Skip to content

resources

OSINT & intelligence glossary

Plain-language definitions of the terms that matter in lawful intelligence work, and how Next Sight applies each of them in practice. Every term also has its own page with fuller context.

Last reviewed:

OSINT (open-source intelligence)
The disciplined collection and analysis of publicly available information — websites, public registries, filings, news, and technical data — to answer an intelligence requirement. Lawful OSINT relies only on legitimately accessible sources, never on hacking or private-account access, and documents provenance so findings can be verified and defended.
How Next Sight applies this: OSINT intelligence servicesFull definition
HUMINT (human intelligence)
Information collected through direct human interaction: structured interviews, participant observation, and trusted source networks. In professional practice HUMINT is lawful and voluntary, handled discreetly, and corroborated against open sources and records before it becomes an assessment — it rarely stands alone.
How Next Sight applies this: HUMINT intelligence servicesFull definition
OPSEC (operational security)
The discipline of protecting an investigator's identity, devices, communications, and casework from adversary observation: anonymity and pseudonymity, secure communications, browser and device hygiene, and digital footprint management. Poor OPSEC exposes the investigator and can compromise the admissibility of evidence.
How Next Sight applies this: OPSEC trainingFull definition
Chain of custody
The documented record of provenance, time, source, and handler for every artifact across collection, analysis, and reporting. A maintained chain of custody is what makes digital findings defensible before internal review, regulators, and courts — without it, open-source evidence is difficult to admit.
How Next Sight applies this: compliance approachFull definition
Deep web vs dark web
The deep web is everything search engines do not index: databases, paywalled and private content. The dark web is the deliberately hidden subset reachable only through overlay networks such as Tor, I2P, Freenet, and Lokinet. Investigating either lawfully requires controlled attribution, documented collection, and verification.
How Next Sight applies this: dark web investigation trainingFull definition
SOCMINT (social media intelligence)
Intelligence derived from social platforms: profiles, connections, reach, and amplification patterns, collected lawfully and analysed for investigative or protective purposes. Social network analysis turns individual posts into a picture of relationships and coordination.
How Next Sight applies this: OSINT trainingFull definition
Entity resolution
Normalising people, organisations, infrastructure, and locations that appear differently across many sources into single, linked entities — so analysts work from a coherent picture instead of raw search results. A core step between collection and analysis in any multi-source investigation.
How Next Sight applies this: Nexus, the AI OSINT platformFull definition
Disinformation & influence operations
Deliberately false or manipulated content spread to deceive, including coordinated campaigns by state and non-state actors using bots, fake personas, and deepfakes. Investigating it combines open-source collection, network visualisation of the accounts behind a campaign, and source-credibility assessment.
How Next Sight applies this: disinformation investigation trainingFull definition
Cryptocurrency tracing
Following the flow of cryptocurrency transactions across wallets, exchanges, and services to connect illicit activity with identifiable actors. A core dark-web investigation skill, since hidden markets and services settle almost exclusively in cryptocurrency.
How Next Sight applies this: dark web investigation trainingFull definition
Protective intelligence
Identifying and assessing threats to people, assets, and operations early enough to act: continuous monitoring of open sources, structured risk assessment, and reporting calibrated to the protected interest. The intelligence-led complement to physical and cyber security controls.
How Next Sight applies this: corporate security use caseFull definition
SIGINT (signals intelligence)
Intelligence derived from intercepted signals — communications between people (COMINT) and electronic emissions from systems (ELINT). SIGINT collection is a regulated state capability requiring explicit legal authority; commercial practitioners work instead with lawful open-source and human-source disciplines, and treat SIGINT-derived material strictly within the authority of the client agency.
How Next Sight applies this: intelligence & government use caseFull definition
GEOINT & IMINT (geospatial and imagery intelligence)
Intelligence from imagery and geospatial data: satellite and aerial imagery, street-level photography, terrain and infrastructure data, and the metadata that anchors online content to a place and time. In open-source practice, geolocation and chronolocation of images are core verification skills — they confirm or refute where and when a piece of content was really produced.
How Next Sight applies this: OSINT trainingFull definition
Threat intelligence
Evidence-based knowledge about existing or emerging threats — actors, capabilities, infrastructure, indicators, and intent — organised so a defender can act on it. Strategic threat intelligence informs leadership decisions; operational and tactical threat intelligence feeds monitoring, hunting, and incident response.
How Next Sight applies this: cybersecurity consultingFull definition
Digital footprint
The cumulative trace a person or organisation leaves online: registrations, posts, metadata, breached credentials, and third-party mentions. Investigators map footprints to locate subjects and assess exposure; OPSEC practice is the inverse discipline — minimising and controlling one's own footprint.
How Next Sight applies this: OPSEC trainingFull definition
Attribution & managed attribution
Attribution is establishing who is behind an action, account, or infrastructure — to an evidentiary standard, not a guess. Managed attribution is the investigator's counterpart: controlling what a research environment reveals about the investigator (network, device, persona) so collection does not tip off the subject or contaminate the case.
How Next Sight applies this: OPSEC trainingFull definition
Dark-web monitoring
Continuous, lawful observation of hidden services, markets, forums, and leak sites for mentions of an organisation's people, data, credentials, or brand. Effective monitoring pairs automated collection with human review, and feeds protective intelligence and incident response rather than standing alone.
How Next Sight applies this: corporate security use caseFull definition
Adverse media screening
Systematically searching news archives, regulatory records, litigation databases, and open sources for negative information about a counterparty — fraud, sanctions, corruption, misconduct — as part of due diligence and compliance workflows. Quality screening resolves identity precisely to avoid false positives and documents sources for the file.
How Next Sight applies this: corporate intelligence servicesFull definition
Due diligence investigation
A structured, lawful inquiry into a counterparty before a consequential decision — investment, acquisition, partnership, or key hire. It combines corporate-registry and beneficial-ownership research, litigation and regulatory history, sanctions exposure, adverse media, and, where warranted, discreet human-source enquiries, delivered with documented sources.
How Next Sight applies this: corporate intelligence servicesFull definition

Put the vocabulary to work.

Explore the services and training behind these definitions, or bring us a requirement.

Request a briefing