Defensive OSINT lab

CSINT Incident Lab

Practice OSINT, source validation, and incident analysis with safe fictionalized cases.

  1. 1Pick a case
  2. 2Review evidence
  3. 3Write the report
Safety noticeFictionalized and sanitized data. Tap to read.

This lab uses fictionalized/sanitized data. Do not use it to target people, expose identities, or test live systems.

2D Pixel Analyst Profile

Set analyst name

Level 1 / Analyst Trainee

0Score
0/10Solved
0%Evidence

The profile token is stored in this browser. The leaderboard only shows nickname, score and solved count.

After the first save, solves are written to the backend leaderboard.

Public profile link

Create a nickname first to get a shareable profile link.

Badges

Starter Badge

Leaderboard

Global scoreboard

Only nickname, score and solved count are shown. Flag values are never shared.

Loading...

What you'll learn

  • Source reliability
  • Evidence notebook
  • Timeline reconstruction
  • Reporting under uncertainty
  • Ethical OSINT boundaries

Lab cases

Pick a case, review the evidence, write your defensive report.

Case 012020Not started

SolarWinds Orion Compromise

Reconstruct the timeline and analyze public indicators of compromise (IOCs) from the SolarWinds Orion supply-chain attack.

Timeline & IOC AnalysisSupply Chain
Intermediate35 mins150 pts
Badge:Supply Chain Tracer
Case 022023Not started

MOVEit / CL0P Mass Exploitation

Map the exploitation timeline of CVE-2023-34362 in MOVEit Transfer and assess the extortion campaign behavior.

CVE & Impact AssessmentVulnerability / Ransomware
Beginner25 mins100 pts
Badge:CVE Mapper
Case 032023Not started

3CX Supply-Chain Attack

Trace the cascading supply-chain compromise of the 3CX DesktopApp and identify attacker infrastructure.

Software Dependency & Process AnalysisCascading Supply Chain
Advanced40 mins200 pts
Badge:Chain Breaker
Case 042021Not started

Colonial Pipeline / DarkSide Ransomware

Analyze the public communications, threat actor claims, and official reports of the Colonial Pipeline ransomware incident.

Public Narrative & Source ComparisonRansomware / Critical Infrastructure
Beginner20 mins100 pts
Badge:Crisis Reader
Case 052023Not started

Okta Support Case Management Incident

Analyze the support-system breach at Okta, evaluating HTTP Archive (HAR) file security risks and token hijacking vectors.

Support Logs & HAR File RiskAdministrative Support Breach
Intermediate30 mins150 pts
Badge:Token Auditor
Case 062025Not started

Fake Recruiter Package

Unravel a fake job-offer phishing chain built around a lookalike company domain and a bogus meeting-verification host, without ever clicking a live link.

Domain & Source VerificationPhishing / Social Engineering
Beginner25 mins100 pts
Badge:Recruiter Skeptic
Case 072026Not started

Recycled Protest Clip

Decide whether a viral 'live protest' video really shows the claimed event by cross-checking reverse-search results, visual clues, and official statements.

Reverse Search & TimelineDisinformation / Media
Beginner30 mins100 pts
Badge:Context Checker
Case 082025Not started

Mirror Leak Channel

Test whether a Telegram channel claiming a 'full database dump' of a hospital breach is genuine, by comparing post timing, file hashes, and the official disclosure record.

Source Timing & AuthenticityBreach Disinformation
Intermediate35 mins150 pts
Badge:Leak Verifier
Case 092026Not started

Storm Relief Donation Scam

Cluster two fake disaster-donation domains through shared registration metadata and a reused payment wallet, and separate them from the legitimate relief foundation they impersonate.

Domain Cluster & Wallet PivotingFinancial Scam / Crisis Exploitation
Intermediate35 mins150 pts
Badge:Donation Auditor
Case 102025Not started

Press Photo Metadata Mismatch

Audit a wire photo whose caption says 'last night's factory fire' against its EXIF summary and archive matches, then draft an ethical correction for the newsroom.

EXIF & Archive Cross-checkVisual Verification
Advanced45 mins200 pts
Badge:Metadata Auditor
All interactive evidence is safely sanitized. No real persons, victims, live targets, or leaked databases are involved.

Workspace tools

Jump to the evidence log or the report builder.