Open Source Intelligence (OSINT)
BeginnerLearn Open Source Intelligence (OSINT) as an investigation process, not a list of tools. Plan collection, search across people, domains, DNS, certificates, images, phone numbers and public records, verify sources, preserve evidence, and write findings for Cyber Threat Intelligence, fraud and digital risk work. The path also covers research OPSEC, isolated workstations and research personas so the investigation does not point back to you. Four sections, 42 lessons, and five case-based investigations.

Curriculum
8 more steps behind a free account
Free account
Ready to start Open Source Intelligence (OSINT)?
Create a free account to open the remaining 8 steps, track every one you finish and earn your certificate.
- Free to start
- Progress saved on every step
- Certificate on completion
Already have an account? Sign in
About this path
Open source investigations rarely fail because there is nothing to find. They fail because the question was vague, the search became noisy, the same claim was repeated by several sources that were not actually independent, or the investigator became visible along the way. This path starts with method before tools. You turn a request into an answerable question, define the scope, decide where the evidence should exist, and set a stopping condition before opening a browser.
The second section is about working safely. You build a separate research workstation, learn what your traffic and browser expose, and create a research persona that can be maintained without linking the work back to your real identity. The goal is not anonymity as a slogan. It is reducing avoidable linkage while keeping the investigation reproducible and the case notes usable.
The third section is collection on the open web. You move from search operators and identifier enumeration into domain, DNS and certificate research, archived material, reverse image search, phone number research, and public records. The emphasis stays on pivots: what one fact lets you test next, what would count as a stronger link, and when a check would cross the line from observation into interaction.
The final section is verification and reporting. You test whether sources are truly independent, catch recycled or manipulated material, preserve evidence before it changes, and write a finding around what the evidence supports, what remains unknown, and what the reader should do next. Five investigations run across the path so the method is practised as a chain rather than recalled as isolated facts.
This is the beginner OSINT path. It does not require prior investigation experience or paid tooling. Advanced infrastructure mapping, passive DNS, internet-wide scanning, large-scale collection, APIs and dataset work belong to Advanced OSINT Investigations.
What you will learn
- Plan a collection before you open a browser. Turn a question into a written plan with its sources named and a stopping condition, so a search ends in a finding rather than in more tabs.
- Grade what you find instead of just collecting it. Separate how reliable a source is from how credible one claim is, and record which of the two you are leaning on.
- Work without leaving a trail back to you. Harden a research workstation, separate your traffic, and know what your browser, your Tor session and your own uploads still give away.
- Build a persona you can keep and abandon cleanly. Create a research identity that stands up to a look, age it so it does not read as new, and recognise the point where it is spent.
- Get from one fact to the next across the open web. Search operators past the basics, usernames and email across platforms, a domain out to its certificates and archived history, then images, phone numbers and public registries.
- Verify a finding before it becomes a claim. Corroborate across independent sources, spot recycled and manipulated material, and say plainly when the evidence does not support the claim.
- Write it so somebody can act on it. Preserve the evidence before it disappears, structure the finding around what it establishes, and put the so-what where a reader will see it.
Who this path is for
- Cyber Threat Intelligence and OSINT analysts who need a repeatable method for turning public information into a finding that can support a decision.
- Fraud, digital risk and digital risk protection analysts who investigate people, companies, domains, accounts and public records across the open web.
- SOC and incident response analysts who already search public sources during investigations and want stronger collection planning, OPSEC, verification and evidence handling.
- Researchers, journalists, students and career changers who need findings that can survive challenge and want to practise on public material without special access.
Guides for this path
- OSINT: The Complete GuideOpen Source Intelligence (OSINT) is the practice of collecting, analyzing, and acting on information gathered from publicly available sources. In a world where digital footprints expand with every click, OSINT has become one of the most powerful disciplines in cyber threat intelligence, law enforcement, journalism, and corporate security. Whether you are investigating a phishing campaign, verifying a source, or mapping an organization's attack surface, OSINT provides the foundation for evidence-
Frequently asked questions
No. The path starts from the investigation process and builds the research workstation, collection plan, search workflow and verification method with you. Basic familiarity with a browser and files is enough.
This path teaches the core OSINT investigation method and the major public collection surfaces. Advanced OSINT Investigations goes deeper into infrastructure history, passive DNS, ASN and netblock analysis, internet-wide scanning, historical datasets, APIs, automation and collection at scale.
No. The core lessons and investigations are designed around public sources, free tools and techniques you can reproduce without a commercial subscription. Paid platforms can make some searches faster, but they are not the method.
No. This path is about collecting and evaluating publicly available material. It teaches where observation ends and interaction begins, and it does not require you to message a subject, test a credential or trigger an action on a live account.
Publicly available does not mean consequence-free. The path treats authorization, privacy, data minimisation, terms of service and evidence provenance as part of the investigation. If a check changes a live account, bypasses access controls or requires credentials that are not yours, it is outside the open-source workflow taught here.