Beginner
Open Source Intelligence Techniques
Michael Bazzell
Best on-ramp from curious to operational. Dense, practical, updated across editions.
Learn · Read · Connect
We don’t own these materials. OSINTverse curates them so it’s easier to learn and improve OSINT skills. Credit stays with the original authors, publishers, and communities.
Five shortlists — learning path, books, guides, newsletters, and communities. Credit stays with the original authors and hosts.
OSINT learning path
A curated skill sequence — not an OSINTverse-owned course product.
OSINT books
Recommended titles from authors and publishers in the field.
OSINT guides
Practical playbooks and reading paths we point people to first.
OSINT newsletters
Independent and community letters worth your inbox.
OSINT communities
Discords, forums, Telegram, and events run by others in the craft.
A suggested skill order — not an OSINTverse-owned course. Start with the first three focus areas below.
OSINT foundations and ethics
What counts as open-source intelligence, legal boundaries, source hygiene, and how to document findings for someone else to reproduce.
People and identity collection
Username, email, phone, and face pivots — how to chain public and commercial sources without drowning in noise.
Infrastructure and surface mapping
Domains, WHOIS history, DNS, hosting, and Shodan-style exposure — mapping an organisation without guessing.
5 focus areas · pair with books and communities we curated
Titles by independent authors — we curated the shortlist, we don’t publish them.
Beginner
Michael Bazzell
Best on-ramp from curious to operational. Dense, practical, updated across editions.
Beginner
i-intelligence / NATO CCDCOE contributors (editions vary)
Strong for teams writing SOPs and training junior analysts.
Intermediate
Justin Seitz & friends (Black Hat Python lineage)
Bridges analyst craft and engineering without requiring a full platform rebuild.
Entry-point playbooks we shortlisted — some ours, many pointing into the wider field.
People search OSINT: email, username, and phone pivots
How to start from a single seed, validate matches across providers, and stop when the dossier is good enough to brief.
Corporate risk OSINT playbook
Vendor diligence, brand abuse, and executive exposure — which SearchIn providers to run first and what to document.
OSINT for cybersecurity teams
From alert enrichment to infrastructure exposure — using open and commercial sources without replacing your SIEM.
Independent and community letters — curated so you can skip the noise.
Investigations & methods
Bellingcat
Investigation write-ups, methodology, and community notes from the open-source investigation outlet that set the modern bar for public verification.
Tips & techniques
Sector035
A long-running OSINT tip letter — tools, techniques, and weekly field notes that many analysts still treat as required reading.
Community & craft
OSINT Curious
Community-driven OSINT writing and event cues from a collective that has trained and convened practitioners for years.
Spaces run by others (plus a few we host and label). Curated starting points.
Bellingcat Discord
Large public community around open-source investigation — channels for methods, geolocation, and peer review when you follow the rules.
OSINT Curious
Long-running community and event series for practitioners who want craft talk without vendor theatre.
Trace Labs
Volunteer missing-persons OSINT challenges and community — structured practice with ethical guardrails.
Resources teach judgment. SearchIn is optional practice on prepaid providers — separate from the curated lists above.