§ Guide, full text

OSINT Open Source Intelligence In Litigation

Open source intelligence (OSINT) involves gathering public data for litigation. This guide covers capturing, preserving, verifying, and attributing OSINT to ensure it is lawful and proportionate. It details the open sources, legal limits, deployment, and common mistakes, helping practitioners turn information into admissible evidence.

17 pages · 25 min read

Loading the PDF reader

OSINT Open Source Intelligence In Litigation

OPEN - SOURCEINTELLIGENCE · A GUIDE FOR UK LAWYERS OSINT: Open-Source Intelligence in Litigation Public Data, Lawful Method and Evidence That Holds Up COMPUTER FORENSICS LAB

§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM

§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: public does not mean proven 03 What OSINT covers: the open sources 04 Capturing and preserving so it can be authenticated 05 Verification, corroboration and attribution 06 Legal and ethical limits 07 Deployment: asset tracing, due diligence and fact-testing 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist

§ 01 · ORIENTATION Executive summary OSINT is only useful when the material is captured and preserved so it can be authenticated, gathered law full y and proportionately, and verified rather than assumed, turning information into evidence that holds up.

§ 02 · FIRST PRINCIPLES The problem in plain English: public does not mean proven

§ 03 · THEOPENSOURCES What OSINT covers: the open sources SOCIAL / WEB COMPANY PROPERTY REGISTERS DOMAIN / WEB

§ 04 · CAPTURE AND PRESERVATION Capturing and preserving so it can be authenticated

§ 05 · VERIFICATIONANDATTRIBUTION Verification, corroboration and attribution

§ 06 · LEGALANDETHICALLIMITS Legal and ethical limits

§ 07 · DEPLOYMENT Deployment: asset tracing, due diligence and fact-testing

§ 08 · THEWIDERMAP Source architecture: where else the evidence lives EVIDENCE OPEN REGISTRAR SHARED ACCOUNT LIVE PLATFORM / OTHERS' DEVICE / SOURCE RECORDS COPIES FORENSICS WE B DELETED / ARCHIVES SUPERSEDED

§ 09 · IN THE WILD Worked examples EXAMPLE1 · THEHOLIDAYPHOTOSTHATANSWEREDTHEINJURYCLAIM EXAMPLE2 · THEHIDDENNETWORKBEHINDTHECOMPANY EXAMPLE3 · THEFAKESCREENSHOTANDTHECLEANMETHOD

§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations

§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent (where relevant) Ask your e Discovery / forensic provider SUGGESTED WORDING · INSTRUCTIONFORANOSINTG AT HERINGANDANA LY SIS

§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The OSINT checklist Red flags When to involve a digital forensic expert

§ 13 · COMMON QUESTIONS Frequently asked questions If information is public, can we just use it? Why is a screenshot not good enough? Can we set up a fake profile to see a private account? How do we know a social-media account belongs to the person? Can OSINT expose fabricated evidence? Is OSINT a substitute for disclosure and forensics?

§ 14 · REFERENCE Glossary Sources and authoritative references DISCLAIMER

§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY

Cite as: Joseph Naghdi, OSINT Open Source Intelligence In Litigation, Computer Forensics Lab, https://e-discovery.uk/library/osint-open-source-intelligence-in-litigation/pdf.

Instruct the practice

Bring us in early. Defensibility is built, not retrofitted.

Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.

WhatsApp