Learn the OSINT basics
28.09.2026
Cronos Defence Academy location (Hasselt)

OSINT FOUNDATION Masterclass

//

The OSINT Foundation Masterclass is an intensive 5-day training programme designed to build the mindset, discipline and methodology required for professional open-source intelligence investigations. Rather than focusing on tools alone, this masterclass teaches participants how to conduct defensible, reproducible and audit-proof investigations in high-trust environments.

Participants develop a strong foundation in information handling, operational security, intelligence methodology and structured research workflows, enabling them to produce reliable intelligence products that withstand scrutiny and support decision-making. The programme is built around the principle that successful OSINT starts with discipline and methodology before collection begins.

By the end of this training, participants will be able to:

[ Operationally focused: Developed by intelligence and investigation practitioners, not academics. ]

[ Methodology over tools: Learn a repeatable process that remains valuable regardless of changing tools and platforms. ]

[ Apply intelligence methodologies including the Intelligence Cycle, EEIs, NATO Admiralty scoring and intelligence reporting principles. ]

[ Execute reproducible OSINT workflows using different selectors such as domains, email addresses, usernames, phone numbers and images. ]

Full programme information

//

Programme Overview

Day 1 – Physical Security & Information Handling

  • Physical security fundamentals and access control
  • Information classification and Traffic Light Protocol (TLP)
  • Need-to-know and compartmentation principles
  • Secure communication and data handling
  • Chain-of-custody concepts
  • Practical handling and classification exercises

Outcome: Participants establish the operational discipline required for professional intelligence work.

Day 2 – OPSEC (Operational Security)

  • The 5-step OPSEC cycle
  • Threat modelling and risk management
  • The 3-layer camouflage model (connection, machine and identity)
  • Personal digital footprint analysis
  • Social media exposure and persona management
  • OPSEC countermeasures and resilience planning

Outcome: Participants create their own Personal OPSEC Action Plan and learn how to protect themselves, their clients and their investigations.

Day 3 – Understanding Information & Critical Interpretation

  • What OSINT is and what it is not
  • Surface web, deep web and dark web fundamentals
  • The 4 Vs of information verification
  • Disinformation, misinformation and malinformation
  • SIFT verification methodology
  • AI, deepfakes and synthetic content risks

Outcome: Participants learn to critically evaluate information and distinguish reliable intelligence from noise.

Day 4 – Intelligence Cycle & Methodology

  • The 5-phase Intelligence Cycle
  • EEIs (Essential Elements of Information)
  • Berkeley Protocol introduction
  • NATO Admiralty source assessment
  • BLUF (Bottom Line Up Front) reporting
  • Collaborative intelligence processes
  • Mini country-study exercise

Outcome: Participants learn to transform raw data into actionable intelligence products.

Day 5 – Structured Research Workflow

  • Selector-based investigation methodology
  • Domain and URL workflows
  • Email investigation workflows
  • Name and username research workflows
  • Telephone and reverse image investigations
  • Research logging and documentation discipline
  • End-to-end practical investigation exercise

Outcome: Participants build a complete, reproducible investigation workflow that can be directly applied in operational environments.

ADDED VALUE

arrow right cronos blue
Operationally focused: Developed by intelligence and investigation practitioners, not academics.
arrow right cronos blue
Methodology over tools: Learn a repeatable process that remains valuable regardless of changing tools and platforms.
arrow right cronos blue
Audit-proof investigations: Emphasis on documentation, traceability, evidence handling and reproducibility.
arrow right cronos blue
Immediate workplace applicability: Participants leave with templates, workflows and action plans they can use immediately.
arrow right cronos blue
Foundation for advanced OSINT: Provides the prerequisite knowledge and discipline required for advanced investigative, threat intelligence and intelligence analysis roles.

Our other trainings

We value your privacy! We use cookies to enhance your browsing experience and analyse our traffic. By clicking "Accept All", you consent to our use of cookies.