This lab uses public incident reporting and sanitized synthetic artifacts for defensive OSINT training. Real incidents are referenced for educational context only. The interactive data is fictionalized and must not be used to identify, contact, expose, or accuse real people.
Fake Recruiter Package
Unravel a fake job-offer phishing chain built around a lookalike company domain and a bogus meeting-verification host, without ever clicking a live link.
Good. The pattern is documented in official consumer-protection and CISA guidance; the specific company, domains, and messages here are entirely fictional training data.
Incident Brief & Analytical Mission
A candidate reports seeing a 'Senior OSINT Analyst' posting attributed to the fictional firm Northline Analytics Ltd. The recruiter messages arrive over a professional networking site, email, and a messaging app, and push the candidate toward an interview link that hops from a lookalike careers domain to a fake meeting-verification host. This mirrors a widely documented 2023-2025 pattern in which threat actors impersonate recruiters, register lookalike hiring domains, and route victims through fake calendar or meeting-verification pages to harvest credentials. All names, domains, and messages in this case are synthetic.
Work as a passive analyst: compare the lookalike hiring domain against the company's real domain using WHOIS/RDAP metadata, check whether the posting exists on the official careers page, reconstruct the full phishing chain from message to final host, and write defensive advice for candidates, all without visiting any live attacker infrastructure.
Recruiter Message Metadata Summary
Sanitized summaries of the three recruiter messages the candidate received. All domains are defanged with .test TLDs; no live links.
Investigative Checklist Tasks
- 01
Compare the WHOIS/RDAP records to state the difference between the real northlineanalytics[.]test domain and the lookalike hiring domain.
- 02
Determine whether the advertised role exists on the company's official careers page and label the posting accordingly.
- 03
Write the phishing chain end to end: recruiter message → shortener → lookalike careers domain → final verification host.
- 04
List three defensive actions a candidate should take when a recruiter pushes an off-domain interview link.
Evidence Notebook
Use this panel to log individual threads of evidence. Your entries are saved locally in this browser only.
No evidence records logged yet.
Report Drafting Board
# CSINT Incident Lab Report ## Research Question Is the 'Senior OSINT Analyst' recruitment package a legitimate Northline Analytics hiring process or a phishing chain? ## Summary No analyst summary provided yet. ## Fact - No forensic facts recorded in the notebook. ## Signal - No analytical signals logged. ## Inference - No alternative explanations recorded. ## Recommendation - No next-pivot recommendations recorded. ## Confidence Low ## Limitations No limitation notes entered. ## Source reliability Not assessed. Annotate each source with its reliability tier before publishing. ## Information validity Not assessed. Confirm whether each item is directly observed, reported, or inferred. ## Missing context Not recorded. List what data is missing or could not be verified from public sources. ## Next safe steps - No next safe steps specified. ## Sources used - No source references listed. --- Generated at: 2026-07-24T18:30:26.714Z

