Group Purchasing
Group Purchasing

What Is the GOSI Certification?

The GIAC Open Source Intelligence (GOSI) certification confirms that practitioners have a strong foundation in OSINT methodologies and frameworks. GOSI holders are well versed in collecting, analyzing, and reporting on people, businesses, and infrastructure using publicly available data, while applying sound operational security throughout the process.

By the numbers

2 hrs

Exam duration

75

Questions

69%

Min. passing score

What GOSI Covers

GIAC groups the GOSI exam objectives into six practical domains, spanning people, business, and infrastructure investigations along with the methodology and operational security that hold an investigation together.

OSINT Methodology

Familiarity with the goals of OSINT and the documentation needed to run a fact-based investigation process.

Privacy and Operational Security Fundamentals

Identifying confidentiality and integrity risks and applying OPSEC best practices to minimize exposure.

Searching, Collecting, and Processing Data

Using search engines and simple automation to collect, process, and analyze data and metadata.

Investigating People

Collecting, analyzing, and reporting on personally identifiable information using public data and social media.

Network Data and Infrastructure Analysis

Discovering and analyzing public information about domains, IP addresses, certificates, and networks.

Investigating Businesses

Collecting, analyzing, and reporting on an organization using public data and breach data to identify and mitigate risk.

Prepare With This Course

SEC497: Practical Open-Source Intelligence (OSINT)

How SEC497 Prepares You for GOSI

SEC497 is built around the exam objectives that make up the GOSI certification: 

  • Section 1, OSINT and OPSEC Fundamentals builds skills tested under OSINT Methodology and Privacy and Operational Security Fundamentals.
  • Section 2, Essential OSINT Skills builds skills tested under Searching, Collecting, and Processing Data.
  • Section 3, Investigating People aligns with the Investigating People objective.
  • Section 4, Investigating Websites and Infrastructure aligns with Network Data and Infrastructure Analysis.
  • Section 5, Automation, the Dark Web, and Large Data Sets aligns with Investigating Businesses, and reinforces Searching, Collecting, and Processing Data at scale.
  • Section 6, Capture the Flag Capstone pulls every objective together in a multi-hour threat assessment exercise for a fictional client.

Across all six sections, 29 hands-on labs and a capstone Capture the Flag exercise give you the chance to apply each skill in live OSINT scenarios before you sit the exam. 

Read the full GOSI certification overview: GIAC's GOSI certification page 

SEC497 Course Author

Matt Edmondson
Matt Edmondson

Matt Edmondson

Founder at Argelius Labs

Matt Edmonson, Senior SANS Instructor, STI faculty, and Founder of Argelius Labs, authored SEC497 and SEC587. An industry veteran with 11 GIAC certifications and OSCP, he draws on 20 years of investigations to deliver accessibly, real-world OSINT training.

Read more about Matt Edmondson

Who Should Pursue GOSI

OSINT Investigators and Analysts

Cyber Threat Intelligence Analysts and Cyber Defenders

Law Enforcement and Intelligence Personnel

Digital Forensics Practitioners and Penetration Testers

Private and Insurance Investigators

Recruiters and Human Resources Personnel

Frequently Asked Questions

The GIAC Open Source Intelligence (GOSI) certification confirms that you have a strong foundation in OSINT methodologies and frameworks. It shows you can collect, analyze, and report on people, businesses, and network infrastructure using publicly available data, while applying sound operational security practices throughout an investigation. 

The GOSI exam is a single proctored exam made up of 75 questions, with a 2-hour time limit and a minimum passing score of 69%. GIAC periodically reviews exam specifications, so confirm the current format and passing score in the Certification Information section of your GIAC account before you sit the exam.  

GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page

GOSI fits practitioners who need to turn public information into actionable findings: OSINT investigators and analysts, cyber threat intelligence analysts, digital forensics and incident response (DFIR) professionals, penetration testers and social engineers, law enforcement and intelligence personnel, private and insurance investigators, and recruiters or HR professionals doing background research. SEC497, the course that prepares you for it, also draws journalists and red team members who rely on the same research skills. 

SEC497: Practical Open-Source Intelligence (OSINT) is the SANS course built to prepare you for GOSI. It runs 6 days instructor-led or 36 hours self-paced, is available in-person, virtual, or self-paced, and carries 36 CPEs. The course includes 29 hands-on labs covering search techniques, metadata and image analysis, username and email investigation, breach data, infrastructure research, and dark web investigation, and it closes with a multi-hour Capture the Flag capstone where you build a threat assessment for a fictional client. 

Ready to earn your GOSI certification?

Add the GOSI exam attempt when you register for SEC497.

Already trained? Register for the exam directly through GIAC here.