Services Method About Archive Contact

OSINT, HUMINT, SIGINT and the Rest: Every Intelligence Discipline Explained, with Historical Examples

In my work I use one acronym every day: OSINT. But OSINT is just one member of a large family of acronyms ending in -INT, short for intelligence. Each one indicates what kind of source a piece of information comes from: public documents, people, intercepted signals, images, physical measurements, money flows.

These acronyms were born in the world of the military and the secret services, mainly in the English-speaking world, but today they appear in companies, investigative journalism and private investigations. Understanding them serves two purposes: finding your way through terms that are often misused, and understanding what a private investigator may lawfully do and what remains reserved for the state.

In this article I go through all of them, with their meaning, a historical example for each, and a final assessment from the point of view of someone working in Switzerland.


Before the acronyms: what intelligence is

In the language of the services, intelligence does not mean "cleverness", but information collected, verified and analysed in order to make a decision. A raw piece of data is not yet intelligence: it becomes intelligence when someone has assessed it, compared it with other data and made it useful to whoever has to decide.

That is why people speak of the intelligence cycle, which in its most common versions has five phases:

  1. Planning and direction: the decision-maker asks the question. What do we need to know, and why?
  2. Collection: information is gathered from sources. This is where the different "-INT" disciplines come in.
  3. Processing: raw data is translated, decrypted, sorted and made readable.
  4. Analysis and production: the information is assessed, cross-checked and turned into conclusions.
  5. Dissemination: the product reaches the decision-maker, who in turn asks new questions.

It is, on a small scale, exactly the structure of a good investigative assignment: a clear question, lawful collection, rigorous analysis and a report that separates facts from hypotheses.


The classic disciplines

OSINT: Open Source Intelligence

What it is. Intelligence from open sources: everything lawfully accessible to the public. Official registers, newspapers, scientific publications, websites, public databases, radio and television broadcasts, images and maps. The key word is not "free" or "online", but lawfully accessible: even a paid extract from the land register is an open source.

A historical example. During the Second World War, both the BBC and the United States government set up services dedicated to systematically listening to foreign radio: BBC Monitoring in 1939 and, in the United States in 1941, the service that would become the Foreign Broadcast Information Service. Listening to what the enemy said openly made it possible to deduce what it did not say.

Today. The best-known case is the Bellingcat collective, founded in 2014 by Eliot Higgins, which showed the general public how photos, videos, satellite images and social media posts, verified and cross-checked, can reconstruct events that someone wanted to keep hidden.

In my work. It is the main discipline. I have applied it to very different cases, from the suspected plague in Irkutsk to the Manzoni plague.

HUMINT: Human Intelligence

What it is. Intelligence obtained from people: witnesses, sources, informants, experts, contacts. It includes conversations, interviews, direct observation and, in the world of the services, the recruitment of agents.

A historical example. It is the oldest discipline. The Art of War, the treatise attributed to the Chinese general Sun Tzu, already devotes an entire chapter to the use of spies and distinguishes several types. Two thousand years later, the Cold War was largely a war of human sources, double agents and defections.

The limits. People misremember, lie, have interests, and are influenced by whoever questions them. I showed this when analysing the witnesses to Hitler's death: two groups of witnesses questioned by rival powers, with results to be weighed one by one.

SIGINT: Signals Intelligence

What it is. Intelligence obtained by intercepting signals. It is a family with two main branches:

  • COMINT (Communications Intelligence): the interception of communications between people, such as phone calls, radio transmissions and messages.
  • ELINT (Electronic Intelligence): the analysis of electronic signals that are not communications, such as those of radars or guidance systems.

To these is added FISINT (Foreign Instrumentation Signals Intelligence), which concerns telemetry signals emitted, for example, by missiles during tests.

Historical examples.

  • In 1917 British codebreakers in the so-called Room 40 decrypted the Zimmermann Telegram, in which Germany proposed to Mexico an alliance against the United States. Its publication contributed to America's entry into the war.
  • In the Second World War, the decryption of messages from the Enigma machine at Bletchley Park, the programme known as Ultra, was one of the best-kept secrets of the conflict. I told its story in the article on the Enigma machine.
  • On the ELINT side, the so-called "Battle of the Beams" saw British scientists detect and jam the radio beams German bombers used to find their targets.

For a private individual. It is a discipline reserved for states, which exercise it within precise legal limits. For a private individual, intercepting other people's communications is a criminal offence.

IMINT: Imagery Intelligence

What it is. Intelligence obtained by analysing images: aerial photographs, satellite images, ground photographs, video. The analyst's job is not just to look, but to interpret: to recognise an object, measure it, and compare it with earlier images to understand what has changed.

A historical example. On 14 October 1962 an American U-2 reconnaissance plane photographed Soviet missile installations in Cuba. Those images triggered the Cuban Missile Crisis, one of the most dangerous moments of the Cold War. It showed how much a well-interpreted photograph could change history.

In my work. As a photographer, this discipline is close to my heart. I told the story of its strangest ancestor in the article on optography, the nineteenth-century illusion of photographing the killer in the victim's eye, and of its modern heir: the analysis of reflections in high-resolution photographs.

GEOINT: Geospatial Intelligence

What it is. The combination of images with geographic data: maps, coordinates, elevation, road networks, borders, buildings. It asks not only "what can be seen", but "where is it, how does it connect to everything else, how does it change over time".

Origin of the term. The acronym spread in the United States in the early 2000s, when the federal agency responsible for mapping and imagery was renamed the National Geospatial-Intelligence Agency.

Today. Geolocating a photo or video, working out exactly where it was taken by comparing mountains, buildings, shadows and signage with maps and satellite images, is one of the most widely used techniques in contemporary OSINT. In Switzerland, the historical maps and orthophotos made available by the Confederation also make it possible to see what a place looked like decades ago.

MASINT: Measurement and Signature Intelligence

What it is. The most technical discipline: intelligence obtained by measuring the physical "signatures" of objects and events. Acoustic, seismic, thermal, chemical, radiological, nuclear. An explosion, an engine or a reactor leaves measurable traces that make it possible to identify them even without seeing them.

Two minor acronyms belong to MASINT, among others:

  • ACINT (Acoustic Intelligence): the analysis of sounds, for example those of submarines. During the Cold War the United States laid a network of hydrophones on the ocean floor, known as SOSUS, to listen to their movements.
  • RADINT (Radar Intelligence): the use of radar data to derive information about the objects observed. Depending on the classification, it is placed under MASINT or ELINT.

For a private individual. It does not fall within a private investigator's work, except indirectly through technical expert reports entrusted to specialised laboratories.


The specialised disciplines

SOCMINT: Social Media Intelligence

What it is. The analysis of social networks: published content, relationships between profiles, places, habits, networks of contacts. Many consider it a branch of OSINT, but it has problems of its own, above all regarding data protection and ethics.

Origin of the term. It was proposed in 2012 in a report by the British think tank Demos, written by David Omand, former director of GCHQ, the British signals intelligence agency, with researchers Jamie Bartlett and Carl Miller.

The limits. A public profile is not unlimited permission. Collecting personal data from a social network is still data processing, and in Switzerland it must comply with data protection law. Creating fake profiles to enter closed groups or deceive a person is a different matter from consulting what is public, and can have legal consequences.

FININT: Financial Intelligence

What it is. The analysis of money flows, transactions, corporate structures and assets. It serves to reconstruct who pays whom, where wealth comes from and who really controls a company.

A historical example. The most cited case is that of Al Capone, convicted in 1931 not for his violent crimes but for tax evasion, thanks to the reconstruction of his income. It shows that money leaves traces even when people do not talk.

Today. Many countries have financial intelligence units that receive suspicious transaction reports. In Switzerland it is the Money Laundering Reporting Office Switzerland (MROS), part of the Federal Office of Police.

In my work. A private investigator has no access to third parties' bank data. They can, however, analyse documents lawfully obtained by the client, such as a deceased parent's bank statements requested by the heirs, and cross-check them against public registers. I covered this in the article on forced heirship and lifetime gifts and in the guide to tracing debtors' assets.

CYBINT or CYBERINT: Cyber Intelligence

What it is. Intelligence on cyber threats: who attacks, with what tools, what infrastructure they use, what vulnerabilities they exploit. In the corporate world it is often called threat intelligence.

The boundary. Analysing addresses, domains, phishing campaigns, data leaks that are already public and technical alerts is a legitimate defensive activity. Accessing other people's systems without authorisation is a criminal offence, even if done "to investigate". I covered a concrete case of a data leak in the article on the Ricardo data breach.

TECHINT: Technical Intelligence

What it is. The analysis of weapons, equipment and technologies, above all an adversary's, to understand their capabilities and weaknesses.

A historical example. In 1976 a Soviet pilot, Viktor Belenko, defected by landing in Japan in a MiG-25 fighter, one of the aircraft most feared by the West. Western experts were able to examine it in detail, and found that some of its capabilities had been overestimated.

MEDINT: Medical Intelligence

What it is. Health intelligence: epidemics, endemic diseases, hospital capacity, biological and chemical risks. In the United States there is a national centre dedicated to this discipline.

Why it matters. An epidemic can be hidden or played down by a government, and reconstructing it from indirect sources is a typical analytical task. It is exactly the problem I tackled in the case of the suspected plague in Irkutsk and, historically, with the Black Death.

Informal acronyms

Alongside the recognised disciplines, informal or humorous acronyms circulate, mostly in industry jargon. The best known is RUMINT, from rumour intelligence: "information" that comes from hearsay. It is not a discipline but a warning. Many of the errors I have analysed in historical cases, from the newspapers inventing the Jack the Ripper letters to the rumours about plague-spreaders, are RUMINT mistaken for intelligence.


All the acronyms in one table

Acronym Full name Source Lawfully accessible to a private individual?
OSINT Open Source Intelligence Open sources Yes
SOCMINT Social Media Intelligence Social networks Yes, within data protection limits
HUMINT Human Intelligence People Yes, through lawful conversations with consenting people
IMINT Imagery Intelligence Images Yes, with public or own images, respecting personality rights
GEOINT Geospatial Intelligence Geographic data Yes, with public maps and data
FININT Financial Intelligence Money flows Partly: only lawfully obtained documents and public registers
CYBINT Cyber Intelligence Cyber threats Partly: defensive analysis yes, accessing others' systems no
SIGINT Signals Intelligence Signals No
COMINT Communications Intelligence Communications No
ELINT Electronic Intelligence Electronic signals No
FISINT Foreign Instrumentation Signals Intelligence Telemetry No
MASINT Measurement and Signature Intelligence Physical signatures Only through technical expert reports
ACINT Acoustic Intelligence Acoustic signals Not relevant
RADINT Radar Intelligence Radar data Not relevant
TECHINT Technical Intelligence Equipment Not relevant
MEDINT Medical Intelligence Health data Only from public sources

Assessing a source: the letters-and-numbers method

Whatever the discipline, every piece of information must be assessed. One of the most widely used systems, born in the military and also used by police forces, assesses two aspects separately:

Source reliability Information credibility
A: completely reliable 1: confirmed by other sources
B: usually reliable 2: probably true
C: fairly reliable 3: possibly true
D: not usually reliable 4: doubtful
E: unreliable 5: improbable
F: reliability cannot be judged 6: truth cannot be judged

The principle is fundamental: a reliable source can give wrong information, and an unreliable source can tell the truth. That is why the two assessments are kept separate. A "B2" item is very different from an "E5" item, and a good report says so.


And in Switzerland?

In Switzerland the state's intelligence activities are entrusted to the Federal Intelligence Service (FIS) and governed by the Federal Intelligence Service Act, in force since 1 September 2017. The most intrusive measures, such as surveillance of communications, are subject to specific authorisations and controls.

For private individuals, and therefore for investigators too, the boundaries are drawn mainly by the Criminal Code, which punishes, among other things, eavesdropping on and recording other people's conversations (arts. 179bis ff.) and unauthorised access to a data processing system (art. 143bis), by the protection of personality under the Civil Code, and by the Data Protection Act, in the version in force since 1 September 2023. In Ticino, private investigation also requires a cantonal authorisation.

In practice: OSINT, SOCMINT, lawful HUMINT, public images and maps, and analysis of lawfully obtained documents are the tools of a serious investigator. Interceptions and computer intrusions are not, and anyone who promises them exposes themselves and the client to criminal liability, as well as producing material that risks being inadmissible in court.


What these acronyms teach investigators

Principle Practical application
Each acronym indicates a source, not a truth Information is only as good as its source and its verification
The disciplines complement one another OSINT shows whom to talk to, HUMINT adds what is not written down, GEOINT places facts in space
The cycle starts with a question Without a precise question, collection produces only noise
Source and information are assessed separately Even the best source can be wrong
RUMINT is always lurking A rumour repeated many times is still a rumour
Legality is part of the method Unlawfully gathered evidence can compromise the entire file

These are the rules I work by every day in my OSINT analysis and investigations, in Lugano and throughout Ticino: few acronyms, a lot of method, and a clear line between what can be done and what must not be done.


Main sources: encyclopaedic entries and public documentation on intelligence disciplines and the intelligence cycle; David Omand, Jamie Bartlett and Carl Miller, #Intelligence (Demos, 2012); Sun Tzu, The Art of War; historical documentation on the Zimmermann Telegram, the Ultra programme, the Cuban Missile Crisis and the Belenko case; Swiss Confederation, Federal Intelligence Service and Federal Office of Police (MROS); Swiss Criminal Code and Federal Act on Data Protection.

Frequently asked questions

What does OSINT mean?

OSINT stands for Open Source Intelligence. It refers to collecting and analysing information that is lawfully accessible to the public: official registers, the press, publications, websites, social networks, images and maps. The key word is not 'free' but 'lawfully accessible'.

What is the difference between HUMINT and OSINT?

OSINT relies on information that is already published or accessible, while HUMINT (Human Intelligence) relies on information obtained from people: witnesses, sources, conversations, interviews. In an investigation the two complement each other: OSINT shows where to look and whom to talk to, HUMINT adds what is not written down anywhere.

What is SIGINT?

SIGINT stands for Signals Intelligence: intelligence obtained by intercepting signals. It is divided mainly into COMINT, the interception of communications, and ELINT, the analysis of electronic signals such as radar. It is an activity reserved for states: for a private individual, intercepting other people's communications is a criminal offence.

What is SOCMINT?

SOCMINT stands for Social Media Intelligence: the analysis of content and relationships on social networks. The term was proposed in 2012 by David Omand, former director of the British agency GCHQ, with researchers Jamie Bartlett and Carl Miller. Many consider it a branch of OSINT.

Which intelligence disciplines can a private investigator use?

In Switzerland a private investigator can lawfully work with OSINT and SOCMINT on accessible sources, with HUMINT through conversations with consenting people, with financial analysis of documents lawfully obtained by the client, and with public images and maps. Intercepting communications and accessing other people's computer systems are prohibited by the Criminal Code.

What is the intelligence cycle?

It is the process by which raw information becomes knowledge useful for decision-making. The classic phases are five: planning and direction, collection, processing, analysis and production, dissemination. Feedback from the users of the product then restarts the cycle.

Address

Via Dante Alighieri 5, 6830 Chiasso (Svizzera)

Hours

Mon–Fri, 9am–7pm · we reply within 24 business hours

Confidentiality

Every request is handled with the utmost confidentiality, without exception.

Write us an email
info@minerva.agency Email info@minerva.agency

For maximum confidentiality we invite you to write from a Proton Mail account: communications between Proton addresses are end-to-end encrypted, so no one — not even the provider — can read their content. Opening one is free. proton.me

No contact forms, no data passing through intermediate servers: you write to us directly, from your own mail client.