Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Strategic OSINT Analyst

GIAC Strategic OSINT Analyst (GSOA)

The GIAC Strategic OSINT Analyst (GSOA) certification validates advanced open-source intelligence skills, from automating investigations with Python to tracking threats across social platforms, darknet forums, blockchain activity, and disinformation networks. Designed for incident responders, DFIR analysts, penetration testers, and intelligence personnel, GSOA proves you can conduct sophisticated OSINT investigations at scale and deliver actionable intelligence.

Exam formatCyberLive: Hands-on performance-based testing
Duration180 minutes
DeliveryGIAC
Passing score66%
Free questions175

Content last reviewed 30 July 2026 · Up to date

The certification

What GIAC Strategic OSINT Analyst proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

2domains
5objectives
28concepts
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The GIAC Strategic OSINT Analyst (GSOA) certification validates a practitioner's expertise in advanced open-source intelligence (OSINT) skills. It goes beyond basic searching to cover the strategic application of OSINT in complex investigations, including automating data collection with Python, conducting Dark Web investigations, tracking public cryptocurrency transactions, and identifying disinformation campaigns.

GSOA certification holders are equipped to analyze data at scale, perform forensics on images, video, and audio, and carry out international and sector-specific OSINT. The certification is delivered through GIAC's CyberLive format, which uses performance-based challenges in realistic lab environments to validate real-world capability, ensuring certified professionals can apply their skills immediately in operational settings.

Who it’s for

The GSOA certification is designed for professionals who conduct or support open-source intelligence investigations as part of their role. This includes Cyber Incident Responders, Security and Digital Forensics (DFIR) Analysts, Penetration Testers and Social Engineers, Law Enforcement Intelligence Personnel, Private Investigators, Insurance Investigators, and Researchers. These individuals are expected to have a strong foundation in cybersecurity and investigative techniques, and seek to validate their advanced skills in OSINT collection, analysis, and reporting.

Recommended experience

Practical work experience in cybersecurity or intelligence roles, along with familiarity with OSINT tools and techniques, is recommended to ensure mastery of the skills necessary for certification. Hands-on experience with OSINT tools and methodologies; Understanding of Python scripting for automation; Familiarity with Dark Web and cryptocurrency investigation techniques; Knowledge of disinformation and influence operations

The syllabus

What you’ll learn

Every domain and objective GIAC (SANS) measures, with the weight they carry on the exam.

The official GIAC (SANS) exam outline · checked 30 July 2026 · See the source

OSINT Fundamentals and Global Context
  • OSINT and International Environment
  • Sector-Specific and Practical OSINT
2 objectives · 77 free questions · 16 pages
Advanced OSINT Tools and Techniques
  • Advanced Operational Techniques and Threats
  • Multimedia and AI in OSINT
  • Python for OSINT: Tools and Techniques
3 objectives · 98 free questions · 21 pages
On the day

The exam itself

Everything GIAC (SANS) publishes about sitting it, and nothing we inferred.

Prerequisites

No mandatory prerequisites — this certification has no required predecessor exam or credential.

CertificationGIAC Strategic OSINT Analyst
Exam formatCyberLive: Hands-on performance-based testing
Duration180 minutes
Questions82 questions
Passing score66%
DeliveryGIAC
LanguagesEnglish
After you pass

Where this credential goes next

The path GIAC (SANS) lays out, how the credential is kept, and where to book.

Step-by-step path to GIAC Strategic OSINT Analyst

GIAC Strategic OSINT Analyst badgeCredential earnedGIAC Strategic OSINT Analyst Certification
Renewal and maintenance

GIAC certifications must be renewed every four years by earning 36 Continuing Professional Education (CPE) credits or by retaking the exam. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. GIAC (SANS) maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by GIAC (SANS)

Exam registration

Register for the exam through GIAC, GIAC (SANS)’s authorized testing partner.

Schedule your exam

Visit the official GIAC (SANS) certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the GSOA exam relate to other GIAC certifications?

GSOA is a standalone Practitioner certification. It does not require any other GIAC certification as a prerequisite, and it is not a replacement for any existing exam.

Is the GSOA exam hands-on?

Yes, the GSOA exam uses the CyberLive format, which replaces traditional multiple-choice testing with performance-based challenges in realistic lab environments. You will work with virtual machines, real security tools, and authentic code.

What are the proctoring options for the GSOA exam?

All GIAC certification exams are web-based and proctored. You can choose between remote proctoring through ProctorU or onsite proctoring through PearsonVUE.

How long do I have to complete the GSOA exam after registering?

Once your certification attempt is activated in your GIAC account, you have 120 days to complete it. You will receive an email notification when your attempt is activated.

What job roles does the GSOA certification map to?

GSOA is designed for Cyber Incident Responders, Security and Digital Forensics (DFIR) Analysts, Penetration Testers and Social Engineers, Law Enforcement Intelligence Personnel, Private Investigators, Insurance Investigators, and Researchers.

Can I renew my GSOA certification by passing a different GIAC exam?

GIAC certifications are renewed by earning 36 CPE credits or retaking the same exam. Passing a different GIAC exam does not automatically renew GSOA, but CPE credits earned from other certifications or training may count toward renewal.

Are there any regional restrictions for taking the GSOA exam?

GIAC exams are available globally through remote proctoring and onsite proctoring at PearsonVUE test centers. Regional availability may vary, so check with GIAC for specific locations.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 175 questions, free, no account needed.