Search Is Cheap, Judgment Is Not: A Field Guide to Defensible OSINT
The internet rewards searching. Courts, clients, and commanders reward reasoning. That gap is the entire discipline.
Anyone with a browser can find something. The hard part, the part that separates an analyst from a search-engine operator, is turning what you found into a claim you can defend when a hostile attorney, a skeptical editor, or a decision-maker with real consequences on the line asks the only question that matters: how do you know? Investigations fail on that question in predictable ways. An analyst matches an image to a location instead of trying to disprove it, and matches the wrong one. An analyst finds a decisive post and screenshots it a week later, after it has been edited, with nothing preserved. The finding was real. The proof was not.
Open-source intelligence (OSINT) is often taught as a tour of tools and sites. That framing is backwards. Tools change every quarter. Platforms lock down APIs, sites die, and this year's clever technique becomes next year's dead link. What persists is judgment: the ability to frame a question, plan collection, weigh sources, reason under uncertainty, guard against your own biases, and write findings that survive scrutiny.
This guide treats OSINT as a reasoning discipline first and a tooling discipline second. It is organized around eight practices, plus a section on capture and chain of custody that most field guides skip and that becomes decisive the moment your work might reach a report, a regulator, or a courtroom. Every example here is generic or composite. The methods are not.
1. Mission Framing: Turn a Tasking Into a Question
Most bad investigations are lost before collection begins, because the analyst accepted a vague tasking and never converted it into an answerable question. "Find everything on this company" is not a question. It has no boundary, no success criterion, and no stop condition, so it produces a pile of material and no judgment.
Start by separating what you actually have into three buckets:
- Known: facts you can already assert with a source.
- Assumed: things you are treating as true without proof, often without noticing. Assumptions are where investigations quietly go wrong, so write them down explicitly.
- Unknown: the specific gaps that, if filled, would change your answer.
Then borrow the structure military and competitive-intelligence shops use. Define Priority Intelligence Requirements (PIRs): the two or three decision-driving questions the customer needs answered. Under each PIR, list Essential Elements of Information (EEIs): the concrete sub-facts you can actually collect that together answer the PIR. A PIR might be "Is this vendor financially capable of delivering the contract?" The EEIs are things you can go and find: registered entity and status, filing history, litigation record, adverse media, ownership structure, and evidence of operating footprint.
Finish framing with two things analysts routinely omit:
- Success criteria: what a complete answer looks like, in advance, so you are not moving the goalposts to match what you found.
- Stop conditions: when you stop collecting. Stop when the PIRs are answered to the required confidence, when additional collection stops changing your assessment (marginal return has flattened), or when you hit a legal or ethical boundary. Without a stop condition, "collect everything" becomes the plan by default.
Decision rule: if you cannot state, in one sentence, what decision your product will inform and what would change that decision, do not start collecting. Go back to the requester.
2. Planned, Intentional Collection
Collection is a plan, not a reflex. The dominant failure mode in OSINT is "collect everything," which feels productive and is actively harmful: it buries the signal, wastes the one resource you cannot recover (attention), and makes your work impossible to reproduce.
A workable collection plan maps each EEI to source layers, a method, and a cadence. Think in layers rather than favorite sites:
- Surface: search engines, mainstream and local media, official statements.
- Registry and record: corporate registries, court dockets, property and regulatory filings, sanctions and enforcement lists.
- Platform and social: profiles, posts, connections, and the metadata around them.
- Technical: domains, WHOIS/DNS history, certificate transparency, infrastructure relationships.
- Media: images, video, and their provenance.
- Archival: cached and archived versions of all of the above.
Assign a cadence to anything that changes: a one-time pull for static records, a recurring check for active accounts, event-driven collection when a trigger fires. And treat reproducibility as a first-class requirement. Another competent analyst, handed your plan, should be able to retrace your steps and reach the same material. That means logging queries, dates, and sources as you go, not reconstructing them from memory a week later.
Practitioner references such as Bazzell and Edison's OSINT Techniques (2024) and Bellingcat's continuously updated Online Investigation Toolkit (2024) are useful precisely because they are organized around workflows and source layers rather than one-off tricks. Use them to populate your plan, not to replace it. The plan is yours; the tools are interchangeable.
Collect Without Burning the Operation (OPSEC and Attribution)
Before you touch a source, decide whether the subject can see that you did, and whether that matters to the case. That single question separates disciplined collection from the kind that tips off a target or attaches your name to the file.
- Passive versus active. Reading and viewing is passive. Following, connecting, messaging, or joining is active engagement, and it can both alert the subject and create evidentiary and ethical problems that a defense attorney will happily explore. Default to passive.
- Silent views are not always silent. Some platforms, professional networks in particular, notify a user who viewed their profile. Know which of your sources report back to the subject before you look.
- Non-attributable infrastructure. Route research through a VPN or VPS and, for sensitive work, a managed-attribution or containerized browser, so a spike in traffic or a revealing referrer does not lead back to you or your organization.
- Separate research accounts. Where you need an account to see a source, keep it fully separated from your personal identity, created and used with organizational approval and within the platform's rules and the law. Pretext and sock-puppet accounts carry legal and ethical exposure; treat them as a decision, not a habit.
- Rate and pattern discipline. Aggressive automated pulls trip anti-automation defenses, and a blocked or throttled account can taint or halt collection at the worst moment.
Collection also has to stay inside the law, and "when you hit a legal boundary" is only a real stop condition if you know where the boundaries usually are. The recurring ones: platform terms of service and anti-scraping provisions; computer-misuse exposure (in the US, the Computer Fraud and Abuse Act) for automated collection or pretext access; and, wherever you operate in or collect on people in the EU or other GDPR-style regimes, a documented lawful basis for processing personal data. Some EEIs are collectible in principle but out of bounds in practice. That determination belongs in the plan, confirmed with counsel where the stakes are high, not discovered after the fact.
3. Source Quality, Provenance, and Traceability
The single most common analytic error in open sources is mistaking repetition for corroboration. Ten accounts posting the same claim are not ten sources. They may be one source and nine echoes. Your job is to trace every claim back toward its origin and to grade what you find.
Distinguish primary sources (the originating document, the person who was there, the first upload of an image) from derivative sources (reporting about the document, a re-upload, a screenshot of a screenshot). Claims launder themselves as they travel: a speculative sentence in a forum becomes a confident headline three hops later, with the hedging stripped and the uncertainty gone. Chase the claim upstream until you hit bedrock or run out of trail, and note where the trail ended. Ask who benefits from the claim being believed. Motive does not make a claim false, but it tells you how hard to push on verification.
To make source assessment consistent instead of impressionistic, grade sources and information separately using the A-F / 1-6 matrix documented in U.S. Army doctrine (FM 2-22.3, 2006, Appendix B) and known in British and NATO practice as the Admiralty Code. Reliability of the source and credibility of the information are independent axes, and keeping them separate is the whole point: a usually reliable source can still relay an uncorroborated rumor.
Source reliability (A-F):
| Grade | Meaning |
|---|---|
| A | Reliable |
| B | Usually reliable |
| C | Fairly reliable |
| D | Not usually reliable |
| E | Unreliable |
| F | Cannot be judged |
Information credibility (1-6):
| Grade | Meaning |
|---|---|
| 1 | Confirmed (by independent sources) |
| 2 | Probably true |
| 3 | Possibly true |
| 4 | Doubtfully true |
| 5 | Improbable |
| 6 | Cannot be judged |
A datum tagged "B2" (usually reliable source, probably true) tells a downstream reader far more than "per an online post." Use the matrix, but do not oversell it. It is only as good as the discipline behind it: studies of how analysts apply the scheme find that grades cluster on middle values and that the two axes, which are supposed to be independent, get treated as correlated. A "B2" is shorthand for your reasoning, never a substitute for showing the actual sourcing chain.
The taxonomy of what you are looking at also matters. Wardle and Derakhshan's Information Disorder framework (Council of Europe, 2017) separates misinformation (false, no intent to harm), disinformation (false, intent to harm), and malinformation (true information weaponized to harm). Wardle's companion "7 types" typology (First Draft, 2017) is a practical checklist: satire, false connection, misleading content, false context, imposter content, manipulated content, and fabricated content. "False context," genuine media presented as something it is not, is the one that catches experienced analysts, because the media itself is real. UNESCO's journalism handbook (Ireton and Posetti, 2018) lays out the source, date, and location verification checks that operationalize this.
4. Reasoning Is the Real Skill
Collection gives you clues. Clues are not claims, and claims are not conclusions. The move from one to the next is reasoning, and it is where most analytic failure actually happens.
Watch for the "therefore trap": a chain of individually plausible steps that quietly loses probability at every link and arrives at a confident conclusion built on multiplied uncertainty. "The account posts in this time zone, therefore the user lives there, therefore they were present at the event, therefore they are involved." Each "therefore" is a hinge, and each hinge can be wrong. Make the chain explicit and interrogate each link on its own: is this an observation or an inference? What else could produce this same clue?
Two lightweight structures keep reasoning honest:
- Hypothesis trees: enumerate the plausible explanations for what you are seeing, including the boring ones (coincidence, error, staging, unrelated activity), before you commit. If you have only one hypothesis, you are not analyzing, you are confirming.
- Evidence-hypothesis matrices: list your evidence down the side and your hypotheses across the top, then score how consistent each piece of evidence is with each hypothesis. The power of this is counterintuitive: you are looking for evidence that is inconsistent with a hypothesis, because a single solid inconsistency can push a candidate to the bottom of the list, whereas consistent evidence rarely proves one. This is the core logic of Richards Heuer's Analysis of Competing Hypotheses (Psychology of Intelligence Analysis, CIA, 1999). One caution the method itself demands: before you drop a hypothesis on a single inconsistency, ask whether that inconsistent datum could itself be wrong, mislabeled, or deliberately planted (see Section 7). Any one piece of evidence can be the deception, so eliminate on weight of disconfirmation, not on a lone data point. Analysts get attached to a favored story and unconsciously collect support for it; ACH forces you to work by disconfirmation instead.
5. Structured Analytic Techniques, Kept Lightweight
Structured analytic techniques (SATs) sound bureaucratic and can be, but a handful of them are fast, high-leverage habits rather than paperwork. They exist to slow down the intuitive, fast-thinking System 1 (in Kahneman's Thinking, Fast and Slow, 2011) long enough for deliberate System 2 to check its work. The CIA's Tradecraft Primer (2009) is the standard reference for the first four techniques below; Premortem Analysis comes from Pherson and Heuer's Structured Analytic Techniques (3rd ed., 2019), which is the fuller catalog of the method.
| Technique | What it does | When to reach for it |
|---|---|---|
| Key Assumptions Check | Surfaces the load-bearing assumptions you are treating as fact | At the start, and any time the answer feels obvious |
| Analysis of Competing Hypotheses | Scores evidence against rival explanations to find disconfirmers | When more than one explanation fits and stakes are high |
| Quality of Information Check | Re-audits your sourcing for reliability, currency, and laundering | Before you write, and before any number goes in a report |
| Red Team / Devil's Advocacy | Argues the opposing case in good faith | When consensus formed fast or nobody disagrees |
| Premortem | Assumes the assessment was wrong, then explains how | Just before delivery, to catch overconfidence |
None of these takes long. A Key Assumptions Check on a tight investigation is fifteen minutes with a notepad. A Premortem is one question asked out loud: "It is six months from now and we were badly wrong. What did we miss?" The discipline is doing them at all, and doing them before you are committed to an answer rather than after you have to defend one.
6. Geolocation and Chronolocation
Placing an image or video in space and time is where OSINT reasoning becomes visible and testable. Do it as a layered accumulation of independent evidence, not a single "gotcha" match.
Work through the layers, treating each as a constraint that narrows the possibility space:
- Terrain and skyline: hills, coastlines, horizon profiles.
- Built environment: architecture, road markings, signage, utility poles, fencing, guardrail styles.
- Language and text: scripts, dialect, phone number formats, license plate patterns.
- Vegetation and climate: species, density, seasonal state.
- Vehicles and objects: models and configurations common to specific regions.
- Sun and shadow: shadow direction and length, which constrain both location and time.
Then match those constraints against satellite and street-level imagery, the workflow Bellingcat has documented since its early guides (Higgins, "A Beginner's Guide to Geolocating Videos," 2014; "Searching the Earth," 2015) and maintains in its toolkit.
Two disciplines separate credible geolocation from confirmation bias:
- Falsification and negative testing. Actively try to prove the claimed location wrong. If a video is said to be in City A, look for what should be present in City A and is absent, or present and inconsistent. A location you failed to disprove is far stronger than one you merely matched.
- Shadow and sun reasoning for chronolocation. Shadow azimuth and length, combined with a solar position calculator such as SunCalc, can constrain the time of day and, with the date, corroborate or contradict a claimed timestamp. Be precise about the mechanics: shadow-length reasoning needs a reference object of known or estimable height; solar calculators return local solar time, so convert for time zone and daylight saving before comparing to a claimed clock timestamp; and use the shadow's azimuth to resolve the morning-versus-afternoon ambiguity that length alone leaves open. Cross-check against dated satellite imagery (construction progress, seasonal vegetation) and historical weather records.
Treat metadata with caution rather than faith. EXIF timestamps and GPS tags are frequently stripped by platforms on upload, are trivially editable, and carry time-zone ambiguities that produce hours of error. Metadata is a lead, not proof. The strongest geolocation rests on independent corroboration: two or more captures, ideally from different uploaders and angles, that agree on the same physical scene. The Berkeley Protocol (UN OHCHR and UC Berkeley Human Rights Center, 2022) is explicit that verification, not metadata, carries the weight.
7. Deception, Coordinated Inauthentic Behavior, and Your Own Bias
Assume some of what you find was put there for you to find. The modern information environment includes staged media, recycled footage, imposter accounts, and coordinated inauthentic behavior (CIB) built to manufacture the appearance of consensus.
Indicators worth checking, none conclusive alone:
- Staging and manipulation: lighting or shadows that do not agree, edges and artifacts around inserted elements, audio that does not match the scene, "too perfect" framing of a candid moment.
- Recycled context: reverse image search that surfaces the same media predating the claimed event, or attached to a different one. Run it across multiple engines, because no single one is comprehensive: Google, Yandex, and TinEye behave very differently, Yandex is often strongest on faces and places, and TinEye is best at finding the earliest known instance of an image.
- Coordination: clusters of accounts posting near-identical content in tight time windows, creation dates bunched together, thin or borrowed profile histories, engagement that does not match reach.
Synthetic and AI-Generated Media
Generative models now produce photoreal images, cloned voices, and video that the classic manipulation tells above will miss, because nothing was spliced; the whole frame was synthesized. This is the fastest-moving deception vector, and it needs its own checks:
- Look for the model's tells: physically implausible hands, teeth, ears, and jewelry; garbled or nonsensical text on signage and clothing; reflections and shadows that do not agree with the scene; background objects that warp or dissolve; and, in video, temporal inconsistency across frames such as flicker, morphing edges, and unnatural blinking or lip-sync.
- Use provenance as a positive signal. The C2PA Content Credentials standard embeds tamper-evident provenance in an asset. Its presence is a useful signal; its absence proves nothing, because most real media carries none.
- Do not trust automated detectors as proof. Current deepfake and AI-image detectors are unreliable in both directions, producing false positives on real media and false negatives on synthetic. They are a lead, never the basis for a claim. Apply your own falsification discipline symmetrically: do not assert "this is AI-generated" without corroboration any more than you would assert a location without it. Over-claiming synthetic origin is as damaging on cross-examination as missing it.
The harder adversary, though, is internal. Heuer's central finding is that the biggest threats to analysis are the analyst's own cognitive habits, and Kahneman gives them names:
- Confirmation bias: weighting evidence that fits your working theory and discounting the rest.
- Anchoring: the first number or framing you saw dragging every later estimate toward it.
- Availability: treating what is vivid or recent as more probable than it is.
- Groupthink: a team converging early and then reinforcing itself.
- Overconfidence: narrow certainty that the evidence does not earn.
You do not defeat these by resolving to be objective. You instrument against them: write down assumptions before you look (Key Assumptions Check), work by disconfirmation (ACH), assign someone to argue the other side (Red Team), and run a Premortem before delivery. Structure is the countermeasure, because willpower is not.
8. Intelligence Writing That Is Decision-Focused and Defensible
A finding that a decision-maker cannot act on, or that collapses under cross-examination, was not worth collecting. Write for the reader who has thirty seconds and the adversary who has all day.
- Lead with BLUF (Bottom Line Up Front). State the answer, then support it. This is the U.S. Army writing standard (AR 25-50, 2020, para 1-38): main point first, active voice, understood in a single reading. Do not make a busy reader excavate your conclusion from paragraph nine.
- Build every assertion as a claim-evidence-confidence triad. The claim, the specific evidence and source behind it, and a calibrated confidence level. A claim with no evidence is an opinion; evidence with no confidence level makes the reader guess how much to trust it.
- Calibrate confidence with standardized language, and keep two things separate that readers constantly conflate: how likely something is, and how confident you are in that judgment. ODNI's ICD 203 (2023) provides a standardized likelihood ladder (almost no chance, very unlikely, unlikely, roughly even chance, likely, very likely, almost certain) and a separate confidence level (low, moderate, high) driven by the quality and corroboration of your sourcing. The case for fixing this vocabulary is old and well made: Sherman Kent's "Words of Estimative Probability" (1964) showed that phrases like "probable" hide wildly different odds in different readers' heads. Pick a scale and use it consistently.
- Keep the language neutral. Strip loaded adjectives and rhetorical certainty. Neutral prose is not timid; it is what survives an adversarial read.
- Source and annex everything. Findings reference evidence; evidence lives in an annex with captures, URLs, timestamps, and method. Ethically, be transparent about what you did not or could not verify. Naming your gaps builds credibility; hiding them destroys it the moment one surfaces.
Capture and Chain of Custody for OSINT Artifacts
Online evidence is perishable and mutable. A post can be edited or deleted, a page can change, an account can vanish, all between the moment you see something and the moment anyone asks you to prove it. If there is any chance your finding reaches a report, a regulator, or a courtroom, you preserve at the moment of collection, not later. This section is the one most field guides omit, and it is the one that decides whether your work is usable.
Preserve so that the artifact is authentic (it is what you say it is) and its provenance is traceable (where it came from and when you got it). The Berkeley Protocol (2022) is the leading international standard for exactly this, and ICD 203's sourcing discipline points the same direction.
A minimum capture routine:
- Screenshot with context: capture the full page including the URL bar, plus a scrolling or full-page capture, not a cropped fragment. A visible local system clock is a convenience, not proof, because it is trivially spoofable; the evidentiary weight comes from the independent archive and the collection log below, not from a clock in the corner of an image.
- Preserve the source, not just the picture: save the underlying HTML and, for video, the original file where lawful, so you hold more than a rendered image.
- Hash your captures: compute a cryptographic hash (for example SHA-256) of each saved file at collection time and record it. A matching hash later demonstrates the file has not changed since capture.
- Archive independently: push the live URL to a third-party archive such as the Internet Archive (archive.org) or archive.today so an immutable, timestamped copy exists outside your own machine.
- Log the metadata of collection itself: for every artifact, record the URL, the date and time of capture (with time zone), the tool or method used, and the collector. This log is your chain of custody.
For anything court-bound, automated contemporaneous capture is the standard, not an ad hoc manual routine. Purpose-built tools (Hunchly is the common example) silently log, hash, and timestamp every page you visit during a session and export a case-oriented report, which is far harder to attack than a folder of screenshots assembled after the fact. For high-stakes work, screen-record the acquisition session and record the tool and its version. Keep the manual method above as the floor, and treat automated logging as the goal.
Understand the limits of what preservation buys you. Authentication (showing what the item is) and integrity (showing it has not changed since collection) are the two preconditions you control by capturing well. They are necessary, not sufficient. Admissibility also turns on rules you do not control and that vary by jurisdiction: authentication standards (in U.S. federal practice, Federal Rules of Evidence 901 and 902), the hearsay problem when a post is offered for the truth of what it asserts, relevance, and best-evidence rules. In the EU and other GDPR-influenced systems, data-protection and civil-evidence rules can differ materially, and evidence gathered without a lawful basis can be excluded. The collector may also need to provide a declaration or affidavit and testify to authenticate the material. You are not making those calls, and this is not legal advice; you are making sure that when counsel does make them, your record supports the case instead of sinking it. The discipline costs minutes at collection and is effectively impossible to reconstruct afterward. Do it every time, or you have a story instead of evidence.
The Field Checklist
Run this end to end on any investigation that might be seen by someone other than you.
Before collection
- Stated the decision the product informs and what would change it
- Written PIRs and EEIs; separated known, assumed, unknown
- Set success criteria and stop conditions
- Confirmed legal and ethical boundaries for the sources in scope, and how you will collect without tipping the subject
During collection
- Working a collection plan mapping EEIs to source layers, method, and cadence
- Collecting passively and non-attributably unless a case decision says otherwise
- Logging every query, source, URL, and capture time as you go
- Capturing and hashing artifacts, and archiving live URLs at the moment of collection
- Tracing each key claim to a primary source; noting where the trail ends
During analysis
- Enumerated competing hypotheses, not just the favored one
- Ran a Key Assumptions Check and, where stakes warrant, ACH
- Graded sources and information (A-F / 1-6) and separated likelihood from confidence
- Checked media for both classic manipulation and synthetic generation
- Ran a Red Team pass or Premortem before committing
Before delivery
- BLUF stated; every claim carries evidence and calibrated confidence
- Language neutral; gaps and unverified items named explicitly
- Evidence annexed with URLs, timestamps, hashes, and method
- A second analyst could reproduce the work from your log
Bottom Line
- Frame the question before you touch a tool. No decision, no boundary, no collection.
- Plan collection in layers with a stop condition, and collect without burning the operation or breaking the law. "Collect everything" is a failure mode, not a strategy.
- Repetition is not corroboration. Trace claims to primary sources and grade them consistently.
- Reason by disconfirmation. Enumerate rival hypotheses and hunt for what breaks them, not what fits.
- Use a few structured techniques as fast habits to check your fast thinking, before you are committed.
- Geolocate and chronolocate by layered, falsifiable evidence, and treat metadata as a lead, not proof.
- Assume some findings are planted, treat synthetic media as a first-order threat, and instrument against your own biases with structure, not willpower.
- Write BLUF, with claim-evidence-confidence triads and calibrated language.
- Capture, hash, and archive at the moment of collection. Evidence you did not preserve is a memory.
The tools will keep changing. The judgment is the durable asset, and it is what decides whether the work holds up when it matters.
References
- Richards J. Heuer, Jr. Psychology of Intelligence Analysis. Center for the Study of Intelligence, Central Intelligence Agency, 1999. https://www.cia.gov/resources/csi/books-monographs/psychology-of-intelligence-analysis-2/
- Center for the Study of Intelligence, Central Intelligence Agency. A Tradecraft Primer: Structured Analytic Techniques for Improving Intelligence Analysis. 2009. https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf
- Randolph H. Pherson and Richards J. Heuer, Jr. Structured Analytic Techniques for Intelligence Analysis, 3rd ed. CQ Press (SAGE), 2019. https://us.sagepub.com/en-us/nam/structured-analytic-techniques-for-intelligence-analysis/book255432
- Office of the Director of National Intelligence. Intelligence Community Directive (ICD) 203: Analytic Standards. 2023. https://www.dni.gov/files/documents/ICD/ICD-203.pdf
- Sherman Kent. "Words of Estimative Probability." Studies in Intelligence, Vol. 8, No. 4, Central Intelligence Agency, 1964. https://www.cia.gov/resources/csi/studies-in-intelligence/archives/vol-8-no-4/words-of-estimative-probability/
- UN Office of the High Commissioner for Human Rights and Human Rights Center, UC Berkeley School of Law. Berkeley Protocol on Digital Open Source Investigations. United Nations, 2022. https://www.ohchr.org/en/publications/policy-and-methodological-publications/berkeley-protocol-digital-open-source
- Bellingcat. Bellingcat's Online Investigation Toolkit. 2024. https://bellingcat.gitbook.io/toolkit
- Eliot Higgins (Bellingcat). "A Beginner's Guide to Geolocating Videos." 2014. https://www.bellingcat.com/resources/2014/07/09/a-beginners-guide-to-geolocation/
- Bellingcat. "Searching the Earth: Essential Geolocation Tools for Verification." 2015. https://www.bellingcat.com/resources/how-tos/2015/07/25/searching-the-earth-essential-geolocation-tools-for-verification/
- Michael Bazzell and Jason Edison. OSINT Techniques: Resources for Uncovering Online Information, 11th ed. IntelTechniques.com, 2024. https://inteltechniques.com/books.html
- Claire Wardle and Hossein Derakhshan. Information Disorder: Toward an Interdisciplinary Framework for Research and Policymaking. Council of Europe (DGI(2017)09), 2017. https://rm.coe.int/information-disorder-report-version-august-2018/16808c9c77
- Claire Wardle. "Fake news. It's complicated." First Draft, 2017. https://firstdraftnews.org/articles/fake-news-complicated/
- Daniel Kahneman. Thinking, Fast and Slow. Farrar, Straus and Giroux, 2011. ISBN 9780374275631.
- Cherilyn Ireton and Julie Posetti (eds.). Journalism, "Fake News" & Disinformation: Handbook for Journalism Education and Training. UNESCO, 2018. https://www.unesco.org/sites/default/files/journalism_fake_news_disinformation_print_friendly_0.pdf
- Headquarters, Department of the Army. FM 2-22.3, Human Intelligence Collector Operations, Appendix B: Source and Information Reliability Matrix. 2006. https://irp.fas.org/doddir/army/fm2-22-3.pdf
- Headquarters, Department of the Army. Army Regulation 25-50, Preparing and Managing Correspondence. 2020. https://armypubs.army.mil/epubs/DR_pubs/DR_a/ARN42124-AR_25-50-007-WEB-13.pdf
Go From Reading About Defensible OSINT to Being Able to Prove It
Everything above is the what. Turning it into a repeatable practice, one that holds up in a report, a declaration, a regulatory filing, or a courtroom, is the how, and that is exactly what the Certified OSINT Investigator, Court-Ready Practitioner (COI-CRP) course was built to teach.
COI-CRP is a self-paced online program that connects every search, every capture, every pivot, and every conclusion back to admissibility and cross-examination:
- 10 modules, 80 lessons, 8 downloadable templates, 10 module quizzes, and a 100-question final exam (75% to pass, unlimited free retakes with a 24-hour cooldown).
- Covers the full arc of this field guide and more: mission framing and investigation discipline, the legal frame for OSINT (Fourth Amendment, CFAA and the public-interface rule, GDPR, cross-border collection and MLAT, lawful use of breach data), operational security and identity resolution, social media intelligence, image and geolocation analysis, dark web and cryptocurrency tracing, AI-assisted OSINT with a hallucination-control discipline, chain of custody and hashing for every artifact, court-ready reporting, and Daubert, Frye, and FRE 702, ending in a mock cross-examination on every technique in the course.
- Built and taught by Eric Waldrep, MCFE: 27 years in law enforcement, 19+ years in active digital forensics, testimony in federal and state courts, selected by the U.S. State Department's Antiterrorism Assistance program as a Cyber Mentor to allied-nation investigators.
Tuition is $2,497. Government purchase orders and net-30 invoicing are accepted, and agency licensing is available at 10, 25, and unlimited seats for procurement and grant cycles.
Enroll or view the full syllabus: thewaldrepcompany.com/courses/coi-crp
Not ready to enroll? Download the full course syllabus as a free PDF from the page above. For agency or PO-based enrollment, call (251) 216-1164.
The COI-CRP program is professional education, not legal advice, and does not create an attorney-client or expert engagement. Tool references are conceptual and drawn from publicly available documentation.
Take it further
This guide is the method. The Certified OSINT Investigator (COI-CRP) course is the practice: 10 modules and 80 lessons that work every one of these practices against realistic taskings, with a 100-question final exam and a verifiable credential at the end. It is self-paced, and agencies get 25% off five or more seats.
For attorneys: if an open-source report has already landed in your matter, the same eight practices are the review standard. An Opposing Expert Report Review ($2,750 flat) applies them to the other side's work before deposition.
Take the field guide with you
The PDF edition has the eight practices, the capture and chain-of-custody section, and the field checklist in a print-friendly layout. Enter your email and the download link appears here; a copy also goes to your inbox.