Open Source Intelligence
Investigations

We find everything a determined adversary could discover about you from public sources — then show you exactly how to reduce it.

100+ Open Sources
Full Digital Profiling
Legal Proceedings Ready
Get a Confidential Assessment →

Tailored pricing · Dedicated specialist · Confidential engagement

The Intelligence Hidden in Plain Sight

Open Source Intelligence — OSINT — is the systematic collection and analysis of information from publicly accessible sources. Intelligence agencies use it. Law enforcement uses it. Private investigators use it. And so do malicious actors. The digital ecosystem has made it extraordinarily powerful: a determined analyst can build a detailed, multi-dimensional profile of virtually any individual without touching a single private system.

Social media, professional networks, public records, electoral rolls, court filings, company registration data, domain records, news archives, forum posts, image metadata, and data broker sites all feed into an open-source picture of a person's life. In the hands of a skilled analyst, these fragments connect — revealing not just who someone is, but where they live, who they associate with, what they own, and where they're exposed.

For most people, that picture already exists in full. The question isn't whether it can be assembled. It's whether you know what it contains — and whether you're doing anything about it.

What Our OSINT Investigations Uncover

Our OSINT Investigations service runs a thorough intelligence sweep using the same methodology a well-resourced adversary would use. We build the fullest possible picture of what's publicly accessible about a subject and deliver it as a structured report — mapping every significant data category, surfacing connections between digital and physical identity markers, and giving you a clear view of the complete exposure profile.

Personal Identity

  • Full legal name & aliases
  • Date of birth indicators
  • Current & historical addresses
  • Phone numbers & email addresses
  • Physical descriptors & photographs

Social & Professional

  • Social media accounts & activity
  • Professional profile history
  • Interests & affiliations
  • Public statements & opinions
  • Event & location check-ins

Financial & Legal

  • Business registrations & directorships
  • Property ownership records
  • Court records & legal filings
  • Financial disclosure documents
  • Bankruptcy & insolvency records

Network & Relationships

  • Family member identification
  • Known associates & connections
  • Organisational affiliations
  • Mutual account relationships
  • Physical & digital co-location data

For Red Team Operations and adversarial threat modelling, we go further — email address variants, password breach records, photographs and metadata, active online accounts on obscure platforms, IP address history, and exposed network infrastructure including open ports and accessible portals.

  • Full Discovery report: all publicly accessible information compiled, correlated, and presented in a structured intelligence product
  • Personal threat assessment: which discovered information creates the greatest risk, and to whom it would be most valuable
  • Digital/physical identity connection mapping — how online and offline identities are linked through open-source data
  • Remediation guidance: specific steps to remove or obscure the most harmful exposures
  • Red Team Operations support: email permutations, breach data, account enumeration, IP history, and infrastructure reconnaissance

Protection and Investigation

This service works two ways. For individuals and organisations wanting to understand and reduce their own exposure, it gives you the complete picture you need to make informed decisions about privacy remediation and security hardening. For clients with a legitimate investigation need — due diligence, threat actor identification, fraud investigation, pre-transaction background research — it provides the depth of open-source intelligence needed to support those decisions and any resulting legal proceedings.

All investigations use publicly accessible sources only and stay within applicable legal boundaries. Findings are delivered in clear, structured reports suited to internal use, security briefings, or legal and regulatory contexts.

Analyst-Led Intelligence
From Public Sources

Our analysts use the same methodologies as sophisticated threat actors — so you know exactly what they see.

Full Discovery Profiling

We sweep all publicly accessible information sources — social platforms, professional directories, court records, company filings, data broker aggregators — to build a complete subject profile.

Personal Threat Assessment

We assess which elements of the discovered profile pose the greatest risk — identifying the most exploitable attack vectors and contextualising exposure based on the subject's role, status, and specific threat environment.

Identity Connection Mapping

We surface the connections between a person's digital and physical identities — showing how disparate online accounts, records, and behaviours can be correlated to reveal things that were never meant to be public.

Remediation & Red Team Support

We provide specific remediation guidance on what to remove and how. For red team operations, we extend coverage to technical intelligence: breach data, IP history, open network ports, and accessible web portals.

How OSINT Investigations Work

A structured, analyst-led investigation delivering usable intelligence from publicly accessible sources.

1

Subject Definition & Scope Agreement

We start with a confidential briefing to establish the subject, the purpose, and the scope of intelligence required. Personal exposure audit, due diligence, threat actor profiling, or red team support — we define clear parameters and deliverables upfront. All engagements use publicly accessible sources only.

2

Intelligence Collection & Correlation

Our analysts run a systematic, multi-layer sweep across the full spectrum of open-source channels relevant to the subject. Data is collected, cross-referenced, and correlated — individual fragments turning into a coherent intelligence picture. Red Team extensions layer in technical reconnaissance alongside open-source profiling.

3

Report Delivery, Threat Assessment & Remediation

Findings are compiled into a structured intelligence report presenting all discovered information alongside a personal threat assessment that prioritises the most significant exposures. For protective engagements, the report includes specific remediation guidance. For investigative engagements, findings are formatted for briefings, legal proceedings, or further investigative action.

Common Questions

What sources do you investigate?
We work across 100+ open sources — social media, public records, corporate filings, court documents, domain registrations, archived web content, forum posts, and media mentions. Everything stays within legal boundaries.
Is OSINT investigation legal?
Yes. OSINT uses only publicly available information. Our investigators work within strict legal and ethical guidelines, and every finding is documented with full source attribution — suitable for evidential use if required.
How is the report delivered?
You receive a written report with an executive summary, detailed findings, risk assessment, and recommended actions. We can format it for legal proceedings, board presentations, or internal security reviews.
Can OSINT be used for due diligence?
Yes. OSINT investigations are widely used for pre-employment screening, M&A due diligence, litigation support, and third-party risk assessment. We tailor the scope to what you actually need.

Discover Your Full Digital Footprint

Protecting yourself starts with knowing what's already visible. Commission a Full Discovery investigation and see what adversaries see.

Start Your Assessment →