Whenever a major security incident occurs, analysts often discover something surprising: the attacker had already left traces in the open — social media posts, underground forums, business records, even job advertisements.
OSINT (Open-Source Intelligence) is the art and science of lawfully collecting this information, then analysing it into actionable intelligence.
What Counts as "Open"?
- Public social media (posts, comments, photos)
- Corporate registries (SSM in Malaysia)
- Public government documents, tenders, annual reports
- Forums, blogs and technical discussion channels
- Public geospatial data (satellite imagery, mapping)
- Archive sites & search caches
- Job ads that reveal internal technology
Security Applications
1. Organisational Threat Assessment
What can outsiders learn about your organisation? Office layout from social photos, technology from job postings, hierarchy from LinkedIn. If you can find it — so can an attacker.
2. Data Leak Detection
Staff credentials being sold on dark forums, internal documents exposed on public repositories, accidental disclosures — detected early before exploitation.
3. Background Research
Consistent checks for sensitive positions, vendors or partners — within legal limits.
4. Threat Group Monitoring
New tactics, techniques and targets of cybercriminal groups — often discussed openly before attacks launch.
Ethics & Limits
Good OSINT has discipline:
- Public information only — no hacking, no account intrusion
- PDPA compliance — personal data processed lawfully
- Legitimate purpose — risk assessment, not personal spying
- Accuracy before action — open information can be wrong; cross-verify
- Storage minimisation — keep only what is necessary
A Basic OSINT Workflow
- Define — what is the intelligence requirement?
- Collect — structured searches across selected sources
- Process — organise, deduplicate, timestamp
- Analyse — connect entities, identify patterns, rate confidence
- Report — findings with confidence levels & sources
- Refresh — OSINT is a cycle, not a one-off project
Conclusion
Organisations that ignore OSINT operate half-blind — unaware of what the outside world already knows about them. A basic, ethically-run OSINT programme is one of the highest-return security investments available.
Raya Protech provides organisational OSINT assessments and basic training for security teams. Contact us to learn more.