Intelligence Collection Expert Knowledge
OSINT Methodology
Collection Cycle
- Planning: Define target, scope, and collection requirements
- Collection: Gather raw data from open sources
- Processing: Extract entities, relationships, and data points
- Analysis: Synthesize findings, identify patterns, detect changes
- Dissemination: Generate reports, alerts, and updates
- Feedback: Refine queries based on what worked and what didn't
Source Categories (by reliability)
| Tier |
Source Type |
Reliability |
Examples |
| 1 |
Official/Primary |
Very High |
Company filings, government data, press releases |
| 2 |
Institutional |
High |
News agencies (Reuters, AP), research institutions |
| 3 |
Professional |
Medium-High |
Industry publications, analyst reports, expert blogs |
| 4 |
Community |
Medium |
Forums, social media, review sites |
| 5 |
Anonymous/Unverified |
Low |
Anonymous posts, rumors, unattributed claims |
Search Query Construction by Focus Area
Market Intelligence:
"[target] market share"
"[target] industry report [year]"
"[target] TAM SAM SOM"
"[target] growth rate"
"[target] market analysis"
"[target industry] trends [year]"
Business Intelligence:
"[company] revenue" OR "[company] earnings"
"[company] CEO" OR "[company] leadership team"
"[company] strategy" OR "[company] roadmap"
"[company] partnerships" OR "[company] acquisition"
"[company] annual report" OR "[company] 10-K"
site:sec.gov "[company]"
Competitor Analysis:
"[company] vs [competitor]"
"[company] alternative"
"[company] review" OR "[company] comparison"
"[company] pricing" site:g2.com OR site:capterra.com
"[company] customer reviews" site:trustpilot.com
"switch from [company] to"
Person Tracking:
"[person name]" "[company]"
"[person name]" interview OR podcast OR keynote
"[person name]" site:linkedin.com
"[person name]" publication OR paper
"[person name]" conference OR summit
Technology Monitoring:
"[technology] release" OR "[technology] update"
"[technology] benchmark [year]"
"[technology] adoption" OR "[technology] usage statistics"
"[technology] vs [alternative]"
"[technology]" site:github.com
"[technology] roadmap" OR "[technology] changelog"
Entity Extraction Patterns
Named Entity Types
- Person: Name, title, organization, role
- Organization: Company name, type, industry, location, size
- Product: Product name, company, category, version
- Event: Type, date, participants, location, significance
- Financial: Amount, currency, type (funding, revenue, valuation)
- Technology: Name, version, category, vendor
- Location: City, state, country, region
- Date/Time: Specific dates, time ranges, deadlines
Extraction Heuristics
- Person detection: Title + Name pattern ("CEO John Smith"), bylines, quoted speakers
- Organization detection: Legal suffixes (Inc, LLC), "at [Company]", domain names
- Financial detection: Currency symbols, "raised $X", "valued at", "revenue of"
- Event detection: Date + verb ("launched on", "announced at", "acquired")
- Technology detection: CamelCase names, version numbers, "built with", "powered by"
Knowledge Graph Best Practices
Entity Schema
{
"entity_id": "unique_id",
"name": "Entity Name",
"type": "person|company|product|event|technology",
"attributes": {
"key": "value"
},
"sources": ["url1", "url2"],
"first_seen": "timestamp",
"last_seen": "timestamp",
"confidence": "high|medium|low"
}
Relation Schema
{
"source_entity": "entity_id_1",
"relation": "works_at|founded|competes_with|...",
"target_entity": "entity_id_2",
"attributes": {
"since": "date",
"context": "description"
},
"source": "url",
"confidence": "high|medium|low"
}
Common Relations
| Relation |
Between |
Example |
| works_at |
Person → Company |
"Jane Smith works at Acme" |
| founded |
Person → Company |
"John Doe founded StartupX" |
| invested_in |
Company → Company |
"VC Fund invested in StartupX" |
| competes_with |
Company → Company |
"Acme competes with BetaCo" |
| partnered_with |
Company → Company |
"Acme partnered with CloudY" |
| launched |
Company → Product |
"Acme launched ProductZ" |
| acquired |
Company → Company |
"BigCorp acquired StartupX" |
| uses |
Company → Technology |
"Acme uses Kubernetes" |
| mentioned_in |
Entity → Source |
"Acme mentioned in TechCrunch" |
Change Detection Methodology
Snapshot Comparison
- Store the current state of all entities as a JSON snapshot
- On next collection cycle, compare new state against previous snapshot
- Classify changes:
| Change Type |
Significance |
Example |
| Entity appeared |
Varies |
New competitor enters market |
| Entity disappeared |
Important |
Company goes quiet, product deprecated |
| Attribute changed |
Critical-Minor |
CEO changed (critical), address changed (minor) |
| New relation |
Important |
New partnership, acquisition, hiring |
| Relation removed |
Important |
Person left company, partnership ended |
| Sentiment shift |
Important |
Positive→Negative media coverage |
Significance Scoring
CRITICAL (immediate alert):
- Leadership change (CEO, CTO, board)
- Acquisition or merger
- Major funding round (>$10M)
- Product discontinuation
- Legal action or regulatory issue
IMPORTANT (include in next report):
- New product launch
- New partnership or integration
- Hiring surge (>5 roles)
- Pricing change
- Competitor move
- Major customer win/loss
MINOR (note in report):
- Blog post or press mention
- Minor update or patch
- Social media activity spike
- Conference appearance
- Job posting (individual)
Sentiment Analysis Heuristics
When track_sentiment is enabled, classify each source's tone:
Classification Rules
- Positive indicators: "growth", "innovation", "breakthrough", "success", "award", "expansion", "praise", "recommend"
- Negative indicators: "lawsuit", "layoffs", "decline", "controversy", "failure", "breach", "criticism", "warning"
- Neutral indicators: factual reporting without strong adjectives, data-only articles, announcements
Sentiment Scoring
Strong positive: +2 (e.g., "Company wins major award")
Mild positive: +1 (e.g., "Steady growth continues")
Neutral: 0 (e.g., "Company releases Q3 report")
Mild negative: -1 (e.g., "Faces increased competition")
Strong negative: -2 (e.g., "Major data breach disclosed")
Track rolling average over last 5 collection cycles to detect trends.
Report Templates
Intelligence Brief (Markdown)
# Intelligence Report: [Target]
**Date**: YYYY-MM-DD HH:MM UTC
**Collection Cycle**: #N
**Sources Processed**: X
**New Data Points**: Y
## Priority Changes
1. [CRITICAL] [Description + source]
2. [IMPORTANT] [Description + source]
## Executive Summary
[2-3 paragraph synthesis of new intelligence]
## Detailed Findings
### [Category 1]
- Finding with [source](url)
- Data point with confidence: high/medium/low
### [Category 2]
- ...
## Entity Updates
| Entity | Change | Previous | Current | Source |
|--------|--------|----------|---------|--------|
## Sentiment Trend
| Period | Score | Direction | Notable |
|--------|-------|-----------|---------|
## Collection Metadata
- Queries executed: N
- Sources fetched: N
- New entities: N
- Updated entities: N
- Next scheduled collection: [datetime]
Source Evaluation Checklist
Before including data in the knowledge graph, evaluate:
- Recency: Published within relevant timeframe? Stale data can mislead.
- Primary vs Secondary: Is this the original source, or citing someone else?
- Corroboration: Do other independent sources confirm this?
- Bias check: Does the source have a financial or political interest in this claim?
- Specificity: Does it provide concrete data, or vague assertions?
- Track record: Has this source been reliable in the past?
If a claim fails 3+ checks, downgrade its confidence to "low".
1---2name: collector-hand-skill3description: Expert knowledge for AI intelligence collection — OSINT methodology, entity extraction, knowledge graphs, change detection, and sentiment analysis4---5
6# Intelligence Collection Expert Knowledge
7
8## OSINT Methodology
9
10### Collection Cycle
111. **Planning**: Define target, scope, and collection requirements
122. **Collection**: Gather raw data from open sources
133. **Processing**: Extract entities, relationships, and data points
144. **Analysis**: Synthesize findings, identify patterns, detect changes
155. **Dissemination**: Generate reports, alerts, and updates
166. **Feedback**: Refine queries based on what worked and what didn't
17
18### Source Categories (by reliability)
19| Tier | Source Type | Reliability | Examples |
20|------|-----------|-------------|---------|
21| 1 | Official/Primary | Very High | Company filings, government data, press releases |
22| 2 | Institutional | High | News agencies (Reuters, AP), research institutions |
23| 3 | Professional | Medium-High | Industry publications, analyst reports, expert blogs |
24| 4 | Community | Medium | Forums, social media, review sites |
25| 5 | Anonymous/Unverified | Low | Anonymous posts, rumors, unattributed claims |
26
27### Search Query Construction by Focus Area
28
29**Market Intelligence**:
30```
31"[target] market share"
32"[target] industry report [year]"
33"[target] TAM SAM SOM"
34"[target] growth rate"
35"[target] market analysis"
36"[target industry] trends [year]"
37```
38
39**Business Intelligence**:
40```
41"[company] revenue" OR "[company] earnings"
42"[company] CEO" OR "[company] leadership team"
43"[company] strategy" OR "[company] roadmap"
44"[company] partnerships" OR "[company] acquisition"
45"[company] annual report" OR "[company] 10-K"
46site:sec.gov "[company]"
47```
48
49**Competitor Analysis**:
50```
51"[company] vs [competitor]"
52"[company] alternative"
53"[company] review" OR "[company] comparison"
54"[company] pricing" site:g2.com OR site:capterra.com
55"[company] customer reviews" site:trustpilot.com
56"switch from [company] to"
57```
58
59**Person Tracking**:
60```
61"[person name]" "[company]"
62"[person name]" interview OR podcast OR keynote
63"[person name]" site:linkedin.com
64"[person name]" publication OR paper
65"[person name]" conference OR summit
66```
67
68**Technology Monitoring**:
69```
70"[technology] release" OR "[technology] update"
71"[technology] benchmark [year]"
72"[technology] adoption" OR "[technology] usage statistics"
73"[technology] vs [alternative]"
74"[technology]" site:github.com
75"[technology] roadmap" OR "[technology] changelog"
76```
77
78---
79
80## Entity Extraction Patterns
81
82### Named Entity Types
831. **Person**: Name, title, organization, role
842. **Organization**: Company name, type, industry, location, size
853. **Product**: Product name, company, category, version
864. **Event**: Type, date, participants, location, significance
875. **Financial**: Amount, currency, type (funding, revenue, valuation)
886. **Technology**: Name, version, category, vendor
897. **Location**: City, state, country, region
908. **Date/Time**: Specific dates, time ranges, deadlines
91
92### Extraction Heuristics
93- **Person detection**: Title + Name pattern ("CEO John Smith"), bylines, quoted speakers
94- **Organization detection**: Legal suffixes (Inc, LLC), "at [Company]", domain names
95- **Financial detection**: Currency symbols, "raised $X", "valued at", "revenue of"
96- **Event detection**: Date + verb ("launched on", "announced at", "acquired")
97- **Technology detection**: CamelCase names, version numbers, "built with", "powered by"
98
99---
100
101## Knowledge Graph Best Practices
102
103### Entity Schema
104```json
105{
106 "entity_id": "unique_id",
107 "name": "Entity Name",
108 "type": "person|company|product|event|technology",
109 "attributes": {
110 "key": "value"
111 },
112 "sources": ["url1", "url2"],
113 "first_seen": "timestamp",
114 "last_seen": "timestamp",
115 "confidence": "high|medium|low"
116}
117```
118
119### Relation Schema
120```json
121{
122 "source_entity": "entity_id_1",
123 "relation": "works_at|founded|competes_with|...",
124 "target_entity": "entity_id_2",
125 "attributes": {
126 "since": "date",
127 "context": "description"
128 },
129 "source": "url",
130 "confidence": "high|medium|low"
131}
132```
133
134### Common Relations
135| Relation | Between | Example |
136|----------|---------|---------|
137| works_at | Person → Company | "Jane Smith works at Acme" |
138| founded | Person → Company | "John Doe founded StartupX" |
139| invested_in | Company → Company | "VC Fund invested in StartupX" |
140| competes_with | Company → Company | "Acme competes with BetaCo" |
141| partnered_with | Company → Company | "Acme partnered with CloudY" |
142| launched | Company → Product | "Acme launched ProductZ" |
143| acquired | Company → Company | "BigCorp acquired StartupX" |
144| uses | Company → Technology | "Acme uses Kubernetes" |
145| mentioned_in | Entity → Source | "Acme mentioned in TechCrunch" |
146
147---
148
149## Change Detection Methodology
150
151### Snapshot Comparison
1521. Store the current state of all entities as a JSON snapshot
1532. On next collection cycle, compare new state against previous snapshot
1543. Classify changes:
155
156| Change Type | Significance | Example |
157|-------------|-------------|---------|
158| Entity appeared | Varies | New competitor enters market |
159| Entity disappeared | Important | Company goes quiet, product deprecated |
160| Attribute changed | Critical-Minor | CEO changed (critical), address changed (minor) |
161| New relation | Important | New partnership, acquisition, hiring |
162| Relation removed | Important | Person left company, partnership ended |
163| Sentiment shift | Important | Positive→Negative media coverage |
164
165### Significance Scoring
166```
167CRITICAL (immediate alert):
168 - Leadership change (CEO, CTO, board)
169 - Acquisition or merger
170 - Major funding round (>$10M)
171 - Product discontinuation
172 - Legal action or regulatory issue
173
174IMPORTANT (include in next report):
175 - New product launch
176 - New partnership or integration
177 - Hiring surge (>5 roles)
178 - Pricing change
179 - Competitor move
180 - Major customer win/loss
181
182MINOR (note in report):
183 - Blog post or press mention
184 - Minor update or patch
185 - Social media activity spike
186 - Conference appearance
187 - Job posting (individual)
188```
189
190---
191
192## Sentiment Analysis Heuristics
193
194When `track_sentiment` is enabled, classify each source's tone:
195
196### Classification Rules
197- **Positive indicators**: "growth", "innovation", "breakthrough", "success", "award", "expansion", "praise", "recommend"
198- **Negative indicators**: "lawsuit", "layoffs", "decline", "controversy", "failure", "breach", "criticism", "warning"
199- **Neutral indicators**: factual reporting without strong adjectives, data-only articles, announcements
200
201### Sentiment Scoring
202```
203Strong positive: +2 (e.g., "Company wins major award")
204Mild positive: +1 (e.g., "Steady growth continues")
205Neutral: 0 (e.g., "Company releases Q3 report")
206Mild negative: -1 (e.g., "Faces increased competition")
207Strong negative: -2 (e.g., "Major data breach disclosed")
208```
209
210Track rolling average over last 5 collection cycles to detect trends.
211
212---
213
214## Report Templates
215
216### Intelligence Brief (Markdown)
217```markdown
218# Intelligence Report: [Target]
219**Date**: YYYY-MM-DD HH:MM UTC
220**Collection Cycle**: #N
221**Sources Processed**: X
222**New Data Points**: Y
223
224## Priority Changes
2251. [CRITICAL] [Description + source]
2262. [IMPORTANT] [Description + source]
227
228## Executive Summary
229[2-3 paragraph synthesis of new intelligence]
230
231## Detailed Findings
232
233### [Category 1]
234- Finding with [source](url)
235- Data point with confidence: high/medium/low
236
237### [Category 2]
238- ...
239
240## Entity Updates
241| Entity | Change | Previous | Current | Source |
242|--------|--------|----------|---------|--------|
243
244## Sentiment Trend
245| Period | Score | Direction | Notable |
246|--------|-------|-----------|---------|
247
248## Collection Metadata
249- Queries executed: N
250- Sources fetched: N
251- New entities: N
252- Updated entities: N
253- Next scheduled collection: [datetime]
254```
255
256---
257
258## Source Evaluation Checklist
259
260Before including data in the knowledge graph, evaluate:
261
2621. **Recency**: Published within relevant timeframe? Stale data can mislead.
2632. **Primary vs Secondary**: Is this the original source, or citing someone else?
2643. **Corroboration**: Do other independent sources confirm this?
2654. **Bias check**: Does the source have a financial or political interest in this claim?
2665. **Specificity**: Does it provide concrete data, or vague assertions?
2676. **Track record**: Has this source been reliable in the past?
268
269If a claim fails 3+ checks, downgrade its confidence to "low".