📅 Day 233 — OSINT: Turning Public Information into Security Intelligence (Google Cybersecurity Certificate)
🔄 Topic
Closing out this stretch of the Google Cybersecurity Certificate, I studied open-source intelligence (OSINT) — the practice of turning publicly available information into usable security intelligence — and the specific distinction between information and intelligence that makes OSINT a discipline rather than just “looking things up.”
🎯 Goal
Understand the difference between information and intelligence, why OSINT matters for vulnerability management and threat detection, and which real OSINT tools security professionals actually reach for.
🛠 What I Did
I worked through the conceptual distinction first, then the practical toolset.
Main areas covered:
- learned the core distinction: information is raw data or facts about a subject; intelligence is what you get after analyzing that information to produce insight that actually supports a decision — the same underlying facts, but intelligence is what you did with them
- worked the example directly: news that an OS update was released is information; discovering through further research that new threats have been linked to that specific update is the analysis that turns it into intelligence guiding a real decision (whether to roll the update out to workstations)
- learned OSINT’s role in InfoSec specifically: monitoring forums and communities for emerging vulnerability discussions, then using that intelligence to prioritize patching before an exploit becomes widespread — treated as a real example of turning a public forum post into an operational security decision
- learned OSINT’s four main uses in vulnerability management: providing insight into past attacks, detecting potential data exposures, evaluating existing defenses, and identifying unknown vulnerabilities
- reviewed real OSINT tools by name and purpose: VirusTotal (analyzing suspicious files, domains, URLs, and IPs for malicious content), MITRE ATT&CK (a knowledge base of real-world-observed adversary tactics and techniques — the same framework I’ve been informally referencing in my own investigation questions all along), OSINT Framework (a web-based directory of OSINT tools organized by source/platform type), and Have I Been Pwned (searching whether an email account has appeared in a known breach)
- learned that OSINT sources are genuinely broad — search engines, social media, discussion boards, blogs — and that the actual skill isn’t access to information (nearly all of it is public) but the discipline of finding what’s relevant and analyzing it into something decision-useful
🔗 Key Cybersecurity Connections
The information-versus-intelligence distinction reframes something I’ve been doing informally throughout this whole month of infrastructure work without naming it: a raw git log entry or a bug report is information; deciding it represents a recurring pattern worth a standing check (the false-assurance pattern I named and hunted systematically a few weeks back) is the analysis step that turns it into something actionable. OSINT formalizes exactly that habit and applies it to publicly available threat data instead of internal system logs.
The MITRE ATT&CK framework specifically closes a loop I’d already half-built on my own — every blog post in this series that includes a “MITRE ATT&CK Techniques” section has been informally referencing this exact knowledge base without treating it as a named external resource. Recognizing it as a formal, citable, real-world OSINT tool (built from real observed adversary behavior, not theoretical) means I can treat future technique mappings as grounded lookups rather than best-guess associations.
🔍 Investigation Questions
- Am I treating a piece of raw information as a decision-ready conclusion, without doing the analysis step that would actually make it intelligence?
- Is there a public forum, advisory feed, or vulnerability disclosure channel relevant to my stack that I’m not monitoring at all?
- Would VirusTotal or Have I Been Pwned catch something relevant to my own systems or accounts if I checked right now, rather than waiting for an incident to prompt it?
- When I reference a MITRE ATT&CK technique, am I treating it as a grounded citation or an informal guess dressed up with a technique ID?
- Does my OSINT gathering stop at “found the information” or does it continue through to “here’s the decision this supports”?
🚨 Detection Opportunities
Checks for OSINT practice maturity:
- raw information treated as an actionable conclusion without an analysis step connecting it to a real decision
- no monitoring in place for public vulnerability disclosures relevant to actively-used software
- accounts or domains never checked against breach databases like Have I Been Pwned
- suspicious files or URLs handled without a VirusTotal (or equivalent) check before further action
- MITRE ATT&CK technique references used loosely rather than grounded in the framework’s actual documented tactics
Example:
project=osint-practice-review
signal=information_treated_as_intelligence_without_analysis
risk_area=decision_made_on_unanalyzed_raw_data
triage=add_explicit_analysis_step_before_acting_on_public_information
🧭 MITRE ATT&CK Techniques
No direct mapping claimed for this material itself — it’s about the intelligence-gathering discipline (including MITRE ATT&CK as a resource) rather than an adversary technique, though OSINT reconnaissance by an adversary maps to:
- T1593 — Search Open Websites/Domains (the adversary-side mirror of the same OSINT skill studied here, used defensively instead of offensively)
🗺 Visual Investigation Diagram
Raw public information (forum post, news, breach dump)
↓
Analysis: does this apply to my systems, and what does it mean?
↓
Intelligence: a decision-ready insight
↓
Tools: VirusTotal / MITRE ATT&CK / OSINT Framework / Have I Been Pwned
↓
Action: prioritize a patch, flag an exposure, evaluate a defense
⚠ Challenges
The hardest part was resisting the temptation to treat “information” and “intelligence” as basically synonyms — they’re used almost interchangeably in casual conversation, and building the habit of asking “have I actually analyzed this, or just found it” took deliberate practice against the reading’s own worked example.
📚 What I Learned
I learned that OSINT isn’t really about access — nearly everything involved is public and searchable — it’s about the analytical discipline of turning a flood of available information into a small number of decisions actually worth making. I also learned that a framework I’d been informally leaning on throughout this whole blog (MITRE ATT&CK) has a name, a real methodology behind it, and a place in the formal OSINT toolkit I can now use more deliberately.
➡ Next Steps
- Check my own email accounts against Have I Been Pwned as a concrete first application of this material
- Identify one or two public vulnerability-disclosure or advisory sources relevant to my actual stack and start monitoring them
- Practice explicitly separating “information found” from “intelligence produced” in future investigation write-ups
- This closes out the current study stretch — next session picks up wherever the certificate continues from here
🧠 Reflection
This felt like a good note to end this study block on: a reminder that everything I’ve been doing across encryption, hashing, AAA, vulnerability management, and defense in depth converges on the same underlying skill — take something true, figure out what it actually means for a real decision, and act on that instead of on the raw fact alone.
🧩 Lessons Learned
What worked
Learning the information-versus-intelligence distinction through a concrete worked example, then immediately connecting it to a framework (MITRE ATT&CK) I’d already been using informally throughout this blog.
What broke
Nothing broke — this was concept study, closing out a dense stretch of encryption, AAA, vulnerability management, and OSINT material.
Why it mattered
OSINT is the discipline that turns the internet’s enormous public information surface into a manageable, decision-relevant security practice.
Fix / takeaway
Always ask whether a piece of public information has actually been analyzed into something decision-ready before acting on it, and use named, real tools (VirusTotal, MITRE ATT&CK, Have I Been Pwned) rather than ad hoc searching alone.
📈 Skill Progression Context
This supports my cybersecurity progression because OSINT is a core reconnaissance and threat-intelligence skill used constantly by both defenders and attackers, and recognizing MITRE ATT&CK as a formal resource I can now cite deliberately strengthens every future post in this series that references adversary techniques.
😄 TL;DR
The internet already has almost everything you need to know — OSINT is just the discipline of turning “I found this” into “here’s what I’m doing about it,” and it turns out I’ve been half-doing that with MITRE ATT&CK this whole time without realizing it had a name.
