OSINT CTF Challenges
Open-source intel gathering from public sources.
Round duration
12 hours
Format
Jeopardy-style CTF
Team size
1–3 members
OSINT challenges are built from information that is genuinely public — a photo with its metadata intact, a username reused across platforms, a screenshot geolocatable from signage and shadows. Nothing is hidden behind a vulnerability; the entire difficulty is in knowing where to look and how to connect what you find.
This is the category with the lowest entry barrier and the highest ratio of thinking to tooling. A clever OSINT solve often takes two minutes of insight and zero lines of code. The failure mode is brute-forcing tool after tool when the answer was sitting in one overlooked field.
It is also the most transferable skill on the board. The same workflow — narrow the frame, enumerate systematically, verify before you conclude — is what professional intelligence work looks like.
What you’ll actually face
Challenge types modelled on the work real security teams do, weighted toward the mid and upper difficulty bands.
Metadata extraction
EXIF data from images, document properties, PDF metadata and camera serial numbers that identify a device, a location or a photographer.
Geolocation
Fixing a position from visual evidence: signage, road markings, terrain, sun position, weather, licence plates and architectural style.
Username & account hunting
Tracing one handle across platforms using archived pages, cached profiles and search operators, then confirming an identity from what they have in common.
Archived web content
Recovering pages from the Wayback Machine to expose information the live site has since removed, or to date when something was published.
Public record research
Company registries, professional listings, public tender records and academic papers used to confirm or refute a claimed affiliation.
Data aggregation
Several weak public sources combining into one strong conclusion — a common correlation a visual check alone would not have caught.
Tools you’ll reach for
- ExifTool
- Google advanced search operators
- Wayback Machine
- Sherlock / Maigret
- WHOIS
- Shodan / Censys
- Reverse image search
- SpiderFoot
How to prepare
None of this is required to enter — it is simply the shortest path to scoring points in this discipline.
Memorise the useful Google operators: `site:`, `filetype:`, `inurl:`, `intitle:`, quotes for exact phrases, and `-` to exclude.
Learn to read ExifTool output properly — GPS coordinates, timestamps and serial numbers solve more OSINT challenges than any other single tool.
Practise geolocation on a blank map. Being able to say "this is eastern UP in October, not the coast" is a real, trainable skill.
Get comfortable with the Wayback Machine, including its CDX API for enumerating every snapshot of a URL.
Verify before you conclude. Most wrong OSINT answers come from an assumption that was never checked.
Quick facts
Everything about Ghost Protocol CTF 2.0 at a glance.
- Online qualifier
- 17 October 2026 · 12 hours · remote
- Grand finale
- 24 October 2026 · 12 hours · on-ground
- Format
- Jeopardy-style CTF
- Team size
- 1–3 members (solo entry allowed)
- Registration fee
- Free per team
- Prize pool
- Up to ₹51,000
- Challenge categories
- 10 disciplines
- Eligibility
- Any student in an undergraduate or postgraduate programme, any stream
- Venue
- NIET Greater Noida
- Organised by
- Cyber Invaders · NIET Greater Noida
Adjacent disciplines
Competitors in CTF teams tend to specialise — here is where the skills overlap.
Ready to prove it on the scoreboard?
OSINT is one of 10 disciplines in Ghost Protocol CTF 2.0. Entry is free and teams of 1–3 are welcome.