The Universal OSINT Investigation Checklist

This time-tested checklist guides you through a methodical, secure, and professional Open Source Intelligence investigation from start to finish.
1. Preparation & Operational Security (OpSec)
[ ] Define the Objective: What is the exact goal of this investigation? (Crucial to avoid getting lost down the internet rabbit hole).
[ ] Protect Your Footprint: Is your VPN active? Are you using a dedicated, clean browser or a Virtual Machine (VM)?
[ ] Verify Sock Puppets: Are your research accounts credible, active, and strictly isolated from your real identity (no shared phone numbers, IPs, or recovery emails)?
[ ] Build a Search Matrix: Have you listed all known names, aliases, emails, phone numbers, and IPs of the target for systematic cross-referencing?
2. Data Gathering & Search Strategies
[ ] Search Engine Dorking: Have you utilized advanced search operators (e.g.,
site:,filetype:,intitle:,"exact phrase") across multiple search engines (Google, Bing, Yandex, DuckDuckGo)?[ ] Social Media Combing: Have you checked all relevant platforms, including regional networks, forums, and chat apps (like Telegram)?
[ ] Whois & DNS Lookups: For web infrastructure: Who registered the domain? Do historical passive DNS records reveal previous ownership?
[ ] Public Registries & Data Leaks: Have you checked official corporate registries, land mandates, or public breach databases (e.g., HaveIBeenPwned) if ethically/legally permissible?
3. Verification & Source Criticism
[ ] Origin Verification: Who published the information first? Is the source reputable, or do they have a motive to spread misinformation?
[ ] Metadata Analysis: Have you run images and documents through metadata viewers (like ExifTool) to check for GPS tags, creation dates, or software footprints?
[ ] Geolocation & Chronolocation: Can the exact location and time of a photo/video be verified using landmarks, architectural styles, shadow lengths, or historical weather data?
[ ] Triangulation: Is the key piece of evidence confirmed by at least two independent, unrelated sources?
4. Documentation & Evidence Preservation
[ ] Maintain an Investigative Log: Are you documenting every step, search query, and discovery chronologically?
[ ] Local Archiving: Have you taken full-page screenshots (including the system clock) and saved web pages locally as HTML or PDF?
[ ] External Archiving: Have you pushed critical URLs to the Wayback Machine (archive.org) or Archive.today to prevent evidence loss if the target deletes the content?
[ ] Final Reporting: Is the final report structured clearly so that a third party (client, court, or colleague) can seamlessly replicate your findings?