Group Purchasing
Group Purchasing

SEC497: Practical Open-Source Intelligence (OSINT)

SEC497Cyber Defense
  • 6 Days (Instructor-Led)
  • 36 Hours (Self-Paced)
Course authored by:
Matt Edmondson
Matt Edmondson
Course authored by:
Matt Edmondson
Matt Edmondson
  • GIAC Open Source Intelligence (GOSI)
  • 36 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 29 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Learn to perform effective, secure OSINT research with practical techniques. Explore critical OSINT tools and apply your skills in hands-on labs based on real-world scenarios.

Course Overview

SEC497: Practical Open-Source Intelligence (OSINT) provides practical, real-world tools and techniques to help individuals perform OSINT research safely and effectively. The OSINT training course also offers real-world examples of how those tools and techniques have been used to solve a problem or further an investigation. Hands-on labs based on actual scenarios give students opportunities to practice the skills they learn and understand how those skills can help in their research.

The Gateway to OSINT Mastery

SEC497 is a comprehensive training course on Open-Source Intelligence (OSINT) written by an industry professional with over two decades of experience. This open source intelligence course is designed to teach you the most important skills, tools, and methods needed to launch or further refine your investigation skills. SEC497 will provide actionable information to students throughout the OSINT world, including intelligence analysts, law enforcement officials, cyber threat intelligence and cyber defenders, pen testers, investigators, and anyone else who wants to improve their OSINT skills. There is something for everyone, from newcomers to experienced practitioners. This course also supports preparation for the GOSI certification (GIAC Open Source Intelligence), which validates your ability to conduct investigations using publicly available data sources.

SEC497 focuses on practical techniques that are useful day in and day out. This course is constructed to be accessible for those new to OSINT while providing experienced practitioners with tried-and-true tools that they can add to their arsenal to solve real-world problems. The course has a strong focus on understanding how systems work to facilitate informed decisions, and includes hands-on exercises based on actual scenarios from the government and private sectors. We will discuss cutting-edge research and outlier techniques and not only talk about what is possible, we will practice doing it! Dive into the course syllabus below for a detailed breakdown of the topics covered.

Hands-On Open-Source Intelligence Training

29 Unique, Immersive Hands-On Labs

SEC497: Practical Open-Source Intelligence offers a unique and immersive learning experience, combining theoretical knowledge with extensive hands-on practice. The course covers essential topics for modern incident response, including managing attribution, dealing with potential malware, and utilizing canary tokens. Students will gain proficiency with tools like Hunchly, Obsidian, Instant Data Scraper, and various search techniques. Labs delve into metadata analysis, reverse image searches, facial recognition, translation services, and researching usernames. Keybase, email analysis, Twitter bot analysis, IP address research, WHOIS, DNS investigations, Amass, Eyewitness, Censys, and Shodan are also integral parts of the curriculum. Additional labs include cloud storage assessments, business intelligence, wireless network security, bulk data triage, and using Tor and PGP for secure communications. The course addresses breach data analysis, preparing students to handle real-world cybersecurity challenges, further reinforcing its value as a leading open source intelligence course for professionals aiming for the GOSI certification.

The capstone for SEC497 is a multi-hour capture the flag event, where students work in small groups to create a threat assessment for a fictional client. This culminating exercise requires applying the skills learned throughout the course across various real-world sites. The final assessment is presented to the instructor, who acts as the client, and provides feedback to each group, ensuring that students are ready to implement their advanced incident response techniques in real-world scenarios. This hands-on approach makes SEC497 an ideal OSINT class for those seeking to apply open-source intelligence skills in professional environments.

  • Section 1: Managing Your Attribution; Dealing with Potential Malware; Canary Tokens; Hunchly; Obisidan; Linux Command Line Practice (Optional)
  • Section 2: Search; Instant Data Scraper; Metadata; Reverse Image Search; Facial Recognition; Translation
  • Section 3: Researching Usernames; Keybase; Email; Twitter; Twitter Bot Analysis
  • Section 4: IP Address Research; WHOIS; DNS; Amass and Eyewitness; Censys and Shodan; Buckets of Fun
  • Section 5: Business; Wireless; Bulk Data Triage; Tor and PGP; Breach Data
  • Section 6: Capture the Flag Capstone

Syllabus Summary

  • Section 1: OSINT and OPSEC Fundamentals: Safe, Effective Information Gathering and Analysis
  • Section 2: Essential OSINT Skills: Web Fundamentals, Search Techniques, and Image Analysis
  • Section 3: Investigating People: Privacy, Usernames, Emails, and Social Media Analysis
  • Section 4: Investigating Websites and Infrastructure: Ips, DNS, WHOIS, and Cloud Analysis
  • Section 5: Automation, the Dark Web, and Large Data Sets: OSINT Techniques and Tools
  • Section 6: Capstone: Capture the Flag - Collaborative Threat Assessment Challenge

Author Statement

"When I started the first open-source intelligence (OSINT) unit for my organization over a decade ago, I was told we had no budget for tools, equipment, or training. I used to joke that one nice thing about not having a budget was that it made many of my decisions very easy. If there was something I needed, I either built it myself or did without.

“Coming from that background forces you to understand how things work and what truly matters. In addition to performing countless OSINT investigations, I've traveled across the world for over a decade teaching operational security (OPSEC) and OSINT to various government agencies and consulted with numerous private companies, ranging from small start-ups to Fortune 100 enterprises. I have helped hunt down international fugitives, identified online infrastructure for a merger and acquisitions due diligence report, and handled numerous tasks in between. This course allows me me share my experience with what works, what does not work, and how we can achieve our goals with minimal effort and cost."

- Matt Edmondson

What You’ll Learn

  • Perform OSINT investigations with strict OPSEC
  • Manage sock puppet accounts for research
  • Recover deleted or hidden data, including breach and dark web content
  • Trace digital footprints across sites and social media
  • Uncover website owners, linked domains, and metadata
  • Analyze large datasets and produce reports for cybersecurity, M&A, and more

Business Takeaways

  • Enhance competitive intelligence through OSINT techniques
  • Improve risk management by identifying vulnerabilities
  • Strengthen incident response with rapid information gathering
  • Identify and mitigate potential threats from publicly available data
  • Streamline data collection and analysis processes for operational efficiency

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC497: Practical Open-Source Intelligence (OSINT).

Section 1OSINT and OPSEC Fundamentals

Learn how to conduct OSINT safely and effectively. This section covers the OSINT process, avoiding analytical pitfalls, and managing OPSEC, including a hands-on Pre-Flight Checklist lab to understand what you expose online.

Topics covered

  • The OSINT Process
  • Avoiding Analytical Pitfalls
  • OPSEC and Attribution
  • Creating Accounts (Sock Puppets)
  • Hunchly, Obsidian, and Report Writing

Labs

  • OPSEC Pre-Flight Checklist
  • Dealing with Potential Malware
  • Canary Tokens
  • Hunchly and Obsidian
  • [Optional] Linux Command Line Practice

Overview

Before diving into tools and techniques to find, gather, and process information, the course starts with a discussion of how to undertake these activities as safely and effectively as possible. This section begins with an overview of the OSINT process and tips on avoiding analytical pitfalls. We then move into Operational Security or OPSEC. A big part of OSINT is going to new sites and downloading files and information.

To make these concepts concrete, students will work through a new hands-on lab—the OPSEC Pre-Flight Checklist—that walks step by step through exactly what you look like to a website you’re visiting, so you understand what you’re exposing before you ever click a link. Creating fictitious accounts (aka sock puppets) has gotten tougher over the past few years, with many sites requiring criteria like a real phone number, facial image, etc. We’ll discuss the issues and cover current methods for creating these accounts.

The course section wraps up by examining two tools that can improve your organization and efficiency. Hunchly is a fantastic tool for cataloging online research, and Obsidian is an effective open-source tool for note-taking and various other uses. We’ll also cover report writing. Many OSINT students have improving Linux skills on their to-do list, so at the end of the section there is an optional lab for Linux command line practice. This gives students who would like to work on these skills the opportunity to do so in a controlled environment.

Section 2Essential OSINT Skills

Build core OSINT skills including search techniques, web data collection, and archiving. Learn how to analyze metadata, images, and translations, and use tools like ArchiveBox to capture and preserve online content.

Topics covered

  • Web Fundamentals and Search Engines
  • Web Archives and Proxy Sites
  • Collecting and Processing Web Data
  • Metadata, Mapping, and Image Analysis
  • Facial Recognition and Translations

Labs

  • ArchiveBox Web Capture Lab
  • Metadata Analysis
  • Reverse Image Search
  • Facial Recognition
  • Translation Techniques

Overview

Section 2 presents a range of fundamental skills that all OSINT practitioners should have, regardless of the industry they work in. We’ll start with a brief overview of curated lists of OSINT resources and quickly move into understanding the fundamentals of how the web works and utilizing search engines effectively. We’ll cover methods to find other sites owned and operated by the same individuals, how to see content that the site owners may not want you to see, and, as always, the OPSEC implications and how to undertake these tasks safely. We’ll also cover the why and how of setting up persistent monitoring alerts. Multiple methods will be presented to archive content from websites, view historical content from websites, and get other sites to visit websites on your behalf—including a new hands-on lab using ArchiveBox to programmatically and automatically capture pages so you have a durable record even when content changes or disappears.

We’ll talk about collecting and preserving Internet data and how to convert raw data into useable formats for processing and analysis. We’ll discuss how to gather useful intelligence from metadata, even if the data initially appear insignificant or do not appear at all, and look at useful sites for mapping, imagery, and analysis. The course section will then turn to image analysis, with a discussion of methodology, tools that can help us, and some real-world examples. From there, we’ll move into facial recognition and real-world examples and resources we can use to find people online.

We’ll conclude with a discussion about translation that goes beyond simply converting text from one language to another—we’ll also cover techniques to detect the underlying source language when content has been machine-translated into English, so you can tell when something originally written in, say, Russian or a Nigerian language has been run through a tool like Google Translate.

Section 3Investigating People

Investigate individuals using usernames, emails, phone numbers, and social media. Learn to work with breach data, APIs, and detect AI-generated content while analyzing identity, behavior, and online presence.

Topics covered

  • Privacy and Identity Research
  • Usernames, Emails, and Phone Numbers
  • Breach Data and APIs
  • Social Media Analysis and Geolocation
  • Detecting AI-Generated Content

Labs

  • API Data Collection Lab
  • Breach Data Investigation Lab
  • Social Media Analysis
  • Geolocation
  • AI-Generated Content Detection

Overview

Section 3 of the course focuses on investigating individuals or groups. We’ll start by discussing privacy and then get into techniques to research usernames and email addresses across popular sites to discover an individual’s accounts. The section then covers how to determine if email addresses are potentially tied to fraud and the places where the individual(s) connected to the email addresses may have been. Many OSINT investigations start with a selector such as a phone number or address and require that the researcher tie that selector to an individual or group. We’ll cover numerous resources and techniques you can use to do this, including some that can help identify the owner of a prepaid phone number. We’ll also explore different types of breach data and how it can be leveraged for both OSINT investigations and cyber defense—followed by a hands-on lab that challenges students to work through breach data and use it in ways many investigators haven’t considered before, opening up pivots that can move an investigation forward in unexpected directions. Some of the most valuable data sources we’ll discuss are available via API, so the first half of the day also includes a brand-new hands-on lab that walks students through using APIs to acquire data. If you’ve never touched an API before, don’t worry—we take a gentle, approachable path through it, and by the end of the lab you’ll see it’s far less intimidating than it sounds.

The remainder of the section focuses on social media sites, including advanced Facebook searches, techniques for recovering and viewing social media content that has been deleted, methods to view content on social media sites when you don’t have an account on the site, searching and analyzing a wide range of social media platforms, geolocation of social media data, and trends, sentiment, and reputation analysis. The day closes with another brand-new addition: a section and hands-on lab on detecting AI-generated content. With AI-generated images, video, and text now flooding social media and the broader web, knowing how to identify it is quickly becoming an essential OSINT skill—and this lab gives students practical, hands-on experience doing exactly that.

Section 4Investigating Websites and Infrastructure

Analyze websites, IPs, and infrastructure to answer key investigative questions. Learn how to uncover ownership, identify technologies, and understand how systems work to avoid missteps and strengthen analysis.

Topics covered

  • IP Addresses and Common Ports
  • WHOIS, DNS, and Certificate Transparency
  • Email Headers and Subdomains
  • Site Attribution and Ownership
  • Cloud and CTI Resources

Labs

  • IP Address Research
  • WHOIS and DNS
  • Amass and Eyewitness
  • Censys and Shodan
  • Buckets of Fun

Overview

Section 4 covers investigating websites, IP addresses, and other infrastructure, including the cloud. Rather than staying abstract, we focus on the questions investigators actually need to answer: Who owns this site? What other sites do they own or operate? What is the true IP address of a site hiding behind a CDN like Cloudflare? What technologies and services is this target really running? For students who don’t consider themselves tech savvy, we’ll take the time to explain what the elements are and how they work, and we’ll provide numerous real-world examples of how these elements have helped in investigations.

This course section is critical even for analysts who don’t focus on technical topics because understanding how these technical elements work reduces the likelihood of falling down rabbit holes during their research. For students who focus more on technology topics, such as those who work in Cyber Threat Intelligence, we’ll cover a variety of tools and resources to go as deep as possible. This course section is a mix of understanding how things work, studying real-world examples and case studies, looking at some cutting-edge research, and using tools in creative ways to achieve things most people did not know were possible.

Section 5Automation, the Dark Web, and Large Data Sets

Work with large datasets, explore the dark web, and automate OSINT tasks. Learn how AI tools like Whisper can speed up investigations and how to efficiently process massive amounts of data.

Topics covered

  • Researching Businesses and Wireless
  • Large Dataset Triage
  • Dark Web Investigation
  • AI for OSINT
  • Automation and Path Forward

Labs

  • Business and Wireless Analysis
  • Bulk Data Triage
  • Dark Web Exploration
  • Whisper Transcription Lab
  • Automation Techniques

Overview

Section 5 is a fun mix of topics ranging from researching businesses and transitions to covering wireless for OSINT, including using Wi-Fi names to enrich digital forensics data and research locations. If you work in OSINT long enough, a giant pile of data will eventually be placed in front of you, and someone will ask you what’s in it. Depending on your job, this may already be a regular occurrence. This section will cover how to triage and search large datasets effectively and quickly using free or cheap resources. We’ll also take a deep dive into the dark web, covering how it works, how we can find things, and what we can expect to find, along with tricks we can use to speed up dark web downloads.

From there, the section turns to a brand-new block on AI for OSINT, where we look at how AI tools can accelerate real investigative work. This includes a hands-on lab using OpenAI’s Whisper to transcribe audio content—an enormous force-multiplier when you’re staring down hours of recordings, videos, or interviews that would otherwise take forever to process manually. As the course section winds down, we’ll talk about different automation options that require no programming. The final portion of the section is called “path forward” and covers a variety of resources that can help you continue your OSINT learning journey.

Section 6Capture the Flag

Apply your skills in a multi-hour capture the flag. Work in teams to build a threat assessment for a fictional client using real-world data and techniques, then present findings for instructor feedback.

Things You Need To Know

Important! Bring your own system configured according to these instructions. 

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system that meets all of the specified requirements. 

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data. 

Mandatory System Hardware Requirements

  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class.
  • CRITICAL: Apple systems using the M1/M2 processor line cannot perform the necessary virtualization functionality and therefore cannot in any way be used for this course.
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 16GB of RAM or more is required.
  • 50GB of free storage space or more is required.
  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration and Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Local Administrator Access is required. (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.
  • Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled or you must have the administrative privileges to disable it.
  • Download and install VMware Workstation Pro 16.2.X+ or VMware Player 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ or VMware Player 17.0.0+ (for Windows 11 hosts), or VMWare Fusion Pro 12.2+ or VMware Fusion Player 11.5+ (for macOS hosts) prior to class beginning. If you do not own a licensed copy of VMware Workstation Pro or VMware Fusion Pro, you can download a free 30-day trial copy from VMware. VMware will send you a time-limited serial number if you register for the trial at their website. Also note that VMware Workstation Player offers fewer features than VMware Workstation Pro. For those with Windows host systems, Workstation Pro is recommended for a more seamless student experience.
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials.
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.

Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files. 

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions. 

Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs. 

If you have questions about the laptop specifications, please contact customer service.

SEC497 training is recommended for a diverse range of individuals, including:

  • OSINT Investigators
  • Cyber Threat Intelligence Analysts
  • Intelligence Personnel
  • Law Enforcement
  • Penetration Testers/Red Team Members
  • Cyber Defenders
  • Recruiters
  • Journalists
  • Investigators
  • Digital Forensics Practitioners
  • Human Resources Personnel

The GIAC Open Source Intelligence (GOSI) certification confirms that practitioners have a strong foundation in OSINT methodologies and frameworks and are well-versed in data collection, reporting, and analyzing targets.

  • Open Source Intelligence Methodologies
  • OSINT Data Collection, Analysis, and Reporting
  • Harvesting Data from the Dark Web
  • Operational Security Fundamentals and Considerations

More Certification Details

  • A Linux Virtual Machine (VM) complete with electronic workbook

Basic computer knowledge is required for this course.

The SEC497 course is a part of the “Design, Detection, and Defensive Controls” Learning Path, which prepares security professionals to identify security anomalies, deploy detection and monitoring tools, and interpret their output.

Depending on your current or desired future role, one of these courses is a great next step in your cybersecurity journey:

Open-Source Intelligence (OSINT) is the practice of collecting and analyzing publicly available data from various sources such as websites, social media, and public records to gather actionable information. OSINT is widely used in cybersecurity, law enforcement, and competitive intelligence to enhance decision-making and threat assessment. By leveraging freely accessible information, organizations can gain critical insights without the need for intrusive measures.

SEC497: Practical Open-Source Intelligence (OSINT) can significantly benefit your cybersecurity career by providing critical skills for threat intelligence and vulnerability assessment. OSINT empowers professionals to proactively identify potential threats by gathering and analyzing publicly available information. This includes:

  • Threat Intelligence
    • Monitoring online forums, social media, and the dark web for indicators of impending cyberattacks.
    • Identifying and tracking threat actors, understanding their tactics, techniques, and procedures (TTPs).
    • Gathering information on emerging threats and vulnerabilities to inform proactive security measures.
  • Vulnerability Management
    • Discovering publicly exposed systems and data that could be exploited by attackers.
    • Identifying potential weaknesses in an organization's online presence, such as misconfigured servers or exposed credentials.
    • Performing technical footprinting to map an organization's digital assets and identify potential attack vectors.

OSINT skills are also invaluable for incident response and digital forensics. By leveraging open-source data, cybersecurity professionals can:

  • Incident Response
    • Trace the origin of cyberattacks and identify the responsible threat actors.
    • Gather evidence to support incident investigations and recovery efforts.
    • Understand the scope and impact of security breaches by analyzing publicly available information.
  • Digital Forensics
    • Collecting and analyzing digital evidence from open sources to support investigations.
    • Verifying information and establishing timelines of events.
    • Using public records to assist in the identification of individuals involved in cybercrimes.

Relevant Job Roles

Data Analysis (OPM 422)

NICE: Implementation and Operation

Responsible for analyzing data from multiple disparate sources to provide cybersecurity and privacy insight. Designs and implements custom algorithms, workflow processes, and layouts for complex, enterprise-scale data sets used for modeling, data mining, and research purposes.

Explore learning path

Protection

SCyWF: Protection And Defense

This role uses cybersecurity tools to protect information, systems and networks from cyber threats. Find the SANS courses that map to the Protection SCyWF Work Role.

Explore learning path

Threat Analysis (OPM 141)

NICE: Protection and Defense

Responsible for collecting, processing, analyzing, and disseminating cybersecurity threat assessments. Develops cybersecurity indicators to maintain awareness of the status of the highly dynamic operating environment.

Explore learning path

OSINT Investigator/Analyst

Cyber Defense

These resourceful professionals gather requirements from their customers and then, using open sources and mostly resources on the internet, collect data relevant to their investigation. They may research domains and IP addresses, businesses, people, issues, financial transactions, and other targets in their work. Their goals are to gather, analyze, and report their objective findings to their clients so that the clients might gain insight on a topic or issue prior to acting.

Explore learning path

Threat Intelligence (THIN)

Skills Framework for the Information Age

Collection and contextual analysis of threat actor activity, indicators, and tactics. Outputs support detection engineering, hunting strategies, and proactive defence planning.

Explore learning path

Cybersecurity Researcher

European Cybersecurity Skills Framework

Research the cybersecurity domain and incorporate results in cybersecurity solutions.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 19

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources