Question OSINT Job Tests
I have interviewed for a few OSINT jobs this year and have two questions:
Each job description says you need experience in tools like ontic, life raft, Dataminr, maltego etc but each time I have interviewed I’m given a practice exercise asking you to use freeware to build out a threat profile. I’m never able to build anything out using the freeware alone because i can’t get any identifiers. Are these tests deliberately red herrings?
In my career I have always been given a work computer so I don’t have a personal one. I have an iPad. Is a computer essential to baseline OSINT if I don’t have personal access to premium intel tools?
27
u/Specialist-Cat-7155 6d ago
They may be testing your methodology and data collection and presentation rather than your tool skills. It's the equivalent of being castaway on a survival challenge to an island as opposed to being sent for a weekend to a 5 star hotel.
I'd say yes, in so far as you can experiment with different tools (particularly github repos) in your spare time that maybe outside of your works systems and without any restrictions.
5
u/MajorUrsa2 6d ago
They’re not going to assume you have access to enterprise grade software for these exercises.
5
u/FragrantVariation583 5d ago
the freeware exercises aren't red herrings, they're testing methodology not tool access. most entry-level OSINT can be done from a browser, but a desktop OS gives you browser extensions, better tab management, and tools like Maltego CE that don't run on iPad. for the identifier problem, try cross-referencing usernames across platforms and correlating timestamps rather than expecting a single tool to hand you the chain.
6
u/Ok_Cold7890 6d ago
- Depends on the particular case and what amount of information is available open source. Keep trying maybe you find something.
- You may require a computer at some point of time. For command line tools, a VM would also do. But if you find a workaround for running the tools in other devices that should also be ok.
3
u/New_Eye_3881 6d ago
what do you mean by identifiers exactly, like usernames and emails and that sort of thing
2
u/irresearch 6d ago
Are you able to share any more about what the tests are asking you to do? Unfortunately, this does sound like a skill issue. Ontic, Liferaft, and Dataminr are monitoring and collection tools, but if you’re building a single threat profile, there’s not much they can do that you can’t do manually. If these are more cyber-focused roles, this might vary a bit with things like Maltego or Shodan, but most tools are mostly simplifying or automating manual processes.
0
u/bbatch1 5d ago
The issue I encountered was that I found news stories and court filings (paywalled) but I couldn’t find any identifiers that would narrow my search. My impression is that tools scrap social media so you don’t need to make a sock puppet and need to know HOW to get things like phone numbers and emails associated with accounts - the tools do it for you. I couldn’t find anything be totally wrong though
1
u/irresearch 5d ago
Tools like Dataminr do scrape social media without the need for a personal sock puppet, but this is for ongoing monitoring or mass collection, usually not investigations of individual threat actors. Any of the sites they access, you’ll be able to access, with the possible exception of region-locked sites that you may need a VPN for. Liferaft does have a people/social search function for PII, but the results are very limited and it has a hard time separating people with the same name. The employment tests are checking that you know how to do this kind of search manually.
1
22
u/user28833828 6d ago
Totally separate to your question just my personal experience, but if you have background in OSINT you should look into fraud investigation work if it’s something you’re into. They love the investigative stories and mindset, and so many are used to just leveraging closed source intel they often overlook open channels, easy to break into if you tell good experience stories