View on GitHub

SANS ICS Summit 2025

OSINT Workshop ~ Using the power of OSINT to protect critical infrastructure and operational environments.

OSINT Workshop

Agenda

Note Taking

For actual OSINT assessment you will need to keep detailed notes. There are many techniques and this will vary by team and client. Good note taking applications include CherryTree (installed by default in Kali), Obsidian, Microsoft OneNote, and Evernote. Some OSINT tools may provide note taking tools in addition to being able to generate reports.

CherryTree Note Taking

The CherryTree is installed by default in Kali. It can also be easily installed in Windows. This note taking tool provides an excellent interface for collecting information during an assessment. Notes can be in plain text format which is excellent for cut and pasting information from terminals and websites. Notes can also be in Rich Text Format which allows for formatted data and images / screenshots.

The power of CherryTree, in the author’s opinion, is in the hierarchial or tree-based note representation using nodes. The following bullet list is an example of tree-based nodes that could be used during this workshop.

Reports

Good assessment reporting includes multiple sections. The following are a basic breakdown of most cybersecurity assessment deliverables. This can be modified depending on scope, client defined deliverables, automated tool reports, and unique information gathering techniques.

Return to Agenda

Agenda