Umbragarde Confidential enquiry
Home/OSINT Framework
Intelligence resources

The OSINT framework used in professional investigations.

Open-source intelligence is not a single tool — it is a discipline. This framework maps every major source category used in corporate intelligence, due diligence, sanctions screening and asset tracing, with the investigative question each category is built to answer.

9 source categoriesEach answers a different investigative question.
Lawful by designEvery source publicly accessible or lawfully obtained.
Cross-corroboratedA finding from one source is a lead. Three or more is a fact.
The framework

Nine source categories. One coherent picture.

A professional OSINT framework is not a list of websites. It is a structured approach to a problem: starting with what is known, identifying what needs to be established, choosing the right source categories in the right order, and corroborating each finding before it becomes a conclusion. The nine categories below cover the full range of open-source intelligence used in corporate and financial investigations.

1. Corporate & company registries

The foundation of any entity investigation. Company registries record incorporation details, registered addresses, officer appointments and, in many jurisdictions, financial filings. Key sources include:

  • Companies House (UK) — free, searchable, with filing history and officer records
  • SEC EDGAR (US) — public company filings, beneficial ownership reports, regulatory submissions
  • OpenCorporates — aggregates 200+ national registries into a single searchable dataset
  • National registries — EGRUL (Russia), Kompass, Orbis (Bureau van Dijk), and jurisdiction-specific registers for Cyprus, BVI, Cayman, UAE, Singapore and others

Corporate registries establish the legal skeleton of an entity. They rarely reveal the full picture — nominee directors, layered ownership and offshore structures are designed precisely to defeat them — but they define the starting graph for any investigation.

2. Court & litigation records

Litigation history is among the most revealing OSINT sources. Courts produce detailed, sworn statements — a counterparty's prior disputes, fraud allegations, judgments against them and the names of those they have sued or been sued by. Key sources:

  • PACER (US) — federal civil, criminal and bankruptcy filings
  • CourtListener / RECAP — free access to millions of US federal documents
  • HMCTS and The Gazette (UK) — County Court Judgments, insolvency notices, winding-up petitions
  • Westlaw / LexisNexis — global case law and litigation analytics
  • Offshore and international — BVI, Cayman and other offshore jurisdictions have increasingly searchable court records following media and regulatory pressure

Skilled analysts read court documents for what they contain about third parties — the counterparty's suppliers, investors, family members and aliases — not just the named parties.

3. Sanctions & PEP databases

Sanctions screening and politically exposed person (PEP) checks are now standard in regulated sectors, but they matter equally in private due diligence. An investor with sanctioned family members, a supplier whose ultimate beneficial owner appears on the UN Consolidated List, or a counterparty who is a foreign official — these are risks that corporate registries do not surface. Primary sources:

  • OFAC Specially Designated Nationals (SDN) List (US)
  • EU Consolidated Sanctions List
  • UK OFSI Consolidated List
  • UN Security Council Consolidated List
  • World-Check (Refinitiv) and Dow Jones Risk & Compliance — aggregated, curated PEP and adverse data
  • ACAMS and national FIU databases

Raw list screening is a minimum. Professional-grade sanctions intelligence maps indirect exposure: relatives, controlled entities, nominee holders and jurisdictional bypass structures used to circumvent designation.

4. Adverse media & news archives

Adverse media screening searches published reporting for connections to fraud, corruption, money laundering, regulatory enforcement and other reputational risk. The discipline requires breadth — local-language press in the subject's home jurisdiction, trade press, court reporting — and judgment about what constitutes genuine risk versus noise. Sources:

  • Factiva (Dow Jones) — 30,000+ sources in 200 countries
  • LexisNexis News — deep archive including regional and specialist titles
  • OCCRP Aleph — leaked documents, structured data from ICIJ investigations, Pandora / Panama Papers
  • Google News, Bing News — real-time and historical, with language and region filtering
  • Wayback Machine — archived pages that have been deleted or modified since publication

The absence of adverse media is never confirmation of integrity. A subject who has successfully managed their press profile, operated exclusively in low-disclosure jurisdictions, or settled disputes under NDA will appear clean in media. Adverse media is one layer; it confirms risk, but does not clear it.

5. Property & asset registers

For asset tracing, property registers are often the most direct route to locating recoverable assets. Ownership of land and real estate is publicly recorded in most developed jurisdictions, and modern beneficial ownership legislation increasingly requires disclosure of the ultimate human owner rather than a nominee or corporate vehicle. Key sources:

  • HM Land Registry (UK) — title register, price paid data, overseas entities register
  • County Recorder / Assessor (US) — property ownership, deed history, liens
  • Dubai Land Department (UAE)
  • Cyprus Land Registry
  • National cadastral databases — most EU jurisdictions maintain searchable land registries
  • Aircraft and vessel registers — FAA (US), CAA (UK), IMO and national maritime registries, including flag-of-convenience registrations

Asset registers answer one specific question: what does the subject own, and in whose name? When the legal owner differs from the economic owner, the gap between the two is where the investigation focuses.

6. Beneficial ownership

Beneficial ownership is the core challenge in financial crime and high-stakes due diligence. The legal owner of a company or asset is frequently a nominee, a trust or an offshore shell — the economic owner sits behind multiple layers, sometimes across multiple jurisdictions. Sources that expose beneficial ownership include:

  • UK PSC (Persons with Significant Control) register — Companies House, mandatory since 2016
  • FinCEN Beneficial Ownership Secure System (BOSS, US)
  • EU beneficial ownership registers — implemented at varying levels of access across member states
  • ICIJ Offshore Leaks database — derived from Panama Papers, Paradise Papers, Pandora Papers and others; not exhaustive, but covers millions of offshore entities
  • Orbis (Bureau van Dijk) — commercial aggregator of corporate ownership data

Beneficial ownership disclosures are self-reported and not comprehensively verified. They are a starting point, not an answer. In complex structures — particularly those involving CIS jurisdictions, BVI, or trust arrangements — OSINT analysis requires mapping connections between entities, timing of incorporations, and shared addresses, directors or registered agents.

7. Blockchain & cryptocurrency

Cryptocurrency transactions are permanently recorded on public ledgers. Blockchain OSINT has become a distinct discipline, with specialist tooling that traces flows across wallets, exchanges and protocols, identifies mixer usage, and maps connections to known illicit addresses. Core tools:

  • Chainalysis Reactor — wallet clustering, transaction flow analysis, exchange identification
  • TRM Labs — compliance-focused on-chain analytics
  • Elliptic — risk scoring for crypto businesses and wallets
  • Etherscan / Blockchair / Blockchain.com — free block explorers for on-chain inspection
  • OFAC virtual currency addresses — designated wallet addresses published by US Treasury

Blockchain OSINT is not limited to cryptocurrency fraud. It is increasingly used in asset tracing (locating crypto held by a judgment debtor), sanctions compliance (identifying indirect exposure to designated actors), and source-of-funds investigations.

8. Social media & digital footprint

Social media OSINT establishes identity, network, location history, affiliations and contradictions between a subject's stated and actual positions. It is particularly useful for verifying track record claims, identifying undisclosed relationships and geolocating activity. Key sources and tools:

  • LinkedIn — employment history, connections, endorsements and activity
  • X / Twitter, Facebook, Instagram, Telegram, VKontakte — depending on subject profile
  • WHOIS and DNS records — domain ownership, registration history, hosting infrastructure
  • Certificate transparency logs — surface subdomains and related web properties
  • Shodan — exposed internet infrastructure and device information
  • Wayback Machine — historical captures of websites, profiles and pages now modified or removed

Social media evidence is admissible in many jurisdictions if collected and preserved correctly. It is particularly valuable in litigation support, where establishing a subject's public statements, location or relationships can corroborate or contradict sworn testimony.

9. Geospatial & satellite

Geospatial OSINT uses imagery, mapping data and location intelligence to verify physical assets, confirm activity at a location and corroborate or refute other findings. It is routinely used in sanctions enforcement (to establish that a sanctioned vessel is at a particular port), asset tracing (to confirm that a property is occupied and maintained) and corporate intelligence (to verify that a business operates from its declared premises). Sources:

  • Google Earth / Google Maps / Street View
  • Maxar, Planet Labs, Airbus Defence & Space — high-resolution commercial satellite imagery
  • Sentinel Hub (ESA) — free multispectral satellite imagery
  • AIS and vessel tracking — MarineTraffic, VesselFinder, Global Fishing Watch
  • ADS-B and flight tracking — FlightAware, Flightradar24, ADSB Exchange
  • Overture Maps, OpenStreetMap — open geographic data for base mapping

From framework to intelligence

The value of a framework is not the list — it is the discipline it enforces. A professional investigation does not query one source and accept the result; it queries multiple categories, cross-references findings, explains discrepancies, and produces conclusions that are only as strong as the evidence behind them. A clean result from a sanctions database does not mean the subject is clean; it means the subject is not on that list. OSINT-grade intelligence requires the analyst to know what each source covers, what it misses, and where its silence is itself a signal.

Umbragarde applies this framework to corporate intelligence, due diligence and asset tracing mandates. We do not deliver database printouts. We deliver corroborated findings — with the sources behind them.

Common questions

OSINT framework, answered.

What is an OSINT framework?

An OSINT framework is an organised set of sources, tools and methods used to gather intelligence from publicly available information. In professional investigations, it covers corporate registries, court records, sanctions databases, adverse media, beneficial ownership disclosures, property records, digital footprint and blockchain data. The framework structures how an analyst moves from raw data to verified, actionable intelligence.

What are the main categories of OSINT tools?

For corporate and financial investigations, the nine main categories are: corporate and company registries, court and litigation records, sanctions and PEP databases, adverse media and news archives, property and asset registers, beneficial ownership disclosures, blockchain and cryptocurrency tracers, social media and digital footprint tools, and geospatial and satellite sources. Each answers a different investigative question.

How do investigators use OSINT in due diligence?

In due diligence, OSINT verifies identity and track record, surfaces litigation history, maps corporate ownership and subsidiaries, identifies sanctions exposure, checks for adverse media, and establishes the real beneficial owner behind an entity. The analyst corroborates findings across multiple independent sources — a finding from one source is a lead; confirmed across three or more, it is a fact.

Is OSINT legal?

Yes. OSINT draws only on publicly available or lawfully accessible sources: company registries, court filings, regulatory announcements, published media, publicly visible social media and open government databases. In the UK, OSINT-based investigations are subject to GDPR and the DPA 2018, which require a legitimate purpose and proportionate scope — both satisfied by professional due diligence and asset recovery mandates.

What is the difference between OSINT and a database check?

A database check queries one or a few structured datasets and returns what matches. OSINT is broader: active collection across dozens of source categories, identifying connections that no single database contains, and applying analytical judgment to corroborate or refute what the data suggests. Professional OSINT uncovers what databases do not, and explains what databases get wrong.

What OSINT tools do professional investigators use?

Professional investigators use primary registries (Companies House, SEC EDGAR, OFAC SDN List, PSC register), specialist databases (World-Check, Dow Jones Risk, LexisNexis, Factiva), blockchain analytics platforms (Chainalysis, TRM Labs, Elliptic), court records systems (PACER, HMCTS, CourtListener), geospatial tools and proprietary systems that cross-reference the above. The tool is only as good as the analyst interpreting it.

Go deeper

OSINT applied.

Need intelligence on a person, company or asset?

One confidential message is enough. Tell us only what you are comfortable sharing — we take it from there.

Make a confidential enquiry