Become an OSINT Researcher
OSINT researchers turn public data — social posts, satellite imagery, corporate filings, breach dumps — into intelligence that journalists, corporate security teams, and law enforcement act on. This diploma teaches the exact workflows used at Bellingcat, top-tier corporate intel teams, and NGO investigations.
An OSINT (Open-Source Intelligence) researcher answers questions using only public information — who owns this company, where was this photo taken, is this person who they say they are, is this claim verifiable. The discipline sits at the intersection of journalism, intelligence, and cybersecurity, and demand has exploded as newsrooms, corporate security teams, and NGOs realise that the fastest, cheapest way to answer most investigative questions doesn't require any confidential source at all.
Why this role matters right now
Every major geopolitical event of the last five years — Ukraine, Gaza, the Wagner Group, sanctions evasion — has been shaped by public OSINT investigations breaking stories weeks before mainstream reporting. That visibility has turned OSINT from a niche craft into a mainstream role: corporate threat-intel teams alone added ~30% headcount YoY.
What it pays
NGO, boutique investigations, contract research.
In-house corporate intel; investigative journalism staff roles.
Threat-intel lead at large tech firms; head of investigations at newsrooms.
Who hires for this role
- Investigative newsrooms (NYT, WaPo, Reuters, Bellingcat)
- Corporate security & threat-intel (Meta, Amazon, banks)
- Due-diligence firms (Kroll, Control Risks, K2)
- NGO investigations (Human Rights Watch, C4ADS)
- Law-enforcement contractors
A day in the life
You pick up an intake ticket (a claim to verify, a person or company to profile, a photo to geolocate). Morning: source triangulation and evidence collection. Afternoon: verification and archiving — every screenshot timestamped, every URL captured to Archive.today. End of day: a short report that a non-technical decision-maker (editor, GC, security lead) can act on.
What you'll learn
- Geolocation from photos and videos
- Person-of-interest profiling from public sources
- Corporate research & UBO tracing
- Verifying and archiving evidence
- Report writing for non-technical stakeholders
- Operational security (opsec) for the researcher
Curriculum — week by week
- Week 1The OSINT mindset & opsec
How professionals frame questions; opsec for the researcher; the ethical lines.
- Week 2People search & profile verification
Sherlock, breach lookups, cross-platform correlation without impersonation.
- Week 3Geolocation from images and videos
Sun position, signage, satellite cross-check, EXIF (and its absence).
- Week 4Corporate & UBO tracing
OpenCorporates, national registries, offshore leaks datasets.
- Week 5Archiving and verification workflow
Archive.today, WebRecorder, screenshot chain-of-custody.
- Week 6Capstone investigation + writeup
You produce an original OSINT investigation and public writeup.
Tools you'll practice on
- Sherlock, Maltego CE, Hunter.io, EPIEOS
- Archive.today, WebRecorder, Wayback Machine
- OpenCorporates, national company registries
- Google Earth Pro, Sentinel Hub, PeakVisor
- GACS scanner suite
The credential
GACS OSINT Analyst Diploma
4–6 weeks part-time (approx. 25 hours total)
Public verification URL plus a portfolio writeup you own.
Ready to start?
Start the OSINT DiplomaFrequently asked questions
Is OSINT legal?
Yes — OSINT works exclusively with publicly available information. The lines you can't cross (unauthorised access, deceptive impersonation, jurisdiction-specific privacy rules) are covered in the ethics module and revisited throughout.
Do I need Linux?
Helpful but not required. We show browser-based workflows first; a lightweight Linux VM is introduced in week 4 for the more sensitive lookups.
Who hires OSINT researchers?
Investigative newsrooms, corporate security and threat-intel teams, due-diligence firms, NGO investigations (human-rights, sanctions monitoring), and law-enforcement contractors.
How much does the tooling cost?
The entire curriculum can be completed on free tiers. A few premium tools (Maltego XL, paid people-search APIs) are optional and only shown for advanced investigations.
Is there a portfolio component?
Yes — the capstone is a public writeup of an original investigation using only public sources. Hiring managers read writeups; that's why this matters more than the certificate alone.
How is this different from cyber threat intelligence?
OSINT is a source discipline; CTI is a use case. OSINT skills are core to CTI, but CTI roles also need malware and network-forensics background. This diploma is the OSINT foundation.
Do I need to be technical?
No. The most successful students come from journalism, research, and paralegal backgrounds. Curiosity plus rigour beats technical background here.
Keep going
Authoritative sources
Independent primary sources used to check and corroborate the guidance on this page.
- NIST National Initiative for Cybersecurity Education (NICE)
US national framework for cybersecurity work roles and competencies.
- Financial Action Task Force (FATF)
Global AML/CFT standards referenced by financial-crime curricula.
- FBI Internet Crime Complaint Center — Annual Reports
Primary loss and typology data used in fraud-investigation training.
- US Federal Trade Commission — Consumer Sentinel Data Book
Official complaint statistics for teaching fraud trend analysis.
