Scope and governance
Define purpose, authority, exclusions, data-minimisation rules and stop conditions before collection begins.
SEC-OSINT-201 · Cybersecurity & intelligence
Build a disciplined, lawful and evidence-led OSINT workflow: define the intelligence question, select passive sources, operate Recon-ng methodically, interpret Shodan observations and produce defensible findings.
Capability outcomes
Define purpose, authority, exclusions, data-minimisation rules and stop conditions before collection begins.
Use workspaces, marketplace metadata, modules, options and passive domain-to-host workflows without treating tool output as truth.
Design bounded queries and interpret time-stamped service observations without assuming current exposure, ownership or vulnerability.
Join search, DNS, certificate, repository and service-index evidence while preserving contradictions and uncertainty.
Collect the minimum data required and use defined escalation routes for secrets, personal data or out-of-scope material.
Separate observation, corroboration, inference, confidence, business relevance and recommended defensive action.
Learning map
Practical evidence
The learning journey includes a collection-plan lab, Recon-ng workspace setup, passive module-selection exercise, synthetic Shodan interpretation, evidence-correlation matrix, the LAB-OSINT-201 browser workbench and a capstone external attack-surface intelligence brief with an executive summary and technical appendix.