Skip to content

OSINT Techniques: Resources for Uncovering Online Information

by Michael Bazzell & Jason Edison

The definitive intelligence analyst's manual. A highly technical, no-nonsense blueprint for building your own investigative infrastructure and abandoning fragile, third-party OSINT tools.

“Stop relying on other people’s websites to do your investigations. Build the infrastructure yourself.”

Every OSINT bookmark folder has the same problem. Half the entries are dead, a quarter have moved behind a paywall, and the ones still working could be gone by the time you need them on a live matter. Being good at this was never supposed to mean curating a list of other people’s websites and hoping they survive the week.

The 11th Edition of OSINT Techniques is where that becomes explicit. Its argument is that a bookmark collection is not a capability, and that anyone who depends on one is a tourist on infrastructure they do not control.

The Problem With Modern OSINT

The scraping era is over. Free Twitter API access ended in 2023, Facebook and Instagram have spent years closing the gaps that made bulk collection trivial, and the reliable free tooling of five years ago is mostly abandoned repositories. Any OSINT book that predates this shift is a directory of dead links.

Michael Bazzell — a former FBI Cyber Crimes investigator — and Jason Edison do not merely note the problem. They restructure the discipline around it, and the answer is unglamorous: stop depending on other people’s interfaces and move the work to your own machine.

The Shift in Thinking

The change is structural rather than tactical. Earlier editions said “here is a site that checks breach data”. This one says: here is how to acquire the raw breach corpora and stealer logs yourself, here is how to index them, and here is the script that queries them locally in milliseconds.

That reframes what “open source” means. The book walks you through building an isolated, hardened Linux VM (or a dedicated macOS setup) for intelligence work, then through acquiring, curating and indexing your own datasets, so the question “was this address in a breach” is answered by your disk rather than by a third party’s server. The operational advantage is not speed. It is that you never tell an external service which address you are interested in — a query to a lookup site is itself intelligence, about you, handed to someone whose logging policy you cannot audit.

The cost is proportionate. You now hold terabytes of other people’s credentials on hardware you are responsible for, which is a legal and ethical position that varies enormously by jurisdiction and by the authority you are operating under. The book is better on the mechanics of this than on the boundaries, and the boundaries are where people get into trouble.

Real-World Relevance

The technical level of this edition is the thing that distinguishes it. It does not simplify.

The section on stealer logs and ransomware intelligence is the one worth the price. Acquiring and parsing the output of info-stealing malware families such as RedLine or Vidar, without contaminating your own operational security in the process, is not covered anywhere else in the mainstream literature. It is also the section that requires the most judgement about what you are permitted to do with the results.

Infrastructure analysis is close behind — historical DNS, IP range correlation, pivoting through registration history, all through command-line tools and direct API calls rather than web portals. The bash aliases and Python scripts included turn what is otherwise an afternoon of tab-switching into a repeatable local workflow. Repeatability matters more than speed: a workflow you can rerun identically in six months is a workflow whose results you can defend.

Who Is This Book REALLY For?

  • Professional intelligence analysts and threat hunters: If the job is tracking actors, attributing operators or mapping adversary infrastructure, this is the current reference and there is no close second.
  • Law enforcement and private investigators: The material on evidence preservation, chain of custody and avoiding contamination is written by people who have had to defend this work under examination.
  • Red teamers and social engineers: The reconnaissance methods build target profiles accurate enough to make a pretext land, which is exactly why the OPSEC chapters are not optional reading.

Who Is This NOT For?

  • The casual searcher: Trying to identify a nuisance caller or run a quick background check? This is a large, expensive book that expects you to install Linux first. Wrong tool.
  • Anyone avoiding the terminal: There are very few graphical interfaces here. If grep, awk and sed are unfamiliar, chapter three is where you stop.
  • People wanting a permanent answer: The APIs and methods will break — that is the premise of the book. The authors maintain a private update site for purchasers, but keeping the capability working is ongoing labour, not a one-time setup.

The Honest Drawbacks

It is exhausting. Effectively a textbook, and the volume alone is enough to stall people before the first real search, because the baseline VM build and script configuration come first and take days.

The OPSEC standards it demands — isolated search traffic, burner VoIP numbers, compartmentalised identities — impose real friction on daily work, and friction is what people quietly abandon at month three when a deadline is close. That is the failure mode to watch for in yourself. The safeguards do not announce their absence; they simply stop being there, and nothing goes wrong until the one investigation where it matters.

The Bottom Line

OSINT Techniques is less a book than a curriculum you get through. It moves you off an unstable public ecosystem and onto infrastructure you own and maintain.

If you want to know what serious online investigation looks like now — as opposed to what the web portals and the film industry suggest — this is the reference. It will find the gaps in your technical knowledge without much sympathy, and then it will show you how to close them.

Advertisement

Share article

Sponsored Links

Subscribe to my newsletter

Receive my case study and the latest articles on my WhatsApp Channel.

Warning

Ask CyberROX AI