OSINT Flashcards
What are the four distinct categories of open information and intelligence according to Nato handbook?
- Open source data - raw print, broadcast, oral or any other form from a primary source, photo, most things on internet etc
- Open source information - generic information that is widely disseminated - news papers
- Open source intelligence - information that has been discovered to a select audience
- OSINTV - very high reliable OSINT (classified documents)
What is socmint
Social media intelligence
What is humint
Human source Intelligence
What is a definition of OSINT?
-Intelligence collection management, finding, selecting, acquiring information from publicly available sources, analyzing and producing actionable intelligence
What is OSINT not?
-Not hacking, spying, not invented by LE, not necessary free, not just internet
What are some sources of OSINT?
- Libraries (off and online)
- Online TV shows
- Government sources
- Business sources
- Academic sources
- Satellite and maps
- Online media
- Social media
- Deep/Dark web
What steps should you take in an online investigation?
- Intake and orientation
- Strategy, search and store
- Technical capabilities, tactical applications
- Analysis (GUID’s)
- Refine, recycle and reporting
What does Intake and orientation mean?
-Where are you going to look? What are you looking for, how much time do you have?, why do you want to know?
What does strategy, search and store mean?
-Consider what strategy you will use and how will you store results
What does Technical capabilities, tactical applications mean?
-Search engine, URL slicing etc
What does analysis mean?
-You have to constantly analysis information and look for global identifier such as email address
What does refine, recycle and report mean?
You constantly refine searches and report
What are four categories of information needs?
- Event eg crime, earthquake
- Theme eg drugs on internet stats
- Organisation eg business, gang
- Person eg background, profiling
What are some useful search techniques
- Unique quriers
- GUID
- use exact phrases
- Use capitals for names
- Translate your keywords
- Use place names
- Use catchphrases
- Add or exclude with + or -
- Use wildcards searches with *
- Use fuzzy search
- Use slang
- Use multiple search engines
What are some operators you can use?
- intitle - must be in the title of the website
- allintitle - all words in title of website
- inurl - must be in the url of the website
- allinurl - all worlds in the url of the website
- site - only seach in that domain eg: Jason site:twitter or site:nz
- file type - pdf, doc
- period - withing a time period eg period:1907…1921
What are some methods for searching for information on net?
- Global search (short internet scan) SIS
- Thorough search
What are the 7 golden W’s?
- What
- Where
- Who
- When
- Why
- What why?
- With what?
What are some search styles and strategies?
- Building blocks = using AND
- Pearl growing =grow quries from relevant documents
- Successive fractions = add bits of data as you go
- Interactive scanning = Researcher has not yet had a good overview but pick out keywords to use
- Berry picking = start with one keyword and build
How can we check something is reliable?
- First hand information likely to be
- Never trust a single source
- Verify facts with as many different sources as possible
- Check the link popularity
- What do other sources say about it (comments, reviews)
- Reliable website (big organisation)
What can we do with an IP address?
- Whois and IP information
- Reverse DNS
- Web and CML queries