This website uses cookies

Read our Privacy policy and Terms of use for more information.

AI-assisted content
 
Block
CZ2 · Course Zero
 
 
Topic
Self-OSINT · Digital Footprint Audit
 
 
Tools
Dork Builder · HIBP · 192.com · Wayback Machine · Google Takeout · Optery
 
 
Difficulty
Foundational
 
Prerequisites

Clean research browser: Firefox and Mullvad for OSINT.

See also: OPSEC for investigators: eight-step security baseline and secure source communications for the standing controls this audit is checked against.

01

Your subject will search for you before you publish

The subject of every investigation will eventually look up the byline. So will their lawyers, their PR firm, and anyone they pay to respond. This tutorial inverts the standard OSINT workflow: you are the target. The exercise maps what is already out before the work begins.

The controls established in CZ1 (browser isolation, VPN, persona hygiene) protect the work you do from this point forward. They cannot retract data already in circulation. Before those controls have any value, you need to know what is already out: the addresses, handles, associations, breach records and archived pages an adversary will find in the first twenty minutes of looking.

Learning outcomes

By the end of this tutorial you will be able to:

  • Map your own digital footprint across search engines, data brokers and breach databases using the same tools applied to investigation subjects

  • Classify each exposure as recoverable or unrecoverable and prioritise remediation accordingly

  • Produce an adversary summary and a remediation list to documented, auditable standard

  • Run a six-month follow-up audit against your own baseline to detect new exposures

Subscribe to keep reading

This content is free, but you must be subscribed to Signal & Shadow to continue reading.

I consent to receive newsletters via email. Terms of use and Privacy policy.

Already a subscriber?Sign in.Not now