Tradecraft
OSINT tradecraft
Open-source intelligence is the disciplined collection and analysis of information that is publicly and lawfully available — records, registries, web content, technical footprints and published documents. Good tradecraft is not about finding more data; it is about collecting it methodically, documenting where each item came from, and separating what a source actually says from what an analyst infers. The rigour lives in the process, not the volume.
Correlation
Entity resolution
Entity resolution is the work of deciding when two records — two names, two accounts, two companies — refer to the same real-world thing. Names are shared, spellings drift, and identifiers are reused, so a match is a judgement supported by evidence rather than a certainty. Done well, it keeps distinct entities apart and merges genuine duplicates while preserving the reasoning behind every decision.
Infrastructure
Infrastructure & domain intelligence
Digital infrastructure leaves a connectable trail. Domains, hosting, name servers and TLS certificates create relationships that recur across seemingly separate operations. Studying registration records, DNS history and certificate data can reveal that unrelated-looking sites share an origin — but shared hosting is common, so analysts must distinguish confirmed overlap from coincidental co-location.
Identity
Digital identity & aliases
People present fragmented identities online: usernames, email addresses, handles and reused identifiers spread across platforms. Correlating these fragments can reconstruct a coherent identity picture, but reuse of a common handle is weak evidence on its own. The discipline is to cluster identifiers, weigh how distinctive each one is, and keep probable associations clearly separate from verified ones.
Reputation
Adverse media analysis
Adverse media analysis reviews public reporting, court records and other published sources for material that bears on a subject’s reputation or risk. The value is in context and corroboration: a single unverified article is a lead, not a finding, and allegations must be distinguished from established outcomes. Careful analysis records the source, its date and its reliability alongside every claim.
Blockchain
Digital-asset & blockchain research
Public blockchains record transactions in an openly readable ledger, which makes address activity, flows and counterparties researchable. Analysis clusters addresses, follows public transaction paths and correlates on-chain indicators with off-chain context. It is research on publicly available data — it does not identify a person from an address by itself, and it does not recover, seize or move assets.
Evidence
Evidence provenance & integrity
Provenance is the documented history of an item of evidence: where it originated, when and how it was collected, and whether it has remained unchanged since. Integrity is often demonstrated with cryptographic hashes and preserved timestamps. Without provenance, even accurate information is hard to rely on later, because no one can show that what is being reviewed is what was originally found.
Assessment
Source evaluation & confidence
Not all sources deserve equal weight. Evaluation considers a source’s reliability and the credibility of the specific information it provides, and expresses the result as an explicit confidence level rather than a false binary. Independent corroboration raises confidence; conflicting sources lower it and are flagged rather than silently reconciled. Making uncertainty visible is a feature, not a weakness.
Corporate
Corporate ownership structures
Ownership rarely sits in a single record. Holding companies, nominee arrangements and cross-border structures can separate the entity on a filing from the parties who actually control it. Mapping directors, shareholders and connected entities across registries builds a structural picture — while noting that public filings can be incomplete, outdated or deliberately opaque.
Monitoring
Continuous monitoring
Intelligence has a shelf life. Directors change, domains move, new certificates appear and fresh associations emerge after a report is delivered. Continuous monitoring watches selected entities, identities and infrastructure for material change and surfaces it in the context of the original investigation — so an update is a meaningful signal, not a contextless alert.