OSINT newsletter
SANS Internet Storm Center
SANS ISC · Daily
Handler diaries and Stormcast at the edge of malware, internet observation, and threat awareness — OSINT-adjacent situational awareness for CTI-minded readers, not a people-search letter.
Who it’s for
- SOC and CTI analysts
- Defenders who want daily internet-threat context
What you get
- Near-daily handler diaries
- Podcast and archives — free, volunteer-handler driven
How to use it
- 01
Skim for relevance to your stack
Most days will not map to your case. When they do, the diary is gold.
Strengths
- High cadence
- Credible threat observation culture
Watch out for
- Weak fit if you only want social or people OSINT
Related in the directory
- BookRead
Intelligence-Driven Incident Response
An O’Reilly text on how CTI and IR teams use intelligence — including open sources — to prioritise detection and response. It is not a people-search OSINT manual; it is the framing that keeps enrichment from becoming hobby collecting.
- GuideRead
OSINT for cybersecurity teams
From alert enrichment to infrastructure exposure — using open and commercial sources without pretending they replace a SIEM, EDR, or TIP.
- NewsletterRead
Krebs on Security
Independent cybercrime, breach, and fraud reporting. Not a pure OSINT methods letter — essential source material investigators quote constantly.
FAQ
Questions, answered
What is SANS Internet Storm Center?
Handler diaries and Stormcast at the edge of malware, internet observation, and threat awareness — OSINT-adjacent situational awareness for CTI-minded readers, not a people-search letter.
Who is this newsletter for?
SOC and CTI analysts; Defenders who want daily internet-threat context. You’ll get: Near-daily handler diaries; Podcast and archives — free, volunteer-handler driven.