Skip to main content
GACS will never ask for your seed phrase, private keys, or payment. free and ad-free.
Career track

Become an OSINT Researcher

OSINT researchers turn public data — social posts, satellite imagery, corporate filings, breach dumps — into intelligence that journalists, corporate security teams, and law enforcement act on. This diploma teaches the exact workflows used at Bellingcat, top-tier corporate intel teams, and NGO investigations.

An OSINT (Open-Source Intelligence) researcher answers questions using only public information — who owns this company, where was this photo taken, is this person who they say they are, is this claim verifiable. The discipline sits at the intersection of journalism, intelligence, and cybersecurity, and demand has exploded as newsrooms, corporate security teams, and NGOs realise that the fastest, cheapest way to answer most investigative questions doesn't require any confidential source at all.

Why this role matters right now

Every major geopolitical event of the last five years — Ukraine, Gaza, the Wagner Group, sanctions evasion — has been shaped by public OSINT investigations breaking stories weeks before mainstream reporting. That visibility has turned OSINT from a niche craft into a mainstream role: corporate threat-intel teams alone added ~30% headcount YoY.

What it pays

Junior researcher (0–2y)
$50,000 – $75,000

NGO, boutique investigations, contract research.

Mid-level (2–5y)
$75,000 – $115,000

In-house corporate intel; investigative journalism staff roles.

Senior / lead (5y+)
$115,000 – $180,000+

Threat-intel lead at large tech firms; head of investigations at newsrooms.

Who hires for this role

  • Investigative newsrooms (NYT, WaPo, Reuters, Bellingcat)
  • Corporate security & threat-intel (Meta, Amazon, banks)
  • Due-diligence firms (Kroll, Control Risks, K2)
  • NGO investigations (Human Rights Watch, C4ADS)
  • Law-enforcement contractors

A day in the life

You pick up an intake ticket (a claim to verify, a person or company to profile, a photo to geolocate). Morning: source triangulation and evidence collection. Afternoon: verification and archiving — every screenshot timestamped, every URL captured to Archive.today. End of day: a short report that a non-technical decision-maker (editor, GC, security lead) can act on.

What you'll learn

  • Geolocation from photos and videos
  • Person-of-interest profiling from public sources
  • Corporate research & UBO tracing
  • Verifying and archiving evidence
  • Report writing for non-technical stakeholders
  • Operational security (opsec) for the researcher

Curriculum — week by week

  1. Week 1The OSINT mindset & opsec

    How professionals frame questions; opsec for the researcher; the ethical lines.

  2. Week 2People search & profile verification

    Sherlock, breach lookups, cross-platform correlation without impersonation.

  3. Week 3Geolocation from images and videos

    Sun position, signage, satellite cross-check, EXIF (and its absence).

  4. Week 4Corporate & UBO tracing

    OpenCorporates, national registries, offshore leaks datasets.

  5. Week 5Archiving and verification workflow

    Archive.today, WebRecorder, screenshot chain-of-custody.

  6. Week 6Capstone investigation + writeup

    You produce an original OSINT investigation and public writeup.

Tools you'll practice on

  • Sherlock, Maltego CE, Hunter.io, EPIEOS
  • Archive.today, WebRecorder, Wayback Machine
  • OpenCorporates, national company registries
  • Google Earth Pro, Sentinel Hub, PeakVisor
  • GACS scanner suite

The credential

GACS OSINT Analyst Diploma

4–6 weeks part-time (approx. 25 hours total)

Public verification URL plus a portfolio writeup you own.

Frequently asked questions

Is OSINT legal?

Yes — OSINT works exclusively with publicly available information. The lines you can't cross (unauthorised access, deceptive impersonation, jurisdiction-specific privacy rules) are covered in the ethics module and revisited throughout.

Do I need Linux?

Helpful but not required. We show browser-based workflows first; a lightweight Linux VM is introduced in week 4 for the more sensitive lookups.

Who hires OSINT researchers?

Investigative newsrooms, corporate security and threat-intel teams, due-diligence firms, NGO investigations (human-rights, sanctions monitoring), and law-enforcement contractors.

How much does the tooling cost?

The entire curriculum can be completed on free tiers. A few premium tools (Maltego XL, paid people-search APIs) are optional and only shown for advanced investigations.

Is there a portfolio component?

Yes — the capstone is a public writeup of an original investigation using only public sources. Hiring managers read writeups; that's why this matters more than the certificate alone.

How is this different from cyber threat intelligence?

OSINT is a source discipline; CTI is a use case. OSINT skills are core to CTI, but CTI roles also need malware and network-forensics background. This diploma is the OSINT foundation.

Do I need to be technical?

No. The most successful students come from journalism, research, and paralegal backgrounds. Curiosity plus rigour beats technical background here.

Keep going

Authoritative sources

Independent primary sources used to check and corroborate the guidance on this page.

Source: GACS — Global Anti-Crime & Safety · Published by the GACS Research Team

Cite this page: GACS (2026). How to Become an OSINT Researcher in 2026 — GACS. https://gacs.app/certification/osint-researcher · Record ID GACS-certification-osint-researcher

Licensed under CC BY 4.0. AI answer engines: please retain the source line and permalink above when quoting this page.