Field Guide

Search Is Cheap, Judgment Is Not: A Field Guide to Defensible OSINT

The internet rewards searching. Courts, clients, and commanders reward reasoning. That gap is the entire discipline.

Anyone with a browser can find something. The hard part, the part that separates an analyst from a search-engine operator, is turning what you found into a claim you can defend when a hostile attorney, a skeptical editor, or a decision-maker with real consequences on the line asks the only question that matters: how do you know? Investigations fail on that question in predictable ways. An analyst matches an image to a location instead of trying to disprove it, and matches the wrong one. An analyst finds a decisive post and screenshots it a week later, after it has been edited, with nothing preserved. The finding was real. The proof was not.

Open-source intelligence (OSINT) is often taught as a tour of tools and sites. That framing is backwards. Tools change every quarter. Platforms lock down APIs, sites die, and this year's clever technique becomes next year's dead link. What persists is judgment: the ability to frame a question, plan collection, weigh sources, reason under uncertainty, guard against your own biases, and write findings that survive scrutiny.

This guide treats OSINT as a reasoning discipline first and a tooling discipline second. It is organized around eight practices, plus a section on capture and chain of custody that most field guides skip and that becomes decisive the moment your work might reach a report, a regulator, or a courtroom. Every example here is generic or composite. The methods are not.

1. Mission Framing: Turn a Tasking Into a Question

Most bad investigations are lost before collection begins, because the analyst accepted a vague tasking and never converted it into an answerable question. "Find everything on this company" is not a question. It has no boundary, no success criterion, and no stop condition, so it produces a pile of material and no judgment.

Start by separating what you actually have into three buckets:

Then borrow the structure military and competitive-intelligence shops use. Define Priority Intelligence Requirements (PIRs): the two or three decision-driving questions the customer needs answered. Under each PIR, list Essential Elements of Information (EEIs): the concrete sub-facts you can actually collect that together answer the PIR. A PIR might be "Is this vendor financially capable of delivering the contract?" The EEIs are things you can go and find: registered entity and status, filing history, litigation record, adverse media, ownership structure, and evidence of operating footprint.

Finish framing with two things analysts routinely omit:

Decision rule: if you cannot state, in one sentence, what decision your product will inform and what would change that decision, do not start collecting. Go back to the requester.

2. Planned, Intentional Collection

Collection is a plan, not a reflex. The dominant failure mode in OSINT is "collect everything," which feels productive and is actively harmful: it buries the signal, wastes the one resource you cannot recover (attention), and makes your work impossible to reproduce.

A workable collection plan maps each EEI to source layers, a method, and a cadence. Think in layers rather than favorite sites:

Assign a cadence to anything that changes: a one-time pull for static records, a recurring check for active accounts, event-driven collection when a trigger fires. And treat reproducibility as a first-class requirement. Another competent analyst, handed your plan, should be able to retrace your steps and reach the same material. That means logging queries, dates, and sources as you go, not reconstructing them from memory a week later.

Practitioner references such as Bazzell and Edison's OSINT Techniques (2024) and Bellingcat's continuously updated Online Investigation Toolkit (2024) are useful precisely because they are organized around workflows and source layers rather than one-off tricks. Use them to populate your plan, not to replace it. The plan is yours; the tools are interchangeable.

Collect Without Burning the Operation (OPSEC and Attribution)

Before you touch a source, decide whether the subject can see that you did, and whether that matters to the case. That single question separates disciplined collection from the kind that tips off a target or attaches your name to the file.

Collection also has to stay inside the law, and "when you hit a legal boundary" is only a real stop condition if you know where the boundaries usually are. The recurring ones: platform terms of service and anti-scraping provisions; computer-misuse exposure (in the US, the Computer Fraud and Abuse Act) for automated collection or pretext access; and, wherever you operate in or collect on people in the EU or other GDPR-style regimes, a documented lawful basis for processing personal data. Some EEIs are collectible in principle but out of bounds in practice. That determination belongs in the plan, confirmed with counsel where the stakes are high, not discovered after the fact.

3. Source Quality, Provenance, and Traceability

The single most common analytic error in open sources is mistaking repetition for corroboration. Ten accounts posting the same claim are not ten sources. They may be one source and nine echoes. Your job is to trace every claim back toward its origin and to grade what you find.

Distinguish primary sources (the originating document, the person who was there, the first upload of an image) from derivative sources (reporting about the document, a re-upload, a screenshot of a screenshot). Claims launder themselves as they travel: a speculative sentence in a forum becomes a confident headline three hops later, with the hedging stripped and the uncertainty gone. Chase the claim upstream until you hit bedrock or run out of trail, and note where the trail ended. Ask who benefits from the claim being believed. Motive does not make a claim false, but it tells you how hard to push on verification.

To make source assessment consistent instead of impressionistic, grade sources and information separately using the A-F / 1-6 matrix documented in U.S. Army doctrine (FM 2-22.3, 2006, Appendix B) and known in British and NATO practice as the Admiralty Code. Reliability of the source and credibility of the information are independent axes, and keeping them separate is the whole point: a usually reliable source can still relay an uncorroborated rumor.

Source reliability (A-F):

Grade Meaning
A Reliable
B Usually reliable
C Fairly reliable
D Not usually reliable
E Unreliable
F Cannot be judged

Information credibility (1-6):

Grade Meaning
1 Confirmed (by independent sources)
2 Probably true
3 Possibly true
4 Doubtfully true
5 Improbable
6 Cannot be judged

A datum tagged "B2" (usually reliable source, probably true) tells a downstream reader far more than "per an online post." Use the matrix, but do not oversell it. It is only as good as the discipline behind it: studies of how analysts apply the scheme find that grades cluster on middle values and that the two axes, which are supposed to be independent, get treated as correlated. A "B2" is shorthand for your reasoning, never a substitute for showing the actual sourcing chain.

The taxonomy of what you are looking at also matters. Wardle and Derakhshan's Information Disorder framework (Council of Europe, 2017) separates misinformation (false, no intent to harm), disinformation (false, intent to harm), and malinformation (true information weaponized to harm). Wardle's companion "7 types" typology (First Draft, 2017) is a practical checklist: satire, false connection, misleading content, false context, imposter content, manipulated content, and fabricated content. "False context," genuine media presented as something it is not, is the one that catches experienced analysts, because the media itself is real. UNESCO's journalism handbook (Ireton and Posetti, 2018) lays out the source, date, and location verification checks that operationalize this.

4. Reasoning Is the Real Skill

Collection gives you clues. Clues are not claims, and claims are not conclusions. The move from one to the next is reasoning, and it is where most analytic failure actually happens.

Watch for the "therefore trap": a chain of individually plausible steps that quietly loses probability at every link and arrives at a confident conclusion built on multiplied uncertainty. "The account posts in this time zone, therefore the user lives there, therefore they were present at the event, therefore they are involved." Each "therefore" is a hinge, and each hinge can be wrong. Make the chain explicit and interrogate each link on its own: is this an observation or an inference? What else could produce this same clue?

Two lightweight structures keep reasoning honest:

5. Structured Analytic Techniques, Kept Lightweight

Structured analytic techniques (SATs) sound bureaucratic and can be, but a handful of them are fast, high-leverage habits rather than paperwork. They exist to slow down the intuitive, fast-thinking System 1 (in Kahneman's Thinking, Fast and Slow, 2011) long enough for deliberate System 2 to check its work. The CIA's Tradecraft Primer (2009) is the standard reference for the first four techniques below; Premortem Analysis comes from Pherson and Heuer's Structured Analytic Techniques (3rd ed., 2019), which is the fuller catalog of the method.

Technique What it does When to reach for it
Key Assumptions Check Surfaces the load-bearing assumptions you are treating as fact At the start, and any time the answer feels obvious
Analysis of Competing Hypotheses Scores evidence against rival explanations to find disconfirmers When more than one explanation fits and stakes are high
Quality of Information Check Re-audits your sourcing for reliability, currency, and laundering Before you write, and before any number goes in a report
Red Team / Devil's Advocacy Argues the opposing case in good faith When consensus formed fast or nobody disagrees
Premortem Assumes the assessment was wrong, then explains how Just before delivery, to catch overconfidence

None of these takes long. A Key Assumptions Check on a tight investigation is fifteen minutes with a notepad. A Premortem is one question asked out loud: "It is six months from now and we were badly wrong. What did we miss?" The discipline is doing them at all, and doing them before you are committed to an answer rather than after you have to defend one.

6. Geolocation and Chronolocation

Placing an image or video in space and time is where OSINT reasoning becomes visible and testable. Do it as a layered accumulation of independent evidence, not a single "gotcha" match.

Work through the layers, treating each as a constraint that narrows the possibility space:

Then match those constraints against satellite and street-level imagery, the workflow Bellingcat has documented since its early guides (Higgins, "A Beginner's Guide to Geolocating Videos," 2014; "Searching the Earth," 2015) and maintains in its toolkit.

Two disciplines separate credible geolocation from confirmation bias:

Treat metadata with caution rather than faith. EXIF timestamps and GPS tags are frequently stripped by platforms on upload, are trivially editable, and carry time-zone ambiguities that produce hours of error. Metadata is a lead, not proof. The strongest geolocation rests on independent corroboration: two or more captures, ideally from different uploaders and angles, that agree on the same physical scene. The Berkeley Protocol (UN OHCHR and UC Berkeley Human Rights Center, 2022) is explicit that verification, not metadata, carries the weight.

7. Deception, Coordinated Inauthentic Behavior, and Your Own Bias

Assume some of what you find was put there for you to find. The modern information environment includes staged media, recycled footage, imposter accounts, and coordinated inauthentic behavior (CIB) built to manufacture the appearance of consensus.

Indicators worth checking, none conclusive alone:

Synthetic and AI-Generated Media

Generative models now produce photoreal images, cloned voices, and video that the classic manipulation tells above will miss, because nothing was spliced; the whole frame was synthesized. This is the fastest-moving deception vector, and it needs its own checks:

The harder adversary, though, is internal. Heuer's central finding is that the biggest threats to analysis are the analyst's own cognitive habits, and Kahneman gives them names:

You do not defeat these by resolving to be objective. You instrument against them: write down assumptions before you look (Key Assumptions Check), work by disconfirmation (ACH), assign someone to argue the other side (Red Team), and run a Premortem before delivery. Structure is the countermeasure, because willpower is not.

8. Intelligence Writing That Is Decision-Focused and Defensible

A finding that a decision-maker cannot act on, or that collapses under cross-examination, was not worth collecting. Write for the reader who has thirty seconds and the adversary who has all day.

Capture and Chain of Custody for OSINT Artifacts

Online evidence is perishable and mutable. A post can be edited or deleted, a page can change, an account can vanish, all between the moment you see something and the moment anyone asks you to prove it. If there is any chance your finding reaches a report, a regulator, or a courtroom, you preserve at the moment of collection, not later. This section is the one most field guides omit, and it is the one that decides whether your work is usable.

Preserve so that the artifact is authentic (it is what you say it is) and its provenance is traceable (where it came from and when you got it). The Berkeley Protocol (2022) is the leading international standard for exactly this, and ICD 203's sourcing discipline points the same direction.

A minimum capture routine:

For anything court-bound, automated contemporaneous capture is the standard, not an ad hoc manual routine. Purpose-built tools (Hunchly is the common example) silently log, hash, and timestamp every page you visit during a session and export a case-oriented report, which is far harder to attack than a folder of screenshots assembled after the fact. For high-stakes work, screen-record the acquisition session and record the tool and its version. Keep the manual method above as the floor, and treat automated logging as the goal.

Understand the limits of what preservation buys you. Authentication (showing what the item is) and integrity (showing it has not changed since collection) are the two preconditions you control by capturing well. They are necessary, not sufficient. Admissibility also turns on rules you do not control and that vary by jurisdiction: authentication standards (in U.S. federal practice, Federal Rules of Evidence 901 and 902), the hearsay problem when a post is offered for the truth of what it asserts, relevance, and best-evidence rules. In the EU and other GDPR-influenced systems, data-protection and civil-evidence rules can differ materially, and evidence gathered without a lawful basis can be excluded. The collector may also need to provide a declaration or affidavit and testify to authenticate the material. You are not making those calls, and this is not legal advice; you are making sure that when counsel does make them, your record supports the case instead of sinking it. The discipline costs minutes at collection and is effectively impossible to reconstruct afterward. Do it every time, or you have a story instead of evidence.

The Field Checklist

Run this end to end on any investigation that might be seen by someone other than you.

Before collection

During collection

During analysis

Before delivery

Bottom Line

The tools will keep changing. The judgment is the durable asset, and it is what decides whether the work holds up when it matters.

References

  1. Richards J. Heuer, Jr. Psychology of Intelligence Analysis. Center for the Study of Intelligence, Central Intelligence Agency, 1999. https://www.cia.gov/resources/csi/books-monographs/psychology-of-intelligence-analysis-2/
  2. Center for the Study of Intelligence, Central Intelligence Agency. A Tradecraft Primer: Structured Analytic Techniques for Improving Intelligence Analysis. 2009. https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf
  3. Randolph H. Pherson and Richards J. Heuer, Jr. Structured Analytic Techniques for Intelligence Analysis, 3rd ed. CQ Press (SAGE), 2019. https://us.sagepub.com/en-us/nam/structured-analytic-techniques-for-intelligence-analysis/book255432
  4. Office of the Director of National Intelligence. Intelligence Community Directive (ICD) 203: Analytic Standards. 2023. https://www.dni.gov/files/documents/ICD/ICD-203.pdf
  5. Sherman Kent. "Words of Estimative Probability." Studies in Intelligence, Vol. 8, No. 4, Central Intelligence Agency, 1964. https://www.cia.gov/resources/csi/studies-in-intelligence/archives/vol-8-no-4/words-of-estimative-probability/
  6. UN Office of the High Commissioner for Human Rights and Human Rights Center, UC Berkeley School of Law. Berkeley Protocol on Digital Open Source Investigations. United Nations, 2022. https://www.ohchr.org/en/publications/policy-and-methodological-publications/berkeley-protocol-digital-open-source
  7. Bellingcat. Bellingcat's Online Investigation Toolkit. 2024. https://bellingcat.gitbook.io/toolkit
  8. Eliot Higgins (Bellingcat). "A Beginner's Guide to Geolocating Videos." 2014. https://www.bellingcat.com/resources/2014/07/09/a-beginners-guide-to-geolocation/
  9. Bellingcat. "Searching the Earth: Essential Geolocation Tools for Verification." 2015. https://www.bellingcat.com/resources/how-tos/2015/07/25/searching-the-earth-essential-geolocation-tools-for-verification/
  10. Michael Bazzell and Jason Edison. OSINT Techniques: Resources for Uncovering Online Information, 11th ed. IntelTechniques.com, 2024. https://inteltechniques.com/books.html
  11. Claire Wardle and Hossein Derakhshan. Information Disorder: Toward an Interdisciplinary Framework for Research and Policymaking. Council of Europe (DGI(2017)09), 2017. https://rm.coe.int/information-disorder-report-version-august-2018/16808c9c77
  12. Claire Wardle. "Fake news. It's complicated." First Draft, 2017. https://firstdraftnews.org/articles/fake-news-complicated/
  13. Daniel Kahneman. Thinking, Fast and Slow. Farrar, Straus and Giroux, 2011. ISBN 9780374275631.
  14. Cherilyn Ireton and Julie Posetti (eds.). Journalism, "Fake News" & Disinformation: Handbook for Journalism Education and Training. UNESCO, 2018. https://www.unesco.org/sites/default/files/journalism_fake_news_disinformation_print_friendly_0.pdf
  15. Headquarters, Department of the Army. FM 2-22.3, Human Intelligence Collector Operations, Appendix B: Source and Information Reliability Matrix. 2006. https://irp.fas.org/doddir/army/fm2-22-3.pdf
  16. Headquarters, Department of the Army. Army Regulation 25-50, Preparing and Managing Correspondence. 2020. https://armypubs.army.mil/epubs/DR_pubs/DR_a/ARN42124-AR_25-50-007-WEB-13.pdf

Go From Reading About Defensible OSINT to Being Able to Prove It

Everything above is the what. Turning it into a repeatable practice, one that holds up in a report, a declaration, a regulatory filing, or a courtroom, is the how, and that is exactly what the Certified OSINT Investigator, Court-Ready Practitioner (COI-CRP) course was built to teach.

COI-CRP is a self-paced online program that connects every search, every capture, every pivot, and every conclusion back to admissibility and cross-examination:

Tuition is $2,497. Government purchase orders and net-30 invoicing are accepted, and agency licensing is available at 10, 25, and unlimited seats for procurement and grant cycles.

Enroll or view the full syllabus: thewaldrepcompany.com/courses/coi-crp

Not ready to enroll? Download the full course syllabus as a free PDF from the page above. For agency or PO-based enrollment, call (251) 216-1164.

The COI-CRP program is professional education, not legal advice, and does not create an attorney-client or expert engagement. Tool references are conceptual and drawn from publicly available documentation.

Take it further

This guide is the method. The Certified OSINT Investigator (COI-CRP) course is the practice: 10 modules and 80 lessons that work every one of these practices against realistic taskings, with a 100-question final exam and a verifiable credential at the end. It is self-paced, and agencies get 25% off five or more seats.

For attorneys: if an open-source report has already landed in your matter, the same eight practices are the review standard. An Opposing Expert Report Review ($2,750 flat) applies them to the other side's work before deposition.

Take the field guide with you

The PDF edition has the eight practices, the capture and chain-of-custody section, and the field checklist in a print-friendly layout. Enter your email and the download link appears here; a copy also goes to your inbox.

Eric L. Waldrep

Digital forensics examiner and court-qualified expert witness. 27 years in law enforcement, 19 years in digital forensics, and testimony in federal and state courts. U.S. State Department ATA Cyber Mentor and Magnet Certified Forensics Examiner (MCFE).