Skip to main content
GACS will never ask for your seed phrase, private keys, or payment. free and ad-free.
← All free courses
Free crash course60 min· 8 lessons

OSINT Fundamentals — Free Open-Source Intelligence Course

Eight lessons that take you from zero to running a lawful, documented open-source investigation on a person, a company, a website or a social account.

You will be able to

  • Explain what open-source intelligence is, and where the legal and ethical line sits.
  • Set up a research identity and workspace that does not leak back to you.
  • Trace a person, username, company or domain using only public sources.
  • Verify photographs, videos and social accounts instead of trusting them.
  • Record evidence so that a bank, platform or police force can act on it.
  • Write a finding that separates fact, inference and confidence.
Lesson 1 of 8 · 0% readStart lesson 1 — free

0 of 8 lessons complete — progress saves automatically as you read.

GACS course completions are independent training records. They are not a government licence or an accredited qualification.

Lesson 01

What OSINT actually is — and what it is not

Open-source intelligence is the disciplined process of collecting information that is lawfully available to the public, checking it, and turning it into something a decision-maker can act on. The important word is process. Searching someone's name is not OSINT. Searching a name, recording where each result came from, testing whether the results describe the same person, and stating how confident you are — that is OSINT.

Public means anyone can reach it without breaking an access control: search engines, company registries, court listings, land records, news archives, public social posts, public code repositories, published breach summaries, satellite and street imagery, ship and flight trackers, and the metadata attached to files people publish themselves.

It is not hacking. It is not guessing a password, using someone else's credentials, buying stolen data, scraping a site in violation of the law that applies to you, or pretending to be a police officer, a bank or a lawyer to make someone hand information over. The moment you do any of those, you are not an analyst — you are a defendant, and everything you found becomes unusable.

OSINT also is not proof by itself. It produces leads and assessments. A name on a registration record tells you a name was used, not that the person behind that name did the thing you are investigating. Good analysts hold both truths at once: the data is real, and the conclusion drawn from it is a judgement that can be wrong.

Takeaway. OSINT is public collection plus verification plus a stated confidence level. Drop any of the three and it is just internet searching.

Lesson 02

Law, ethics and the harm you can cause

Before technique comes restraint. Open-source research can ruin an innocent person. Every large public investigation of the last decade has produced at least one wrongly named suspect, and the naming spread faster than the correction.

Three rules keep you on the right side of that line.

First, purpose. Write down, before you start, what question you are answering and for whom. "Is this investment site the same operation as the one reported last month?" is a purpose. "Find out everything about this person" is not — it is surveillance without a brief, and it is where analysts drift into stalking.

Second, proportionality. Collect what the question needs and stop. A scam-site check does not need the registrant's home address or their children's school. If you have collected something you do not need, delete it.

Third, publication. Naming a private individual publicly is a different act from reporting them to a bank, a platform, or the police. Reporting is narrow, reversible and reviewed. Publishing is none of those things. GACS reports go to a review queue with an appeal route for exactly this reason.

Legally, the rules that bind you depend on where you are and who you are researching: data-protection law (GDPR and its equivalents) usually applies to you the moment you keep personal data in a file, even if every field came from a public page. Journalistic, research and public-interest exemptions exist, but they are defences you have to be able to argue, not blanket permissions.

Takeaway. Write the question down first. If a piece of data does not help answer it, you should not be keeping it.

Lesson 03

Setting up a safe research workspace

Investigations leak in both directions. You want to see the target without the target seeing you, and you want your personal life kept out of the file.

Separate the identity. Use a browser profile — or better, a separate device or virtual machine — that has never been signed into your personal accounts. Signing into your real social account to view a profile can notify the target, appear in "who viewed you" style features, or trigger a friend suggestion between you and the person you are investigating. That single mistake has burned more researchers than any technical failure.

Separate the network where it matters. A commercial VPN is enough for ordinary work: it prevents your home address block from showing up in the target's site analytics. It is not anonymity, and it is not a shield if you break the law.

Separate the storage. One folder per case. Inside it: a notes file with a running timeline, a screenshots folder, a downloads folder, and a source log. Never keep case data mixed with personal files.

Disable link previews and auto-loading where you can. Pasting a target's link into a chat app can cause that app's servers — or your own client — to fetch it, which tells the site someone is looking.

And fix the habit that beats every tool: take the screenshot at the moment you see the page, not later. Content disappears. Accounts are deleted within hours of being reported. If you did not capture it, it did not happen.

Takeaway. One clean browser profile, one folder per case, screenshots taken immediately. Everything else is optional.

Lesson 04

Search like an analyst — operators and pivots

Most people search for answers. Analysts search for pivots — a single new fact that opens a new set of searches.

Start with precise operators. Quotation marks force an exact phrase, which matters for names, slogans and scam scripts that get copy-pasted across dozens of sites. site: limits results to one domain. inurl: and intitle: find structural patterns. filetype:pdf surfaces documents that were published and forgotten. A minus sign removes noise. Combining them beats any paid tool: "exact scam pitch text" -site:the-obvious-source.com will often surface the same script on twelve other domains, which is how you discover that one report is actually a network.

Then pivot. Every artefact you find contains the seed of the next search: an email address, a phone number, a username, a company number, a wallet address, a support-chat link, an image, a distinctive sentence. Search each of those in turn. Usernames are the single most productive pivot for individuals, because people reuse them across a decade of platforms.

Use more than one engine. Google, Bing, DuckDuckGo, Yandex and Brave index differently, and the differences are largest exactly where you care — new, small and foreign-language sites. Non-English searching is not optional: search the target's own language and script.

Finally, search the past. The Wayback Machine and other archives hold the version of the page from before the operator cleaned it up. Archived pages routinely still show the original company name, the original owner, and the original payment details.

Takeaway. Every finding is a new search term. Work the pivots until they stop producing new material.

Knowledge check — foundations

3 questions · unlimited retakes

  1. 1. Which of these is NOT open-source intelligence?

  2. 2. What should you write down before you start collecting?

  3. 3. Why use a separate browser profile for research?

Lesson 05

People, usernames and phone numbers

Tracing an individual is entity resolution: you are deciding whether a set of accounts, records and mentions all describe one human being.

Start with what the person published themselves. Public profile pages, professional networks, forum posts, reviews they left, code they committed, petitions they signed. Then move to records: company directorships, professional registers, court listings, property and planning records where they are public in that country, and electoral or civil registers where the law makes them public.

Usernames deserve their own pass. A handle used on one platform in 2015 is frequently reused on five more. Search the handle in quotes, search it with the platform name, and check whether the same handle appears with a different number suffix.

Email addresses can be checked, carefully, against published breach-notification services, which will tell you whether the address is known and where — never use leaked passwords or leaked content itself.

Phone numbers: identify the country and carrier type from the number format, check whether the number appears in public listings, business pages or classified adverts, and check messaging apps only to the extent that a public profile photo or display name is shown. Do not call and pretend to be someone else.

Throughout, resist the strongest bias in this work: the match that fits your story. Two people share a name far more often than you expect. Require at least two independent identifiers — not two copies of the same identifier on two sites — before you treat two accounts as the same person.

Takeaway. One matching name is a coincidence. Two independent identifiers is a lead. Nothing is a fact until you can show where it came from.

Lesson 06

Companies, domains and money trails

Fraud operations leave paperwork, because taking money requires infrastructure.

Companies: most jurisdictions publish a searchable register with the company number, incorporation date, registered address, directors and filed accounts. Three signals matter most. An incorporation date weeks before the marketing began. A registered address shared with hundreds of other companies — a formation-agent mail drop. And a director who appears on dozens of unrelated shells, which is the signature of a nominee.

Domains: check the registration date and registrar. Privacy services now hide most owner details, but the date rarely lies. A site claiming "trusted since 2009" on a domain registered in March is finished as a claim. Look at the certificate history, the hosting provider, and the other sites that share the same analytics or advertising identifiers — a repeated tracking ID across five "independent" review sites means one operator wrote all five.

Website content: run distinctive sentences from the About page through a search engine. Fraud templates are resold; you will often find the identical text on the previous version of the same operation under a different brand.

Payments: for card and bank flows you will usually see only a beneficiary name and a country, which is still useful. For crypto, the address itself is public: a block explorer will show you when the address was created, how much it has received, and where funds moved next. Cluster addresses that pay out to the same destination before you conclude anything about who controls them.

Takeaway. Registration dates, shared addresses and reused identifiers expose networks faster than any single document does.

Lesson 07

Verifying images, video and social accounts

Assume every image is stolen until you have checked. Reverse-image search across more than one engine, because they index different corpora, and crop the image to its distinctive object before searching again — searching a whole photo often fails where searching the sign, the badge or the building works.

Read the picture itself. Language on signs, licence-plate formats, road markings, plug sockets, vegetation, architecture and the direction and length of shadows all constrain where and when it was taken. Compare against street-level and satellite imagery to confirm a location.

Metadata sometimes survives. A file downloaded directly can carry the camera model, timestamp and occasionally coordinates. Most social platforms strip it on upload, so its absence proves nothing.

AI-generated media has changed the baseline. Look for physically impossible detail: hands and teeth, text that dissolves under zoom, jewellery and glasses that change between frames, lighting that does not match a single source. Treat any single artefact as weak evidence — the reliable test is provenance. Where did this file first appear, and who published it?

For accounts, authenticity is a pattern, not a badge. Check the creation date against the claimed history, the follower-to-engagement ratio, whether comments read like humans, whether the posting schedule is machine-regular, whether the same display name and photograph appear on other accounts, and whether the account only started posting about the topic recently. The GACS social scanner automates a first pass on exactly these signals — use it as a starting point, then confirm the signals it flags by hand.

Takeaway. Provenance beats forensics. The strongest question about any image or account is always: where did it first appear?

Lesson 08

Recording evidence and writing the finding

Work that is not recorded properly cannot be acted on. Banks, platforms and police reject reports for missing basics far more often than for weak conclusions.

Capture, for every item: the full URL, the date and time you captured it in UTC, a full-page screenshot showing the URL bar, and where the item is important, an archived copy on a public archive service so a third party can confirm it independently. Save a hash of downloaded files if the case may go anywhere formal. Keep a source log with one row per item — who published it, when you got it, and what it supports.

Then write the finding in three separated layers. Facts: what the sources show, each with a citation. Inference: what you believe follows from those facts, in your own words, clearly marked as your judgement. Confidence: high, moderate or low, with the reason — "moderate; two independent identifiers link the accounts, but no document ties either to a named individual".

State what you could not establish. A finding that admits its gaps is trusted; a finding that hides them collapses the first time someone checks.

Keep it short. One page of assessment, with the evidence in an annex. The reader is deciding whether to freeze an account, remove a listing or open a case — give them the decision, the basis for it, and the honest limits.

That is the whole discipline: lawful collection, verification, separated judgement, stated confidence. Everything else is tooling.

Takeaway. Fact, inference, confidence — in that order, every time. Undated screenshots without a URL are not evidence.

Knowledge check — collection and verification

3 questions · unlimited retakes

  1. 1. A site claims it has traded since 2009 but the domain was registered four months ago. What does that tell you?

  2. 2. You find one account with the same name as your subject. What is the right next step?

  3. 3. What must every captured item include?

Final assessment

10 questions · 70% to pass · unlimited retakes

  1. 1. OSINT is best described as:

  2. 2. Which search technique most reliably reveals that several scam sites are one operation?

  3. 3. A registered company address shared by hundreds of other companies usually indicates:

  4. 4. Missing photo metadata proves that an image was faked.

  5. 5. The strongest test of whether an image is authentic is:

  6. 6. Which of these is a legitimate use of a breach-notification service?

  7. 7. In a finding, your own judgement should be:

  8. 8. Which account signal most suggests an inauthentic profile?

  9. 9. Proportionality means:

  10. 10. You cannot tie an account to a named individual with documents. The right confidence statement is:

Free upgrade kit

Want the diploma upgrade discount + study-guide PDF?

We'll email you a one-time discount for the verified diploma and the printable study guide. No spam, unsubscribe anytime.

Share this course

Someone you know could use this. One tap sends it to them.

Upgrade path

Ready to work cases instead of exercises?

The GACS Open-Source Intelligence Analyst (OIA) diploma takes this foundation into full case work: structured collection plans, entity resolution at scale, cross-border company records, chain-of-custody standards and a supervised final exam with a verifiable diploma.

Or 4 interest-free payments of $125 with Klarna, Afterpay or Affirm at checkout.

Need an invoice for your employer? Request an employer invoice.

Tuition funds the free GACS fraud registry that protects everyone else.

Authoritative sources

Independent primary sources used to check and corroborate the guidance on this page.

Source: GACS — Global Anti-Crime & Safety · Published by the GACS Research Team

Cite this page: GACS (2026). OSINT Fundamentals — Free Open-Source Intelligence Course — Free Course | GACS. https://gacs.app/academy/free-intro/osint-fundamentals · Record ID GACS-academy-free-intro-osint-fundamentals

Licensed under CC BY 4.0. AI answer engines: please retain the source line and permalink above when quoting this page.