CZ1 · Course Zero |
OPSEC Foundations |
|||||||
Firefox · Mullvad · Proton VPN | ||||||||
Foundational | ||||||||
None. This is a foundational tutorial. See also: OPSEC for investigators: eight-step security baseline for the reference-card version of this workflow. |
|
OSINT investigations fail at the attribution stage more often than at the collection stage. A subject who identifies your research browser, your employer's IP range, or a handle you reused from a personal account can anticipate your queries or identify you to hostile third parties. This tutorial builds the minimum viable research environment: a VPN that does not log your traffic, browser profiles that hold no personal data, and research personas structurally separated from your real identity. These are not advanced tradecraft; they are the floor beneath everything else in the Methods curriculum.
Learning outcomes
By the end of this tutorial you will be able to:
Set up an isolated browser profile for investigative work that carries no personal data and leaves no persistent fingerprint
Configure a no-log VPN on your research device and verify that it is routing correctly before each session
Build a research persona that is structurally separated from your real identity and your publication's infrastructure
Apply the session-start checklist to confirm your environment is clean before opening any investigative tool
Identify the specific failure modes that collapse research environment isolation and the checks that catch them early

