Generally, we consider two types of approaches in OSINT and that are totally divided on the basis of how information is collected in both the approaches.
Passive OSINT -
Passive OSINT also called passive approach in OSINT is the way in which we collect information without doing any interaction with your target. In simple words, neither messaging your target, nor follow them on social media platforms and so on. It also includes that you don't even interact with them with sock puppets too.
If you don't know, what a sock puppet is?
Don't worry we learn about this in the second section: A Practical Approach to OSINT.
In this approach, we mainly collect information about our target without making them aware that someone is collecting information about it.
A passive approach includes -
Searching the target’s username using any username checker like Maigret or namecheck.com
Searching the target’s phone number using phoneinfoga and other phone number lookup tools
Searching the target’s email in data breaches and data leaks
Exploring the target’s social media accounts for gathering some useful information
There are many other passive approaches other than the above listed ones.
Active OSINT -
Active OSINT also called active approach in OSINT is the way in which you are making contact with the target or their is a risk that your online activities can be detected by the target. Normally, we dont use active OSINT as their is always a chance that your target can get alerted in this approach and as result, he may start deleting his online presence and other data from internet inorder to safeguard himself and preventing the investigater in proceeding furthur.
Also, sometimes its necessary to do a interaction with your victim in some situations, while doing so never use your identity, instead use sock puppets and also take other safety measures in order to protect your real identity like using VPNs, VMs, and other.
An active OSINT includes -
Sending your target a follow or connect request on social media sites
Messaging them on social media sites for any intention
Using any OSINT tools that alerts the target while doing so
Performing a nmap scan on target’s device

