Study notes

My GOSI study notes

While preparing for the GIAC GOSI exam I kept my own binder reports over eight weeks. This page gathers the ideas that came out of those notes, written in my own words and with their sources.

There is no course material here, no exam question, and no question and answer list. These are study notes written the way I understood things. Where I am unsure, the note says so.

40 topics7 sectionsLast updated 2026-07-25

Process and question

The OSINT research process

OSINT (intelligence gathered and verified from publicly available sources) runs in five steps: plan, collect, process, analyse, report.

Why it matters

The order is what keeps the work from drifting. If I start collecting before writing the question, I end up with a pile of screenshots and no context.

Method

  • Plan: write the question, the limits, and which sources are allowed.
  • Collect: take the raw data together with its source address and a UTC timestamp.
  • Process: name and order the files, and leave the raw copy alone.
  • Analyse: separate Fact, Inference, and Assumption.
  • Report: attach a source and a confidence level to every finding.

Example

For one domain I first wrote: "When was this registered and who might be running it?" Only then did I look at the registration record. Without the question I would have jumped straight to a subdomain list, and that list did not answer the question.

Common mistake

Starting with a tool. Typing something into a search box feels like starting work, but it does not set the scope.

OPSEC and ethics note

In the planning step I also write down the legal and OPSEC limits (operational security, meaning protecting myself and the work). Remembering them later does not work.

Question before tool, limits before question.

Sources I used

Related notes

Quick review

The lines I compressed things down to for the last day before the exam.

  • Scope before tools.
  • OPSEC before research.
  • Fact before inference.
  • Confidence before conclusion.
  • Source before claim.
  • Every recorded item carries an address, a time, and a tool.
  • Registration data is not proof of ownership.
  • Metadata is a clue until it is confirmed.
  • Not found and does not exist are different things.
  • The same handle does not mean the same person.
  • Two sites resting on one origin are one source.
  • Careful language replaces absolute wording.
  • When the evidence is weak, the confidence level comes down.
  • Passive reads; active touches.
  • The report is data that needs protecting too.

Sources

The sources cited in the notes. Access dates are the day I last checked the link. My own binder reports are not published; they are only where this page started.

These notes are for defence and verification. They are not for unauthorised access, for tracking individuals, or for monitoring live conflict.