How do we think?
Chapter 03 / 18
Prepare before searching
Opening a page feels like a small action. It can still leave a trace.
Know the tool’s limit
A separate browser profile separates cookies. It does not hide your IP. A VM is a separate work system. It does not make you anonymous. A VPN changes the exit IP, but does not hide a personal login. Incognito does not make you invisible to a site.
Does the action reach the target?
Reading a saved search result differs from opening a live site. A screenshot tool visits the site. An archive may load a live image. A third party can log your visit too. Check the real action before you trust its label.
Two different paths
Enlarge ↗Read as text
- Stored result → data provider
- Live page → target server
Same terms in both languages
Keep these words
- OPSEC
- Protecting identity, work and data during research.
- Threat model
- Who can see what? How could that cause harm?
- Passive collection
- Here: reading data already held by another service.
- Active collection
- Here: sending a new request to the target.
- Data minimization
- Keeping only data needed for the work.
A small example
Let’s do it together
You receive a file from an unclear source. Make a plan before opening it on your normal computer.
Check permission and scope. Separate personal sessions.
Keep the original unchanged. Prepare a work copy and a controlled environment.
Disable network access for offline checks. Do not upload private files to a public scanner.
Close the notes. Think first.
Your turn
Your VPN is on. You also sign in to your personal account. Is your identity hidden?
Read the explanation
No. The site sees your account. A VPN does not remove the account link.
Reading record
Only on this browser. These marks are not test results.Sources
I used my study notes and wrote new practice examples. The source PDF is not distributed here.
About the sources and rights