Training Track
Mandatory · Pass/Fail · Compliance-gated · 85% pass threshold
01Define OPSEC and explain its relevance to special operations personnel and their families using the five-step process: identify critical information → analyze threats → analyze vulnerabilities → assess risk → apply countermeasuresOPEN
02List 10+ categories of critical information that must never appear on public-facing platforms: unit assignment, deployment dates, duty location, operational capabilities, personnel rosters, equipment types, training schedules, foreign partner identities, base access procedures, mission objectivesOPEN
03Configure correct privacy settings on all five major platforms: Facebook (profile visibility, friend list, check-ins, tagging), Instagram (private account, story controls, location tagging off), LinkedIn (profile visibility, connection visibility, employer display), X (protected tweets, location tagging off), TikTok (private account, location off, duet/stitch off, DM restrictions)OPEN
04Explain what EXIF/location metadata is, how it embeds in photos automatically, and demonstrate removal using device settings (iOS: turn off location for Camera; Android: remove GPS from Camera settings) or ExifTool before posting to any public platformOPEN
05Identify five concrete ways family members inadvertently expose operationally sensitive information: deployment countdown posts, homecoming photos with unit insignia, spouse Facebook groups with member lists, school directories listing parent military affiliation, pet tags with home address visible in posted photosOPEN
06Define aggregation risk and demonstrate with a worked example: show how name + unit + gym location + morning routine + vehicle type individually appear benign but collectively create a precise, predictable, targetable patternOPEN
07Identify OPSEC violations in a set of sample photographs: visible unit patches, base layout or entry control points in backgrounds, sensitive equipment in foreground or reflection, personnel identifiable via name tapes, departure/arrival formations, weapons or classified equipment visibleOPEN
08Describe the chain-of-command reporting procedure when a potential digital threat is identified: who to contact (unit security manager, S2), what to document (platform, account details, content, timestamps, your actions), and what NOT to do (do not engage the account, do not delete your own posts, do not share with uninvolved parties)OPEN
09Complete the TierWatch digital hygiene baseline checklist — 40-item self-administered assessment covering social media, device, location, and family hygiene — with a passing score of 85% or higherOPEN
10Acknowledge the TierWatch Acceptable Use Policy, individual assessment consent documentation, and data handling notice; complete digital signature on all three documents before platform access is grantedOPEN
Education Track
Advancement-gated · Self-paced · Platform-scored
01Conduct a basic self-Google audit: search name + hometown, name + unit name, name + rank, name + email address across Google, Bing, and DuckDuckGo with and without quotation marks; document what is publicly visible in a structured findings logOPEN
02Identify which people-search data broker sites contain your personal information — Spokeo, BeenVerified, Whitepages, Intelius, FastPeopleSearch, TruthFinder — and initiate at least one opt-out request; document the opt-out process and expected removal timeline for the recordOPEN
03Explain how social media posts enable an adversary to construct a pattern-of-life: identify four data categories that enable pattern construction (routine, location, social network, behavioral predictors) and provide a concrete example of how each enables threat actionOPEN
04Review and describe two documented historical cases where social media OPSEC failures compromised military operations — e.g., the 2014 ISIS location identification from unit photos; the 2017 Strava Global Heatmap intelligence disclosure; the 2019 Iran strike force identification — and identify the specific failure mode in eachOPEN
05Map your own social media presence: list all active accounts by platform, identify which are public vs. private, assess which expose PII (name, location, employer, family links), and produce a one-page self-exposure summaryOPEN
06Complete the TierWatch T-I self-profile survey across all 8 assessment characteristics — Social Media, Digital Footprint, Financial, Location Intel, Family/Associates, Professional Networks, Credentials & Device, Foreign Contact — and submit for baseline scoringOPEN
07Score at or above the T-I advancement threshold on the platform-administered digital awareness assessment; successfully submit your first formal self-assessment request via the TierWatch platform to unlock T-II accessCAPSTONE
Cert Alignment
AMU OSINT Microcredential (foundational)
TCM OSINT Fundamentals (free)
SANS SEC497 · Modules 1–3
Primary Characteristics
Social Media
Digital Footprint
Location Intel
Family/Associates
Delivery Mode
Self-service · Platform LMS
Training Track
Mandatory · Pass/Fail · 80% pass threshold
01Execute a structured self-OSINT audit using standardized search methodology: advanced Google operators (site:, intext:, inurl:, filetype:, "exact phrase", AROUND(n), before:, after:), Bing People search, reverse image search (TinEye + Google Images), and username cross-platform search (Sherlock, WhatsMyName.app)OPEN
02Complete opt-out procedures for all 15 major data broker and people-search aggregators; document opt-out submission date and expected removal timeline for each: Spokeo, BeenVerified, Whitepages, Intelius, FastPeopleSearch, Radaris, PeopleFinder, ZabaSearch, Pipl (public), US Search, TruthFinder, PeekYou, MyLife, Instant Checkmate, LexisNexis public portalOPEN
03Audit all active, dormant, and forgotten online accounts: use HaveIBeenPwned.com to identify compromised accounts; deactivate or delete unused accounts; enable multi-factor authentication on all active accounts; document the audit in the TierWatch Account Inventory formOPEN
04Configure all fitness and location-sharing applications to maximum privacy or disable entirely: Strava (hide location, disable route visibility, turn off flyby), Apple Find My (share only with named trusted individuals), Google Timeline (disabled), Garmin Connect (private profile), AllTrails (private), Peloton (private profile)OPEN
05Set all financial transaction apps to fully private: Venmo (private transactions, private friend list, private past transactions), CashApp (username not publicly searchable), PayPal (private transaction history), Zelle (no public history by design — verify); document settings applied for each app in useOPEN
06Audit and reduce professional network exposure: LinkedIn — remove connections you cannot identify; set profile visibility to non-indexed; remove specific duty station and unit name from employment history; disable "open to work" signals; remove endorsements from foreign national connections; turn off profile view notifications to othersOPEN
07Review all family and associate social media accounts and document which publicly link to or expose your information: search for your name tagged in others' posts; identify family accounts that list your employment or location; complete the Family Network Exposure Form and brief identified family members on required adjustmentsOPEN
08Understand and complete all foreign contact reporting obligations under SEAD-3: define what constitutes a reportable foreign contact; document all contacts with foreign nationals in the preceding 12 months using the required form; establish a standing calendar reminder for 30-day new-contact reportingOPEN
09Demonstrate correct device security hygiene: full-disk encryption enabled on all personal devices; OS auto-update active; unnecessary location permissions revoked (audit which apps have Always On location access); app permissions audited and restricted to "while using"; VPN configured for all public Wi-Fi network use; password manager in use for all accountsOPEN
10Pass the T-II digital footprint management assessment — 50-question platform quiz covering all training objectives — with a score of 80% or higher; review any failed sections and retest within 14 daysOPEN
11Complete the Family Member Digital Hygiene Brief with all household members and obtain a signed acknowledgment from each; submit acknowledgment forms via TierWatch platform to fulfill family compliance requirementOPEN
Education Track
Advancement-gated · Analyst-reviewed capstone
01Conduct a full multi-platform self-OSINT audit: primary platforms (Facebook, Instagram, LinkedIn, X, TikTok, YouTube), secondary platforms (Reddit, Discord, gaming profiles — Steam, Xbox, PSN), professional publications, news mentions, conference appearances, academic papers — document all attributable content foundOPEN
02Build a structured personal digital footprint map as a flat entity list: all accounts → associated email addresses → linked phone numbers → connected physical addresses → identifiable family links → professional associations → organizational memberships; identify which links are publicly attributableOPEN
03Conduct a photo history audit: run reverse image search (TinEye, Google Images) on all profile photos you have publicly used across platforms; check for embeddable EXIF data on downloadable images; review your photo-posting history for visible OPSEC violations; document and remediate findingsOPEN
04Research your financial OSINT exposure via public records: county property assessor (property ownership, purchase price, mailing address), FEC.gov (campaign finance donations), professional license databases (state licensing boards), federal court records (PACER public), and any state court records where you have resided; document all accessible recordsOPEN
05Identify and document any anomalies in your digital profile: impostor accounts using your name or photo, unexpected search results linking your name to unfamiliar content, unexplained account access alerts, login notifications from unknown devices, unsolicited contact from unverifiable organizations; document and report per T-I reporting procedureOPEN
06Explain how commercial OSINT tools aggregate public data into subject profiles: describe what a Maltego transform does (executes an API query against a data source and returns connected entities), what data Pipl aggregates (social profiles, public records, email history, phone, addresses), and what Babel Street monitors (real-time social media against keyword/location filters)OPEN
07Explain the concept of OSINT pivoting: demonstrate how an analyst moves from one seed data point to connected identifiers — from an email address to associated usernames, from usernames to linked accounts, from accounts to phone numbers, from phone numbers to physical addresses — using only publicly available sourcesOPEN
08Explain how financial OSINT reveals operational patterns: show how public Venmo transactions can expose social network, political affiliation, and financial stress indicators; how property records reveal location history; how GoFundMe campaigns can expose family situation; how donation records link to organizational membershipsOPEN
09Complete a detailed self-assessment submission across all 8 TierWatch characteristics with supporting documentation for each; submission must be reviewed by a certified analyst for accuracy and completeness; discrepancies identified by the analyst must be remediated before T-III eligibility is confirmedCAPSTONE
10Score at or above the T-II advancement threshold on the structured footprint management assessment; all Training Track requirements must be confirmed complete before advancement to T-III is unlockedCAPSTONE
Cert Alignment
GIAC GOSI / SANS SEC497 (modules 1–5)
TCM PORP (beginner track)
Intel Techniques intensive (Day 1)
Primary Characteristics
Digital Footprint
Financial
Location Intel
Professional Networks
Credentials & Device
Training Track
Mandatory · Pass/Fail · 85% pass threshold
01Demonstrate functional understanding of all 8 assessment characteristics — including the specific behavioral indicators analysts evaluate within each: for Social Media, platform count, privacy settings, content type, posting frequency, and identifiable information; for Financial, public transaction exposure, debt indicators, and unexplained wealth signals; for all others per the TierWatch Assessment Reference GuideOPEN
02Explain the composite risk scoring methodology: how each characteristic's sub-score is derived, how sub-scores are aggregated into a 0–150 composite, what the 50 (ELEVATED) and 70 (HIGH RISK) thresholds mean operationally, and what automated actions each threshold triggers (queue re-assessment, leader notification, commander review)OPEN
03Understand data currency and residual risk: explain why a 421-day-old assessment carries higher residual uncertainty than a 90-day assessment; identify the platform's auto-queue trigger thresholds (30-day flag, 60-day auto-queue with +25 risk adjustment); describe how life events (PCS, promotion, foreign travel, significant relationship change) trigger out-of-cycle assessment requestsOPEN
04Describe the full assessment lifecycle end-to-end: self-assessment request submission → SLA assignment by tier → analyst queue intake → OSINT collection phase → Shell Products drafting (all 8 sections) → QC review → adjudication → subject notification → findings record → retention schedule → next assessment triggerOPEN
05Know the complete SLA framework by tier: T-I (14 days standard / 7 expedited), T-II (10 / 5), T-III (7 / 3), T-IV (5 / 2), T-V (3 / 1); identify qualifying circumstances for expedited request; describe the chain-of-command approval process; explain what happens when SLA is breached (escalation to manager → leader notification → auto-flag in platform)OPEN
06Understand the legal and regulatory framework: explain the role of EO 12968 (Access to Classified Information), SEAD-3 (Foreign Contact Reporting obligations and timelines), SEAD-7 (Insider Threat Program — what behaviors trigger referral), and ICD 704 (Personnel Security Standards for adjudication) — identify which applies to each assessment characteristicOPEN
07Define pattern of life and explain how analysts construct one from open-source data: list the six data categories that contribute (routine, location, social network, behavioral predictors, financial patterns, digital behavior), explain why historical data matters for pattern detection, and give a concrete example of how a pattern anomaly raises riskOPEN
08Understand counter-OSINT protective measures at the conceptual level: data broker opt-out maintenance cycle (quarterly audit, re-opt-out after 6 months as re-indexing is common), privacy settings audit schedule, EXIF discipline as a standing practice (not a one-time action), digital network minimization (reducing attributable connections to known, vetted individuals)OPEN
09Brief family members to T-III-level digital hygiene requirements — covering all platform-specific settings, data broker opt-outs, financial app privacy, and foreign contact awareness — and submit a completed Family Compliance Form with named household members and verification that brief was completedOPEN
10Know what constitutes a reportable anomaly and complete a practice anomaly report using a simulated scenario: correctly identify all required fields (platform, account descriptor, content summary, date observed, action taken), demonstrate correct escalation path, and confirm no-engage and no-delete protocolOPEN
11Pass the T-III comprehensive knowledge assessment — 60-question platform quiz — with a score of 85% or higher; the assessment covers all training objectives including regulatory framework questions that require precise, not approximate, answersOPEN
12Understand what foreign intelligence service (FIS) interest means in the context of a military personnel security assessment: define the three phases of FIS collection (passive, active, contact), list four behavioral indicators that appear in open-source data during the passive collection phase, and describe the two-step reporting procedure if any indicator is observedOPEN
Education Track
Advancement-gated · Analyst-adjudicated
01Apply Analysis of Competing Hypotheses (ACH) to a structured scenario: given a hypothetical digital profile with three plausible threat explanations, systematically list the evidence relevant to each hypothesis, rate each piece of evidence as consistent/inconsistent/not applicable for each hypothesis, and produce a written assessment with an explicit confidence rating (High/Medium/Low) and identified key assumptionsOPEN
02Conduct an advanced self-OSINT audit using analyst-level search techniques: Google/Bing dork syntax with 10+ operator combinations, site-specific search (LinkedIn company employee search, Facebook group membership search), cached and historical content retrieval (Wayback Machine CDX API, CachedPages, Google Cache), and breach data queries (HIBP full check, email enumeration across known breach datasets)OPEN
03Interpret a redacted Shell Products assessment report: identify each section's findings; understand how each characteristic score was derived and what evidence justified it; identify what specific changes to the subject's digital behavior would have lowered the score; and produce a one-paragraph risk summary matching the analyst's overall findingOPEN
04Analyze a synthetic social media profile and identify behavioral patterns that elevate composite risk score: produce a structured findings document listing each identified indicator, the assessment characteristic it affects, the estimated score impact (+low/+med/+high), and a recommended remediation action — minimum 5 findings required across at least 3 separate characteristicsOPEN
05Demonstrate proficiency with OSINT tools available on the TierWatch analyst panel: run a full HIBP breach check on a provided email address and interpret all returned breach records; conduct a basic Shodan host search on a provided IP and interpret the exposed services; execute a reverse image search workflow and document all platform results; produce a structured research report for eachOPEN
06Understand geolocation analysis methodology: explain how analysts extract precise location coordinates from EXIF metadata using ExifTool; describe the process of cross-referencing extracted coordinates with Google Earth and SentinelHub satellite imagery; identify a minimum of 3 geolocation indicators from a set of sample images (landmark, sun angle, infrastructure, vegetation, signage)OPEN
07Demonstrate understanding of how the TierWatch platform fits within the broader Intelligence Cycle: map each platform workflow stage (request → collection → Shell Products → QC → adjudication) to the corresponding Intelligence Cycle phase (direction, collection, processing, analysis, dissemination); explain where the cycle restarts and what triggers reassessmentOPEN
08Explain what constitutes foreign intelligence service (FIS) interest in a U.S. military target at a structured level: list 6 behavioral indicators that appear in open-source data during passive collection; describe how the transition from passive to active collection typically manifests in a target's digital environment; identify the specific fields in the anomaly report that capture each indicator typeOPEN
09[ANALYST-ADJUDICATED CAPSTONE] Complete a full T-III self-assessment submission across all 8 characteristics with structured supporting documentation for each; submission is reviewed by a certified analyst; analyst adjudicates accuracy, completeness, and self-awareness rating; subject receives written feedback; score must meet passing adjudication threshold to unlock T-IV eligibilityCAPSTONE
Cert Alignment
GIAC GOSI (full certification)
Treadstone 71 CCIA (foundational modules)
SANS FOR578 (modules 1–2)
TCM PORP (full)
Primary Characteristics
All 8 Characteristics
Pattern-of-Life Analysis
Regulatory Framework
Training Track
Mandatory · Pass/Fail · 90% pass threshold
01Demonstrate operational proficiency with the full TierWatch analyst tool stack: Pipl (people aggregation, identity resolution, contact history), Maltego (graph-based entity mapping, transform execution), HIBP (breach and credential exposure, paste monitoring), Babel Street (social media monitoring against keyword/location/account filters), Shodan (device and infrastructure exposure search) — produce a structured output from each tool on synthetic training subjectsOPEN
02Construct a subject profile from seed data using a standardized 6-phase OSINT methodology: (1) seed identification and verification, (2) entity expansion across platforms, (3) network mapping of associates and organizations, (4) timeline construction from posting history and records, (5) pattern-of-life analysis, (6) exposure assessment and risk scoring — document each phase with source citations in the required formatOPEN
03Apply Maltego link analysis to a synthetic training target: build an entity network graph from a seed email address, execute the relevant transform chain (email → accounts → usernames → associated profiles → physical addresses → telephone numbers), identify the three highest-exposure nodes in the resulting graph, and produce a written network summary with risk interpretationOPEN
04Conduct a full pattern-of-life analysis from a synthetic social media dataset: identify routine (peak posting times, recurrent locations, recurring activity types), social network (named associates, tagged locations, recurring venues and their significance), behavioral anomalies in the dataset, and high-exposure events — produce a 1-page pattern summary with confidence ratings on each findingOPEN
05Produce a complete Shell Products assessment report for a synthetic training subject: all 8 characteristics scored with justified sub-scores, structured boilerplate findings using the Platform / Observation / Risk Indicator / Operational Relevance format, composite risk score with written narrative summary, and recommended adjudication action with supporting rationaleOPEN
06Conduct a QC review of a synthetic draft Shell Products report: evaluate completeness (all 8 sections present and fully documented), scoring accuracy (sub-scores consistent with stated findings), finding quality (structured format followed, operational relevance rated), and standard format compliance — produce a written QC disposition (pass / return with specific deficiencies noted)OPEN
07Conduct full geolocation analysis on a set of 5 synthetic training images: extract coordinate data from EXIF metadata using ExifTool; cross-reference coordinates with Google Earth and SentinelHub satellite imagery to confirm location; identify landmarks via visual analysis (structural, vegetative, infrastructure, signage, astronomical indicators); produce a structured location report with confidence rating and source documentation for each imageOPEN
08Identify disinformation and synthetic persona indicators in a set of social media accounts: detect coordinated posting behavior patterns (synchronized activity windows, identical content with minor variation, shared amplification networks); identify recycled profile photos via reverse image search; assess account age vs. follower/activity ratio anomalies; apply the Admiralty Code (source reliability A–F, information credibility 1–6) to rate each account's trustworthinessOPEN
09Demonstrate understanding of cryptocurrency and blockchain OSINT: given a public Bitcoin or Ethereum wallet address, trace transaction history using a block explorer (Blockchain.com, Etherscan); identify exchange interactions (deposit/withdrawal patterns to known exchange addresses); assess what operational conclusions can and cannot be drawn from public blockchain data without additional sourcesOPEN
10Demonstrate understanding of dark web monitoring concepts as they apply to personnel security: identify the categories of personnel data that appear in breach databases and dark web marketplaces (credentials, PII, financial data, health records, location history from compromised apps); explain how breach data is acquired, packaged, and sold; demonstrate how to determine whether specific credentials have been exposed using HIBP and authorized Dehashed queriesOPEN
11Apply three structured analytic techniques to a multi-source scenario: produce an ACH matrix (Analysis of Competing Hypotheses) with confidence ratings; apply Devil's Advocacy by steelmanning the least-supported hypothesis; conduct a Key Assumptions Check listing all assumptions embedded in the primary assessment and their verifiability; integrate the three technique outputs into a final written analytic productOPEN
12Pass the T-IV technical proficiency assessment — 70-question platform quiz with practical component — with a combined score of 90% or higher; the practical component requires submitting a full synthetic Shell Products report that meets the QC passing standardOPEN
Education Track
Analyst-gated content marked [AG] · Controlled setting delivery
01Conduct corporate and professional OSINT on a synthetic target: business registry research (Secretary of State filings, business entity status), beneficial ownership lookup (FinCEN BOI database, OpenCorporates), SEC EDGAR filings (10-K, proxy statements for executive identification), federal court records (PACER), state court records (CourtListener), county property records, UCC filings — produce a structured corporate entity and financial exposure reportOPEN
02Apply image and video forensic analysis: execute reverse image search across TinEye and PimEyes on a provided image set; apply AI-generated content detection tools (Hive Moderation, Content at Scale, Illuminarty); conduct EXIF analysis using ExifTool and identify all embedded metadata fields; detect image manipulation indicators (clone stamp artifacts, lighting inconsistency, JPEG compression anomalies) — produce a forensic finding for each imageOPEN
03Demonstrate advanced search technique proficiency across 5 platforms: Google (dork chaining, AROUND() operator, date-range filtering, cache: and related: operators), LinkedIn (company employee enumeration, alumni search, Boolean search in profile fields), Reddit (subreddit and user history search), X/Twitter (advanced search with geo-filter, date range, account type), GitHub (code search for PII, dork for email and API keys) — conduct structured research on synthetic targets using each and document findingsOPEN
04Conduct a disinformation network analysis on a synthetic social media dataset: identify a coordinated inauthentic behavior pattern — map the amplification network graph, identify likely origin/hub accounts, distinguish organic engagement from automated amplification, assess the narrative being amplified and its target audience, estimate operational reach (unique accounts reached × average follower count) — produce a structured influence operation assessmentOPEN
05Demonstrate understanding of how OSINT integrates with the full Intelligence Cycle in the TierWatch context: produce a collection plan for a hypothetical high-priority subject (Priority Intelligence Requirements → Essential Elements of Information → collection sources by characteristic → exploitation timeline → production format → dissemination route); defend the plan to a senior analyst in a 15-minute structured debriefOPEN
06[AG] Understand social engineering and elicitation techniques at the pattern-recognition level: identify the 8 primary elicitation methods (flattery, provocative statement, false statement, knowingly naïve question, feigned ignorance, bracketing, quid pro quo, best guess); recognize when each is being directed at yourself or peers in a professional or social context; understand how OSINT-derived profile data enables personalized elicitation targeting — sufficient to recognize and report; content delivered by certified analyst in authorized group settingANALYST-GATED
07[AG] Identify the behavioral signature of a foreign intelligence service (FIS) online recruitment approach: recognize initial contact patterns (unsolicited LinkedIn requests from academic/research organizations, conference networking from unverifiable attendees, social media engagement campaigns targeting specific personnel), escalation vectors (rapport-building, information-sharing as reciprocity trigger, introduction of financial incentive, third-country national as cutout), and extraction mechanics — recognize and document the specific behavioral indicators that distinguish FIS activity from legitimate professional contact; analyst-delivered in controlled settingANALYST-GATED
08[AG] Understand honey trap and online relationship manipulation methodology at the pattern-recognition level: recognize the targeting profile (isolated, recently relocated, relationship instability, financial stress indicators), initial contact approach, relationship escalation pattern, and the transition from relationship development to request escalation — sufficient to identify the pattern when directed at yourself or a peer and report it; not sufficient to replicate; analyst-delivered with case study examples in controlled settingANALYST-GATED
09[AG] Understand how adversaries build targeting packages on specific SOF personnel: collection priority determination methodology, passive OSINT collection phase (what is collected, from which sources, in what order), active collection phase (what additional collection is triggered by passive findings), pre-contact assessment (what determination is made before contact is authorized), and what personal characteristics increase targeting priority — recognize when these phases are being applied against yourself or a known subject; analyst-delivered in controlled setting with authorized case study materialsANALYST-GATED
10[AG CAPSTONE] Complete a supervised full-cycle OSINT investigation on a synthetic authorized subject: produce a complete Shell Products report meeting QC standard, present findings to a senior analyst panel, receive written feedback on analytic quality and methodology, and remediate all identified deficiencies in a revised submission — written endorsement from supervising analyst required for T-IV completion record; T-V nomination requires separate commander endorsementCAPSTONE
Cert Alignment
GIAC GSOA / SANS SEC587
Treadstone 71 CCIA (full)
SANS FOR578 (full)
Maltego Certified Analyst
Intel Techniques intensive (full)
Primary Characteristics
All 8 · Full Workflow
Foreign Contact
Network Analysis
Delivery Mode
Self-service (obj. 01–12)
Analyst-controlled (obj. AG 06–10)
▸ All objectives below are CONTROLLED. Content is not delivered via the TierWatch LMS. Delivery requires a certified TierWatch analyst, an authorized physical or secure virtual setting, and a confirmed T-IV completion record plus commander endorsement on file. Completion is entered by the certifying analyst only.
Training Track
Controlled · Analyst-delivered · Oral/written assessment
01[CTRL] Understand the end-to-end methodology foreign intelligence services use to build targeting packages on U.S. special operations personnel: collection priority determination (what makes a target high-value), passive OSINT collection phase, active collection phase, pre-contact assessment, and contact plan construction — using appropriately authorized case study materials (unclassified analogs or sanitized confirmed CI investigations)CONTROLLED
02[CTRL] Identify the specific digital and human vectors FIS use for initial access against military targets: academic conference exploitation, social media cold contact, third-country national cutouts, professional networking platform recruitment, financial distress exploitation (identifying and approaching personnel with elevated financial risk indicators), and ideological targeting — with observable behavioral indicators for each vector typeCONTROLLED
03[CTRL] Understand adversarial OSINT tooling and collection at scale: how foreign actors use commercial open-source tools and data aggregators at scale against U.S. personnel; which commercial data sources are known to be accessed or proxied by foreign intelligence services; how automated collection against specific units, installations, and personnel rosters is conducted; and what data categories are prioritized in collection taskingCONTROLLED
04[CTRL] Understand how HUMINT and OSINT intersect in adversarial targeting: when physical surveillance follows digital surveillance; how an online reconnaissance phase informs a contact plan (what information the collector needs before approaching); how to detect the transition from passive collection to active engagement in your own or a known subject's environment; what digital indicators correlate with physical surveillance activityCONTROLLED
05[CTRL] Recognize the behavioral indicators of active targeting at each collection phase: passive phase (unexplained changes in search result rankings for your name, new followers from accounts with low engagement ratios, professional outreach from unverifiable organizations with no web presence), active phase (direct contact attempts, repeated contact across multiple channels, vouching from an existing trusted contact), contact phase (in-person approach at predictable locations, controlled meeting scenario setup, request escalation pattern)CONTROLLED
06[CTRL] Demonstrate knowledge of protective measures for elevated threat environments: pattern-of-life disruption techniques; counter-surveillance basics (detection, assessment, loss); digital sanitization protocol for travel to threat-designation countries (device selection, account preparation, VPN and communication discipline); persona separation for sensitive activities; device security for high-threat environments (clean devices, no biometric unlock, encrypted communications only)CONTROLLED
07[CTRL] Understand the legal and policy boundaries governing analyst collection activities in the TierWatch context: what domestic collection is prohibited without specific authorization (U.S. persons, collecting beyond publicly available information); what requires written authorization; how to handle incidentally collected third-party PII; chain-of-custody requirements for assessments that enter legal proceedings; and why these limits exist operationally — explain how boundary violations have historically compromised programs and prosecutionsCONTROLLED
08[CTRL] Pass the T-V written and oral assessment administered by a certifying analyst: the oral component is conducted in person or via approved secure video, covers all Training Track objectives with scenario-based questions, and is documented with the analyst's written summary; a passing result plus the analyst's written endorsement is submitted to the platform for completion record entryCAPSTONE
Education Track
Controlled · Analyst-supervised practicum
01[CTRL] Conduct supervised analysis of an authorized case study involving confirmed FIS targeting of U.S. military personnel (appropriately sanitized or unclassified version): identify the collection phases evident in the timeline, identify the missed indicators at each phase, determine the earliest intervention point in retrospect, and produce a structured lessons-learned assessment with specific actionable indicators that could have triggered reportingCONTROLLED
02[CTRL] Understand offensive OSINT collection tradecraft at the operational awareness level: how professional collectors structure a target profile build (what they collect, in what sequence, from which sources), what a finished targeting package contains and how it is structured, and how to identify when the methodology is being applied against yourself or a known subject — awareness sufficient to recognize and defend against, not to replicateCONTROLLED
03[CTRL] Demonstrate proficiency in counter-OSINT measures for elevated-threat environments: legend construction principles and maintenance discipline; account and network isolation techniques; physical and digital pattern-of-life disruption; travel sanitization protocol (device selection, account preparation, communication plan, re-integration upon return); contact management in environments where FIS presence is known or assessed as likelyCONTROLLED
04[CTRL][ANALYST-DELIVERED ONLY] Understand elicitation and social engineering from an offensive awareness perspective: the specific scripts, rapport-building sequences, and escalation mechanics used by FIS case officers and trained online recruiters; the six psychological influence principles they exploit (Cialdini: reciprocity, commitment/consistency, social proof, authority, liking, scarcity) and how each is operationalized in a recruitment approach; the specific verbal and behavioral tells that betray the methodology when used by an operator less skilled than the training subject — delivered by certified analyst only, no recording or documentation distributedCONTROLLED
05[CTRL] Demonstrate ability to construct a defensive threat brief for a specific personnel profile: given a realistic personnel digital footprint, identify the top 3 threat vectors specific to that profile (ordered by probability and consequence), assign a probability rating to each vector with stated rationale, prescribe specific measurable mitigation steps for each vector with verification criteria, and produce a brief suitable for delivery to a unit leader — supervised by certifying analystCONTROLLED
06[CTRL][FINAL EVALUATION] Successfully complete a supervised full-cycle sensitive activities assessment on an authorized synthetic subject: produce a classified-equivalent threat brief covering all 8 characteristics plus threat actor methodology assessment; present findings to a review board (minimum: certifying analyst + one senior analyst); receive written disposition from the board; written endorsement from certifying analyst required for T-V completion record to be entered in TierWatchCAPSTONE
Cert Alignment
JCITA — DCAC / CICCEC
FOR578 + CI tradecraft integration
IC internal programs (agency-specific)
Treadstone 71 advanced CI modules
Delivery Requirement
Certified analyst only
Authorized setting required
Commander endorsement on file
No platform delivery of content
OPEN — Self-service, platform LMS delivery
ANALYST-GATED [AG] — Controlled setting, certified analyst delivery
CONTROLLED [CTRL] — Not on platform, analyst-delivered, commander endorsement required
CAPSTONE — Advancement gate; requires passing adjudication to unlock next tier