Defensive OSINT lab

CSINT Incident Lab

Practice OSINT, source validation, and incident analysis with safe fictionalized cases.

  1. 01Pick a case
  2. 02Review evidence
  3. 03Write the report
Safety noticeFictionalized and sanitized data. Tap to read.

This lab uses fictionalized/sanitized data. Do not use it to target people, expose identities, or test live systems.

Campaign · 12 linked stages

Operation Glass Harbor

One incident file split across four acts. It opens on mail headers, runs through deleted Git history and TLS records, and closes with an evidence-led incident report.

  1. 01Act I: First Light01-04 · Beginner
  2. 02Act II: The Human Layer05-07 · Intermediate
  3. 03Act III: The Build Room08-10 · Advanced
  4. 04Act IV: The Board11-12 · Advanced
Operation Glass Harbor fictional North Pier evidence frame

Lab cases

Pick a case, review the evidence, write your defensive report.

Case 01Supply ChainNot started

SolarWinds Orion Compromise

Reconstruct the timeline and analyze public indicators of compromise (IOCs) from the SolarWinds Orion supply-chain attack.

Difficulty: Intermediate35 mins150 pts

Core skill: Timeline & IOC Analysis

Case 02Vulnerability / RansomwareNot started

MOVEit / CL0P Mass Exploitation

Map the exploitation timeline of CVE-2023-34362 in MOVEit Transfer and assess the extortion campaign behavior.

Difficulty: Beginner25 mins100 pts

Core skill: CVE & Impact Assessment

Case 03Cascading Supply ChainNot started

3CX Supply-Chain Attack

Trace the cascading supply-chain compromise of the 3CX DesktopApp and identify attacker infrastructure.

Difficulty: Advanced40 mins200 pts

Core skill: Software Dependency & Process Analysis

Case 04Ransomware / Critical InfrastructureNot started

Colonial Pipeline / DarkSide Ransomware

Analyze the public communications, threat actor claims, and official reports of the Colonial Pipeline ransomware incident.

Difficulty: Beginner20 mins100 pts

Core skill: Public Narrative & Source Comparison

Case 05Administrative Support BreachNot started

Okta Support Case Management Incident

Analyze the support-system breach at Okta, evaluating HTTP Archive (HAR) file security risks and token hijacking vectors.

Difficulty: Intermediate30 mins150 pts

Core skill: Support Logs & HAR File Risk

Case 06Phishing / Social EngineeringNot started

Fake Recruiter Package

Unravel a fake job-offer phishing chain built around a lookalike company domain and a bogus meeting-verification host, without ever clicking a live link.

Difficulty: Beginner25 mins100 pts

Core skill: Domain & Source Verification

Case 07Disinformation / MediaNot started

Recycled Protest Clip

Decide whether a viral 'live protest' video really shows the claimed event by cross-checking reverse-search results, visual clues, and official statements.

Difficulty: Beginner30 mins100 pts

Core skill: Reverse Search & Timeline

Case 08Breach DisinformationNot started

Mirror Leak Channel

Test whether a Telegram channel claiming a 'full database dump' of a hospital breach is genuine, by comparing post timing, file hashes, and the official disclosure record.

Difficulty: Intermediate35 mins150 pts

Core skill: Source Timing & Authenticity

Case 09Financial Scam / Crisis ExploitationNot started

Storm Relief Donation Scam

Cluster two fake disaster-donation domains through shared registration metadata and a reused payment wallet, and separate them from the legitimate relief foundation they impersonate.

Difficulty: Intermediate35 mins150 pts

Core skill: Domain Cluster & Wallet Pivoting

Case 10Visual VerificationNot started

Press Photo Metadata Mismatch

Audit a wire photo whose caption says 'last night's factory fire' against its EXIF summary and archive matches, then draft an ethical correction for the newsroom.

Difficulty: Advanced45 mins200 pts

Core skill: EXIF & Archive Cross-check

GH 01Email & IdentityNot started

The 04:17 Handover

Follow a convincing handover message through its raw headers and find the point where trust breaks.

Difficulty: Beginner20 mins100 pts

Core skill: Header reconstruction

GH 02Repository ForensicsNot started

The Note That Isn't There

Pull a removed handover detail back out of repository history instead of searching only the current files.

Difficulty: Beginner20 mins100 pts

Core skill: Deleted Git history

GH 03Infrastructure OSINTNot started

Certificate Drift

Tie a certificate observation to the mirror before the public DNS change shows up anywhere.

Difficulty: Beginner25 mins120 pts

Core skill: TLS and passive DNS correlation

GH 04Web InfrastructureNot started

Eleven Minutes on the Mirror

Measure the real exposure window by lining the DNS collectors up against the isolated redirect captures.

Difficulty: Intermediate35 mins140 pts

Core skill: DNS and redirect timeline

GH 05Visual VerificationNot started

Frame 183

Normalize one CCTV frame using what is visible in it, the camera inventory, the clock drift and the weather record.

Difficulty: Intermediate40 mins150 pts

Core skill: Chronolocation and metadata

GH 06HUMINT AssessmentNot started

Three Sources, One Cabinet

Assess three fictional sources without mixing up trust in a source with trust in a claim.

Difficulty: Intermediate45 mins160 pts

Core skill: Source reliability grading

GH 07Shadow IntelligenceNot started

The Shadow Brief

Separate an early technical cluster from a later copycat without trying to identify a real operator.

Difficulty: Intermediate50 mins170 pts

Core skill: Provenance-led clustering

GH 08Identity CorrelationNot started

The Innocent Maintainer

Test a public accusation against account, badge, camera and service records without claiming an alibi you can't prove.

Difficulty: Advanced55 mins180 pts

Core skill: Account and physical-evidence separation

GH 09Software Supply ChainNot started

Trusted Build, Wrong Source

Compare approval, branch history, workflow permissions and provenance to find where the release source stops matching.

Difficulty: Advanced60 mins200 pts

Core skill: Workflow provenance

GH 10Network TelemetryNot started

The Quiet Callback

Find the machine-like cadence in harmless synthetic telemetry and stop short of a malware or exfiltration claim.

Difficulty: Advanced60 mins220 pts

Core skill: Interval and limitation analysis

GH 11Intelligence AssessmentNot started

Four Competing Stories

Test four explanations with inconsistency rather than by counting supporting evidence.

Difficulty: Advanced75 mins240 pts

Core skill: Analysis of competing hypotheses

GH 12Final SynthesisNot started

The Glass Harbor Board

Deliver the final timeline, the scope, the attribution boundary, the containment plan and what stays uncertain.

Difficulty: Advanced90 mins300 pts

Core skill: Evidence-led incident reporting

All interactive evidence is safely sanitized. No real persons, victims, live targets, or leaked databases are involved.

Workspace tools

Jump to the evidence log or the report builder.