Personal Field Guide
OSINT Manual
Each chapter ends with Practical Exercises and a Suggested Approach section — this is meant to be worked through, not just read.
Part A — Foundations
- Chapter 1: Principles of OSINT, Methodology & the Legal/Ethical Framework
What OSINT actually is, passive vs. active collection, and the legal/ethical lines that matter.
- Chapter 2: The Research Cycle: Hypothesis → Collection → Verification → Correlation
The Intelligence Cycle, the NATO Admiralty code, thinking like an adversary, and the core hypothesis-driven loop.
Part B — Core Collection Techniques
- Chapter 3: Advanced Search & Google Dorking
How search engines index the web, Google dorking, cache/archives, and pivoting methodology.
- Chapter 4: Identity Investigation
Email forensics, digital identity, username correlation, deanonymization, and confidence scoring.
- Chapter 5: Social Media Intelligence
Pattern-of-life analysis, cross-platform correlation, social network analysis, and mis/dis/malinformation.
- Chapter 6: Image & Media Forensics
Reverse image search, EXIF/IPTC/XMP metadata, manipulation detection, and video frame extraction.
- Chapter 7: Geolocation & Mapping
The 7-step geolocation workflow, environmental indicators, mapping tools, and historical geolocation.
Part C — Specialized Fields
- Chapter 8: Dark Web & Deep Web Investigations
Surface, deep, and dark web distinctions, safe access, and what's actually there.
- Chapter 9: Domain & Network Infrastructure OSINT
WHOIS, DNS, subdomain enumeration, and internet-wide scanning.
- Chapter 10: Financial Intelligence & Cryptocurrency Tracing
Traditional financial intelligence plus cryptocurrency wallet and transaction tracing.
- Chapter 11: Automating OSINT with Python & APIs
APIs, JSON, scraping, regex, and automating the routine parts of OSINT work.
- Chapter 12: Corporate Due Diligence
Corporate structure, official registries, shell-company tells, and a due-diligence workflow.
- Chapter 13: Disinformation & Verification
Verification methodology and the current state of AI-generated content and deepfakes.
Part D — Operational Matters
- Chapter 14: OPSEC for Investigators
Threat modeling, attribution risk, browser/account separation, and sock puppet discipline.
- Chapter 15: Analysis, Correlation & Report Writing
Report structure, confidence scoring, and a full worked capstone example.
Part E — Applied Domains
- Chapter 16: OSINT for Counter-Terrorism & Radicalization Indicators
Behavioral/linguistic radicalization indicators, Explainable AI (XAI), crowd-sourced intelligence (Crosint), chaos-theory pattern detection in large datasets, and legal/ethical guardrails.
See also the Appendix: Tools & Resources.