Week 07 · lesson
OSINT: What Can Public Information Reveal?
Open-source intelligence, or OSINT, is information collected from publicly available sources and analyzed to answer a question.
Public does not mean harmless. A collection of ordinary details can become powerful when combined.
This lesson uses a teacher-provided fictional profile. Do not investigate classmates, teachers, family members, school staff, or random real people.
The Tony Stark exercise
The Garden State Cyber curriculum uses a Tony Stark-style OSINT scenario because a fictional public figure lets students practice information analysis without targeting a real person.
Your teacher provides a synthetic profile containing items such as:
- public company biography
- fictional conference schedule
- social-media-style posts
- photos with visible background details
- public event announcements
- fictional domain or organization information
Your task is not to prove how clever you are at finding private information.
Your task is to answer:
How can separate public clues be combined into a security-relevant picture?
Collection is not analysis
Suppose the profile shows:
- a public post says the subject is traveling Friday
- a conference page lists the hotel hosting the event
- a photo shows a company badge style
- an event schedule identifies the keynote time
Each item may be normal public information.
Combined, they can make a social-engineering pretext more convincing.
OSINT analysis connects evidence to a question.
Build an intelligence question
Do not begin with "find everything."
Use a focused question such as:
Which public details could help someone impersonate event staff to the fictional subject?
Or:
Which public details reveal timing, location, or organizational relationships that could strengthen a phishing pretext?
A focused question keeps the exercise bounded.
Source table
Create this table:
| Source item | Public detail | Security relevance | Confidence | What it does not prove |
|---|---|---|---|---|
| Conference page | Keynote at 10:00 | Timing could strengthen event-related pretext | High | Subject's exact movements before or after |
Use at least eight items from the supplied fictional dataset.
Confidence matters
Use simple confidence labels:
- high: directly stated in the supplied source
- medium: supported by multiple clues but not explicit
- low: plausible inference with limited support
Do not present a low-confidence inference as a fact.
Metadata and visual clues
Images can reveal information without containing secret text.
A fictional photo might show:
- badge color
- room number
- laptop stickers
- whiteboard content
- Wi-Fi network name
- calendar information
- building signage
Your task is to identify what is visible and explain the possible risk.
Do not attempt to extract hidden data from real people's photos in this exercise.
Correlation lab
The teacher gives you four fictional sources:
Source A
A company post announces attendance at the Metro Tech Expo.
Source B
An expo schedule lists a keynote at 10:00.
Source C
A photo caption says, "Setting up tonight for tomorrow's keynote."
Source D
A fictional support email template uses the phrase "Expo Services Desk."
Build a correlation graph showing how the sources could support a fake event-support pretext.
Then mark which parts are:
- directly observed
- inferred
- unknown
OSINT has an ethical boundary
The fact that information is public does not mean every collection activity is appropriate for a classroom.
This course does not authorize:
- profiling classmates
- searching private individuals without consent
- compiling home addresses
- tracking real-time locations
- contacting subjects
- testing passwords or accounts
- attempting access based on discovered information
Use only the fictional or teacher-approved dataset.
Minimize unnecessary collection
A good analyst collects what is needed for the question.
If the task is to evaluate phishing risk, you do not need unrelated personal details.
Use the principle:
Collect for a purpose, not because the information is reachable.
Build a fictional OSINT risk brief
Your brief must contain:
Intelligence question
One focused question.
Key findings
Three to five findings supported by the supplied sources.
Correlation
Explain how separate public details become more useful when combined.
Confidence
Rate each finding high, medium, or low.
Risk
Explain how the information could support social engineering or phishing.
Mitigation
Recommend practical changes such as:
- reduce unnecessary schedule detail
- review photos before posting
- separate public contact channels from privileged workflows
- teach staff how official support verifies identity
- avoid exposing internal tools or badges unnecessarily
Limits
State what the dataset does not establish.
Evidence for Lesson 2
Submit:
- eight-item source table
- correlation graph
- fictional OSINT risk brief
Finish with:
The most important OSINT lesson is not "public information is dangerous." It is ________.
Good OSINT analysis is focused, evidence-based, and bounded. It explains what public information means without turning curiosity into surveillance.