Group Purchasing
Group Purchasing
AI SKILLS

SEC587: Advanced Open-Source Intelligence (OSINT) Gathering and Analysis

SEC587Cyber Defense, Artificial Intelligence
  • 6 Days (Instructor-Led)
  • 36 Hours (Self-Paced)
Course authored by:
Matt Edmondson
Matt Edmondson
Course authored by:
Matt Edmondson
Matt Edmondson
  • GIAC Strategic OSINT Analyst (GSOA)
  • 36 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 28 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Learn how to perform advanced OSINT investigations as well as utilize JSON and Python. Explore topics such as cryptocurrency, the dark web, disinformation, and advanced image and video OSINT analysis.

Course Overview

Open-Source Intelligence (OSINT) is the engine behind most modern investigations. As cases grow more complex and data sources multiply, basic techniques often fall short. SEC587 is fast-paced advanced OSINT training that tackles these challenges head-on, delivering cutting-edge methods to collect and analyze OSINT data at scale.

You'll learn to integrate programming and automation using Python and APIs to gather information efficiently. The curriculum also teaches rigorous techniques to verify sources and ensure your findings are unbiased. SEC587 also explores specialized OSINT domains: the Dark Web, cryptocurrency tracing, disinformation campaigns, Russian and Chinese OSINT, advanced image/video forensics, and even leveraging AI for analysis.

Throughout the six-day course, 28+ hands-on labs immerse you in realistic scenarios—from tracing cryptocurrency transactions to sanctioned entities to exposing deepfake videos. This intensive practice ensures that, by the end of SEC587, you will be able to confidently apply these advanced techniques in real-world investigations.

Beyond the Basics: Advanced OSINT Techniques

SEC587 is designed for OSINT practitioners who already understand the fundamentals and are eager for more. It builds on your existing knowledge and shows you how to apply the same cutting-edge techniques used by expert investigators in law enforcement, intelligence agencies, cybersecurity firms, and journalism. If you know the basics of open-source intelligence, this course will propel you into truly advanced territory.

Why go beyond the basics? In today's world, billions of people share information online every day, creating an ever-expanding ocean of data. SEC587 teaches you to navigate that ocean efficiently – to find the crucial intel hidden in plain sight or buried deep on the web. You’ll learn to dig deeper and work smarter, transforming vast open data into actionable intelligence while maintaining precision and speed.

This course is highly immersive and hands-on. Every module introduces real-world scenarios using live data (including content from the Dark Web and social networks) to mirror the complex investigations professionals face. Instead of just learning theory, you’ll practice OSINT tradecraft through challenges like unraveling fake news stories, analyzing digital footprints, and tracking covert threat actors across platforms. By working through these scenarios, you gain experience that translates directly to the challenges you encounter in the field.

Importantly, SEC587 not only introduces new tools and methods, it also strengthens your core toolkit. You will reinforce foundational OSINT methodologies and even pick up basic coding skills along the way. The course incorporates scripting with Python, handling data in JSON format, and using shell utilities to automate repetitive tasks. You’ll also learn how to safely use APIs and open-source automation frameworks to scale up your investigations. By blending technical skills with OSINT know-how, SEC587 prepares you to handle large-scale data collection and analysis with confidence.

Whether you’re a seasoned investigator looking for the latest techniques or a newer analyst ready to dive into deeper waters, SEC587 will expand your capabilities. Seasoned professionals will discover innovative tools and methodologies to add to their arsenal, while those earlier in their OSINT journey will gain the extra depth needed to tackle challenging cases. The result is a well-rounded, expert-level OSINT skillset – empowering you to produce thorough, unbiased intelligence findings in any environment.

Hands-On Advanced OSINT Training

SEC587: Advanced Open-Source Intelligence Techniques offers an immersive experience through practical labs and real-world scenarios, allowing students to master intelligence gathering using publicly available data. This course emphasizes hands-on practice with real-world tools and data, providing guided labs for beginners and more challenging tasks for advanced users, enabling tailored learning at any skill level. Participants will tackle a variety of case studies and simulations that mirror the complex challenges faced by professionals in corporate, security, and governmental fields. The curriculum is designed not only to build a solid foundation in OSINT methodologies but also to instill the ability to ethically and legally apply these skills in professional settings. Students will leave with continued access to course materials and tools, empowering them to further refine their abilities after taking the course.

Hands-on Labs Include:

  • Section 1: Analyzing the Macron video, Checking Disinformation, Russian Facial Recognition, U.S. Foreign Agents Registration Act (FARA), Accessing Chinese Websites
  • Section 2: Python
  • Section 3: Image Verification, Video Verification, Steganography, Speaker Diarization, Advanced Enumeration, Gaming
  • Section 4: Network OPSEC Analysis, dark Web De-Anonymization, Dark Web Search, Cryptocurrency, Detecting Modern Drones
  • Section 5: N8n, SearxNG, Dealing with Password Protected Files, Aviation OSINT, Maritime OSINT, Secrets

Syllabus Summary

  • Section 1: Disinformation, Intelligence Analysis, Russian and Chinese OSINT
  • Section 2: Intelligence Analysis and Data Analysis with Python
  • Section 3: Video, Image and Audio Analysis, AI for OSINT, Advanced Enumeration and Gaming
  • Section 4: Sock Puppets, OPSEC, Dark Web, Cryptocurrency and Wireless
  • Section 5: Automated Monitoring, Vehicle Tracking, and Dealing with Password-Protected Files
  • Section 6: Capstone

Author Statement

"I am truly honored and thrilled to join the team as a co-author the SANS SEC587 Advanced OSINT course. It is a privilege to contribute to the development of a curriculum that empowers students with cutting-edge skills to navigate the vast and ever-evolving landscape of open-source intelligence. I am excited to build on a foundation laid out in the SEC497 OSINT course and explore advanced topics focused on equipping professionals with the necessary tools and techniques to effectively gather, analyze, and utilize information in an effective and responsible manner."

- Matt Edmondson

What You’ll Learn

  • Use advanced OSINT techniques to gather and analyze public data for actionable intelligence
  • Automate OSINT processes to improve efficiency and accuracy in data collection
  • Detect and prevent security threats by identifying potential vulnerabilities
  • Ensure compliance by navigating legal and ethical considerations in intelligence gathering
  • Leverage OSINT for market analysis and data-driven business decision-making

Business Takeaways

  • Enhance decision-making with actionable insights from public data
  • Proactively identify risks using advanced OSINT techniques
  • Increase efficiency through automated intelligence gathering
  • Stay ahead competitively by monitoring industry and market trends
  • Ensure compliance in legal and ethical intelligence collection

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC587: Advanced Open-Source Intelligence (OSINT) Gathering and Analysis.

Section 1Disinformation, Intelligence Analysis, Russian and Chinese OSINT

Section one introduces disinformation and methods for assessing information reliability using techniques like Admiralty code, CRAAP, and ACH. It also covers Russian and Chinese OSINT, with hands-on labs in disinformation detection, facial recognition, and accessing restricted platforms.

Topics covered

  • Detect Disinformation with Reliability Models
  • Apply OSINT Frameworks: NATO, CRAAP, ACH
  • Use UILs For Analysis of Sensitive Groups
  • Explore Russian OSINT: Facial, Business Intel
  • Overcome Access Issues in Chinese OSINT

Labs

  • Analyzing the Macron Video
  • (Optional) Checking Disinformation
  • Russian Facial Recognition
  • U.S. Foreign Agents Registration Act (FARA)
  • Accessing Chinese Websites

Overview

We live in an information age where disinformation is becoming more and more common.

In the first section of day 1 students will learn what disinformation is by understanding how disinformation campaigns are set up and deployed.

Standard intelligence information analysis techniques and processes for assessing the reliability of information are a key element of intelligence, and application of these techniques to OSINT are discussed.

We have a section on how to analyze gathered OSINT information using several reliability rating and analytic assessment techniques such as Admiralty code, Analysis of Competing Hypothesis and CRAAP analysis. These techniques will help students to make their overall analysis outcome become more solid.

Many of the targets of OSINT work may be individuals who like to identify themselves within a group or as part of a group, so we'll cover how to analyze sensitive groups and individuals who identify with groups online.

There's an all-new section on Russian OSINT covering social media and other popular sites, Russian focused facial recognition searches and finding foreign ties to U.S. owned businesses.

There's also an all-new section on Chinese OSINT covering topics including translation options and overcoming difficulties with creating accounts including methods for acquiring +86 Chinese phone numbers and accessing websites only available in China, without relying on western VPNs.

Full Topic Details

  • Detecting and analyzing disinformation and fake news
  • Understanding reliability rating models for OSINT
  • Rating the reliability of information
  • US Army OSINT and the Admiralty/NATO system
  • Currency, Relevance, Authority, Accuracy & Purpose (CRAAP)
  • Standard intelligence assessment techniques
  • Analysis of Competing Hypotheses (ACH) and other methods
  • Use of Unique Identifying Labels (UILs)
  • Identifying Sensitive Groups using UIL techniques
  • Russian OSINT including facial recognition and creating accounts
  • Identifying Russian businesses with licenses to do classified work
  • Identifying foreign ties to U.S. businesses
  • Accessing Chinese websites which only allow domestic visitors
  • Dealing with account creation challenges on Chinese apps

Section 2Python for OSINT

In Section two, students learn key Python skills for OSINT, including web scraping and attribution management. You’ll build a real-time intelligence dashboard, integrate AI-powered APIs, and explore persistent monitoring of platforms like Telegram and Discord, plus deploying Python code via AWS Lambda.

Topics covered

  • Learn Python for OSINT & Web Extraction
  • Manage Attribution & Perform Web Scraping
  • Build An Automated Intelligence Dashboard
  • Interact With APIs, Including AI Tools
  • Automate & Deploy Python Code in The Cloud

Labs

  • Python Levels 1–7

Overview

This content is all new, includes seven new hands-on labs and requires no previous experience! We start off with the building blocks of Python that are most important for OSINT and keep increasing the functionality to perform such tasks as web scraping, all while managing our attribution.

We use Python to build an automated intelligence dashboard that updates in real time and can be customized in endless ways. We cover out to utilize third-party APIs including those belonging to AI providers to help us automatically evaluate programs and perform other tasks.

Finally, we end the section by covering persistent monitoring of sites like Telegram and Discord, and how we can move our Python code to the cloud using serverless infrastructure like AWS Lamba.

Full Topic Details

  • Python fundamentals for OSINT
  • Web requests and parsing web pages
  • Managing attribution with Python
  • Intermediate web scraping
  • Creating an automated intelligence dashboard
  • Interacting with APIs, including AI
  • Persistent Monitoring
  • Automating your Python code in the cloud

Section 3Video, Image and Audio Analysis, AI for OSINT, Advanced Enumeration and Gaming

This section covers advanced image and video verification, steganography detection, and AI-powered audio analysis, including transcription and speaker recognition. Students learn to integrate AI into OSINT research while detecting AI-generated content. It also explores advanced domain enumeration techniques and concludes with a new section on gaming OSINT.

Topics covered

  • Conduct Image/Video Analysis & Reverse Search
  • Use AI For Audio Analysis & Speaker ID
  • Leverage AI For OSINT & Social Media Tasks
  • Detect AI Content & Perform Website Scans
  • Discover Cloud Assets & Gaming OSINT

Labs

  • Image and Video Verification
  • Steganography
  • Speaker Diarization
  • Advanced Enumeration
  • Gaming

Overview

This section starts off with practical and advanced image and video verification techniques and then shifts into an all-new section on steganography including a lab on using, and detecting steganography.

There's an all-new section on AI for audio analysis including transcription, translation, speaker diarization (identifying which speaker said which words) and speaker recognition.

We will then discuss practical ways to incorporate artificial intelligence into their OSINT research as both a means for increasing our efficiency and effectiveness, but also in detecting AI being used by others to generate content.

We will discuss some advanced enumeration techniques where we cover methods to find domains related to your target, to discover difficult to find infrastructure on websites and in the cloud, and perform 100% passive enumeration on a target website.

Finally, we end with an all-new section on gaming OSINT discussing why it's important and key sites for searching and monitoring the space.

Full Topic Details

  • Image analysis and reverse image searches
  • Video analysis
  • AI for Audio analysis
  • AI for OSINT
  • AI for automating social media accounts
  • Detecting AI generated content
  • Automated scans of a website for sensitive files
  • Discovering cloud-based assets
  • 100% passive enumeration of a website
  • Gaming OSINT

Section 4Sock Puppets, OPSEC, Dark Web, Cryptocurrency and Wireless

This section covers creating and managing sock puppets while maintaining OPSEC. Students explore OSINT techniques for the Dark Web, tracking criminal marketplaces, locating hidden servers, and automating monitoring. It includes a cryptocurrency lab on transaction tracking and sanctioned entities. The day ends with a wireless OSINT overview.

Topics covered

  • Create & Manage False Personas With OPSEC
  • Search Dark Web & Understand Cybercrime
  • Use Tech to De-Anonymize Dark Websites
  • Track Crypto Transactions & Sanctioned Addresses
  • Explore Wireless Tech & Detect Modern Drones

Labs

  • Network OPSEC Analysis
  • Dark Web De-Anonymization
  • Dark Web Search
  • Cryptocurrency
  • Detecting Modern Drones

Overview

This day starts off with instruction on useful concepts for creating and maintaining fictitious identities (sock puppets), particularly those used to interact with others, and how to maintain Operations Security (OPSEC).

Within SEC587, students will get a more advanced understanding of how OSINT techniques can be applied on the Dark Web by learning about the criminal underground including the initial access marketplaces fed by data stealer logs. Students will learn advanced techniques for finding the true location of servers hosting sites on the dark web as well as automated methods for dark web monitoring.

We will discuss the fundamentals of cryptocurrency, techniques for tracking public cryptocurrency transactions, and how to identify transactions involving sanctioned entities. These topics are also covered in an all-new cryptocurrency lab.

Understanding wireless capabilities is becoming more important to OSINT practitioners so we finish with a brief overview of wireless technologies such as Wi-Fi, Bluetooth and software defined radios (SDRs) as well as a lab where demonstrate how to detect modern drones and research their identifiers.

Full Topic Details

  • Creating and maintaining false personas
  • Communicating with targets and other sources of information
  • Operational security (OPSEC)
  • Searching for dark web content
  • Essential cybercrime underground concepts
  • Technical methods to de-anonymize dark websites
  • Understanding cryptocurrency and the blockchain
  • Identifying cryptocurrency addresses tied to sanctioned entities
  • An overview of the wireless spectrum and widely used technologies
  • Detecting modern drones including the newest DJIs

Section 5Automated Monitoring, Vehicle Tracking, and Dealing with Password-Protected Files

Section five covers building and using OSINT monitoring tools, including third-party and self-hosted options for OPSEC. Students learn to access password-protected files, gather vehicle-related OSINT, and automate credential discovery across offline and online sources. A new lab explores workflow automation frameworks for efficient intelligence gathering.

Topics covered

  • Conduct OSINT Monitoring with Tools
  • Use Self-Hosted Workflow Automation
  • Visualize Data for Network Analysis
  • Collect & Analyze Open-Source Vehicle Data
  • Access Password-Protected Files & Credentials

Labs

  • N8n
  • SearxNG
  • Dealing with Password Protected Files
  • Aviation and Maritime OSINT
  • Secrets

Overview

Day five will start with tools and techniques that will aid OSINT analysts in using and building their own monitoring and online searching tools. This section will teach students how to utilize third party web-based monitoring tools as well as how to monitor various topics of interest. We'll also have an all new lab where we use a workflow automation framework which can be locally hosted to mitigate budget and/or OPSEC issues.

We'll cover technical methods to access information in password-protected files encountered online and will also learn how to find, gather, and analyze information that is related to vehicles (cars, boats, planes, etc.) using open-source information.

We'll end the day by using automated methods to identify sensitive credentials in various offline and online sources.

Full Topic Details

  • Practical OSINT monitoring using web services
  • Automated internet monitoring using third-party tools
  • Utilizing a self-hosted workflow automation framework
  • Visualization of data sets to support network analysis
  • Collection and analysis of open-source vehicle tracking information
  • Methods to access information in password-protected files
  • Methods to identify sensitive credentials in both offline and online repositories

Section 6Capstone

The SEC587 capstone is a team-based OSINT challenge, collecting live data under time pressure. Teams apply Python and advanced techniques, delivering findings to peers.

Overview

This will be the capstone for SEC587 that brings together everything that students have learned throughout the course. This will be a team effort where groups compete against each other by collecting OSINT data about live online subjects. The output from this capstone event will be turned in as a deliverable to the client (the instructor and fellow classmates). This hands-on event reinforces what students have practiced during labs and adds the complexity of performing OSINT using Python code and various advanced OSINT techniques under time pressure as a group.

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class.
  • CRITICAL: Apple systems using the M1/M2 processor line cannot perform the necessary virtualization functionality and therefore cannot in any way be used for this course.
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 16GB of RAM or more is required.
  • 50GB of free storage space or more is required.
  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration And Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Local Administrator Access is required. (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.
  • Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled or you must have the administrative privileges to disable it.
  • Download and install VMware Workstation Pro 16.2.X+ or VMware Player 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ or VMware Player 17.0.0+ (for Windows 11 hosts), or VMWare Fusion Pro 12.2+ or VMware Fusion Player 11.5+ (for macOS hosts) prior to class beginning. If you do not own a licensed copy of VMware Workstation Pro or VMware Fusion Pro, you can download a free 30-day trial copy from VMware. VMware will send you a time-limited serial number if you register for the trial at their website. Also note that VMware Workstation Player offers fewer features than VMware Workstation Pro. For those with Windows host systems, Workstation Pro is recommended for a more seamless student experience.
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials.
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.

Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.

If you have additional questions about the laptop specifications, please contact customer service.

SEC587 training is recommended for a diverse range of individuals, including:

  • Open-Source Intelligence and All-Source Analysts
  • Law Enforcement Investigators
  • Military Investigators
  • Private Investigators
  • Insurance Claims Investigators
  • Intelligence Analysts
  • Geopolitical Analysts
  • Journalists
  • Researchers
  • Social Engineers
  • Political and Information Campaign Researchers
  • Incident Responders
  • Digital Forensics (DFIR) Analysts
  • Cyber Threat Intelligence Specialists

The GSOA certification validates a practitioner’s ability to master advanced OSINT skills—automating investigations with Python, analyzing data at scale, and uncovering threats across social platforms, darknet forums, blockchain activity, and disinformation networks. Real-world scenarios prepare professionals to identify and efficiently track adversarial activity while safely managing personas and maintaining operational security.

  • Automating data collection with Python scripting
  • Conducting Dark Web investigations
  • Tracking public cryptocurrency transactions
  • Identifying and tracking disinformation
  • International and sector specific OSINT
  • Image, video and audio forensics

  • Physical and digital workbooks
  • A course-specific Virtual Machine (VM) tailored for SEC587

SEC587 is a fast-paced, advanced course that is meant to build upon previous knowledge and experience in OSINT. The SANS SEC497: Practical Open-Source Intelligence (OSINT) course is recommended, but not required prior to taking this course.

  • Basic knowledge and experience with open-source intelligence collection.
  • Rudimentary understanding of intelligence analysis
  • Knowledge of how to use a Virtual Machine (VM)

The SEC587 course is a part of the “Advanced Cyber Defense” Learning Path, which aims to equip security professionals to harden specific defenses, including OSINT, PowerShell, and traffic analysis.

Depending on your current or desired future role, one of these courses is a great next step in your cybersecurity journey:

Open-source intelligence automation leverages advanced software tools and algorithms to expedite the collection, analysis, and interpretation of publicly accessible data. By automating the processing of vast amounts of information from sources like social media, news outlets, and databases, it enhances the speed, accuracy, and scalability of intelligence gathering. This technology is crucial for real-time decision-making in fields such as cybersecurity, market analysis, and national security.

SANS SEC587 offers valuable skills and knowledge for advancing your cybersecurity career. When you master advanced Open-Source Intelligence (OSINT) techniques, you will be able to gather and analyze intelligence, detect threats, and enhance security operations. This course empowers professionals to apply OSINT in practical, real-world scenarios, making it an essential asset for those in cybersecurity.

In this advanced OSINT gathering analysis course, you will:

  • Learn to gather actionable intelligence from open sources, including the dark web, to identify and assess security risks.
  • Apply Python and automation to streamline data collection, analysis, and monitoring for improved efficiency.
  • Gain skills in investigating dark web activity and tracking cryptocurrency transactions related to cybercrime.
  • Participate in labs and a capstone project to reinforce learning and apply techniques under time pressure in real-world environments.
  • Expand your cybersecurity toolkit, making you a valuable asset in roles such as threat intelligence analyst, digital forensics, and penetration testing.

By completing SEC587, you'll be prepared to tackle complex security challenges and enhance your role within the cybersecurity field.

Relevant Job Roles

Data Analysis (OPM 422)

NICE: Implementation and Operation

Responsible for analyzing data from multiple disparate sources to provide cybersecurity and privacy insight. Designs and implements custom algorithms, workflow processes, and layouts for complex, enterprise-scale data sets used for modeling, data mining, and research purposes.

Explore learning path

Protection

SCyWF: Protection And Defense

This role uses cybersecurity tools to protect information, systems and networks from cyber threats. Find the SANS courses that map to the Protection SCyWF Work Role.

Explore learning path

Threat Analysis (OPM 141)

NICE: Protection and Defense

Responsible for collecting, processing, analyzing, and disseminating cybersecurity threat assessments. Develops cybersecurity indicators to maintain awareness of the status of the highly dynamic operating environment.

Explore learning path

OSINT Investigator/Analyst

Cyber Defense

These resourceful professionals gather requirements from their customers and then, using open sources and mostly resources on the internet, collect data relevant to their investigation. They may research domains and IP addresses, businesses, people, issues, financial transactions, and other targets in their work. Their goals are to gather, analyze, and report their objective findings to their clients so that the clients might gain insight on a topic or issue prior to acting.

Explore learning path

Threat Intelligence (THIN)

Skills Framework for the Information Age

Collection and contextual analysis of threat actor activity, indicators, and tactics. Outputs support detection engineering, hunting strategies, and proactive defence planning.

Explore learning path

Cybersecurity Researcher

European Cybersecurity Skills Framework

Research the cybersecurity domain and incorporate results in cybersecurity solutions.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 11

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources