IronSights

Network & infrastructure

Open Source IntelligenceOSINT

The practice of collecting and analysing publicly available information — from websites, social media, job postings, public records, and technical data — to build intelligence about a target.

Also known asOSINTopen-source intelligencepassive reconnaissance

In plain English

OSINT is reconnaissance using only public sources. Attackers use it before launching an attack to map an organisation's technology stack, identify key personnel, find exposed credentials in data breach dumps, and discover forgotten subdomains or internet-facing systems. Penetration testers use the same techniques to show organisations their exposure before an attacker does.

Keep learning

More terms in the IronSights Glossary.