corporate services provider. An unexplained gap in vessel transmissions might be suspicious, but it could also result from technical or coverage limitations.
Good analysis tests these alternatives before reaching a conclusion.
7. Assess confidence and information gaps
Conclusions should reflect the strength of the available evidence.
Where sources are incomplete, contradictory or difficult to verify, the report should say so. Confidence should never be presented more strongly than the evidence permits.
Material gaps may also guide further investigation. In some cases, the most valuable result is identifying precisely what cannot be established from open sources.
8. Report the findings
The final report should answer the original question clearly.
It should distinguish between:
- Verified facts
- Analytical assessments
- Unverified claims
- Reasonable inferences
- Information gaps
- Recommended next steps
A decision-maker should not have to reconstruct the investigation from a collection of screenshots or database results. The purpose of the report is to explain what the evidence means and why it matters.
How are OSINT sources assessed?
A source should not be considered reliable simply because it appears official, professional or widely repeated.
Professional investigators assess sources according to their origin, purpose, proximity to the event, date, consistency and susceptibility to error or manipulation.
Relevant questions include:
- Who created the information?
- How would the source know it?
- Was the source recording a fact directly or repeating another account?
- When was the information created and last updated?
- Does the source have a reason to omit, exaggerate or misrepresent information?
- Can the underlying record be examined?
- Do independent sources support the same conclusion?
- Are there material contradictions?
- Could the information concern a different person, company, vessel or event?
These questions help distinguish strong evidence from information that is merely plausible.
Primary and secondary sources
A primary source is generally a record produced by a person, organisation or system directly connected to the information being examined.
Examples may include:
- A statutory corporate filing
- A court judgment
- A regulatory notice
- A sanctions designation
- A property record
- A vessel registry entry
- A company’s published accounts
- An original social media post
- A contemporaneous photograph or video
- An archived version of a website
Secondary sources interpret, summarise or report information from elsewhere. They may include news articles, research reports, commercial databases and industry analysis.
Primary sources are often preferable, but they are not automatically correct. Corporate filings can be inaccurate, incomplete or outdated. Official records may reflect information supplied by the subject rather than independently verified facts. Registers can also differ in their quality, accessibility and enforcement standards.
Secondary sources can provide essential context, expose inconsistencies and direct an investigator towards records that would otherwise be difficult to locate.
The objective is not to rely exclusively on one type of source. It is to understand what each source can prove and where its limitations begin.
Corroboration and source independence
Corroboration means testing a finding against additional evidence.
The number of sources is less important than their independence. Five websites repeating the same original article do not provide five separate confirmations. They provide one claim reproduced in five places.
An investigator must trace information back to its earliest available source and determine whether apparently separate reports rely on the same underlying material.
Strong corroboration may come from records created independently for different purposes. For example, a corporate filing, a court document and an archived company website may collectively support a finding more convincingly than several databases drawing from the same registry.
Corroboration can also reveal disagreement. When reliable sources conflict, the investigation should explain the discrepancy and assess which account is better supported.
Conflicting evidence should not be treated as an inconvenience. It is often central to understanding the subject.
Identity resolution
One of the most important parts of an OSINT investigation is establishing that a record relates to the correct subject.
Names are rarely sufficient on their own. Different people may share the same name, while one person may appear under several spellings, aliases, transliterations or former names.
Company names can create similar problems. A trading name may be used by several legal entities. A group may contain subsidiaries with nearly identical names. A dissolved company may later be replaced by another entity using the same brand.
Investigators use combinations of identifiers to resolve identity, such as:
- Full name and date of birth
- Residential or business address
- Employment history
- Director identification details
- Company registration number
- Known associates
- Email address
- Telephone number
- Domain registration details
- Vessel IMO number
- Historical names and jurisdictions
The standard should be proportional to the consequence of the finding. A low-risk lead may justify further research. A serious allegation requires a much higher level of certainty before it can be attributed to a named person or organisation.
Fact, inference and assessment
A credible intelligence report separates what is known from what is assessed.
A fact is supported directly by evidence. An inference is a conclusion drawn from one or more facts. An assessment considers the evidence, its limitations and reasonable alternative explanations.
For example:
Fact: Two companies were registered at the same address during the same period.
Inference: The companies may have used the same service provider or may have been operationally connected.
Assessment: The shared address alone does not establish common control. However, the address, combined with overlapping directors, matching contact details and coordinated ownership changes, provides stronger evidence of a relationship.
This separation helps the reader understand how far the evidence goes. It also prevents an analytical judgement from being presented as an established fact.
How should confidence be expressed?
Intelligence conclusions should be accompanied by a level of confidence that reflects the quality, consistency and completeness of the evidence.
A practical framework might use three levels.
High confidence
The conclusion is supported by multiple reliable and independent sources. There are no significant contradictions, and alternative explanations are unlikely.
High confidence does not mean absolute certainty. It means that the available evidence strongly supports the conclusion.
Moderate confidence
The conclusion is supported by credible evidence, but important gaps, source limitations or reasonable alternative explanations remain.
Further investigation may strengthen or weaken the assessment.
Low confidence
The conclusion is based on limited, indirect or difficult-to-verify information. Significant gaps or competing explanations remain.
Low-confidence findings may still be useful as leads, but they should not be treated as established conclusions.
Confidence relates to the strength of the evidence, not the confidence or seniority of the analyst. It should be explained, not merely labelled.
What are the limitations of OSINT?
OSINT can answer a wide range of questions, but it cannot answer every question.
Understanding its limitations is part of conducting an effective investigation.
Public records may be incomplete
Not every jurisdiction publishes the same information. Some corporate registries provide detailed ownership records, while others disclose very little. Records may be delayed, inconsistently maintained or available only in local languages.
The absence of a public record does not necessarily mean that an interest, relationship or event does not exist.
Information can be false or manipulated
Online profiles, company websites, images, documents and social media posts can be fabricated or altered.
Even authentic content can be presented with a false description. A genuine photograph may be attributed to the wrong location or event. An old video may be presented as recent. A document may be real but incomplete.
Verification must address both authenticity and context.
Automated systems produce false positives
Databases and monitoring tools are useful for identifying potential matches, but they can combine records incorrectly or fail to distinguish between people with similar names.
Automated alerts should usually be treated as leads for review rather than final conclusions.
Historical information can disappear
Websites change, social media accounts are deleted and public databases are updated. Earlier versions may no longer be easily accessible.
This makes timely collection and preservation important, particularly where a finding may later need to be reviewed or relied upon.
Behaviour is open to interpretation
Observable activity does not always reveal intent.
A corporate restructuring may be designed to conceal ownership, or it may have a legitimate tax, legal or operational purpose. A vessel movement may appear unusual without being improper. An individual’s association with a company may be historical rather than current.
An investigation should distinguish suspicious indicators from proof of misconduct.
Some conclusions require non-public information
Open sources may identify gaps that can only be resolved through disclosure, interviews, local enquiries, legal process or access to internal records.
A professional report should state when open-source research has reached its evidential limit.
OSINT tools versus OSINT investigations
Modern investigations may use search platforms, corporate databases, mapping systems, vessel-tracking services, archive tools and analytical software.
These tools can make collection faster and help identify connections across large quantities of information. They do not remove the need for investigative judgement.
A platform may identify that two companies share an address. It cannot automatically determine whether the connection is material.
A database may match a director’s name to an adverse media report. It may not establish whether the article concerns the same person.
A vessel-tracking system may display an unusual movement pattern. It cannot, by itself, determine whether the behaviour was deceptive.
A language model may summarise a collection of records. It may omit caveats, combine unrelated facts or present an unsupported conclusion fluently.
The investigator remains responsible for defining the question, selecting appropriate sources, testing identity, resolving contradictions, assessing alternatives and communicating uncertainty.
Tools assist the investigation. They do not replace it.
Database checks versus professional investigation
A database check usually compares a subject against one or more structured datasets.
This can be appropriate for routine screening, including:
- Sanctions checks
- Politically exposed person checks
- Corporate registration searches
- Basic litigation searches
- Adverse media monitoring
- Directorship searches
Screening is valuable when the objective is to identify obvious matches or trigger further review. It becomes less effective when ownership is layered, names are ambiguous, records conflict or the relevant risk is not captured in a structured database.
A professional investigation is designed around a specific intelligence requirement. It can follow connections across sources, jurisdictions, time periods and entity types.
The investigator may need to:
- Resolve the identity of a person or company
- Reconstruct historical ownership
- Compare formal records with observable activity
- Trace relationships across several entities
- Examine evidence in multiple languages
- Test an allegation against primary records
- Identify conflicting accounts
- Explain the significance of the findings
- Recommend further collection or due diligence
The distinction is not that one approach is good and the other is bad. They serve different purposes.
Screening asks whether a known risk indicator appears in the selected data. Investigation asks what the available evidence, taken together, reveals about the question.
What makes intelligence decision-grade?
Decision-grade intelligence is clear, relevant, traceable and appropriately qualified.
It should enable a reader to understand:
- What question was investigated
- What information was examined
- What was established
- What was not established
- Which findings are most significant
- How reliable the evidence is
- What alternative explanations were considered
- What the findings mean for the decision
- What further action may be required
A report does not become more useful by including every fact discovered during the investigation. Excessive detail can obscure the findings that matter.
The analyst’s role is to organise the evidence around the decision. Supporting records should remain available for review, but the main report should prioritise clarity and materiality.
What should an OSINT report contain?
The precise structure will depend on the investigation, but a professional report will often include the following sections.
Executive summary
A concise answer to the intelligence requirement, including the most material findings, principal risks and overall level of confidence.
Scope
A description of the subjects, jurisdictions, time period and questions covered by the investigation.
The scope should also identify material exclusions. This helps prevent the report from being interpreted more broadly than the work supports.
Methodology
An explanation of the main source types and investigative methods used.
The methodology should provide enough information for the work to be understood and reviewed without unnecessarily exposing sensitive processes or personal data.
Findings
A structured account of the relevant evidence, organised around the intelligence questions rather than the order in which the information was found.
Analysis
An assessment of what the findings mean, including relationships, patterns, inconsistencies and alternative explanations.
Confidence and limitations
A clear statement of evidential strength, unresolved questions and source limitations.
Implications
An explanation of how the findings affect the client’s decision, risk assessment or investigative strategy.
Recommended next steps
Proportionate actions that may clarify remaining gaps or reduce identified risk.
These might include additional jurisdictional research, document verification, enhanced monitoring, legal review or direct requests for information.
Ethical and proportionate OSINT
The fact that information can be accessed does not automatically mean that it should be collected, retained or published.
Professional investigations should have a defined and lawful purpose. Collection should be relevant to that purpose and proportionate to the risk or decision involved.
Particular care is required when research concerns:
- Personal data
- Children or vulnerable individuals
- Health or other sensitive information
- Criminal allegations
- Residential locations
- Family members and associates
- Information that could create a safety risk
- Material obtained from a questionable or unlawful source
Investigators should avoid collecting information merely because it might be interesting. They should also consider whether the same objective can be achieved through less intrusive means.
Responsible OSINT is not defined only by what can be found. It is also defined by what the investigator chooses not to collect, use or disclose.
Frequently asked questions
Is OSINT just searching the internet?
No. Searching is one collection method, but OSINT requires verification, analysis and communication.
A search result is information. It becomes intelligence when its relevance and reliability have been assessed and it is used to answer a defined question.
Is OSINT legal in the UK?
OSINT can be conducted lawfully in the UK, but access to a source does not remove legal and regulatory obligations.
Investigations may involve data protection, privacy, intellectual property, defamation, contractual restrictions and other legal considerations. The lawful basis, necessity and proportionality of collecting personal information should be considered before research begins.
Higher-risk matters should receive appropriate legal review.
Does OSINT include information behind a paywall?
It can. A source may still be open for intelligence purposes if it is lawfully available through a subscription, registration process or access fee.
The investigator must comply with the source’s access conditions and applicable law.
Does OSINT involve hacking?
No. Hacking, credential theft, unlawful system access and deceptive acquisition methods are not OSINT.
Professional OSINT uses publicly available or lawfully accessible information.
Can OSINT prove who owns a company?
Sometimes, but not always.
Corporate records may provide clear evidence of direct and beneficial ownership. In more complex structures, an investigation may need to compare several jurisdictions, historical filings, related entities and indicators of effective control.
Where the evidence is incomplete, the report should present the strongest supportable assessment and explain the remaining gaps.
Can OSINT identify hidden assets?
OSINT may identify property, companies, vessels, business interests and other connections associated with a subject.
However, the presence of an apparent connection does not automatically establish legal or beneficial ownership. Asset findings often require additional verification and may need to be combined with legal disclosure or other investigative methods.
Can OSINT be used in legal proceedings?
Open-source material may support legal strategy, internal investigations or evidential development. Its usefulness will depend on provenance, preservation, authenticity, relevance and the applicable rules of evidence.
Investigators should maintain a clear record of where information came from, when it was accessed and how it was analysed.
How reliable are OSINT databases?
Databases vary considerably in their coverage, accuracy and update frequency.
They are useful for discovery and screening, but significant findings should be checked against underlying records wherever possible. A database entry should not automatically be treated as an established fact.
How long does an OSINT investigation take?
The timeframe depends on the question, number of subjects, jurisdictions, languages, source availability and required level of assurance.
A focused verification task may be completed quickly. A cross-border ownership or corporate network investigation may require substantially more time.
A clear intelligence requirement allows the work to be scoped realistically.
What information is needed to start an investigation?
Useful starting information may include:
- The decision or concern prompting the investigation
- The subject’s full name
- Known companies or trading names
- Registration numbers
- Relevant jurisdictions
- Known addresses
- Dates of birth, where appropriate and lawfully held
- Vessel IMO numbers
- Relevant dates or events
- Existing documents, allegations or research
- The required deadline
Incomplete starting information does not always prevent an investigation, but it may affect scope, confidence and timing.
What should I look for in an OSINT provider?
A credible provider should be able to explain:
- How the intelligence requirement will be defined
- Which legal and ethical boundaries apply
- How identities will be resolved
- How sources will be evaluated
- How findings will be corroborated
- How confidence and uncertainty will be expressed
- How personal and confidential information will be protected
- What the final report will contain
- What the investigation cannot establish
Be cautious of providers that promise certainty before examining the evidence or present access to tools and databases as a substitute for methodology.
Turn public information into decision-grade intelligence
The most important information is rarely contained in a single search result, database or document.
It emerges from the connections between records, the inconsistencies that require explanation and the judgement used to separate fact from assumption.
Greywing Intelligence conducts structured open-source investigations for organisations facing complex corporate, legal, reputational and maritime questions. Our work is designed to provide clear, defensible findings with transparent confidence levels and practical implications.
If you need to establish ownership, assess a counterparty, investigate a corporate network, verify a claim or understand a potential risk, speak to Greywing Intelligence about the question you need answered.
Contact Greywing Intelligence to discuss your investigation.
This article is general commentary on intelligence practice. It does not describe any client, engagement, or individual, and it is not advice on a specific situation.