Law-enforcement personnel in resource-constrained environments increasingly face doxxing and technology-facilitated targeting built entirely from publicly available information. This paper proposes and evaluates a defensive Open-Source Intelligence (OSINT) framework designed for underfunded policing units in Malawi. The framework integrates three functional stages: (1) passive exposure mapping with auditable provenance and structured data schemata; (2) authorized breach-indicator checking via public APIs with k-anonymity safeguards; and (3) investigator operational security through hardware-isolated Linux environments. A controlled proof-of-concept on ten synthetic officer profiles demonstrates the pipeline reduces median assessment time by 62%, achieves 83% recall across six exposure categories, and records zero investigator-attribution events. The framework is situated within Malawi’s Electronic Transactions and Cyber Security Act and Data Protection Act, translating statutory principles into operational controls.