Skip to content
Breachfolio
A set of overlapping collection channels feeding a single intelligence picture — the -INT disciplines, OSINT, SIGINT, HUMINT, GEOINT, MASINT, TECHINT
CYBERSECURITY · OSINT

The -INT disciplines: where OSINT fits among them.

OSINT, SIGINT, HUMINT, GEOINT, MASINT, TECHINT — the full taxonomy intelligence work is organized around, what each one actually collects, and why OSINT is the one open to everyone else.

July 22, 202611 min read

Our deep dive into OSINT covers one discipline in full — the tools, the workflow, the legal line, the OPSEC. What it deliberately doesn't do is answer a question that comes up the moment you start reading intelligence work more broadly: if OSINT is intelligence from open sources, what are all the other -INT acronyms you keep running into — SIGINT, HUMINT, GEOINT, and the rest? This article is that map. It won't make you an expert in any single discipline, but it will tell you what each one actually collects, who realistically gets to use it, and exactly where OSINT sits on that spectrum — which turns out to explain a lot about why OSINT became the default discipline for security researchers, journalists, and private investigators who don't have a government badge.

Why intelligence work is split into "-INT" disciplines

Professional intelligence work has long organized itself around collection disciplines — categories defined not by the subject under investigation but by the type of source the information comes from. A question like "what is this organization planning?" could be answered by reading their public statements (OSINT), intercepting their communications (SIGINT), talking to someone inside (HUMINT), or examining satellite imagery of their facilities (GEOINT). Each source type demands entirely different collection methods, tools, legal authority, and training, so treating them as separate disciplines — each with its own tradecraft — is simply how the work gets organized, whether inside a national intelligence agency or a much smaller security team.

The suffix pattern is consistent across all of them: take the source type, abbreviate it, append -INT. Once you know the pattern, unfamiliar acronyms stop being mysterious.

OSINT — open-source intelligence

OSINT is intelligence built entirely from sources that are already, legitimately public: websites, DNS records, court filings, company registries, social media, satellite imagery available commercially, and public breach data. Nothing about OSINT requires special access, a badge, or breaking into anything — if a private citizen with a browser can eventually find it, it's fair game for OSINT. That accessibility is precisely what makes it the one discipline on this list that security researchers, journalists, threat-intel analysts, and private investigators can practice without any government affiliation at all.

We treat OSINT at full depth elsewhere — the intelligence cycle, tooling by category, legal limits, and investigator OPSEC all live in What is OSINT? Tools and workflow. Consider this article the map of the surrounding territory; that one is the deep dive on the territory itself.

SIGINT — signals intelligence

SIGINT is intelligence derived from intercepting communications and electronic emissions that were never meant to be public — phone calls, radio transmissions, radar signals, satellite links. It's traditionally split into two sub-branches: COMINT (communications intelligence, intercepting the content of conversations) and ELINT (electronic intelligence, analyzing non-communication emissions like radar signatures to characterize a system's capabilities without needing to understand what's "said").

Unlike OSINT, SIGINT collection requires intercepting something private, which puts it firmly inside the domain of national intelligence agencies operating under specific legal authority — it is not a discipline available to private researchers, and attempting to intercept communications you have no right to access is a serious crime in essentially every jurisdiction. The dividing line between OSINT and SIGINT is exactly this: OSINT reads what's already open; SIGINT intercepts what isn't.

HUMINT — human intelligence

HUMINT is the oldest intelligence discipline by a wide margin — information gathered through direct interpersonal contact: interviews, elicitation, cultivated informants, and in its more adversarial forms, social engineering. Where OSINT is passive (you read what's already published) and SIGINT is technical (you intercept a signal), HUMINT is fundamentally relational — it depends on a person, willingly or not, providing information through conversation.

In a security context, HUMINT techniques underpin authorized social engineering engagements: pretexting a phone call to test an organization's verification procedures, or a phishing campaign designed to elicit credentials through a crafted pretext. The moment an OSINT investigator picks up the phone and talks their way into information rather than reading it from a public source, they've stepped out of OSINT and into HUMINT — a distinction worth keeping precise, since HUMINT-style techniques carry legal and ethical weight that pure OSINT does not.

GEOINT — geospatial intelligence

GEOINT is intelligence derived from imagery and geographic data: satellite photos, aerial imagery, mapping data, and the geographic clues embedded inside any photo or video. Classic GEOINT work includes identifying a facility's layout from overhead imagery or tracking changes to a location over time by comparing historical satellite passes.

GEOINT overlaps with OSINT more than almost any other pair on this list, because a substantial amount of geospatial data is now openly available — commercial satellite providers, Google Earth, OpenStreetMap, and the imagery ordinary people post to social media every day. When an open-source investigator geolocates a photo by matching a mountain silhouette, a shop sign, or the sun's position against a known location and time (a technique also covered under GEOINT tradecraft), they're practicing open-source GEOINT — the two disciplines genuinely blend at the working level, even though classified, government-tasked satellite imagery remains firmly outside civilian reach.

MASINT — measurement and signature intelligence

MASINT is the most technical and least accessible discipline here: intelligence derived from measuring and analyzing the distinctive physical signatures objects and events produce — radar cross-sections, acoustic signatures, seismic readings, spectral and chemical traces, even the particular electromagnetic "fingerprint" of a specific piece of equipment. The goal is usually to identify or characterize something — a vehicle, a weapon system, a nuclear test — from the physical traces it inevitably leaves behind, rather than from anything it communicates or that's photographed.

MASINT depends on specialized, often extremely expensive sensor equipment and deep technical expertise to interpret the resulting data, which keeps it almost entirely within military and national intelligence agencies. There is essentially no civilian or private-researcher equivalent — it's the discipline furthest from anything OSINT touches.

TECHINT — technical intelligence

TECHINT is intelligence derived from examining foreign equipment, weapons, or materiel directly — taking apart a captured piece of hardware or a piece of malware to understand exactly how it works, what it's capable of, and who built it. Historically this meant physically examining captured military equipment; in a cybersecurity context, the closest modern equivalent is malware reverse engineering — pulling apart a sample to understand its capabilities, infrastructure, and likely authorship.

TECHINT sits closer to OSINT's civilian accessibility than SIGINT or MASINT do, since malware samples are often publicly shareable (through services like MalwareBazaar) and reverse engineering doesn't require government authority — just the right tools and skill. It's frequently blended with OSINT in threat-intelligence work: OSINT maps an attacker's public-facing infrastructure while TECHINT-style analysis of their tooling reveals how that infrastructure is actually being used.

CYBINT and the newer, less formal disciplines

The six disciplines above are the classic, doctrinally established set, but they don't fully capture how much intelligence work has shifted toward digital infrastructure. Some practitioners and organizations now talk about CYBINT (or digital-network intelligence) as an emerging discipline in its own right: intelligence derived from network traffic analysis, digital forensics, and the infrastructure of cyberspace itself — closely related to, and often overlapping heavily with, both OSINT and TECHINT, since so much of what CYBINT covers (domain infrastructure, malware artifacts, network logs) is either openly observable or recovered through direct technical examination.

Unlike the six classical disciplines, CYBINT doesn't have the same decades-long doctrinal standing, and different organizations draw its boundaries differently — some fold it entirely into OSINT and TECHINT rather than treating it as separate. It's worth knowing the term exists, but the underlying techniques it describes are ones this cluster already covers: OSINT-style infrastructure mapping and TECHINT-style artifact analysis, applied specifically to networks and systems.

A worked example: one claim, three disciplines

Say a hacktivist group posts a photo online claiming to have breached a facility, alongside a snippet of code they say they extracted from it. Assessing that claim in a way you can actually stand behind draws on more than one discipline at once, even though every step here stays entirely within what's legally open to a civilian researcher:

  • OSINT collects the post itself: who published it, when the account was created, what else that account has posted, and whether the claim has been corroborated anywhere else.
  • GEOINT examines the photo: does the equipment, signage, or visible terrain match the facility being claimed, using satellite imagery and street-level photos as a comparison baseline?
  • TECHINT-style analysis examines the code snippet: does it actually correspond to systems the facility would plausibly run, or is it generic, copy-pasted, or fabricated to look convincing?

None of that required intercepting a signal or cultivating an informant — it's three disciplines' worth of technique, applied entirely through open channels, converging on one assessment. This is the practical shape all-source intelligence takes at civilian scale: not agencies pooling classified feeds, but a single researcher deliberately working through several angles before treating a claim as verified.

How the disciplines combine: all-source intelligence

Real investigations rarely stay inside one discipline's lane. Professional intelligence work has a name for combining multiple collection disciplines into a single assessment: all-source intelligence — the practice of triangulating a conclusion from several independent source types rather than trusting any single one. A national intelligence assessment might combine SIGINT intercepts, HUMINT reporting, and GEOINT imagery into one picture, each discipline covering a gap the others can't.

The same fusion happens at civilian scale, just with a narrower set of disciplines available. A threat-intelligence analyst geolocating an attacker's server photo from a leaked screenshot is blending OSINT and GEOINT. A malware researcher pulling command-and-control domains from a reverse-engineered sample and then pivoting through Certificate Transparency logs to map the rest of that infrastructure is blending TECHINT and OSINT. Naming which discipline a given piece of evidence came from isn't academic — it's what lets you weigh how reliable that evidence actually is and where its blind spots sit.

The disciplines at a glance

DisciplineSource of intelligenceWho typically collects itCybersecurity-relevant example
OSINTPublicly available informationAnyone — researchers, journalists, security teamsCertificate Transparency logs revealing an org's subdomains
SIGINTIntercepted communications & electronic signalsNational intelligence agenciesNot accessible to private researchers or civilians
HUMINTDirect human interactionIntelligence officers, investigators, authorized red teamsPretext phone calls during an authorized social-engineering test
GEOINTImagery and geographic dataGovernment imagery analysts; overlaps heavily with OSINT for open imageryGeolocating a leaked photo using shadows and landmarks
MASINTPhysical measurements and technical signaturesMilitary and national intelligence agenciesNot accessible to private researchers or civilians
TECHINTExamination of equipment, hardware, and softwareMilitary technical analysts; overlaps with security researchersReverse-engineering a malware sample to map its infrastructure

Why OSINT is the one open to everyone else

Line up all six disciplines and one thing becomes obvious: OSINT is the only one whose barrier to entry is skill and diligence rather than legal authority, government clearance, or specialized interception hardware. SIGINT and MASINT are effectively closed to anyone outside a national agency, both legally and technically. HUMINT and TECHINT partially overlap with civilian practice — social engineering and malware reverse engineering — but carry real legal and ethical weight the moment they're not authorized. GEOINT is split down the middle, with a genuinely open half that OSINT investigators already use daily.

That's the honest answer to "why does everyone talk about OSINT and not the others": it's not that OSINT is more important, it's that it's the only discipline a curious person can actually pick up and start practicing, legally, today. If that's the piece you came here for, the full workflow — the intelligence cycle, tooling by category, and how to stay on the right side of the legal line — is waiting in What is OSINT? Tools and workflow.

The takeaway

The "-INT" suffix marks a collection discipline, defined by where the information comes from rather than what it's about. OSINT collects from what's already public; SIGINT intercepts signals; HUMINT gathers from people; GEOINT reads imagery and geography; MASINT measures physical signatures; TECHINT examines equipment and code directly. Real investigations blend several of these into an all-source picture, but only OSINT — and, partially, GEOINT and TECHINT — is realistically available to anyone without a government mandate. Knowing which discipline a piece of evidence actually belongs to is the first step to judging how much to trust it.

Frequently asked questions

What does "-INT" mean in intelligence terminology?
The "-INT" suffix marks a collection discipline — a category defined by the type of source the information comes from, rather than by the subject being investigated. OSINT is intelligence from open, public sources; SIGINT is intelligence from intercepted signals; HUMINT is intelligence from people. The taxonomy exists because each source type demands different collection methods, tools, legal authority, and skill sets, so intelligence organizations (and, at a smaller scale, security researchers) organize their work around which disciplines a given investigation actually draws on.
What is the difference between OSINT and SIGINT?
OSINT is built entirely from information that is already publicly available — anyone can access the same website, WHOIS record, or social media post an OSINT investigator does. SIGINT is built from intercepting communications and electronic signals that are not public, such as phone calls, radio transmissions, or radar emissions, which generally requires specialized interception equipment and legal authority that only government agencies possess. The practical line is access: if you can get the information without intercepting a private communication, it's OSINT territory; if it requires intercepting a signal that wasn't meant for you, it's SIGINT and outside what any private researcher can legally do.
Is HUMINT the same as social engineering?
They're closely related but not identical. HUMINT is the broader intelligence discipline of gathering information through direct human interaction — interviews, elicitation, informants, and relationship-building. Social engineering, as used in security testing, is a specific application of HUMINT techniques toward manipulating a target into taking an action or revealing information, usually as part of an authorized penetration test or phishing simulation. Every social engineering engagement uses HUMINT methods, but HUMINT as a discipline is much broader than security testing alone — it includes legitimate diplomatic, journalistic, and investigative interviewing that has nothing to do with manipulation.
Can civilians or private researchers use GEOINT?
Yes, to a meaningful degree. While the most sensitive GEOINT — classified satellite tasking, military-grade sensor data — stays restricted to government agencies, a large amount of geospatial and imagery data is now openly accessible: commercial satellite imagery providers, Google Earth, OpenStreetMap, and the imagery embedded in social media posts themselves. This overlap is exactly why open-source investigators regularly practice a form of GEOINT when they geolocate a photo or video using landmarks, shadows, and terrain features, even without any government access.
Why is OSINT the most commonly used discipline outside of government agencies?
OSINT is built entirely on sources that are already legally accessible to the public, which means it requires no special legal authority, government clearance, or interception capability to practice — unlike SIGINT, MASINT, or classified GEOINT, which depend on capabilities and legal powers that are effectively reserved for state agencies. That accessibility is why OSINT is the discipline used by security researchers, journalists, threat intelligence teams, and private investigators: it's the one -INT discipline where the barrier to entry is skill and diligence rather than legal authority or specialized hardware.