What is OSINT?
OSINT (open-source intelligence), told as a story about a thief who gathers village gossip to draw a map of the castle before ever climbing the wall.
Before climbing the wall, the thief gathers gossip first.A good thief doesn't rush. Before the wall, he first collects everything the village already knows about the castle.
The pieces are all public. Nothing was stolen.A job post reveals which locks we use; castle folk's board posts reveal who is away and when. Gate nameplates feed the directory and door-counting; a leaked list in an old paper feeds password guessing.
OSINT: gather only the open gossip, and the castle map appears.Not one thing was stolen. Fit the market, the board, the nameplates, and the old paper together, and out comes the castle map and a name list. That becomes the sketch for the next attack.
Before the thief looks, we look at our own gossip first.The blue hat looks at our castle with the thief's eyes — counting doors from outside and gathering gossip like a scout. Pull the stray nameplates, and teach the folk to watch castle talk in the square.
Recon is the thief's very first step.OSINT is the first of the thief's steps: reconnaissance. Shrink our footprints (the attack surface) here, and the thief's map goes blurry.
OSINT = before climbing the wall, a thief gathers only the open gossip — job posts, social media, gate nameplates, old leaked lists — to draw the castle map and a name list. Nothing is stolen; only open pieces are fitted together.
Gathering publicly available information — websites, job posts, social media, DNS records, breach data, the dark web — to profile a target. It's the first stage of the kill chain, so defenders use the same methods to audit their own attack surface first.
When grown-ups say it
- OSINT
- Gossip alone makes a map. Profiling a target from public information only. Not stealing — collecting what's already out in the open.
- Reconnaissance
- The thief's first step. The stage of sizing up a target before attacking. → step 1 of the thief's steps
- Footprinting
- Collecting nameplates. Gathering an org's domains, IPs, and staff list. → the village directory
- Social media exposure
- What the folk post themselves. People reveal who is away and what tools they use, all by themselves. → the thief class
- Breach data search
- The list in the old paper. Finding passwords in lists that leaked long ago. → the thief who tries a thousand keys
- Dark web monitoring
- Listening in the back alleys. Watching whether our lists are being sold in the back alleys. → the friend on the watchtower
- Reducing digital footprint
- Removing nameplates. Removing needless public information so the thief's map goes blurry.
- Attack surface
- Our doors, seen from outside. Every point a thief could aim at. → counting our castle's doors from outside