The OSINT mirror: reading your own footprint

The OSINT mirror: reading your own footprint

Open-source intelligence is how your exposure gets found. Run the same mirror on yourself before someone else does.

OSINT / 2026-09-08

Open-source intelligence, OSINT, is the discipline of assembling a picture of a person from public information: records, posts, breaches, and the resale market. It requires no hacking, no special access, and often nothing more than a browser and persistence. It is the method behind most doxxing, most targeted phishing, and most of the credible threats a principal faces.

How a profile gets assembled

The assembler starts with a legal name and a state. Public records add property, business filings, and court history. Data brokers fuse those records with contact data and household links, and the people-search industry sells the result for pocket change. Breach data adds the passwords and emails that were never meant to be public, the residue of the record 3,322 compromises the Identity Theft Resource Center logged in 2025.

What an attacker does with it

  • Pretext: real travel plans and real colleagues make phishing scripts believable
  • Target selection: wealth markers and household structure decide who is worth attacking
  • Account access: reused credentials from breach data open the door, and recovery questions are answered by public record
  • Physical escalation: an address is all a fixated actor needs to move offline

Running the mirror on yourself

The same readout can be commissioned for legitimate purposes, and it should be, before an adversary runs it. The audit asks four questions: what does a broker file hold on you, what ranks for your name, what credentials of yours are circulating, and what do your own accounts reveal about your household. Most clients are surprised by the answer to at least two of them.

Hardening basics

  • Separate your public identity from your private one: distinct names on records where the law allows, distinct emails, distinct phone numbers
  • Stop the data from compounding: remove broker files, retire old accounts, and keep credit files frozen
  • Make the watch standing: re-verify quarterly, because exposure rebuilds on its own
  • Give your household the same treatment; attackers target the family, not just the principal
PROTOCOL NOTE The mirror audit is RECON, phase 01 of the BlackBox Defense protocol. It runs before any removal or hardening work, because you cannot erase what you have not mapped.