Skip to main content

OSINT, SOCMINT, HUMINT, GEOINT and FININT: The Disciplines Explained

What OSINT, SOCMINT, HUMINT, GEOINT, IMINT, FININT and SIGINT actually mean, where the boundaries sit, which identifiers belong to which discipline, and the UK legal context for organisations doing open-source research.

· By UserSearch Team · 13 min read

Disclaimer: This article is for education and for lawful, authorised professional research. Use these methods only where you have a legitimate purpose and a lawful basis, and follow the laws and platform terms that apply to you, including data protection law such as the UK GDPR and EU GDPR. See our Terms of Service.

TL;DR

  • The difference in OSINT vs SOCMINT vs HUMINT, and in every other "INT", is where information comes from and how it is collected, not the topic. OSINT is public and commercially available information; SOCMINT is the social media slice of it; HUMINT comes from people; GEOINT and IMINT come from imagery and geography; FININT from financial data; SIGINT from intercepted signals.
  • Private-sector teams work almost entirely in OSINT, SOCMINT, open-source GEOINT and IMINT, and the open side of FININT. HUMINT and SIGINT belong to specialists and statutory bodies.
  • We map common identifiers (username, email, domain, IP, image, wallet, company number and more) to the discipline they sit in and to the UserSearch Search type that handles them.
  • Labels matter legally: in the UK, public bodies may need RIPA authorisation for some repeated online research, and every organisation needs a lawful basis under data protection law.

Why Do the Intelligence Acronyms Cause Real Mistakes?

OSINT, SOCMINT and HUMINT differ by source: OSINT is intelligence from publicly or commercially available information, SOCMINT is the social media slice of it, and HUMINT is intelligence gathered from people. Most people meet the intelligence acronyms in a job advert or a vendor pitch, and the words get used loosely. A manager asks for "some SOCMINT on this supplier" and means a Google search. A fraud team calls a phone call to a customer "HUMINT". A journalist describes checking a satellite image as "doing GEOINT" and is not wrong, but is not doing what a defence analyst means by it either.

Loose labels cause three practical problems. Teams scope work badly, because they do not know which skills and sources a task needs. Reports mix evidence types without saying so, so a reader cannot tell a public register entry from a remark someone made on the phone. And, most importantly, some disciplines carry legal and ethical obligations that others do not. Talking to people, joining closed groups or intercepting communications sits under different rules from reading a public web page.

This explainer sets out what each discipline is, where the boundaries sit, which identifiers belong where, and what the UK legal context looks like for organisations doing open-source work.

The Intelligence Disciplines in Plain English

Each discipline is named after its source and collection method. The topic of the research does not change the label: a question about a company can draw on OSINT, FININT and HUMINT at once.

OSINT: Open-Source Intelligence

OSINT is intelligence produced from information that is publicly or commercially available. The US intelligence community's IC OSINT Strategy 2024-2026 defines it as intelligence derived exclusively from publicly or commercially available information that addresses specific intelligence priorities, requirements or gaps. Two parts of that definition matter. "Commercially available" means paid datasets count, not just the free web. And "addresses specific requirements" means OSINT is collection with a question, not browsing. A pile of search results is information. An answer to a stated question, with sources graded, is intelligence.

SOCMINT: Social Media Intelligence

SOCMINT is intelligence drawn from social media: accounts, posts, comments, groups, channels and the connections between them. The term was coined in the 2012 Demos paper #Intelligence by Sir David Omand, Jamie Bartlett and Carl Miller, which argued that it needed its own ethical principles and legal framework precisely because social media blurs public and private. Much SOCMINT is simply OSINT on social platforms. The boundary appears when access changes: reading a public Reddit thread is open source, while anything that needs membership, approval or interaction before you can see it belongs to a different category with its own legal and ethical rules.

HUMINT: Human Intelligence

HUMINT is intelligence gathered from people: interviews, debriefs, conversations with sources and relationships built over time. In the private sector the closest equivalents are due diligence interviews, reference calls and expert network consultations. It becomes HUMINT the moment you interact with a person to obtain information, rather than read what they published. That interaction carries duties of honesty and care that pure OSINT does not, and in the public sector it is heavily regulated.

GEOINT and IMINT: Geospatial and Imagery Intelligence

The US National Geospatial-Intelligence Agency describes GEOINT as the use of imagery, imagery intelligence and geospatial information to describe and depict features, activities and places on Earth. IMINT is the imagery part: analysis of photographs, satellite and aerial images. In open-source work, the two overlap heavily. Verifying where a photo was taken, comparing a building against satellite imagery, or checking shadows against the claimed time of day is open-source GEOINT. Free imagery such as the EU's Copernicus Browser makes this accessible to any newsroom.

FININT: Financial Intelligence

FININT is intelligence from financial information: transactions, accounts, ownership and payment flows. Formally, it is the business of financial intelligence units, which the Egmont Group describes as national centres for the receipt and analysis of suspicious transaction reports. In the UK, the National Crime Agency's UKFIU receives more than 850,000 Suspicious Activity Reports a year. Private firms hold financial data about their own customers and contribute to FININT through reporting. The open-source side of FININT, such as public blockchain records, company filings and sanctions lists, is where OSINT tools come in.

SIGINT: Signals Intelligence

SIGINT is intelligence from intercepted communications and electronic signals. In the UK it is GCHQ's core business; its mission overview describes collecting communications and data under strict legislation, then analysing them to produce intelligence reports. For private-sector teams the line is simple: reading public technical data, such as DNS records or a server's public banner, is OSINT. Capturing communications is SIGINT, and it belongs to bodies with statutory authority.

What Separates OSINT, SOCMINT, HUMINT and the Other Disciplines?

The quickest way to classify a piece of work is to ask two questions: where did the information come from, and did collecting it involve anything other than reading what is openly available?

DisciplineSourceCollection methodTypical private-sector use
OSINTPublic and commercially available informationSearch, read, query, purchase datasetsDue diligence, verification, security research, journalism
SOCMINTSocial media platformsRead public accounts, posts and channelsBrand protection, disinformation research, fraud prevention
HUMINTPeopleInterviews, conversations, debriefsReference calls, expert interviews, reporting
GEOINT / IMINTImagery and geospatial dataAnalyse maps, satellite and ground imageryPhoto and video verification, site checks, supply-chain research
FININTFinancial records and flowsTransaction analysis, reporting, public ledgersAML reviews, sanctions screening, payments risk
SIGINTCommunications and signalsInterception under statutory authorityNot applicable outside statutory bodies

You will also see CYBINT or technical intelligence used for infrastructure research: domains, IP addresses, certificates and internet-facing services. Most of it is OSINT applied to technical data, and we treat it that way below.

Mapping Identifiers to Disciplines and Search Types

In practice, research starts with an identifier, not a discipline. This table shows where common identifiers sit, which other disciplines they often touch, and which UserSearch Search type handles them. All examples are placeholders.

IdentifierExamplePrimary disciplineOften touchesUserSearch Search type
Username@example_handleSOCMINTOSINTUsername Intelligence
Email address[email protected]OSINTSOCMINTEmail Intelligence
Domainexample.comOSINT (technical)FININT (ownership)Domain Intelligence (ownership, history, favicon)
IP address203.0.113.10OSINT (technical)GEOINT (hosting region)IP Intelligence; Cyber Intelligence (Shodan Modules)
Image or video stilla photo posted by @example_handleIMINT / GEOINTSOCMINTPicture (reverse image search, geolocation, synthetic-image checks)
Crypto walletbc1q...placeholderFININT (open ledger)OSINTCryptocurrency
Company number00000000OSINT (corporate records)FININTCorporate Intelligence
Phone number+44 7700 900123OSINTSOCMINTPhone Intelligence
Telegram channel@example_channelSOCMINTOSINTChat Messaging (Telegram)
Reddit accountu/example_handleSOCMINTOSINTPublic Forums (Reddit)
Wi-Fi network (SSID/BSSID)00:00:5E:00:53:01GEOINT (technical)OSINTWireless Device (WiGLE data)
Vehicle registrationplaceholder plateOSINTGEOINTVehicle Lookup
Product, patent or appan app listingOSINT (business)FININTProduct Intelligence

Notice how few identifiers sit in one discipline alone. A wallet is financial data, but the address you start from usually came from a social post or a website. That is why good reports label the provenance of each finding, not just the topic.

Why Do the Distinctions Matter for Your Team?

Getting the label right is not academic. It decides what authorisation you need, who should do the work and how the output is stored. The Investigatory Powers Commissioner's Office publishes annual reports on public authorities' use of these powers; the report covering 2024 was published in December 2025, and the Commissioner's inspections look at how public bodies authorise and record their work. If you work alongside police, local authorities or regulators, expect them to ask which category your work falls into.

For private organisations, the pressure comes from data protection. In March 2026 the ICO published guidance on recognised legitimate interest, the new lawful basis introduced by the Data (Use and Access) Act 2025, which covers a narrow set of pre-approved purposes such as crime prevention and safeguarding. Most commercial OSINT will still rely on ordinary legitimate interests with an assessment on file, and knowing exactly which discipline and sources you used makes that assessment far easier to write.

It also shapes hiring and tooling. A research team that is 90% OSINT and SOCMINT needs different skills from one that runs interviews. Our page for research professionals covers how teams structure open-source work across these disciplines.

Working the Open-Source Disciplines by Hand

Here is what each open-source discipline looks like with free tools, so you can see the joins.

SOCMINT: Username Enumeration with Sherlock

Sherlock checks a username across several hundred sites. No API key is needed.

pipx install sherlock-project
sherlock example_handle --timeout 10 --csv

--timeout 10 stops slow sites stalling the run, and --csv writes results to a file you can attach to a report. Expect false positives on sites that return a generic page for every username, and false negatives on platforms that block automated requests. Every hit is an account with that handle, not proof of who runs it.

SOCMINT: Public Reddit Account Data

curl -s -A "acme-research/1.0 (contact: [email protected])" \
  "https://www.reddit.com/user/example_handle/about.json"

-s silences progress output and -A sets a descriptive user agent; Reddit throttles or refuses generic default clients quickly. The JSON includes account creation time and karma, which help separate a long-standing account from a new one. For deeper work, see our Reddit OSINT guide.

OSINT (Technical): Domain and DNS Records

whois example.com
dig +short A example.com
dig +short MX example.com

whois returns registration data, often redacted for privacy since GDPR. dig +short A returns the IPv4 addresses a domain resolves to and MX the mail servers. Both are public records, so this is OSINT even though it feels technical.

FININT (Open Ledger): Wallet Activity

curl -s "https://mempool.space/api/address/bc1q...placeholder"

The mempool.space REST API returns funded and spent totals and transaction counts for a Bitcoin address, with no key required for light use. It tells you what the public ledger shows. It does not tell you who controls the address; that attribution needs other sources.

GEOINT and IMINT: Verifying Where a Photo Was Taken

Here the tools are mostly visual: reverse image search engines, map services and satellite imagery. Compare fixed features (road layouts, rooflines, signage) against imagery from the claimed place and date, and check sun angle against the claimed time. Bellingcat's Online Investigation Toolkit lists the current free options by category and notes which require accounts.

The friction is the same across all of these: five disciplines, a dozen tools, separate logins, results in different formats, and no single record of what you searched.

One Platform Across the Open-Source Disciplines

UserSearch 2.0 brings the open-source side of these disciplines into one workspace with 18 Search types and 100+ third-party data sources behind one account. The identifier table above is, in effect, our product map: Username Intelligence and Public Forums (Reddit) and Chat Messaging (Telegram) for SOCMINT; Email, Phone, Domain, IP and Corporate Intelligence for OSINT; Picture for open-source IMINT and GEOINT; Cryptocurrency for the open ledger side of FININT; Wireless Device for WiGLE-based network data.

OneScan runs one input across several sources you choose and merges the results with source attribution, which is how you keep provenance labels intact when one identifier crosses disciplines. Cases in Forensic Mode store your search history and bookmarks, so a report can state which discipline and which source each finding came from. And SargeBot, our AI research assistant, can plan entity searches against a lawful objective you set, using the AI model you choose; its output is a draft for you to verify.

Worked Scenario: A Newsroom Verifies a Viral Video

Context. A regional newsroom receives a video, posted by @example_handle, claiming to show flooding at a named industrial estate yesterday. The desk editor needs to know, before publishing, whether it is where and when it claims.

Actions. This is SOCMINT plus open-source IMINT and GEOINT. The researcher runs a keyframe through Picture for reverse image search and a synthetic-image check, and the handle through Username Intelligence. Reverse search finds the same footage posted two years earlier by a different account. Comparing the warehouse roofline with satellite imagery shows it matches a site in another country, not the named estate. The account itself is four days old.

Outcome. The newsroom does not publish the video as current and instead runs a short verification note. The report labels each finding by discipline (SOCMINT for the account history, IMINT for the image match, GEOINT for the site comparison), so the editor can see the strength of each strand. Our journalism page covers this kind of verification work.

Worked Scenario: An AML Team Keeps FININT and OSINT Apart

Context. A payments firm's AML analyst reviews a business customer, Example Trading Ltd (company number 00000000), whose incoming transfers come from a crypto exchange. The customer's website lists a wallet for payments.

Actions. The firm's own transaction data is internal FININT: it stays in the firm's systems and feeds any report the firm is obliged to make. The open-source work runs separately: Corporate Intelligence on the company number, Cryptocurrency on the published wallet, and Domain Intelligence on the website. The analyst finds the company was incorporated eight months ago, the domain four months ago, and the wallet received funds from addresses the firm's screening had already flagged.

Outcome. The analyst records open-source findings in the Case with sources, and escalates internally under the firm's reporting procedure. Keeping the two strands labelled matters: the open-source findings can be shared with a partner bank, while the internal transaction analysis and any report made to the UKFIU cannot be disclosed to the customer.

Advanced Uses of Discipline Labels

Label Provenance in Every Report

Add a "discipline" column to your findings table. It takes seconds and it tells reviewers immediately which findings came from public sources and which came from people or internal data, which is often the first question a lawyer asks.

Fuse, Then Grade

All-source analysis means combining disciplines, not averaging them. A public register entry and an interview note are different kinds of evidence. Grade each on its own terms, then say how they support or contradict each other.

Know When to Hand Off

If your research reaches a point where the next step is talking to people, entering closed spaces or obtaining non-public records, stop and escalate. That step belongs to a different discipline, a different authorisation and often a different team.

Use Product Intelligence for Business Questions

Due diligence on a technology supplier is often better served by patents, scholarly material, app listings and trend data than by social media. Product Intelligence covers those sources, and they rarely carry the personal-data weight of SOCMINT.

For public bodies in the UK, Part II of the Regulation of Investigatory Powers Act 2000 is the key framework. Part II of RIPA sets out when authorisation is needed for planned, non-overt activity that is likely to obtain private information about a person. Home Office codes of practice explain that a single look at public online material will not usually need authorisation, but repeated or systematic viewing of a specific person's online activity, or recording and analysing it, may. Public-sector teams should follow their own force or authority policy and the relevant code, and keep a record of each decision.

For every organisation, UK GDPR applies. Identify a lawful basis before you start, which for most private-sector OSINT is legitimate interests supported by a written assessment. Collect only what the question needs, keep it no longer than necessary, and be ready to explain your sources. The Berkeley Protocol, produced by the UC Berkeley Human Rights Center with the UN Human Rights Office, is a sound reference for ethical open-source practice, including the principle of minimising harm to the people whose data you handle.

Stay within open sources and platform terms. Interaction with people, access to closed spaces and anything resembling interception belong to other disciplines with their own rules. When in doubt, ask your legal or data protection team before, not after.

Frequently Asked Questions About OSINT vs SOCMINT vs HUMINT

What is the difference between OSINT, SOCMINT and HUMINT?

OSINT, SOCMINT and HUMINT are defined by source and collection method. OSINT is intelligence from publicly or commercially available information. SOCMINT is the social media part of it: accounts, posts, groups and channels. HUMINT is gathered from people through interviews, debriefs and conversations. Reading published material is OSINT or SOCMINT; interacting with a person to obtain information is HUMINT.

Is SOCMINT the same as OSINT?

Much SOCMINT is simply OSINT carried out on social platforms, such as reading a public Reddit thread or a public Telegram channel. The boundary between SOCMINT and OSINT appears when access changes: material that needs membership, approval or interaction before it can be seen falls outside open source and carries different legal and ethical obligations from reading a public page.

What is GEOINT in open-source research?

GEOINT, or geospatial intelligence, uses imagery and geospatial information to describe features, activities and places on Earth, and IMINT is the imagery part. In open-source research, GEOINT means verifying where a photo was taken, comparing a building against satellite imagery, or checking shadows against the claimed time of day, often with free imagery such as the Copernicus Browser.

What is FININT?

FININT, or financial intelligence, comes from transactions, accounts, ownership and payment flows. Formally, FININT is the work of financial intelligence units such as the UKFIU at the National Crime Agency. Private firms contribute through reporting, while the open-source side of FININT covers public blockchain records, company filings and sanctions lists that any analyst can read.

OSINT is lawful in the UK when it is done with a lawful basis and within the rules. Every organisation needs a lawful basis under UK GDPR, usually legitimate interests with a written assessment, and should collect only what the question needs. Public bodies may also need authorisation under Part II of RIPA for repeated or systematic viewing of a person's online activity.

Which intelligence disciplines can private companies use?

Private-sector teams work almost entirely in OSINT, SOCMINT, open-source GEOINT and IMINT, and the open side of FININT, such as public ledgers and company filings. HUMINT in the form of reference calls and expert interviews carries duties of honesty and care, while SIGINT, the interception of communications, belongs only to bodies with statutory authority such as GCHQ.

Clear Labels, Better Research

The disciplines are a vocabulary for being precise about where evidence came from. Use them that way and your scoping improves, your reports become easier to check, and your legal position becomes easier to explain.

Stop guessing. Start researching with UserSearch. One account covers the open-source disciplines through 18 Search types and 100+ data sources, OneScan keeps source attribution when one identifier crosses from SOCMINT into OSINT or open-ledger FININT, Cases in Forensic Mode record which search produced each finding, team Cases share the work, and SargeBot drafts a PDF report you can verify and label by discipline. For a primer on the social media side, see our social media knowledge base.

About the author

UserSearch Team
Updated on Oct 2, 2026