In plain English
OSINT is reconnaissance using only public sources. Attackers use it before launching an attack to map an organisation's technology stack, identify key personnel, find exposed credentials in data breach dumps, and discover forgotten subdomains or internet-facing systems. Penetration testers use the same techniques to show organisations their exposure before an attacker does.
