1.1 What publicly available information is
Publicly available information (PAI) is information that any member of the public could lawfully obtain: by reading it, watching it, asking for it, subscribing to it or buying it. Organisations word the definition differently, but they share that core idea. Typical examples:
- news reporting, broadcasts and press releases
- official publications, public registers and court records that the law makes public
- company filings, annual reports and product documentation
- posts, photos and videos that people publish openly on social platforms
- commercial satellite imagery and maps that anyone can buy or view
- academic papers, conference talks and public datasets
Some information looks public but is not PAI for our purposes, because obtaining it would mean breaking a rule or deceiving someone:
- content behind a login or paywall that you are not entitled to use
- private messages, closed groups and anything you would need a false identity to join
- leaked, hacked or stolen material
- anything you would need to bypass a technical control to reach
1.2 From information to intelligence
PAI is raw material. Open-source intelligence (OSINT) is what you produce from it: publicly available information that has been collected to answer a specific question, evaluated, analysed and delivered in time to someone who needs it. A widely used government definition describes OSINT in those terms: produced from publicly available information, collected and exploited, and disseminated in a timely manner to an appropriate audience to address a specific requirement.
The difference is purpose and judgement. A folder of screenshots is PAI. A short, sourced assessment that answers a decision maker's question is OSINT.
1.3 The intelligence cycle
Most intelligence work follows a cycle. Its stages overlap in practice, but naming them helps you notice when one has been skipped.
- Direction. Agree what question you are answering, for whom, and by when.
- Collection. Gather material that could answer the question, and record where each item came from.
- Processing. Organise, translate, archive and de-duplicate what you collected so it can be analysed and found again.
- Analysis. Evaluate sources and claims, look for corroboration and contradiction, and reach a judgement.
- Dissemination. Deliver the judgement in a form the reader can use, with sources and confidence.
- Feedback. Ask whether the product answered the question, and adjust the next round.
What goes wrong when a stage is skipped:
| Skipped stage | What happens |
|---|---|
| Direction | You collect everything and answer nothing. |
| Processing | You cannot find, reproduce or prove what you found. |
| Analysis | You forward rumours instead of judgements. |
| Dissemination | Good work arrives too late or in a form nobody reads. |
| Feedback | You repeat the same mistakes. |
1.4 Requirements: asking the right question
An intelligence requirement is the question you have agreed to answer. A good requirement is:
- specific: it names the subject, place and scope
- answerable: open sources could plausibly answer it
- time-bound: it says when the answer is needed and what period it covers
- tied to a decision: someone will do something differently depending on the answer
Break a large requirement into smaller key questions, and for each one list the indicators that would tell you the answer: what you would expect to see if the answer were yes, and what you would expect to see if it were no.
1.5 Thinking clearly under uncertainty
Open sources are noisy and often wrong. Your own mind adds errors of its own. Common biases and a practical check for each:
| Bias | What it looks like | A check |
|---|---|---|
| Confirmation bias | You notice evidence that fits your first idea and discount the rest. | Before concluding, write down what evidence would prove you wrong, then look for it. |
| Anchoring | The first report you saw sets the frame for everything after. | Re-read the question and list at least two alternative explanations. |
| Availability | Vivid or recent events feel more likely than they are. | Ask how often this has actually happened before. |
| Mirror imaging | You assume others think and act as you would. | Ask what the other party's incentives and constraints really are. |
| Groupthink | A team converges early and stops challenging itself. | Assign someone to argue the opposite case. |
A simple discipline helps most: keep what the source says, what you infer and what you do not know in separate places. Mixing them is how rumours become facts.
1.6 The research log
A research log is a running record of what you did, so that you, a colleague or a reviewer can retrace your work. Keep it from the first search, not after you find something interesting. Record:
- the date and time, in UTC
- what you searched for and where
- what you found, with the URL or reference
- an archived copy or screenshot, and for downloaded files a SHA-256 hash, so you can show the file has not changed
- your own notes, clearly separated from the source's words
- decisions you made, including dead ends and why you dropped them
1.7 Words that carry weight
Readers act on your words, so choose them deliberately. Say what you know, what you assess and how confident you are, using consistent terms such as "almost certainly", "likely", "roughly even chance" and "unlikely". Modules 4 and 8 cover calibrated language in depth.
1.8 How this course works
Each module ends with a short quiz. You pass a module quiz at 80 percent; if you do not pass, you can try again after one hour. When every module is passed, the final exam unlocks: 30 questions, 80 percent to pass, and a 24 hour wait before a retry. Passing the final exam earns a certificate. On SITREP, the course earns the gray check, which shows while you hold a personal Plus or higher subscription. You can finish first and subscribe later. It appears beside your handle when it is your highest visible mark, you have a username, and you have not hidden it.
Next: Module 2: Ethics and law