Advanced OSINT Investigations

Intermediate

Take one domain or one address and turn it into a verified picture of the infrastructure behind it. This path works the public record layer in depth, which means reading a DNS answer rather than running a lookup, reading a certificate rather than checking that it is valid, and dating a change rather than describing a state.

By CTI Academy Team59 steps6 sections~6 hoursCertificate

Curriculum

59 steps across 6 sections. Sections unlock in order as you complete them.

8 more steps behind a free account

Free account

Ready to start Advanced OSINT Investigations?

Create a free account to open the remaining 8 steps, track every one you finish and earn your certificate.

  • Free to start
  • Progress saved on every step
  • Certificate on completion
Sign up with email

About this path

Fundamentals showed you what each open source surface can do. This path goes down into them. You will spend it on records, registration data, transparency logs, passive DNS, subdomains, scanning engines, archives and images, and every module ends with the same discipline, which is separating what the evidence establishes from what it only suggests. The path deliberately stops short of threat actor context. Whether infrastructure belongs to an actor is the question the next paths in the journey answer, and they reuse these techniques to do it.

What you will learn

  • Read a DNS response end to end, including the codes and counters that say whether a name exists at all
  • Pull registration data over RDAP and read what survives redaction
  • Work certificate transparency logs without mistaking rows for hosts
  • Turn a resolution history into dated events rather than a description of today
  • Map an organisation's domain portfolio and record the evidence beside every entry
  • Enumerate subdomains and hidden paths from several sources and reconcile them
  • Fingerprint an exposed asset from its banner, its certificate and its technology stack
  • State a correlation as a hypothesis with the sentence that would break it

Who this path is for

  • Analysts who finished OSINT Fundamentals and want depth rather than more surfaces
  • SOC and CTI analysts who read infrastructure data daily and want to read it more precisely
  • Attack surface and exposure management people mapping an estate from outside
  • Investigators and journalists who need infrastructure findings that hold up to challenge

Guides for this path

  • Sock Puppet Accounts: How OSINT Analysts Build PersonasMost research accounts are not burned by clever adversaries, they are burned by the analyst who made them, and by the account nobody ever authorised in writing. This is a working method for building an OSINT research persona: the six-step process, the law behind it, and how platform detection has evolved.

Frequently asked questions

It is advisory rather than enforced. This path assumes you already know search operators, the OSINT cycle, source rating, verification and how to keep an investigation account separate from your own. It will not reteach any of those.

No. It teaches the infrastructure techniques that threat intelligence work rests on, without actor context. Requirements, source grading, structured analytic technique and estimative language belong to the Cyber Threat Intelligence path, and actor clustering and attribution belong to the two paths after it.

Every lesson ends with a task you run yourself, and every section ends with two missions. The techniques work against any domain you are permitted to query, and the lab environment is there for the ones that need a controlled target.

Most of the path is passive. Where a technique sends requests to somebody else's infrastructure, the lesson says so plainly and tells you where authorisation stops being a formality.