Public information is a double-edged sword. Understanding how OSINT works is how you learn to protect yourself and others from being doxxed.
Open-Source Intelligence (OSINT) is the collection and analysis of information that is publicly available. This includes public social media posts, domain records, news articles, maps, public databases, and the contents of websites that do not require special access.
OSINT is used by journalists, researchers, security teams, law enforcement, and ordinary people who want to understand what is publicly known about a topic. The key is that the information is lawfully available and the methods are defensive, not invasive.
Doxxing is the public release of private or identifying information with malicious intent. Prevention starts with reducing your public attack surface. The same OSINT techniques used to find information about you can be used to find and remove that information first.
Search your name, usernames, email addresses, and phone numbers. See what comes up on search engines, social media, and public records.
Set social profiles to private, remove location data, and limit who can see posts, photos, and contact information.
Opt out of people-search sites, data brokers, and public directories where allowed. Document what you removed and when.
Do not reuse the same username or avatar across platforms. A unique identity per site slows cross-platform correlation.
Use legitimate breach-notification services like Have I Been Pwned to learn when your credentials appear in disclosed data breaches.
Know in advance which platforms, hosts, and law-enforcement channels to contact if doxxing occurs. Speed matters.
I do not use OSINT to target, harass, stalk, or dox individuals. I use it to understand how attackers operate, to help victims reduce exposure, and to document evidence that can be reported through proper channels. The goal is safety, not surveillance.
"If you know how the enemy sees you, you can learn to hide."