Introduction: Why "Architecture," Not "Collection"

When people hear OSINT (Open Source Intelligence), they usually picture a list: this site, that tool, this Google dork, that Telegram bot. But the truth is, a tool list isn't OSINT — it's OSINT's raw material. What separates one framework from another isn't how many tools it has, but the architecture through which the raw data from those tools gets processed.

My goal here isn't to write a "use these 50 tools" list. Instead, I want to walk through, layer by layer, how a raw digital trace (a username, an email, an IP, a piece of metadata) moves through a pipeline and becomes actionable intelligence — verified, contextualized information you can actually build decisions on. At the end, I'll get into the genuinely contested parts of this field: the ethical limits of automation, the "collection vs. targeting" distinction, and the data asymmetry problem.

1. The Intelligence Cycle: The Backbone of OSINT

The classic "intelligence cycle" from military and intelligence literature also forms the foundation of OSINT frameworks: