A complete intelligence report in BLUF format from a training scenario — expand each finding to see how evidence, interpretation, and confidence fit together.
This page is a finished, end-to-end OSINT intelligence report in BLUF (Bottom Line Up Front) format. It is the capstone deliverable this manual trains toward, and the full-length counterpart of Chapter 17, which presents the same case in condensed form. It demonstrates how a professional report reads when the audience is a decision-maker without a technical background. The report leads with the conclusion, followed by the claims under test, the findings with a confidence level each, the reasoning that ties them together, and an OPSEC note recording how the collection was done.
Every person, company, and platform named in this report is a fictional training entity. "Daan Verhoeven", "Halcyon Risk Advisors", "Nordhaven Security BV", "ProFolio", and "Pling" do not exist, and any similarity to real persons or organizations is accidental. The scenario is pre-hire due diligence. Halcyon Risk Advisors is about to extend an offer for the role of Threat Intelligence Analyst to its final candidate, Daan Verhoeven, and internal policy requires an open-source review before the offer goes out. The analyst is handed four starting points only: the application email (an .eml file), the attached profile photo, the username dverhoeven_sec, and the candidate's ProFolio profile, and must turn them into a documented conclusion.
The investigation is organized around explicit, testable claims rather than undirected browsing. Each claim is logged together with its source, so the reader can see at a glance which claims held up, which collapsed, and which were left open.
| Claim | Source |
|---|---|
| The name is Daan Verhoeven | Application / CV |
| Based in Amsterdam, Netherlands | Application / CV / Profile |
| 10+ years of security experience | CV / Application email |
| Employment at Nordhaven Security BV | CV / Cover letter |
Portfolios and profiles (dverhoeven_sec / daanverhoeven) | Application email / Online search |
Each finding stands on its own: the evidence, the interpretation, and a confidence level with the reasoning behind it. Expand a finding to read it.
Evidence: an email sent from daan.verhoeven.sec@protonmail.com, asserting more than a decade of enterprise defense work and pointing to dverhoeven-sec.example.
What it indicates: a privacy-hardened mailbox chosen deliberately, with a .sec suffix appended to signal a security affiliation.
Confidence justification (Medium): ProtonMail and similar providers are a routine choice inside the security community, so the mailbox proves nothing by itself, but it verifies nothing either.
Evidence: a headshot supplied with the application and reused on the ProFolio profile.
What it indicates: a polished, generic studio-style portrait (a stock or AI-generated image), identical across the persona's freshly registered profiles and absent from any public index before 2025.
Confidence justification (Medium): the image carries no traceable public history, yet it is at least uniform across the persona's new accounts.
Evidence: an automated username-enumeration sweep (Sherlock/Maigret/WhatsMyName type) for dverhoeven_sec and close variants across 340 websites: 7 accounts located.
What it indicates:
daan-verhoeven-sec, GitHub dverhoeven-sec, Pling @dverhoeven_sec, portfolio dverhoeven-sec.example) appeared within a few weeks of each other, September–October 2025.Confidence justification (High): the tight 2025 registration cluster flatly contradicts a claimed decade of security employment and shows the persona free-riding on an unrelated person's naming history.
Evidence: the ProFolio profile (daan-verhoeven-sec).
What it indicates: the profile was registered in October 2025 and lists a handful of connections (6) and nothing else: no recommendations, no endorsements, no education entries, no text under any role. The GitHub account (dverhoeven-sec) contains zero public repositories.
Confidence justification (High): nobody spends ten years as a senior analyst and leaves behind an empty repository list plus a professional profile that is months old and essentially blank.
Evidence: the CV line "Security Contractor at Nordhaven Security BV (2019–present)".
What it indicates: no public record corroborates it: there are no verifiable records, public writeups, or employee cross-references tying the subject to Nordhaven Security BV or to any of the claimed years of threat-hunting work.
Confidence justification (High): before September 2025 there is no operational residue of any kind: no blog posts, no commits, no conference appearances, no published threat research.
Independent agreement: the ProFolio registration date (October 2025), the GitHub sign-up (September 2025), the Pling account date (October 2025), and the portfolio domain's registration each come from a different system, yet all four land inside the same two-month window. That convergence is exactly what makes the correlation strong: separate platforms, one coordinated build-out.
Innocent explanation versus deception: in isolation, a thin professional-network profile could belong to a genuinely private person. That reading collapses once it is combined with an applicant who is actively pursuing corporate roles, circulates a public portfolio link and a ProtonMail address, and has never committed a line of code. The report spells this weighing out: it does not merely list what was found, it records why the charitable reading was set aside.
Name correlation, the false positive: the daanverhoeven accounts on Behance, Dribbble, and Instagram are a textbook OSINT false positive. They confirm that a real Daan Verhoeven lives in Antwerp and works in UI design (a namesake, not the subject) whose established history the candidate appears to lean on, inadvertently or deliberately, to acquire instant seniority. An analyst who merged the two men into one would hand a fraudster a favorable report.
Justification: the candidate's whole online presence was stood up in September–October 2025. The asserted 10+ years of security experience is contradicted on every axis: no historical footprint of any kind, no GitHub activity, an unverifiable self-employment claim at Nordhaven Security BV, and a social footprint only months old.
Recommendation to HR: decline the candidate. Do not move forward with an offer. If HR needs legal certainty before issuing the formal rejection, request formal background screening and government identity documents: an OSINT report supports a decision, it is not legal proof.
.eml and the headshot image) were examined inside an isolated virtual machine, and no embedded link was ever opened on a primary corporate machine.The BLUF is written last and placed first. It cannot be drafted before the analysis is complete, because the conclusion does not exist until the findings converge. Yet it is the first thing the reader sees, because no decision-maker should ever have to hunt to the end of a report to discover its outcome.
Every finding is self-contained: evidence, interpretation, and a confidence level with the reasoning written out. Remove any single finding and the rest still stand. The verdict rests deliberately on that convergence rather than on any one item. An unsupported "High" label makes a report useless. The written justification states both why the evidence points the way it does and which alternative readings remain open. One matched item is coincidence, not confirmation. Score High only when independent sources agree.
For every suspicious finding, the report weighs the innocent reading and records why it was rejected: a sparse profile on its own proves nothing. The Antwerp namesake is the sharpest lesson here: the decade-old Behance, Instagram, and Dribbble accounts under daanverhoeven belong to a real, uninvolved designer. Folding them into the candidate's history would have manufactured a false ten-year career, produced a report favorable to a fraudster, and wronged an uninvolved third party. Verifying subject matter, location, and timeline continuity before attributing any account to the subject is mandatory, not optional.