Challenge Category

OSINT CTF Challenges

Open-source intel gathering from public sources.

Round duration

12 hours

Format

Jeopardy-style CTF

Team size

1–3 members

OSINT challenges are built from information that is genuinely public — a photo with its metadata intact, a username reused across platforms, a screenshot geolocatable from signage and shadows. Nothing is hidden behind a vulnerability; the entire difficulty is in knowing where to look and how to connect what you find.

This is the category with the lowest entry barrier and the highest ratio of thinking to tooling. A clever OSINT solve often takes two minutes of insight and zero lines of code. The failure mode is brute-forcing tool after tool when the answer was sitting in one overlooked field.

It is also the most transferable skill on the board. The same workflow — narrow the frame, enumerate systematically, verify before you conclude — is what professional intelligence work looks like.

What you’ll actually face

Challenge types modelled on the work real security teams do, weighted toward the mid and upper difficulty bands.

Metadata extraction

EXIF data from images, document properties, PDF metadata and camera serial numbers that identify a device, a location or a photographer.

Geolocation

Fixing a position from visual evidence: signage, road markings, terrain, sun position, weather, licence plates and architectural style.

Username & account hunting

Tracing one handle across platforms using archived pages, cached profiles and search operators, then confirming an identity from what they have in common.

Archived web content

Recovering pages from the Wayback Machine to expose information the live site has since removed, or to date when something was published.

Public record research

Company registries, professional listings, public tender records and academic papers used to confirm or refute a claimed affiliation.

Data aggregation

Several weak public sources combining into one strong conclusion — a common correlation a visual check alone would not have caught.

Tools you’ll reach for

  • ExifTool
  • Google advanced search operators
  • Wayback Machine
  • Sherlock / Maigret
  • WHOIS
  • Shodan / Censys
  • Reverse image search
  • SpiderFoot

How to prepare

None of this is required to enter — it is simply the shortest path to scoring points in this discipline.

  1. Memorise the useful Google operators: `site:`, `filetype:`, `inurl:`, `intitle:`, quotes for exact phrases, and `-` to exclude.

  2. Learn to read ExifTool output properly — GPS coordinates, timestamps and serial numbers solve more OSINT challenges than any other single tool.

  3. Practise geolocation on a blank map. Being able to say "this is eastern UP in October, not the coast" is a real, trainable skill.

  4. Get comfortable with the Wayback Machine, including its CDX API for enumerating every snapshot of a URL.

  5. Verify before you conclude. Most wrong OSINT answers come from an assumption that was never checked.

Quick facts

Everything about Ghost Protocol CTF 2.0 at a glance.

Online qualifier
17 October 2026 · 12 hours · remote
Grand finale
24 October 2026 · 12 hours · on-ground
Format
Jeopardy-style CTF
Team size
1–3 members (solo entry allowed)
Registration fee
Free per team
Prize pool
Up to ₹51,000
Challenge categories
10 disciplines
Eligibility
Any student in an undergraduate or postgraduate programme, any stream
Venue
NIET Greater Noida
Organised by
Cyber Invaders · NIET Greater Noida

Ready to prove it on the scoreboard?

OSINT is one of 10 disciplines in Ghost Protocol CTF 2.0. Entry is free and teams of 1–3 are welcome.