Open-source intelligence can expose cover-ups and validate sources. Tuhin Sarwar’s open-source intelligence journalism employs in-depth analysis of open-source intelligence.
August 21, 2026, Dhaka
Report summary: Journalists use a structured OSINT process to gather data, verify its authenticity (using metadata and geolocation), identify patterns and networks, and attribute the findings. OSINT journalism has many benefits, but it must also comply with privacy laws like GDPR and CCPA, consent requirements, doxxing restrictions, and data security. Cognitive bias, information overload, and deepfakes are common issues. This guide explains OSINT step-by-step, lists free and paid tools for 2025, includes real-world case studies, addresses legal and ethical issues, highlights common mistakes, and includes a beginner’s checklist. A detailed analysis, practical tables, and a glossary follow the executive summary.
OSINT
Open-Source Intelligence (OSINT) gathers and analyses public data for insights. OSINT uses social media, videos, news articles, and corporate data to verify stories in journalism. Satellite imagery, social media, and leaked databases are used by journalists and OSINT specialists to confirm events, expose wrongdoing, and support news stories. OSINT uses only publicly available information, unlike covert intelligence. According to experts, “OSINT analyses open digital materials—videos, audio, images (including satellite photos), geolocation data, and more—to answer important investigative questions. OSINT verifies facts, improves reporting, and provides evidence when normal reporting access is denied in the newsroom. OSINT methods are used by Cat and other major investigative journalism teams to expose corruption, verify war crimes, and support accountability journalism.
How OSINT Works: A Step-by-Step Workflow for Journalists
In a professional OSINT investigation carried out by journalists, a systematic workflow is adhered to so that each step is clear, repeatable, and designed with both accuracy and efficiency in mind. The typical steps are:
- 1. Define the research question or the scope of the investigation: First, set out a specific question to investigate (for instance, “Who is responsible for this explosion?” or “Where did that shipment come from?”), and then decide which kinds of open-source data might be used to find the answers.
- 2. Identify data sources: OSINT investigations use social media platforms like Twitter/X, Facebook, and TikTok, websites and news archives, public records like company registries and government filings, forums, satellite imagery, mapping services, video-sharing sites, and some dark web sources. Corporate registries and leaked databases reveal financial networks. Social media posts, videos, and satellite maps can confirm events and locations.
- 3. Gather relevant data from all identified sources using manual methods (e.g., advanced Google searches and Boolean searches on social media) and specialised or data-scraping software. Keep screenshots, downloads, URLs, timestamps, and user IDs organised. Use OSINT tools and data aggregators for efficiency and reliability.
- 4. Verify and confirm: OSINT journalism needs to carry out verification. Reporters should examine the metadata (for example, EXIF data and video frames), use geolocation by matching up landmarks with maps, and employ chronolocation methods (such as shadows, weather conditions, and contextual clues). Typical practices involve conducting reverse image searches, cross-referencing with other independent sources, and using tools like the InVID plugin to analyse findings from OSINT, which should be treated as investigative leads—every piece of evidence must be checked against other sources. Analyse and Corroborate: After the data has been checked, search for any patterns, connections, and evidence that supports the findings. This might include carrying out a network analysis (for instance, by linking people or organisations), creating a timeline (by putting the events in chronological order), or using geospatial mapping (to monitor movements). For example, ship-tracking data can be combined with satellite imagery to plot the course of a shipment. The objective is to transform raw open data into actionable intelligence that supports the journalistic claims. Data is transformed into actionable intelligence that supports the journalistic claims.
- 6. Attributing responsibility and giving context: In the field of OSINT, it is important to allocate specific actions to individual people or organisations, identifying the authors of the posts, the units that took part in various events (by using markings or vehicle IDs), or the companies linked to illegal activities. For attribution to be valid, it must be based on multiple pieces of evidence—for example, uniforms, language, and official records—to avoid misidentification and minimise the potential harm.
It is essential to maintain careful records at every stage of the OSINT process, with investigators thoroughly recording their search queries, tool results, screenshots, and data sources, and ensuring each entry includes the date and time. Only in this way can a clear chain of evidence be established and accountability be ensured during the investigation.
mermaidCopyflowchart LR A[Define Question/Scope] --> B [Identify Open Data Sources] B --> C[Collect Data (search, archive, scrape)] C --> D[Verify Authenticity (metadata, geolocation, reverse search)] D --> E[Examine Patterns & Corroborate] E --> F[Attribute to Actors and Context] F --> G[Report Findings (with sources and documentation)]
Figure: Journalistic OSINT investigation workflow
OSINT Investigative Intelligence Hub: A Global Reference for Journalists, Researchers, and Human Rights Investigators
Powered by Tuhin Sarwar
It is not merely a collection of tools; the OSINT Investigative Intelligence Hub is meant to serve as a comprehensive knowledge ecosystem and reference library for journalists, researchers, human rights investigators, fact-checkers, and OSINT analysts worldwide. It combines:
– OSINT Library
– Intelligence Portal
– Satellite Intelligence Centre
– Data Journalism Academy
– Investigation Knowledge Base
– Research Database. Tools and Resources: A collection of OSINT tools that have been organised and searched, along with information regarding their practical use, reviews, and specific applications.
3. Intelligence Portal: The platform offers live feeds, alerts, and analytical dashboards which are used for monitoring global incidents and investigative leads.
4. Satellite Intelligence Centre: Offers access to both real-time and archived satellite imagery, tutorials on geospatial analysis, and open datasets. Categorised OSINT tools, along with information on their contextual usage, reviews, and case applications.
3. Intelligence Portal: It provides live feeds, alerts, and analytical dashboards which are used for monitoring global incidents and investigative leads.
4. Satellite Intelligence Centre: Provides access to real-time and archived satellite imagery, as well as to geospatial analysis tutorials and open datasets.
The Data Journalism Academy offers training modules, tutorials, and masterclasses designed to help build skills in OSINT, verification, and digital safety.
For investigations, the following resources are available: case studies, workflows, expert commentary, and research publications.
7. Research Database: This section refers to a collection which includes leaked datasets, public records, and investigative archives that can be searched.
8. AI Investigation Lab: Various tools and guides relating to AI-powered OSINT, deepfake detection, and automated content analysis.
The structure is appropriate for both beginners and experienced practitioners since it offers not only various tools but also a complete ecosystem that supports learning, conducting investigations, and collaborating on a global scale.
The following table lists the main OSINT tools and services used by journalists in 2025. Sources for individual tools: Since many OSINT tools are complementary, journalists can use them together to carry out more comprehensive investigations. For example, journalists generally make use of ExifTool (which is free) to extract image metadata, carry out reverse image searches using Google or Yandex, and locate landmarks with Google Maps or Google Earth. While some platforms (such as Maltego, Orbis, and LexisNexis) do require a subscription, basic resources including Google Search, Google Earth, reverse-image search tools, the OSINT Framework, the InVID plugin, ExifTool, and the Sentinel-EO Browser are available free of charge. Bellingcat’s most recent Online Investigations Toolkit includes hundreds of OSINT tools. It clearly indicates which ones are free and which are paid, helping journalists select the tool that best suits their needs.
Case studies from real-life situations: the effect of OSINT on investigations.
The application of open-source intelligence has transformed investigative journalism by allowing extensive reporting on a wide range of topics. The following real-world examples illustrate how open-source intelligence results in major news investigations. In conflicts and war crimes, investigators have used videos from social media and satellite imagery to document the atrocities. During the Tigray war in Ethiopia (2021), analysts discovered videos that seemed to depict a massacre. By studying the shadows and the landscape, they were able to establish both the place (the village of Mahbere Dego) and the time of the incident. They identified the Ethiopian soldiers (based on the language and their uniforms) as the ones who had carried out the killings and prepared a report for Newsy/BBC, stating that the local forces were responsible for the killings. Many people used freely available tools (such as Google Earth, PeakVisor and open data) to carry out the investigation. As another instance, Bellingcat traced a ship carrying grain (the Zafar) that was breaking Ukraine’s sanctions. They combined satellite images from Planet Labs with AIS vessel data and records from Lloyd’s ship registries to reconstruct the ship’s route from Crimea to Yemen. This showed how Russia channelled grain into global markets. One OSINT journalist said that such OSINT findings are “really, really important.” Checking Attacks: In conflict zones, open-source intelligence (OSINT) can be used to establish which weapon or direction was responsible for an incident. For example, after an explosion at a hospital in Gaza in October 2023, reporters looked at open-camera footage and satellite maps to trace the trajectory of the rocket. The analysts from the Wall Street Journal found that footage taken from some different locations indicated that the rocket had started inside Gaza, not in Israel. Likewise, a science reporter from NPR noted that an acoustic analysis (based on open audio recordings of rockets) confirmed this conclusion. As a result of these OSINT investigations, the analysts corrected the initial incorrect reporting by establishing the true source of the blast. Origin of the blast.
- Environmental Crimes: OSINT is valuable for environmental reporting. NGOs have created platforms (e.g., Global Forest Watch) that publish satellite data on deforestation. In Ukraine, an OSINT Forest Area Tracker (built on Google Earth Engine) enabled analysis of war-related forest damage. Researchers selected dates and areas to map burnt or cleared land, cross-checking with Sentinel-2 satellite imagery. By combining these findings with local reports, they could assess unexplored environmental harm from conflict. More broadly, public databases (e.g., land registries and pollutant reports) have supported investigations into illegal mining, deforestation, or pollution. For example, an African non-profit used public data to expose ‘green supply chains fuelling conflict’, while OSINT can also reveal both financial and political corruption. (Although there is not a single instance mentioned here, historically investigations such as the Panama Papers made use of leaked data through networked collaboration.) Existing OSINT procedures enable reporters to link together corporate filings, large collections of leaked documents (using tools such as Datashare or Aleph), and public sanctions lists. As a result, they have been able to reveal the true owners of companies and detect illegal flows. Even Bellingcat’s toolkit has dedicated resources (for example, the Open Source Munitions Portal) that help users identify weapons from photographs they upload. What this work shows is that journalists can find facts which conventional methods of reporting might fail to discover when they systematically analyse open-source intelligence (OSINT). The use of OSINT usually results in news stories that are faster, more accurate and based on evidence, for example, by identifying the type of aircraft, verifying footage of human rights abuses and keeping track of disaster events; the capacity to gather and analyse open-analysed data has caused several major investigative breakthroughs. Open-source data has led to several major investigative breakthroughs. Doing OSINT journalism requires careful attention to complicated legal and ethical questions. Even though it is usually legal to gather publicly available information, journalists must always put privacy, consent, and safety first when conducting their investigations. The key points to consider when carrying out responsible and ethical OSINT journalism are that privacy laws still apply even when data is in the public domain. In the European Union, the General Data Protection Regulation (GDPR) places restrictions on how personal data (even if it has already become public) can be processed. Likewise, California’s CCPA has introduced such requirements in some situations. Journalists should apply the principle of data minimisation – only the information that is relevant to the story; where possible, they should anonymise incidental personal details, especially those relating to private individuals. As one analyst puts it, “Collect only relevant data… store it securely.” Although open data on public figures can generally be used more freely, there is still a risk of violating privacy and journalistic ethics if sensitive details about private individuals (for example, their home addresses) are made public. When it comes to consent and the difference between public and private data, journalists must not engage in illegal acts such as hacking or buying information from private databases since OSINT is based on publicly available information. For example, it would be illegal to scrape a website that requires a paywall or to take advantage of a login breach. Information can only be used if it is legally obtainable, such as from a public archive or database; otherwise, journalists should not hack to obtain it. From an ethical standpoint, although some information may be considered public, its use could still be exploitative (for instance, private home videos uploaded by victims). Journalists should take into account both consent and the public interest: it is acceptable to identify a war-crime suspect, but it would be unethical to publish someone’s home address with the intention of harassing them since that would amount to doxxing. Regarding OSINT and harassment, journalists must steer clear of doxxing since releasing personal information like contact details and addresses can have a detrimental effect on individuals. There ought to be a clear ethical line between responsible journalism—which involves disclosing the names of officials who commit atrocities—and an invasion of privacy, which means making unrelated personal details public. As the guidelines say, “Don’t dox people.” It is critical to weigh the consequences in each case, since exposing a whistleblower’s identity without their consent or a valid reason is both unethical and risky.
- Laws vary from country to country, since what is permissible in one place may be illegal in another. For instance, the strong legal protections found in Europe might make it problematic to scrape certain social data, while in other places there are fewer safeguards. Investigators should be conscious of the local regulations, such as those relating to recording (in some countries consent is needed before interviews or phone calls). One OSINT guide advises journalists to learn local laws. VPNs and secure browsers can help investigators protect their identities abroad.
- Ethical guidelines: Traditional standardsardsanalysislapplyll app code. The Society of Journalists’ principle of seekingito minimise the ruth, minimising harm, and bappliesaccountable—also apply to OSINT. This means that all findings must be thoroughly verified (since OSINT should be regarded as leads and not as final answers) and that mistakes should be corrected when th” happen. The phrase ‘We ver’fy before we publish’ has become an important rule in the field of OSINT. It is appropriate for journalists to be open about their methods (for instance, by keeping records of their sources and citing evidence) and to be ready to take responsibility. Many newsrooms have already established clear OSI” protocols, such as ‘We never hack or break the law. We never publish private information without a good reason. We fact-check ‘nd verify each claim’.
- Journalists using OSINT tools risk digital and physical safety. Websites and links may contain malware, and open networks may monitor or censor investigators. A secure and up-to-date operating system (or a dedicated OSImachine), VPNs, Tor, and not using personal accounts are recommended. Since war footage and hate speech can be traumatic, reporters should seek counselling or peer support. If an OSINT investigation targets a powerful entity (organised crime or an authoritarian regime), reporters must consider retaliation. Anonymous publication through intermediaries or investigation confidentiality may be needed. One analyst suggests setting a personal code of conduct (e.g., “what I will never do”) before starting an investigation.
The summary below sets out the most important legal and ethical dimensions of OSINT journalism (the citations mentioned above).
| Privacy & Data Laws | Violating GDPR/CCPA by mishandling personal data. Legal action or fines. | Avoid unnecessary personal data. Use anonymisation. Know relevant laws (GDPR, CCPA, etc.). Only use data clearly in the public domain. |
| Consent & Hacking | Illegal access (hacking) or unethical intrusion. | Use only legally accessible sources. Do not bypass passwords or paywalls. Maintain journalistic integrity. |
| Doxxing / Harassment | Publishing private PII harms individuals. Legal/ethical liability. | Never publish sensitive personal data without clear public interest. Focus on public actors, accountability. |
| Jurisdiction | Running afoul of local laws (e.g. data scraping rules, surveillance laws). | Research regional laws (e.g., using the UNCTAD privacy map). Adapt methods based on location and consult legal counsel if necessary. |
| Verification Failures | Relying on fakes or misattributed data leads to false reports. | Always cross-check with multiple sources. Use techniques (geolocation and metadata analysis) for authenticity. Fact-check before publishing. |
| Deepfakes / Misinformation | AI-generated or doctored media may mislead even experienced analysts. | Stay up-to-date on deepfake detection techniques. Treat all open-source content with scepticism. Use specialised AI-detection tools, but verify them manually. |
| Safety (Digital/Physical) | Online surveillance, malware, personal data leaks, or real-world threats. | Use VPNs, secure devices, and separate accounts. Avoid sites known for malware. Plan for physical safety ( anonymise communications). |
Table: The legal and ethical aspects of OSINT. Since it has great power, OSINT journalism has some inherent limitations; journalists should remain aware of the following common pitfalls and challenges. They must be aware of the following common pitfalls and errors due to misidentification and wrong attribution: Since OSINT sources are merely raw data and not confirmed facts, care must be taken to avoid misidentifying individuals or places. For instance, a picture of a bystander could be taken for a suspect if it is not checked against other sources. Raw data usually includes errors such as out-of-date information, duplicate entries, or false leads. It is therefore necessary to carry out cross-verification. As OSINT “attributions”, “misattributed IP addresses”, “false positives”, or “outdated records” may lead analysts to the wrong conclusion. One must always confirm an identity using a number of different pieces of evidence (for example, by matching a name with a consistent online presence, official identification, or a source that can confirm the information). Because of advances in AI, it has become increasingly common to produce convincing fake images and videos. Generative models can insert realistic landmarks or people into footage, creating what are known as ‘shallowfakes’ or ‘deepfakes’. In the past, OSINT practitioners relied on geolocation as evidence of authenticity, but nowadays it is possible for a geolocated scene to have been artificially created. As the study points out, “A geolocated video may indicate that an event took place at that location, but it does not guarantee that the footage is genuine.” Analysts have to examine the content for subtle artefacts (such as inconsistent lighting, irregular facial geometry, and audio glitches) and make use of detection tools. Nevertheless, AI detection software is not perfect and can give false positives or false negatives. The only solution is to remain sceptical: where possible, get a source or a witness, and regard any content that might have been generated by AI as unverified until it has been confirmed. People can be affected by confirmation bias and may then, either consciously or unconsciously, look for evidence that supports their hypothesis. For instance, if a person thinks a particular official is guilty, they might be inclined to accept weak evidence which supports that belief. Journalists should systematically look into evidence that contradicts their claim and take into account other possible explanations. The process of peer review or the use of collaborative groups (as is done by OSINT collectives) can help in identifying any bias. The methods used to verify clues have been vied are only leads and not conclusions. You should always ask yourself, “What kind of evidence would disprove this?” and then seek it out. The sheer volume of data available online can leave analysts overwhelmed, with important clues often hidden amongst irrelevant material. Additionally, relevant data might be spread out over different platforms (for example, fragments of a story on Twitter, Telegram, and YouTube). To carry out effective open-source intelligence research, it is necessary to use the right tools, and a stakeholder should make use of aggregation tools or databases to collect the relevant information (such as the Online Investigations Toolkit). Sources are prioritised according to their reliability, and records should be kept in an organised manner to prevent important details from being lost. The limitations of platforms mean that success in OSINT can be affected by those platforms’ policies. Recent changes—such as the restrictions imposed by the Twitter/X API—have decreased the amount of data that is accessible. This in turn can obstruct investigations. It is therefore important for journalists to use a variety of sources and not put all their faith in one platform. If data vanish or accounts are suspended, it will be necessary to use alternative archives or contributions from users. Due to technical limitations, some types of analysis—such as the use of detailed satellite imagery or proprietary databases—may be beyond journalists’ means, which in turn can affect the quality of the evidence. This shortcoming can be partly overcome by forming partnerships with organisations like NGOs or academic institutions, or by using open-access, low-resolution alternatives (such as Sentinel imagery).
To sum up, while OSINT is an asset in the field of investment journalism, it has to be cautioned in an ethical manner. The degree of confidence one should place in any findings must correspond to the extent of verification—although geolocation or metadata can confirm when and where something happened, they do not always provide information about the context or meaning of the event. With digital deception technologies becoming more advanced, journalists need to keep updating their OSINT skills and stay alert to new kinds of misinformation.
Getting Started: Responsible OSINT Practices
For journalists or researchers new to OSINT, here is a concise workflow and checklist to ensure responsible, effective practice:
- Set your objective by clearly stating the question or the claim that you wish to investigate. Make it specific (for example, “Did X happen on date Y at location Z?”). Having a clear scope will stop you from collecting irrelevant data.
- When carrying out our work ethic, gathering any data, take into account the possible legal and ethical considerations shown in the above table before gathering any data. We should decide in advance that “we will only use public data, we will not hack, and we will not collect irrelevant personal information.” By putting these rules in writing (creating a personal OSINT code of conduct), you will be better prepared to deal with difficult situations.
- Gather Open Data: Search through multiple sources. Use targeted queries (e.g., site:domain.com [keyword], hashtag or user searches, and corporate registry searches). Use archival tools (Internet Archive) to find deleted content. Save all raw data: take screenshots and note URLs, timestamps, and any user info. Keep a log (spreadsheet or database) of every finding. For efficiency, use known tools: e.g., reverse-image search engines, social media monitoring tools, and the Bellingcat toolkit directory.
- Verify Carefully: For each piece of evidence (a photo, video, or check), ensure the landmarks correspond to the maps (you can use Google Earth, Mapillary, or SunCalc for the shadows). Chronolocation: Are timestamps believable? Check shadows, seasonal clues, and metadata. For verifying the source: can you locate the original upload? (You can do this by using the Wayback Machine or by referring to the metadata.) As one “dvisory note states, “OSINT on its own is never sufficient… what it means is that you have to seek the ground truth”; therefore, every OSINT clue should be regarded as a lead. You can use tools such as InVID for videos, ExifTool for images, and analysis tools (for example, GIJN’s AI-detection checklists). The time required for each item will be a few minutes; it is essential to carry out these steps before publishing in order not to be misled. essential to avoid being misled.
- An analysis and a record should be made by organising the verified data to reach a conclusion. Spreadsheets or databases should be used to link the various entities (such as people, companies, and locations). Evidence files should be kept (including PDFs or images together with URLs and date stamps). Any uncertainties must be noted clearly. If possible, another colleague should review your chain of evidence.
- To ensure security, when dealing with sensitive OSINT leads, you should use secure communication methods such as encrypted email or Signal. You should carry out your research on a separate OSINT device or on a virtual machine in order to lower the risk of malware. Use VPNs or proxies to hide your IP address and minimise your personal exposure by carrying out the research from accounts that are not linked to your own identity.
- Follow-up and report: Before you publish, check over the key facts (for example, by referring to a reliable source). Make sure you properly cite your sources (where possible) and explain the methods used so that other people can carry out your verification themselves. If any new information comes to light that contradicts your earlier findings, you should be ready to update your report.
mermaidCopyflowchart LR A[Define clear research question] --> B [Plan ethics & legal constraints] B --> C [Collect open data systematically (with logs)] C --> D [Verify each piece (metadata, context, cross-check)] D --> E [Analyse data (compile evidence, look for patterns)] E --> F[Document sources and reasoning transparently] F --> G [Publish findings responsibly (with citations)]
Figure: a checklist for a responsible OSINT workflow.
Journalists can develop effective and ethical OSINT practices by following these steps and by keeping on learning (for example, by attending OSINT training or reading the guides for the tools in question). To remain up to date on new tools and techniques, it is necessary to regularly refer to resources such as the Bellingcat tutorials, the GIJN guides and the various communities (such as those on Discord and Telegram).
Glossary of Key Terms
- OSINT (which stands for Open-Source Intelligence) involves gathering and analysing information from sources that are publicly available—such as the media and the internet—in order to generate actionable intelligence. It must not be confused with open-source software.
- Verification refers to the process of confirming that data or content is genuine. In the field of OSINT, this means checking the metadata, the geolocation, the timestamps, and the geolocation.
- The method of geolocation involves identifying the geographical location at which an image or video was taken by matching visual marks or by using the GPS metadata.
- Chronolocation refers to the method of establishing the date and time at which an image or video was created by examining indicators such as the position of the sun (as shown by shadows), the weather conditions, or the timestamps provided in the metadata.
- Refers to data that is included in files (for example, the manufacturer of the camera, the GPS coordinates and the timestamps in a photograph) to be extracted in order to verify authenticity.
- A deepfake is an image, video, or audio file created using artificial intelligence which convincingly imitates a real event or person and needs to be carefully detected.
- ‘Doxxing’ refers to the act of publishing another person’s private details, such as their address or phone number, with malicious intent and is regarded as unethical.
- A VPN (which stands for Virtual Private Network) is a service that encrypts internet traffic and hides IP addresses in order to ensure privacy, and it is used by journalists to secure their OSINT activities.
- The Wayback Machine is an archive of previous versions of web pages (at archive.org), and it can be used to find out when some content first appeared or to check whether it has been altered.
- Crowdsourcing refers to collecting information from a large number of people, usually through online communities or platforms; in the field of OSINT, it can take the form of making public appeals for information or using collaborative databases.
- Chain of custody refers to the recording of how evidence was collected and handled to ensure its integrity; in journalism, keeping details of sources (such as URLs and dates) is an informal way of observing this concept.
- Confirmation Bias: The tendency to search for or interpret information so that it confirms one’s preconceptions. Journalists must actively use CrowdTangle, a tool owned by Facebook, which is analysing public content on Facebook and Instagram (it is used by journalists to monitor viral posts). EXIF (Exchangeable Image File) is a metadata format used for images and contains information about the camera settings as well as often GPS data. Examples of public GIS datasets for use in maps and geography can be found from sources such as Natural Earth, etc. OpenCorporates is an open database containing corporate registry data from around the world and is frequently used in OSINT. Globally, often used in OSINT.
All of these terms are essential for an understanding of OSINT workflows. With the help of this glossary, journalists will be able to quickly understand the technical jargon and then concentrate on applying OSINT techniques properly.
