← All Posts Training · Offensive OSINT

Offensive OSINT Course Launch

Seeing Foreign Ecosystems Through Different Lens

Real red-team tradecraft applied to open sources — what the Offensive OSINT program teaches, what it found, and how to get in.

July 20, 2026 |

Here's an uncomfortable question: how much intelligence have you walked straight past in your career — not because it was hidden, but because no one taught you it was there?

In August 2026 we're opening the Offensive OSINT Training Program: real red-team and penetration-testing tradecraft, applied to intelligence practitioners and OSINT analysts. It's taught through China, because China is the hardest ecosystem there is to work — but the frameworks and methods apply to any ecosystem, anywhere.

Zero hacking. A completely different way of seeing.

To be clear about what this is: we will not teach you to find vulnerabilities in your target's systems, and not how to break in. This is about gently opening the curtain to see what is already there, available for you to see, that most don't — for intelligence and OSINT purposes.

Why this course exists

In 15+ years across this industry, we've watched the same pattern repeat: the frameworks taught to OSINT analysts train straightforward, linear thinking — step one, step two, collect, report. They don't teach creative thinking. They don't expand your horizons. They hand you a checklist and call it tradecraft.

Here's the uncomfortable part. Everyone uses the same tools, takes the same courses, and repeats the same methodologies — so everyone looks in the same places, finds the same things, and misses the same things. If your process is identical to everyone else's, your results will be too.

This is how 95% of real intelligence is missed — not locked away in some vault, but sitting in plain sight, in the bits and bytes of the data, where no standard framework ever thinks to look.

What that looks like in practice

In one of our recent investigations, we identified a poorly secured server tied to China's national state-owned media infrastructure. The server, connected to a state-owned broadcasting provider, was surfaced using open-source methods enhanced by offensive techniques.

The exposed configuration revealed Redis credentials and full system environment files. We identified ten separate servers across different regions, all containing valuable data. Among the findings were WeChat API tokens — which could allow someone to impersonate official media platforms — access to a cloud environment with full credentials, as well as TV broadcast scheduling metadata, including file upload and download access.

Live TV broadcasting infrastructure with read and write permissions
Credit: EPCYBER, July 2025 — live military TV broadcasting infrastructure with read/write permissions.
Exposed cameras surfaced during infrastructure mapping
Exposed cameras surfaced during infrastructure mapping.

These discoveries were not the result of basic scraping or keyword monitoring. They came from merging structured OSINT with an offensive-security mindset borrowed from red teaming and penetration testing — understanding how these systems were configured, how the data became visible in the first place, and what could be uncovered by thinking like an attacker while working strictly within OSINT investigative bounds.

What you'll learn to find

The examples below are redacted, but real. Each one is a category of skill you walk away with — the frameworks and methodology to find this yourself, on real targets, once the training's done.

Valuable data and internal access

You'll learn to surface data that was never meant to be public. Not by breaking in, but by understanding how these systems are built and configured — and where the misconfigurations hide that open the door to valuable intelligence, new leads, and the breakthroughs that move a real open-source investigation forward.

Internal data surfaced through a misconfiguration, redacted
Internal data reached through a misconfiguration. Redacted — EPCYBER.

Bypassing login portals

Some of the richest data sits behind portals that only look locked — registration walls, login screens, captchas. To most open-source practitioners they really are locked, and that's where the trail ends. Dig a layer deeper, learn what to look for, work through the frameworks we've developed in-house over the years, and the full records open up. No login attempts, nothing improper. The data was always there, waiting for someone who knew how to walk through a door already open.

Full records reached without a login attempt, redacted
Records behind a portal that only looked locked. No login attempts. Redacted — EPCYBER.

Worth noting: no +86 number, and none of the access-bypass methods our other China trainings teach directly. Here you'll often reach the same closed data through the offensive angle alone — a different way in, and one most analysts never think to try.

Connecting cross-platform intelligence

This is the layer most OSINT never reaches. Beyond collecting data is the harder skill: connecting it. You'll learn to link accounts to people, people to companies, and scattered fragments across platforms into networks, relationships, and complete profiles — cross-platform attribution that turns a handful of signals into a name, and a name into the whole story behind it.

Cross-platform attribution in progress — scattered fragments resolving into one profile. Redacted — EPCYBER.

The curriculum: five modules

  • The Offensive-OSINT Mindset — every analyst is trained inside the same box. This module rewires that, so entire layers of an ecosystem light up that conventional OSINT never knew to look for, while staying within the right boundaries.
  • Finding Leaks & Exposures — how genuinely new leaked data actually surfaces, or where it's waiting for you to find it. Identify and analyze leaked data, pivot from misconfigured and exposed data, and understand how it became visible — something no OSINT framework will ever teach.
  • Tracing Files Across Unfamiliar Platforms — finding a file is one thing; tracing it is another. Unique sources, places, and spaces that no Western tool or framework finds, from domestic environments to overlooked endpoints.
  • From One File to Full Exposure — the core skill. Search, pivot, and uncover the hidden layers beneath a single point of data, with the logic behind every decision, so you can reproduce the reasoning rather than just the result.
  • Real Case Studies & Hands-On Exercises — everything is practiced on real case studies and live investigations, then run yourself in hands-on labs and field exercises, until seeing what others miss becomes reflex rather than theory.
A case study walked through end to end, as taught in Module 5. Redacted — EPCYBER.

Who it's for

First and foremost, this is for OSINT analysts. But at the end of the day it is still OSINT — approached from a very different angle — so the same methods apply to almost anyone who works with intelligence: government, defense, and corporate teams included.

Penetration testers are welcome too. If you already think offensively and want to expand that mindset into offensive OSINT, this opens a whole new surface to work.

And you don't need to be an expert to start. Years of penetration-testing experience aren't required — a basic understanding of the concepts is plenty, and some existing OSINT knowledge is nice to have but not necessary. This is genuinely for anyone ready to see more than the average analyst.

100% manual tradecraft

Everything above was found manually. No scanners, no automation, none of the off-the-shelf tooling that defines most offensive-security work. What others reach for a tool to do, we do with attention — a trained way of looking that no software can replicate. It's impossible to automate, which is exactly what makes it so valuable, and exactly why almost no one else can teach it.

Redacted finding from a live investigation Redacted finding from a live investigation Redacted finding from a live investigation
All found by hand, on real targets. Redacted — EPCYBER.

Access and eligibility

The program opens in August 2026, with an early-bird fee of €4,500. It runs with 80 days of access and support through the EPCYBER Training Platform, and includes hands-on labs, field exercises, two live lessons, an exam, and a certificate.

It is released only through corporate email verification, and is not sold to the open public. Before purchasing, email us from your corporate address — we briefly confirm your organization and role, and most verifications are completed within one business day. No documentation is required beyond your corporate email and a short professional context.

  • If you're with a Fortune 500 company, government agency, federal body, military, or intelligence organization, you can purchase directly and follow up afterward using your corporate email.
  • If you're unsure whether your organization qualifies, email us first so we can confirm eligibility upfront — the eligibility criteria are published in full.
  • For organizations, other payment options are available depending on requirement.

By purchasing, you acknowledge that you have read and agree to the course terms — including the access model, account policy, content policy, and monitoring policy.

Full programme details, curriculum, and enrolment →

The mindset is what carries. It's taught through China because China is the hardest place to practise it — but once you stop looking through the same narrow frame as everyone else, it works on any ecosystem, anywhere.

What to take away

  • Everyone using the same tools and the same frameworks looks in the same places — so if your process matches everyone else's, your results will too.
  • One investigation surfaced ten poorly secured servers tied to Chinese state-owned media: Redis credentials, environment files, WeChat API tokens and broadcast scheduling access — found manually, with no scanners or automation.
  • It opens August 2026 at an early-bird fee of €4,500, through corporate email verification only, and no prior penetration-testing experience is required.
Written by

The EPCYBER Intelligence Team

We run China-focused OSINT and dark-web investigations for government, defense, and corporate clients — and teach the same tradecraft through the EPCYBER Training Platform. Everything we publish comes out of real casework.

See how we work →
Subscribe

New investigations, in your inbox

Redacted findings, China OSINT methods, and dark-web intelligence — straight from real casework. No spam, unsubscribe anytime.

Keep reading

RELATED INVESTIGATIONS

← PreviousThreat Intelligence Platforms Suck. Here's Why

GOT A QUESTION ABOUT OUR TRAININGS?

Not sure which program fits, or whether we cover what you need? Just ask.

We're happy to tell you whether a specific platform, or focus area is included in a given course — and if it's not, whether we can build it in.

Reach out to sales@epcyber.com about:

  • Whether we cover a specific platform (Weibo, Xiaohongshu, Douyin, CSDN, or anything not listed)
  • A particular focus area you need
  • Group rates, team enrollment, and custom corporate bundles
  • Eligibility — if you're unsure whether your organization qualifies
  • Payment options — wire transfer and other methods for organizations
  • Custom or tailored training built around your team's mission
  • Whatever you're trying to accomplish, tell us where you're headed and we'll point you to the right program.
All contact routes

WHY EPCYBER FOR CHINA OSINT?

Read Post