OSINT, or open-source intelligence, is information gathered from publicly available sources such as leak-site trackers, social media posts, company websites, code repositories, and public records. In cyber security, OSINT helps defenders spot exposed assets, identify phishing campaigns, and monitor threat actor activity without touching private systems.
OSINT matters because attackers use it too. They collect employee names, email formats, cloud endpoints, and public mentions of incidents to improve phishing, extortion, and impersonation. Defenders use the same data to verify whether a leak-site listing is credible, correlate public claims with internal logs, and decide whether to escalate to incident response. OSINT is valuable, but it is not proof by itself: a public tracker entry or post may be a real breach, a rumor, or a negotiation tactic. Good analysis combines OSINT with internal telemetry and other evidence.


