Active Incident? 24/7 Response →
SleuthX

For Journalists

OSINT for Journalists

Verification, provenance, and the lawful line — how open-source methods corroborate a story, and how forensic discipline supports editorial diligence without replacing it.

By Quinn Varcoe, Founder & CEO, SleuthX

Open-source method, applied to reporting

Open-source intelligence for journalism is not a different craft from verification — it is verification, done rigorously, with publicly available material.

This guide is for reporters: it covers the techniques that corroborate online content, the legal line you must not cross, and the ethics of when not to use something.

It deliberately does not rehash the generic primer on what OSINT is; the goal here is the journalist-specific discipline that makes a finding hold up.

The verification toolkit

A handful of techniques do most of the corroboration work, and the point of all of them is the same: never trust a single signal.

The canonical method references are Bellingcat’s open-source research guides and First Draft’s five pillars of verification.

For legal and human-rights contexts, the Berkeley Protocol formalizes how to document method and preserve originals.

We apply these standards and cite them as the model.

The lawful line: access, not motive

The most important legal idea in journalist OSINT is simple.

Under the Computer Fraud and Abuse Act (18 U.S.C. §1030), as the Supreme Court read it in Van Buren v. United States, liability turns on whether you were authorized to access a system — not on your purpose once you are there.

Viewing and analyzing genuinely public information is open-source work.

Using stolen credentials or defeating an access control is not — that is the Computer Fraud and Abuse Act line.

Intercepting communications in transit (the Wiretap Act, 18 U.S.C. §2511) and reaching into an account or stored messages that are not yours (the Stored Communications Act, 18 U.S.C. §2701) are off-limits too, no matter how newsworthy the result.

Terms of service and other laws can still shape how you may collect, so anything aggressive belongs in front of counsel before you do it.

We do not perform unlawful access, and we do not help anyone else do it.

Provenance, corroboration, and when to hold

The ethic that separates verification from rumor is restraint.

First Draft’s rule is the one to adopt: if in doubt, do not use it.

A single unverifiable source, a provenance you cannot reconstruct, or a chain you cannot show is a reason to wait.

Build corroboration from independent signals, preserve the original, and be candid about your confidence.

This is the same discipline that makes forensic evidence defensible — show your work, and do not claim more than the material supports.

Where forensics supports the reporting

A forensic practice supports OSINT-driven stories at the edges where credibility is tested: confirming the integrity of a file, preserving and documenting material to a standard that survives challenge, and corroborating a finding with artifact-level evidence.

It does not become the reporter.

Where a matter moves from public-record verification into formal investigation — for legal or corporate purposes — that is a different engagement; see our OSINT investigation services for legal and corporate matters.

What working with us means

Related guides

To harden the devices and accounts you do this work on, see digital security for journalists.

The overview of how forensics supports reporting is on the For Journalists hub.

Plain terms

What we are — and what we are not

What we are

A digital forensics practice with an AI agent at the center. Credentialed examiners, documented chain of custody, explainable findings you can verify, and court-admissible reports under FRE 901/902. When field work is needed — backgrounds, locates, physical surveillance — we coordinate with licensed private investigators. Lawful, confidential, on your side.

What we are not

Spyware, stalkerware, or a way to secretly monitor another person. We do not “hack back,” promise guaranteed money recovery, or touch any account or device without its owner's lawful authorization — and we decline engagements that ask us to.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

Certified Expertise

GIAC

Frequently asked about OSINT for journalists

Is OSINT legal for journalists?
Gathering and analyzing genuinely public information is lawful — that is what open-source means. The line that matters under U.S. law is access, not motive. In Van Buren v. United States, the Supreme Court read the Computer Fraud and Abuse Act as turning on whether you were authorized to access a system at all, not on why you accessed data you were allowed to see. So scraping or viewing public posts is generally fine; using stolen credentials, defeating an access control, or logging into an account that is not yours is not — regardless of the public interest in the story. Terms of service and other laws can still constrain how you collect, so this is a question to run past counsel for anything aggressive.
How is this different from your OSINT investigation services?
This guide is about journalist tradecraft: verification, provenance, ethics, and the lawful line. Our transactional OSINT work for legal and corporate matters is a separate service with a different purpose and a different buyer. A reporter usually needs help confirming and corroborating what they have found and documenting it credibly — not outsourcing the reporting. We support editorial diligence; we do not replace it.
What techniques actually verify a piece of online content?
The workhorses are geolocation (pinning where an image was taken from visible landmarks), chronolocation (when, from shadows, weather, and other time signals), reverse-image search (has this appeared before, and where), EXIF and file-metadata analysis where it survives, and archiving the source the moment you find it so it cannot quietly change or vanish. None of these is conclusive alone; they corroborate. Bellingcat's open-source guides and First Draft's framework are the standard references for the methods.
When should I not use something I found?
First Draft's guidance is blunt and worth adopting: if in doubt, do not publish it. A single source, an unverifiable provenance, or a chain you cannot reconstruct is a reason to hold, not to hedge. The Berkeley Protocol on digital open-source investigations formalizes this for human-rights and legal contexts — document your method, preserve the original, and be honest about confidence. The discipline is the same one that makes evidence defensible: show your work.
Can OSINT prove who is behind an account or a campaign?
Sometimes it strongly supports an attribution; it rarely proves one outright. Open-source signals can build a high-confidence case — consistent patterns, reused infrastructure, corroborating records — but a careful examiner distinguishes “consistent with” from “proven,” and names the uncertainty. We will tell you when the evidence supports a confident claim and when it only supports a careful one. Guaranteed attribution is not something honest OSINT offers.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Corroborate it. Document it. Make it hold.

A direct, confidential conversation with Quinn, the founder and CEO who reviews every case. We support editorial diligence; we do not replace your reporting. NDA-protected. No sales process.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 15-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management