OSINT for Law Enforcement Agencies

OSINT for law enforcement works best when the agency keeps the authority and the decisions, and gets extra analytical capacity when a case needs it. We support police forces, prosecutors' investigators and regulatory enforcement units with surge research, attribution work, training and evidence-grade documentation.

  • Surge analyst capacity
  • Attribution and verification
  • Police OSINT training
  • Court-ready capture and logs
Short answer

OSINT for law enforcement is the lawful use of publicly and commercially available information to support investigations, intelligence and public safety work. OSINT-S adds capacity to agency teams: identifying who is behind accounts, verifying images and video, mapping companies and assets, and training officers. Every task runs on a written requirement from the agency, which keeps its own legal authorities and decisions.

What Agencies Ask an OSINT Partner to Do

Mostly four things: attribute an online identity, verify media, map a network of people and companies, and absorb a backlog when a major case lands.

Most agencies already run open-source research in-house. They call in a partner when volume or specialism exceeds what the unit can absorb:

  • Attribution. Who is most likely behind an account, domain, channel or wallet, and with what confidence?
  • Verification. Is this video from the date and place it claims, or recycled?
  • Network mapping. Which companies, directors, addresses and identities connect to a suspect?
  • Surge capacity. A major incident or large fraud needs vetted analysts for weeks, not months.
  • Capability. Officers need consistent tradecraft and a shared recording standard.

Services That Fit Police and Enforcement Work

Six of our services map directly onto investigative tasks; most agency engagements combine two or three of them.

Attribution

Social media investigations

Account histories, links between profiles, archived content and documented attribution reasoning.

Social media investigations →
Verification

Geolocation and media verification

Where and when an image or video was captured, checked against imagery, shadows and earlier uploads.

Geolocation verification →
Assets

Asset tracing

Property, companies, vehicles and other holdings linked to suspects, to support restraint and confiscation work.

Asset tracing →
Networks

Company investigations

Shell structures, nominee directors, shared addresses and cross-border registrations behind a fraud or laundering scheme.

Company investigations →
Skills

OSINT training

Courses for analysts and investigators on search, attribution, verification, capture and research hygiene.

OSINT training →

Legal Authority Stays With the Agency

We research under your tasking; authorizations, covert activity and decisions about people remain the agency's responsibility under its own law.

In the UK, the Home Office code of practice on covert surveillance says that preliminary examination of online material is unlikely to interfere with a reasonable expectation of privacy, but where an authority is systematically collecting and recording information about a particular person or group, a directed surveillance authorization should be considered (Covert Surveillance and Property Interference Code, paras 3.10–3.17).

In the US, agencies that run federally funded criminal intelligence systems are bound by 28 CFR Part 23, which allows information on an individual to be kept only where there is reasonable suspicion of involvement in criminal conduct, and bars collecting information on political, religious or social views unless it directly relates to criminal conduct (28 CFR 23.20). The Bureau of Justice Assistance has published guidance on social media policies that addresses access, use, storage and dissemination with attention to civil liberties (BJA, 2013).

QuestionWho decidesWhat we do
Is an authorization needed for this research?The agencyDescribe the planned collection so your authorizing officer can decide
Can anyone interact with the subject online?The agency, under its covert rulesPassive research only; we never engage subjects
Can findings be used as evidence?Prosecutor and courtCapture, log and document method so the question can be answered

How a Surge-Capacity OSINT Engagement Runs

Written tasking, confirmed legal basis, documented collection, verification, senior review, then a report and exhibit set the agency owns.

  1. Written taskingThe officer in charge sets the questions, the subjects and the purpose in writing. We do not self-task or widen the scope.
  2. Legal basis confirmedThe agency confirms the authority for the research and any limits on it.
  3. Collection with captureAnalysts work from attributable-safe research environments and capture each page with URL, time and hash as they go.
  4. VerificationKey findings are corroborated from independent sources; confidence levels are stated, not implied.
  5. Senior analyst reviewA senior analyst checks method, logic and wording before anything is delivered.
  6. Report and exhibitsYou receive a report that separates fact from assessment, the capture files, and a collection log. Focused tasks start from 10 business days; urgent work carries a 50% surcharge.

Evidence-Grade Documentation for Court

If a finding may reach court, its capture, provenance and method must survive disclosure and cross-examination, so we document as if it will.

A finding nobody can reproduce is intelligence at best. We record what was found, where, when, with which tool and by whom. Capture tools such as Hunchly automatically record the URL, timestamps and hashes of every page visited (Hunchly); we add an analyst log of the reasoning between pages.

This matters because research material is subject to disclosure. In England and Wales, the Criminal Procedure and Investigations Act 1996 sets out disclosure duties and a code on recording and retaining material obtained in an investigation (CPIA 1996). For international and atrocity-related cases, our workflow follows the stages of the Berkeley Protocol: inquiry, preliminary assessment, collection, preservation, verification and analysis (Berkeley Protocol).

OSINT Tools for Law Enforcement by Category

No single tool covers an investigation; units need capture, link analysis, imagery, blockchain and search capability, plus the tradecraft to use them safely.

CategoryWhat it doesWatch-outs
Capture and case notesSaves pages with timestamps and hashes, builds an audit trailOnly as good as the analyst's discipline about what is captured
Link analysisGraphs relationships between people, companies, domains and accounts (Maltego is a common example)Automated transforms can create false links; each edge needs a source
Selector searchChecks emails, phone numbers and usernames against public registrations and breach indexesBreach data raises legal and ethical questions; use only lawful sources
Imagery and mappingSatellite, street-level and historical imagery for geolocationImagery dates are often older than they look
Blockchain analyticsTraces flows between wallets and servicesClustering is probabilistic; label sources matter

OSINT Police Training and Capability Building

Training works when it uses your agency's policies and real case types, and ends with a shared standard for recording research.

Our OSINT training for police units covers search technique, attribution, image and video verification, company and asset research, capture and logging, and research hygiene so that officers do not reveal their agency to a subject. Exercises use your typical case types with fictional subjects, so research by one officer can be checked and repeated by another.

Typical Scenarios We Support

Illustrative examples of the work agencies bring, framed as typical patterns rather than specific cases.

Major incident

Video verification under time pressure

Footage circulating after a public incident needs dating and locating within hours, and recycled clips need to be separated from new ones.

Fraud

Mapping an investment fraud network

Victim reports name several websites; research links the domains, companies and promoters behind them.

Threats

Threats against a public official

Anonymous accounts post threats. Analysts document the posts and research likely attribution from public account history.

Protected Activity and Other Limits

We do not monitor lawful protest, religion, journalism or political activity, do not run covert identities, and do not handle classified material.

  • No surveillance of protected activity. We do not monitor people or groups for lawful protest, political, religious or press activity. Requirements must tie to suspected crime or a specific safety risk.
  • No covert engagement. We do not create fake profiles to befriend subjects, join closed groups or access private content. That is covert activity reserved to the agency under its own authorizations.
  • No hacking or stolen data. No intrusion, no credential use and no purchase of stolen databases.
  • No classified work. We work at the unclassified level only.

For private-sector cases later referred to police, see our OSINT investigations and the wider range of OSINT services for public and private clients.

Brief Us on a Case or a Training Need

Send the requirement, the deadline and the legal basis you are working under. We reply with scope, timeline and a fixed quote; if we miss the agreed date, the fee goes down.

OSINT for Law Enforcement: Questions Agencies Ask

Our fraud unit is buried in a case with dozens of linked websites and companies — how does OSINT for law enforcement from an outside firm work without us losing control of the investigation?

You keep control through written tasking. The officer in charge defines the questions, subjects and limits, and we research only within that scope. The report, captures and collection log become agency material, and decisions on suspects and charges stay with you. Focused tasks start from 10 business days; larger network mapping can take up to about a month.

I'm a detective sergeant in the UK and want to know whether we'd need a directed surveillance authorization before you research a suspect's public social media for us?

That is a decision for your authorizing officer, not for us. The Home Office code says simple reconnaissance of public material is unlikely to engage privacy, but systematic collection and recording about a particular person or group should lead you to consider a directed surveillance authorization. We describe the planned collection in writing so your force can decide before we start.

Can your analysts create undercover profiles to join closed groups where suspects are organizing, if our department gives you permission to do it on our behalf?

No. Covert interaction with subjects is reserved to the agency under its own legal framework and trained undercover officers. We do passive research on publicly and commercially available information only; we do not create fake profiles, befriend subjects or access private content.

Our county sheriff's office wants OSINT police training for six investigators who have only used Google — what would a course cover and would it fit our policies?

A course for that group would cover search technique, account and username research, image verification, company and property records, capture and logging, and how to research without revealing your agency. Exercises use your office's typical case types with fictional subjects, and the recording standard follows your policy or, if it is silent, published BJA guidance.

We're a state agency and our civil liberties board worries about monitoring protest groups — would you take on social media monitoring around an upcoming demonstration for us?

We would not monitor the protest or its organizers. Lawful protest, political and religious activity is outside our scope, and in the US, 28 CFR Part 23 restricts federally funded intelligence systems from holding information on political or social views unless it directly relates to criminal conduct. We can support a narrow public safety requirement, such as verifying a specific public threat of violence, under a written tasking your board can review.

Which OSINT tools for law enforcement should my small unit buy first if we only have budget for one or two licenses this year?

Start with capture, because every finding you cannot document is weaker in court. A tool that records URLs, timestamps and hashes automatically is the base layer. The second purchase depends on your caseload: link analysis for fraud and organized crime, blockchain analytics for crypto-heavy work, or imagery for verification. Pair any purchase with training, and check each vendor's license terms.

If findings you produce end up in a prosecution, will the defense be able to see how you found them and will that cause problems for our case?

Assume the defense will see the method, and plan for it. Disclosure rules, such as the Criminal Procedure and Investigations Act 1996 in England and Wales, require relevant material to be recorded and retained. Our logs include null searches, tool versions and the reasoning between steps. Reproducible method usually strengthens a finding; undocumented research is the real risk.