OSINT book
Intelligence-Driven Incident Response
Scott J. Roberts & Rebekah Brown
An O’Reilly text on how CTI and IR teams use intelligence — including open sources — to prioritise detection and response. It is not a people-search OSINT manual; it is the framing that keeps enrichment from becoming hobby collecting.
Who it’s for
- SOC and IR analysts who enrich alerts with open sources
- CTI analysts writing for operators, not for slides
- Security engineers connecting collection to outcomes
What you get
- Process models for adversary-focused incident response
- Language for prioritising collection during an incident
- A bridge between OSINT enrichment and SOC decision-making
How to use it
- 01
Read before you buy more tools
If your enrichment does not change a ticket decision, you do not need another provider — you need this framing.
- 02
Map chapters to your runbooks
Take one incident type (phishing, exposed host, leaked credential) and rewrite the runbook with intel questions first.
Strengths
- Connects open sources to detection and response outcomes
- Useful shared vocabulary for SOC + CTI handoffs
- Keeps OSINT honest about purpose
Watch out for
- Not a beginner OSINT techniques book
- Confirm current edition/ISBN with O’Reilly or your bookseller
Related in the directory
- GuideRead
OSINT for cybersecurity teams
From alert enrichment to infrastructure exposure — using open and commercial sources without pretending they replace a SIEM, EDR, or TIP.
- NewsletterRead
SANS Internet Storm Center
Handler diaries and Stormcast at the edge of malware, internet observation, and threat awareness — OSINT-adjacent situational awareness for CTI-minded readers, not a people-search letter.
- BookRead
OSINT Techniques
The practical field manual most investigators mean when they say “the Bazzell book.” Current editions focus on self-hosted VMs, people and social search, breach and stealer data, and a repeatable investigation workflow — not theory for its own sake.
FAQ
Questions, answered
What is Intelligence-Driven Incident Response?
An O’Reilly text on how CTI and IR teams use intelligence — including open sources — to prioritise detection and response. It is not a people-search OSINT manual; it is the framing that keeps enrichment from becoming hobby collecting.
Who is this book for?
SOC and IR analysts who enrich alerts with open sources; CTI analysts writing for operators, not for slides. You’ll get: Process models for adversary-focused incident response; Language for prioritising collection during an incident.