Week 07 · lesson

OSINT: What Can Public Information Reveal?

Open-source intelligence, or OSINT, is information collected from publicly available sources and analyzed to answer a question.

Public does not mean harmless. A collection of ordinary details can become powerful when combined.

This lesson uses a teacher-provided fictional profile. Do not investigate classmates, teachers, family members, school staff, or random real people.

The Tony Stark exercise

The Garden State Cyber curriculum uses a Tony Stark-style OSINT scenario because a fictional public figure lets students practice information analysis without targeting a real person.

Your teacher provides a synthetic profile containing items such as:

  • public company biography
  • fictional conference schedule
  • social-media-style posts
  • photos with visible background details
  • public event announcements
  • fictional domain or organization information

Your task is not to prove how clever you are at finding private information.

Your task is to answer:

How can separate public clues be combined into a security-relevant picture?

Collection is not analysis

Suppose the profile shows:

  • a public post says the subject is traveling Friday
  • a conference page lists the hotel hosting the event
  • a photo shows a company badge style
  • an event schedule identifies the keynote time

Each item may be normal public information.

Combined, they can make a social-engineering pretext more convincing.

OSINT analysis connects evidence to a question.

Build an intelligence question

Do not begin with "find everything."

Use a focused question such as:

Which public details could help someone impersonate event staff to the fictional subject?

Or:

Which public details reveal timing, location, or organizational relationships that could strengthen a phishing pretext?

A focused question keeps the exercise bounded.

Source table

Create this table:

Source itemPublic detailSecurity relevanceConfidenceWhat it does not prove
Conference pageKeynote at 10:00Timing could strengthen event-related pretextHighSubject's exact movements before or after

Use at least eight items from the supplied fictional dataset.

Confidence matters

Use simple confidence labels:

  • high: directly stated in the supplied source
  • medium: supported by multiple clues but not explicit
  • low: plausible inference with limited support

Do not present a low-confidence inference as a fact.

Metadata and visual clues

Images can reveal information without containing secret text.

A fictional photo might show:

  • badge color
  • room number
  • laptop stickers
  • whiteboard content
  • Wi-Fi network name
  • calendar information
  • building signage

Your task is to identify what is visible and explain the possible risk.

Do not attempt to extract hidden data from real people's photos in this exercise.

Correlation lab

The teacher gives you four fictional sources:

Source A

A company post announces attendance at the Metro Tech Expo.

Source B

An expo schedule lists a keynote at 10:00.

Source C

A photo caption says, "Setting up tonight for tomorrow's keynote."

Source D

A fictional support email template uses the phrase "Expo Services Desk."

Build a correlation graph showing how the sources could support a fake event-support pretext.

Then mark which parts are:

  • directly observed
  • inferred
  • unknown

OSINT has an ethical boundary

The fact that information is public does not mean every collection activity is appropriate for a classroom.

This course does not authorize:

  • profiling classmates
  • searching private individuals without consent
  • compiling home addresses
  • tracking real-time locations
  • contacting subjects
  • testing passwords or accounts
  • attempting access based on discovered information

Use only the fictional or teacher-approved dataset.

Minimize unnecessary collection

A good analyst collects what is needed for the question.

If the task is to evaluate phishing risk, you do not need unrelated personal details.

Use the principle:

Collect for a purpose, not because the information is reachable.

Build a fictional OSINT risk brief

Your brief must contain:

Intelligence question

One focused question.

Key findings

Three to five findings supported by the supplied sources.

Correlation

Explain how separate public details become more useful when combined.

Confidence

Rate each finding high, medium, or low.

Risk

Explain how the information could support social engineering or phishing.

Mitigation

Recommend practical changes such as:

  • reduce unnecessary schedule detail
  • review photos before posting
  • separate public contact channels from privileged workflows
  • teach staff how official support verifies identity
  • avoid exposing internal tools or badges unnecessarily

Limits

State what the dataset does not establish.

Evidence for Lesson 2

Submit:

  • eight-item source table
  • correlation graph
  • fictional OSINT risk brief

Finish with:

The most important OSINT lesson is not "public information is dangerous." It is ________.

Good OSINT analysis is focused, evidence-based, and bounded. It explains what public information means without turning curiosity into surveillance.