×

Four days of OSINT and Dark Web training for Western Balkan law enforcement

18.09.2026

Image for Four days of OSINT and Dark Web training for Western Balkan law enforcement

This week at WB3C, police officers and prosecutors from the Western Balkans worked through a four-day practical programme on Open-Source Intelligence (OSINT) and Dark Web investigations, delivered in cooperation with CIVIPOL and EU4FAST.
Led by WB3C training team Cyril CORRIAS and Jean-Pierre Bonnet, the course focused on the practical skills needed to collect and analyse publicly available information in support of Internet investigations — from identifying potential threats and gathering digital evidence to producing actionable intelligence. 

The programme moved progressively through the fundamentals of Internet investigations and evidence preservation, protection and anonymisation techniques, social network investigations, online checks and surveys, and safe navigation of the Dark Web, combining each area with practical exercises. Participants also worked on approaches to data collection and the legal and ethical considerations linked to the use of digital information. 

The training brought together law-enforcement practitioners from the WB6 who were attending a WB3C programme for the first time, expanding the network of professionals in the region equipped to work with open-source information in increasingly complex digital investigations. 

Our thanks to our partners CIVIPOL and EU4FAST, and especially Marie Pierre MOSIN for supporint this programme, and to all participants for four intensive and highly practical days in Podgorica.


Minister Delegate Marie-Pierre Vedrenne Visits WB3C

On the sidelines of the BerlinProcess meetings held in Montenegro this week, we were honoured to welcome Ms Marie-Pierre Vedrenne, Minister Delegate to the Minister of the Interior, responsible for Citizenship.

Accompanied by the newly appointed French Ambassador to Montenegro, Ms Cécile Humbert-Bouvier, the Minister met with the WB3C team and learned more about the training programmes being delivered at the Cyber Centre this week.

She spoke with participants, WB3C trainers and external experts, including Reza Elgalai from the University of Technology of Troyes (UTT) and Major Marc TEROUANNE of the French Gendarmerie, who travelled to the WB3C specifically to deliver digital forensics training.

The Minister also met with Polish experts from NASK, who are working alongside Slovenia’s URSIV to deliver cybersecurity training focused on disinformation. She also engaged with CIVIPOL experts from the EU4FAST project, who are providing specialised cybercrime and OSINT training to strengthen the fight against migrant smuggling and irregular migration.

Cyber awareness, disinformation and OSINT: three connected perspectives on working safely with information

This week at WB3C, participants from public institutions across the Western Balkans are looking at the information environment from three different but closely connected perspectives: cyber awareness, disinformation and open-source intelligence (OSINT).
The training is delivered by Marcin Napiórkowski, Sylwia Adamczyk and Jakub Orzeszek from NASK – the Polish Research and Academic Computer Network, combining practical cyber hygiene with an understanding of how information is manipulated, verified and analysed online. 
The first part of the course focuses on cyber awareness in both private and professional environments. Participants examine common threats from an end-user perspective, incident reporting, protection of email and social media accounts, and the security practices that organisations can put in place to reduce everyday exposure.
From there, the discussion moves to disinformation and the mechanisms that make it effective: filter bubbles, cognitive biases and techniques such as false context and cherry-picking. An important part of the work is not only recognising manipulation, but understanding how institutions can respond and communicate when misleading information begins to affect their reputation or the audiences they serve. 
The OSINT component then takes participants into the practical work of finding, verifying and evaluating information from open digital sources. Search techniques, social media and visual-media analysis are combined with exercises in identifying disinformation and checking the reliability of what has been found.
There is also another side to OSINT that is sometimes overlooked: protecting the analyst. Participants are introduced to OPSEC methodologies and operational anonymity, looking at how research can be conducted without unnecessarily exposing the analyst, the organisation or the investigative workflow. 
Bringing these three areas together is particularly relevant for public institutions. The same digital environment in which staff communicate and work is also the environment in which information is collected, manipulated, amplified and investigated.
By the end of the course, the objective is therefore not simply to know more tools or terminology, but to be better able to recognise threats, question information, verify sources and work more securely online. 
Gilles Schwoerer, our Programme Director, greeted the participants and thanked our partners in URSIV, Urad Vlade Republike Slovenije za informacijsko varnost for funding this training and its continued support to WB3C activities.

The last two-week block of the Cybersecurity Diploma Course with the French Université de Technologie de Troyes

This week, our students had the opportunity to explore digital forensics through a practical and investigation-oriented approach, combining technical knowledge, forensic tools and, most importantly, analytical reasoning.
The training was delivered by Ljuban Petrovic, Reza Elgalai and Marc TEROUANNE, digital forensics specialists, drawing on several years of operational experience in digital investigations and forensic examination.
Throughout the week, participants worked progressively from the fundamentals of digital evidence to a complete forensic investigation.
They learned about evidence preservation, integrity and hashing, before exploring key Windows forensic artefacts such as Prefetch, UserAssist, JumpLists and ShellBags. Rather than simply learning where artefacts are located, the objective was to understand the link between a user action and the digital traces left behind on a system.
The participants first generated activity themselves inside their own virtual machines, then used tools such as Eric Zimmerman's forensic tools, X-Ways Forensics and Magnet AXIOM to identify and interpret the traces they had created.
The second part of the week introduced OperationBlueHarbor, a realistic investigation scenario designed specifically for the course. From a forensic disk image, participants had to work as real analysts: explore the system, recover deleted information, identify relevant evidence, correlate artefacts and distinguish facts from assumptions.
Later in the investigation, a memory dump was introduced as a new source of evidence. Using Volatility 3, participants examined running processes, focused on Tor-related activity, extracted process memory and searched for relevant strings and indicators. Particular attention was given to one of the most important skills in digital forensics: understanding what a trace can prove — and what it cannot prove.
The week concluded with evidence correlation, reporting and discussion around how technical findings can be transformed into clear, understandable and useful information for an investigation.
The philosophy throughout the course was simple:
Digital forensics is not about clicking buttons in a forensic tool. It is about understanding the traces, questioning the results, correlating the evidence and being able to explain your conclusions.
A demanding but very rewarding week, with an engaged group of participants who progressively moved from following demonstrations to conducting their own investigation.
Congratulations to everyone who took part in the course for their dedication throughout the intensive 10 week training — especially for surviving Operation Blue Harbor! What comes next are the final exams, the dissertation defence and the internationally recognised university diploma.


Copyright © WB3C

Disclaimer: Translations of the original content written in English into other languages are AI generated by Weglot.