Skip to content

Passive Collection

Definition

OSINT collection that queries third-party databases and archived sources without sending any traffic directly to the target's systems, avoiding any trace on the target's server logs.

Field
OSINT
Method
Queries third-party databases and archives
Key property
No traffic sent to the target's systems
Benefit
No trace in the target's server logs

Common questions

Why do investigators prefer passive collection early in an OSINT investigation?+

It avoids alerting the subject to the investigation, since no request reaches the target's own infrastructure or leaves a record in logs they control.

What is an example source used for passive collection?+

Archived web page snapshots, cached search results, and third-party WHOIS or passive DNS databases all let an investigator gather information without querying the target directly.

Related terms

Digital Footprint
The cumulative set of data traces a person or entity leaves across internet-accessible sources, including domain registrations, social media posts, forum accounts,...
Metadata
Data about data. In document forensics, metadata includes file-creation timestamps, last-modified dates, author fields, revision history, and embedded GPS coordinates in images....
OSINT
Open-Source Intelligence. Investigation using publicly available sources: social media, satellite imagery, news archives, public databases. In deepfake casework, OSINT corroborates or contradicts...
Sock Puppet
A fictitious online identity created and controlled by an investigator to observe or interact with a target without revealing the investigation. The...
WHOIS
A query protocol that returns registration data for a domain, including registrant name, organisation, email, nameservers, and registration and expiry dates. Since...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.