Private digital intelligence bureau Lawful OSINT — Cyber monitoring — Due diligence
Analyst ordering events, dated sources, contradictions and unknown intervals

OSINT method guide · 12 min

Build an OSINT timeline that separates events, publications and unknowns.

A folder of screenshots is not a timeline. Separate when something happened, when a source reported it and when the analyst observed it.

Published 15 September 2026Reviewed by IIS editorial team

At a glance

Four rules for a useful review.

  • Keep multiple dates per item.
  • Normalise time zones.
  • Link every row to its source.
  • Display gaps and contradictions.

Step-by-step method

A reproducible path from question to conclusion.

  1. 1

    Define the time question

    Set the period, event to explain and useful granularity. A crisis lasting hours and a company history need different precision.

  2. 2

    Create core fields

    Separate event, publication, update and consultation dates, time zone, source and confidence for every item.

  3. 3

    Preserve original meaning

    Summarise without removing source caveats. Keep a short excerpt or contextual copy that supports review.

  4. 4

    Normalise without inventing

    Convert times to a chosen zone, mark approximate dates and never turn a vague period into a precise instant.

  5. 5

    Test competing sequences

    Place contradictions side by side, identify source dependence and look for events that should exist if a hypothesis were true.

  6. 6

    Write the decision reading

    Identify what precedes what, uncertainty windows, turning points and checks that could change the order or conclusion.

One source often contains several dates

A displayed date may describe publication, last modification or the reported event. Metadata, archives and syndication may reveal a different sequence.

Record what each date means. Apparent precision without definition creates a misleading timeline.

Expose time zones and uncertainty

Use a stable format, retain the original zone and state conversion. Do not force a date-only item before or after an event with an exact time.

Intervals, “before”, “no later than” and “between” should remain visible. Unknowns are methodological information, not defects to hide.

Compare hypotheses against sequence

A timeline tests causality without assuming it. One event preceding another does not prove that it caused it.

Mark sources copying each other. Five successive articles may all derive from one report and are not five confirmations.

Common pitfalls

Four shortcuts that weaken the result.

Using publication date only

It may be days later than the event described.

Mixing time zones

Offsets can reverse close events.

Filling gaps by intuition

An unknown interval should remain explicit.

Confusing order with causation

Sequence guides analysis but does not alone prove cause.

Practical questions

Frequently asked questions.

Which date format should be used?

An unambiguous format such as ISO 8601, including time zone where time matters.

How can a screenshot without metadata be dated?

Keep at least the observation date and seek an independent source or archive for first visibility.

Should everything enter the timeline?

No. Keep what answers the question and move secondary detail to appendices.

Editorial scope

Written and reviewed by Internet Intelligence Service on 15 September 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.