case library

OSINT Case Lab

Ten research files derived from real events. Review the data package, solve tasks, build evidence chains, and practice safe reporting reflexes.

Available files

Ten case files based on real public sources.

Case 01GEOINT
Case 01·GEOINT·35-50 min·Bellingcat

Visual geolocation check

Check whether a convoy image was taken on the claimed route by comparing fixed visual clues with maps, satellite imagery, and a basic timeline.

Case 02Crisis verification
Case 02·Crisis verification·25-40 min·Associated Press Fact Focus

Old video shared as a new event

Test whether a crisis video is actually from the claimed event by checking first publication traces and visual context.

Case 03Institution verification
Case 03·Institution verification·20-30 min·ABC News / Reuters

Fake institutional announcement

Check whether a statement that appears to come from an institution is supported by the real account, domain, and official correction channels.

Case 04Domain / CTI
Case 04·Domain / CTI·35-55 min·Citizen Lab

Phishing domain chain

Read a phishing claim as a chain: short link, lookalike domain, passive DNS, certificate traces, and page similarity.

Case 05Blockchain / media verification
Case 05·Blockchain / media verification·30-45 min·Full Fact

Crypto wallet claim

Assess a political or institutional donation claim by checking source authenticity, wallet evidence, and whether a transaction can be verified.

Case 06Attribution risk
Case 06·Attribution risk·25-40 min·The Guardian

Wrong-person attribution

Study how crowdsourced investigations can harm innocent people when similarity, rumor, and limited official information are treated as proof.

Case 07Public records
Case 07·Public records·25-35 min·TechCrunch

Company name and legal record change

Check whether a company changed its legal identity by separating brand name, product name, court filings, and formal records.

Case 08Disaster verification
Case 08·Disaster verification·20-35 min·AFP Fact Check

Disaster image verification

Verify whether a disaster photo or video really belongs to the claimed event by using reverse image search, archives, and date context.

Case 09Maritime OSINT
Case 09·Maritime OSINT·35-55 min·Bellingcat

Flight or vessel route claim

Assess a vessel route claim by combining AIS history, satellite imagery, media reports, and gaps in public tracking data.

Case 10Defensive CTI
Case 10·Defensive CTI·30-45 min·CISA

CVE exploitation claim

Verify whether a CVE is actively exploited by checking vendor advisories, CISA KEV, and reliable threat reports.

File format

Every file uses the same learning structure.

01

Data package

What open-source material is available?

02

Task

What question should the analyst answer?

03

Hint

A direction without giving away the result.

04

Answer key

The evidence chain and expected conclusion style.

05

Bad analysis

A common but unsafe or weak inference.

06

Good report

A short, sourced, and careful output example.

Original Turkish lab

The Turkish Case Lab remains available.

The English lab is being localized step by step. The Turkish archive keeps the full original platform structure.

Open Turkish lab

New Practice Area

Real Incident-Based Incident Lab

Practice OSINT timeline analysis and threat indicators using fully sanitized, local simulated artifacts derived from historical cyber events.

Open Incident Lab