OSINT: Open Source Intelligence
Methodology
- Planning and Requirements
- Collection
- Processing and Evaluation
- Analysis and Production
- Dissementation and Consumption
- Repeat
Subject Intelligence
Intelligence about a person and direct metadata (address, name, email, accounts, …)

Social Media of a Subject/business
-
Note that especially younger generations might have multiple accounts for various audiences (friends, themselves, a business, ….)
-
MIS/DIS/MAL-information
- Misinfoformation: Misleading or incorrect information that is not knowlingly deceptive.
- Example: Grandma posts article about vitamines curing cancer.
- Misinfoformation: Misleading or incorrect information that is knowlingly deceptive/deliberate.
- Usually entirely fabricated.
- Example: Mascot from one team posts false information about competing mascot, about being arrested for assault.
- Malinformation: Based in reality but is purposfully harmfull. It’s is based on reality but shared out of context or intent to cause harm.
- Example: Political party post fake story of immigrant assaulting a native woman to ignite hated.

Business and Organisational intelligence
- Usual data points
- Corporate/business structure disclosures
- Parent
- Subsidary
- Holding companies
- Contract disclosures
- Government Contracts > Usually public by law > You can check if a given organizatio had government contracts
- Sounds boring, but very juicy details can be found, especially in appendix
- Technologies, subcontractors used, blueprints, contacts, building specs,…
- Financial Records / annual reports
- Affiliation and relationship disclosures
- Procurement / supply chain disclosures
- Innovative / proprietary technology disclosures
- Business discretions and lawsuits
- santions / illegal activity
- Public disclosures
- Published material disclosures
- Public companies must submit reports, so that helps with public companies
- Social media and other public info allows to pivot to subject intelligence
- Recognizing Oranizational Crimes
- Be informed about sanctions to know if someone is doing shady stuff
- Non profit are not allowed various things, non profits can be often used to attract funds for good things but in practice do other things that benefit private persons for example.
- Non profits usually have less oversight, that’s why they’re so tempting for fraud.
- In every country normally non profits have to do some declarations or statements that should be publicly available . Or they might self publish reports to attract trust.
- Organizations Domain / Site / IP
- Look at robots.txt of any site for potential attempted hidden stuff
- Search for a domain, you might find what other sites refer to the site, that can uncover stuff.
- The content of a site can indicate if the site is fraudulent, just a quick shell, images and text can be analyzed or reverse searched to see if it’s stock or fake, fotoforensics etc…
- If content is legit, it can tell alot about partners, customers, org, employees, structure, contacts, social media, …
- Website metadata
- Find hidden but public data by google dorking :
site: tandbergeiendom.no ext:docx | ext:xlsx | ...
- Use FOCA for screening a site
- IPs can show connections or shared infrastructure between seemingly unrelated organizations . Remember, a single hosting can run for various companies sites that are unrelated to, rhey just use the same hosting (e.g wordpress).

Transport Intelligence
… todo
Transportation intelligence
… todo
Critical Infrastructure and Industrial intelligence
… todo
Financial intelligence
… todo
Cryptocurrency intelligence
… todo
Non-Fungible Tokens intelligence
… todo
Search
Archives
Workflow
Others
Norway Specific
- PureHelp
- Finn
- Skattesjekk.no - Check tax of people
- anonymskatt - Check tax of people
- skatteetaten - Check tax of people - not anonymous
- Brønnøysundregistrene - Norway’s central register authority. Contains multiple registers such as the Register of Business Enterprises, the Register of Company Accounts, and the Register of Bankruptcy.
- Proff - A commercial website using data from the Brønnøysund Register Centre and other sources to present company overviews.
- Maybe you can find here if someone owns or runs a business
- Einnsyn - A centralized service for searching through Norwegian government agencies’ public records (post journals)
- Kvartverket - National authority responsible for mapping, property registration, and geographic data.
- seeiendom - public-facing portal that combines property information from the Norwegian Mapping Authority, the Cadastre, and the Land Register
- Domstol - Norwegian court rulings can be made partially available to the public, though privacy restrictions apply and many legal documents are anonymized.
- 1881.no - Online directories for phone numbers, addresses, and sometimes additional public info (e.g., businesses and individuals).
- arkivverket - Repository of historical and archival materials, both for governmental and non-governmental entities.
- NB.no - National repository of publications in various media, some digitized and freely available.
- Vegvesen - Contains Vehicle Information
- You can check all the cars that someone has owned (require SSN)
- You can check who (only name) ons a car with a given license plate
- https://www.digitalarkivet.no/
- https://www.doffin.no/ - Database for public procurement
- Public Tenders Database
Resources