Tell me what you have, or pick a starter below. I will point you to the right CSINT page and the next safe step.
OSINT Case Lab
Ten research files derived from real events. Review the data package, solve tasks, build evidence chains, and practice safe reporting reflexes.
Available files
Ten case files based on real public sources.

Visual geolocation check
Check whether a convoy image was taken on the claimed route by comparing fixed visual clues with maps, satellite imagery, and a basic timeline.

Old video shared as a new event
Test whether a crisis video is actually from the claimed event by checking first publication traces and visual context.

Fake institutional announcement
Check whether a statement that appears to come from an institution is supported by the real account, domain, and official correction channels.

Phishing domain chain
Read a phishing claim as a chain: short link, lookalike domain, passive DNS, certificate traces, and page similarity.

Crypto wallet claim
Assess a political or institutional donation claim by checking source authenticity, wallet evidence, and whether a transaction can be verified.

Wrong-person attribution
Study how crowdsourced investigations can harm innocent people when similarity, rumor, and limited official information are treated as proof.

Company name and legal record change
Check whether a company changed its legal identity by separating brand name, product name, court filings, and formal records.

Disaster image verification
Verify whether a disaster photo or video really belongs to the claimed event by using reverse image search, archives, and date context.

Flight or vessel route claim
Assess a vessel route claim by combining AIS history, satellite imagery, media reports, and gaps in public tracking data.

CVE exploitation claim
Verify whether a CVE is actively exploited by checking vendor advisories, CISA KEV, and reliable threat reports.
File format
Every file uses the same learning structure.
Data package
What open-source material is available?
Task
What question should the analyst answer?
Hint
A direction without giving away the result.
Answer key
The evidence chain and expected conclusion style.
Bad analysis
A common but unsafe or weak inference.
Good report
A short, sourced, and careful output example.
Original Turkish lab
The Turkish Case Lab remains available.
The English lab is being localized step by step. The Turkish archive keeps the full original platform structure.
New Practice Area
Real Incident-Based Incident Lab
Practice OSINT timeline analysis and threat indicators using fully sanitized, local simulated artifacts derived from historical cyber events.

