OSINT
Intelligence built from public sources: websites, social media, records. The same information serves defense and attack preparation.
Full definition
OSINT (open source intelligence) is the collection and analysis of publicly available information: corporate websites, social media, business registries, indexed documents, metadata and already public leaks.
It is a dual-use discipline. Security teams use it to map their own exposure and that of their vendors; attackers use it to prepare spear phishing and pretexting: the org chart on LinkedIn, an employee's email in a publication, the tech stack in job postings. Every public profile is reconnaissance material.
For defenders, the lesson is to look at the company through the attacker's eyes: knowing what information is exposed about each person and system lets you anticipate which deceptions are plausible and train against them.
Related terms
Spear phishing
Phishing aimed at a specific person, built with real data about their role, company and tools. Far more effective than mass campaigns.
Pretexting
Social engineering built on an invented but plausible story: an audit, a vendor, a technician. The pretext justifies asking for data or access.
Attack surface
The set of points where an attacker can try to get in: exposed systems, accounts, vendors and, above all, people.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.