OSINT Manual Worked Example
Worked Example

Sample OSINT Report

A complete intelligence report in BLUF format from a training scenario — expand each finding to see how evidence, interpretation, and confidence fit together.

This page is a finished, end-to-end OSINT intelligence report in BLUF (Bottom Line Up Front) format. It is the capstone deliverable this manual trains toward, and the full-length counterpart of Chapter 17, which presents the same case in condensed form. It demonstrates how a professional report reads when the audience is a decision-maker without a technical background. The report leads with the conclusion, followed by the claims under test, the findings with a confidence level each, the reasoning that ties them together, and an OPSEC note recording how the collection was done.

Every person, company, and platform named in this report is a fictional training entity. "Daan Verhoeven", "Halcyon Risk Advisors", "Nordhaven Security BV", "ProFolio", and "Pling" do not exist, and any similarity to real persons or organizations is accidental. The scenario is pre-hire due diligence. Halcyon Risk Advisors is about to extend an offer for the role of Threat Intelligence Analyst to its final candidate, Daan Verhoeven, and internal policy requires an open-source review before the offer goes out. The analyst is handed four starting points only: the application email (an .eml file), the attached profile photo, the username dverhoeven_sec, and the candidate's ProFolio profile, and must turn them into a documented conclusion.

Case Summary

BOTTOM LINE UP FRONT (BLUF): The professional persona the candidate presents does not hold up. His entire security-themed footprint was stood up within a single two-month window, September–October 2025, while the older accounts registered under the same name trace back to an unrelated graphic designer in Antwerp. Overall confidence: High.

Claims Being Tested

The investigation is organized around explicit, testable claims rather than undirected browsing. Each claim is logged together with its source, so the reader can see at a glance which claims held up, which collapsed, and which were left open.

ClaimSource
The name is Daan VerhoevenApplication / CV
Based in Amsterdam, NetherlandsApplication / CV / Profile
10+ years of security experienceCV / Application email
Employment at Nordhaven Security BVCV / Cover letter
Portfolios and profiles (dverhoeven_sec / daanverhoeven)Application email / Online search

Findings

Each finding stands on its own: the evidence, the interpretation, and a confidence level with the reasoning behind it. Expand a finding to read it.

Finding 1: The application email (Confidence: Medium)

Evidence: an email sent from daan.verhoeven.sec@protonmail.com, asserting more than a decade of enterprise defense work and pointing to dverhoeven-sec.example.

What it indicates: a privacy-hardened mailbox chosen deliberately, with a .sec suffix appended to signal a security affiliation.

Confidence justification (Medium): ProtonMail and similar providers are a routine choice inside the security community, so the mailbox proves nothing by itself, but it verifies nothing either.

Finding 2: The profile photo (Confidence: Medium)

Evidence: a headshot supplied with the application and reused on the ProFolio profile.

What it indicates: a polished, generic studio-style portrait (a stock or AI-generated image), identical across the persona's freshly registered profiles and absent from any public index before 2025.

Confidence justification (Medium): the image carries no traceable public history, yet it is at least uniform across the persona's new accounts.

Finding 3: Username / identity trail and account cluster (Confidence: High)

Evidence: an automated username-enumeration sweep (Sherlock/Maigret/WhatsMyName type) for dverhoeven_sec and close variants across 340 websites: 7 accounts located.

What it indicates:

Confidence justification (High): the tight 2025 registration cluster flatly contradicts a claimed decade of security employment and shows the persona free-riding on an unrelated person's naming history.

Finding 4: Social and professional footprint (Confidence: High)

Evidence: the ProFolio profile (daan-verhoeven-sec).

What it indicates: the profile was registered in October 2025 and lists a handful of connections (6) and nothing else: no recommendations, no endorsements, no education entries, no text under any role. The GitHub account (dverhoeven-sec) contains zero public repositories.

Confidence justification (High): nobody spends ten years as a senior analyst and leaves behind an empty repository list plus a professional profile that is months old and essentially blank.

Finding 5: Claims versus the public record (Confidence: High)

Evidence: the CV line "Security Contractor at Nordhaven Security BV (2019–present)".

What it indicates: no public record corroborates it: there are no verifiable records, public writeups, or employee cross-references tying the subject to Nordhaven Security BV or to any of the claimed years of threat-hunting work.

Confidence justification (High): before September 2025 there is no operational residue of any kind: no blog posts, no commits, no conference appearances, no published threat research.

Correlation & Analysis

Independent agreement: the ProFolio registration date (October 2025), the GitHub sign-up (September 2025), the Pling account date (October 2025), and the portfolio domain's registration each come from a different system, yet all four land inside the same two-month window. That convergence is exactly what makes the correlation strong: separate platforms, one coordinated build-out.

Innocent explanation versus deception: in isolation, a thin professional-network profile could belong to a genuinely private person. That reading collapses once it is combined with an applicant who is actively pursuing corporate roles, circulates a public portfolio link and a ProtonMail address, and has never committed a line of code. The report spells this weighing out: it does not merely list what was found, it records why the charitable reading was set aside.

Name correlation, the false positive: the daanverhoeven accounts on Behance, Dribbble, and Instagram are a textbook OSINT false positive. They confirm that a real Daan Verhoeven lives in Antwerp and works in UI design (a namesake, not the subject) whose established history the candidate appears to lean on, inadvertently or deliberately, to acquire instant seniority. An analyst who merged the two men into one would hand a fraudster a favorable report.

Verdict

Verdict: Constructed persona. The presented identity does not hold up. Overall confidence: High.

Justification: the candidate's whole online presence was stood up in September–October 2025. The asserted 10+ years of security experience is contradicted on every axis: no historical footprint of any kind, no GitHub activity, an unverifiable self-employment claim at Nordhaven Security BV, and a social footprint only months old.

Recommendation to HR: decline the candidate. Do not move forward with an offer. If HR needs legal certainty before issuing the formal rejection, request formal background screening and government identity documents: an OSINT report supports a decision, it is not legal proof.

OPSEC Note

Why This Structure Matters

The BLUF is written last and placed first. It cannot be drafted before the analysis is complete, because the conclusion does not exist until the findings converge. Yet it is the first thing the reader sees, because no decision-maker should ever have to hunt to the end of a report to discover its outcome.

Every finding is self-contained: evidence, interpretation, and a confidence level with the reasoning written out. Remove any single finding and the rest still stand. The verdict rests deliberately on that convergence rather than on any one item. An unsupported "High" label makes a report useless. The written justification states both why the evidence points the way it does and which alternative readings remain open. One matched item is coincidence, not confirmation. Score High only when independent sources agree.

For every suspicious finding, the report weighs the innocent reading and records why it was rejected: a sparse profile on its own proves nothing. The Antwerp namesake is the sharpest lesson here: the decade-old Behance, Instagram, and Dribbble accounts under daanverhoeven belong to a real, uninvolved designer. Folding them into the candidate's history would have manufactured a false ten-year career, produced a report favorable to a fraudster, and wronged an uninvolved third party. Verifying subject matter, location, and timeline continuity before attributing any account to the subject is mandatory, not optional.