Passive Collection
Definition
OSINT collection that queries third-party databases and archived sources without sending any traffic directly to the target's systems, avoiding any trace on the target's server logs.
- Field
- OSINT
- Method
- Queries third-party databases and archives
- Key property
- No traffic sent to the target's systems
- Benefit
- No trace in the target's server logs
Common questions
Why do investigators prefer passive collection early in an OSINT investigation?+
It avoids alerting the subject to the investigation, since no request reaches the target's own infrastructure or leaves a record in logs they control.
What is an example source used for passive collection?+
Archived web page snapshots, cached search results, and third-party WHOIS or passive DNS databases all let an investigator gather information without querying the target directly.
Related terms
- Digital Footprint
- The cumulative set of data traces a person or entity leaves across internet-accessible sources, including domain registrations, social media posts, forum accounts,...
- Metadata
- Data about data. In document forensics, metadata includes file-creation timestamps, last-modified dates, author fields, revision history, and embedded GPS coordinates in images....
- OSINT
- Open-Source Intelligence. Investigation using publicly available sources: social media, satellite imagery, news archives, public databases. In deepfake casework, OSINT corroborates or contradicts...
- Sock Puppet
- A fictitious online identity created and controlled by an investigator to observe or interact with a target without revealing the investigation. The...
- WHOIS
- A query protocol that returns registration data for a domain, including registrant name, organisation, email, nameservers, and registration and expiry dates. Since...