Group Purchasing
Group Purchasing

What Is the GSOA Certification?

The GIAC Strategic OSINT Analyst (GSOA) certification validates a practitioner's expertise in advanced OSINT skills. GSOA certification holders have the skills to automate investigations with Python, analyze data at scale, and uncover threats across social platforms, darknet forums, blockchain activity, and disinformation networks.

By the numbers

3 hrs

Exam duration

82

Questions

66%

Min. passing score

What GSOA Covers

GIAC publishes five exam objectives for GSOA, and each one lines up with a section of SEC587.

Advanced Operational Techniques and Threats

Covers creating and maintaining fictitious identities, Dark Web OSINT, tracking public cryptocurrency transactions, and using wireless capabilities to gather intelligence.

Multimedia and AI in OSINT

Covers practical and advanced image, video and audio verification, plus practical ways to bring artificial intelligence into OSINT research.

OSINT and International Environment

Covers identifying disinformation, assessing the reliability of information, and analyzing sensitive groups and individuals.

Python for OSINT

Covers automating OSINT workflows locally and in the cloud with third-party APIs, and persistent monitoring of sites.

Sector-Specific and Practical OSINT

Covers third-party monitoring tools, access to password-protected files, transportation-related open-source information, and automated detection of sensitive credentials.

Prepare With This Course

SEC587: Advanced Open-Source Intelligence (OSINT) Gathering and Analysis

How SEC587 Prepares You for GSOA

Taking SANS SEC587 maps directly to the certification objectives in GSOA. The course is built around the five exam objectives that make up the GIAC Strategic OSINT Analyst certification: 

  • Section 1, Disinformation, Intelligence Analysis, Russian and Chinese OSINT builds skills tested under OSINT and International Environment: identifying disinformation, assessing the reliability of information, and analyzing sensitive groups and individuals.
  • Section 2, Python for OSINT aligns with Python for OSINT: Tools and Techniques: automating OSINT workflows locally and in the cloud with third-party APIs, and monitoring sites persistently.
  • Section 3, Video, Image and Audio Analysis, AI for OSINT, Advanced Enumeration and Gaming builds skills tested under Multimedia and AI in OSINT: image, video and audio verification, and practical ways to bring AI into OSINT research.
  • Section 4, Sock Puppets, OPSEC, Dark Web, Cryptocurrency and Wireless aligns with Advanced Operational Techniques and Threats: creating and maintaining fictitious identities, Dark Web OSINT, tracking public cryptocurrency transactions, and gathering intelligence with wireless capabilities.
  • Section 5, Automated Monitoring, Vehicle Tracking, and Dealing with Password-Protected Files builds skills tested under Sector-Specific and Practical OSINT: third-party monitoring tools, access to password-protected files, transportation-related information, and automated detection of sensitive credentials.

Across the course's five instructional sections, 28 hands-on labs and a team-based capstone challenge using live data give you the chance to apply each skill in realistic investigation scenarios. 

Read the full GSOA certification overview 

SEC587 Course Author

Matt Edmondson
Matt Edmondson

Matt Edmondson

Founder at Argelius Labs

Matt Edmonson, Senior SANS Instructor, STI faculty, and Founder of Argelius Labs, authored SEC497 and SEC587. An industry veteran with 11 GIAC certifications and OSCP, he draws on 20 years of investigations to deliver accessibly, real-world OSINT training.

Read more about Matt Edmondson

Who Should Pursue GSOA

Cyber Incident Responders and DFIR Analysts

Penetration Testers and Social Engineers

Law Enforcement and Intelligence Personnel

Private and Insurance Investigators

Researchers

OSINT, All-Source and Cyber Threat Intelligence Analysts

Frequently Asked Questions

The GSOA certification validates a practitioner's expertise in advanced OSINT skills. Holders have the skills to automate investigations with Python, analyze data at scale, and uncover threats across social platforms, darknet forums, blockchain activity, and disinformation networks. 

The GSOA exam is one proctored exam delivered in GIAC's CyberLive format, hands-on lab challenges rather than traditional multiple choice. It has 82 questions, a 3-hour time limit, and a minimum passing score of 66% for candidates who receive the exam version released on or after November 8, 2025. 

GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page. 

GSOA fits cyber incident responders, security and digital forensics (DFIR) analysts, penetration testers and social engineers, law enforcement and intelligence personnel, private and insurance investigators, and researchers. 

SANS SEC587: Advanced Open-Source Intelligence (OSINT) Gathering and Analysis maps directly to the GSOA exam objectives. The course includes 28 hands-on labs, a team-based capstone challenge using live data, and a course-specific virtual machine, and it provides great training if you're thinking of pursuing GSOA. 

SANS Institute is a training organization. GIAC LLC is an independent certification body accredited by the ANSI National Accreditation Board (ANAB) under ISO/IEC 17024:2012. Completion of SANS training is not required for GIAC certification, nor does it guarantee a passing exam result.

Ready to earn your GSOA certification?

Add the GSOA exam attempt when you register for SEC587.