Modern digital investigations depend on far more than investigators alone. Behind every successful covert online operation is a secure, resilient, and intelligently managed technical environment. From secure deployment platforms and hardened devices to encrypted communications, server infrastructure, and discreet operational networks, success depends on the ability to build, manage, and protect the environment in which investigations take place.
The MSc in Cyber Security & Intelligence is Sorinteq’s flagship postgraduate programme, delivered in partnership with the University of Buckingham, designed for professionals operating within intelligence, investigations, cyber security, protective security, and covert operational environments.
Modern investigations demand professionals who can operate confidently across the full digital investigative landscape. From cybercrime and cryptocurrency to darknet environments, radio frequency exploitation, covert research, and advanced cyber reconnaissance, investigators must be able to work across multiple technical disciplines while maintaining evidential integrity and operational security.
The modern investigative landscape demands professionals who can operate confidently in both the digital and human intelligence environments. Traditional online investigation skills alone are no longer enough—today’s investigators must be capable of combining OSINT, Digital HUMINT, covert engagement, behavioural analysis, darknet awareness, cryptocurrency understanding, and cyber investigative tradecraft to operate effectively against sophisticated adversaries.
The Pg Diploma (PgDip) in Cyber Security & Intelligence forms Year Two of Sorinteq’s MSc pathway and is designed for students who have successfully completed a Year One specialist pathway and achieved a Postgraduate Certificate (PgCert).
The digital trail left behind by individuals and organisations is growing in both size and complexity. Every online interaction, connected device, account, and communication creates opportunities for adversaries to identify, track, profile, and exploit targets.
The Cyber Incident Investigator course equips participants with the skills to effectively investigate cyber security incidents while ensuring business continuity and service restoration.
The Cyber Incident Responder course is an intensive five-day training programme designed to equip participants with the knowledge and practical skills to detect, respond to, and recover from cyber security incidents.
The Ransomware Responder Course is an intensive, practical programme designed to equip participants with the skills and knowledge to detect, respond to, and recover from ransomware incidents.
Cryptocurrencies and blockchain technologies are now firmly embedded within criminal, terrorist, and state-level threat activity. From ransomware and fraud to sanctions evasion and hostile state financing, digital assets present complex investigative and intelligence challenges.#
At the advanced level, darknet investigations move beyond observation into controlled environments, infrastructure awareness, and high-value intelligence development.
The darknet continues to play a significant role in criminal activity, illicit trade, and covert communication, presenting both challenges and opportunities for investigators.
Cryptocurrency has become a significant feature in modern criminality, fraud, financial investigations, and intelligence operations. From ransomware payments and fraud to money laundering and organised crime, digital currencies present both investigative challenges and valuable intelligence opportunities.
As cryptocurrency use becomes increasingly sophisticated, investigators must move beyond basic tracing and develop the capability to identify complex transaction patterns, laundering methodologies, and behavioural indicators across digital asset ecosystems.
As darknet ecosystems continue to evolve, investigators must move beyond basic navigation and develop the capability to conduct structured, intelligence-led investigations across complex and interconnected platforms.
In many investigations, the opportunity to seize a device for full forensic examination is either unavailable, operationally undesirable, or would compromise wider investigative objectives. In these environments, the ability to conduct covert digital acquisition becomes a critical capability.
In modern investigations, valuable intelligence and evidential opportunities often exist within personal devices, cloud platforms, and connected digital ecosystems. Where lawful authority and operational necessity exist, covert digital forensic recovery can provide critical investigative advantage.
Digital forensics is far more than operating forensic software. Effective forensic examination requires a strong understanding of evidential recovery, investigative strategy, exhibit handling, legal compliance, court presentation, and the role digital evidence plays in both intelligence development and criminal investigations.
Modern investigations increasingly require digital forensic examiners to operate in live environments, where critical evidential opportunities exist before a device can be seized, powered down, or removed for traditional laboratory examination.
The Advanced Digital HUMINT Course is designed for experienced practitioners who are already conducting online engagement and now require the skills to operate in complex, sensitive, and high-risk intelligence environments.
The management of Covert Human Intelligence Sources (CHIS) in digital environments requires advanced skills in operational planning, risk mitigation, behavioural understanding, and governance compliance. As online engagement becomes more complex, so too does the requirement for structured, controlled, and defensible CHIS handling practices.
Foreign Information Manipulation and Interference (FIMI) is the contemporary term used to describe coordinated disinformation, propaganda, and influence operations conducted by state and state- aligned actors. These activities target democratic processes, critical infrastructure, public trust, and organisational decision-making.
Human Intelligence (HUMINT) remains a critical component of modern intelligence and investigative operations. As communication increasingly takes place in digital environments, practitioners must be able to identify, engage, and manage human sources through online platforms safely and effectively.
Building on foundational Digital HUMINT principles, the Intermediate Digital HUMINT Course develops the practical skills required to effectively engage, influence, and elicit information from individuals in online environments.
The use of Covert Human Intelligence Sources (CHIS) within digital environments presents unique operational, legal, and ethical challenges. As communication and human interaction increasingly move online, practitioners must be equipped to identify, assess, and manage CHIS activity within virtual spaces.
As a digital media investigator, you will already know that much of the available training in the industry only scratches the surface and fails to address the complex, real-world challenges encountered during live investigations.
Digital media investigators are increasingly expected to operate across complex and rapidly evolving online environments. However, much of the training traditionally provided in this field remains basic, platform-specific, and insufficient for the realities of modern investigations.
For experienced practitioners, the advanced requirement is not simply to use AI but to engineer it into an investigative capability: combining technologies, validating outputs and maintaining operational security, evidential integrity and professional accountability.
Duration
7 days: 2 days virtual preparation and 5 days classroom-based practical training
Internet Intelligence & Investigation (I3) enables professionals to harvest a rich source of accurate and timely data left by individuals, organisations, and threat actors within the digitally connected world. This is the third course in Sorinteq’s I3 suite of OSINT training and is designed to take learners to an Advanced level of capability. The fusion of advanced OSINT with conventional investigative methods provides organisations with a powerful tool for intelligence gathering, due diligence, corporate investigations, fraud enquiries, threat monitoring, and strategic decision-making. The Advanced Open Source Intelligence Course is designed for experienced and technically competent professionals who are already operationally active in investigative or intelligence-gathering roles and who require higher-level technical capability to deal with increasingly sophisticated online subjects and complex digital environments. This course builds on the skills taught in our Intermediate I3 Programme and develops enhanced technical capability, particularly in the use of code-based tools, APIs, advanced digital tradecraft, and analytical techniques that significantly improve the effectiveness of internet-based investigations. The programme is delivered as a 7-day blended course, consisting of: 2 Days Virtual Pre-Course Learning 5 Days Classroom-Based Practical Delivery This structure allows learners to complete foundation preparation remotely before progressing into intensive operational classroom delivery.
Artificial intelligence is becoming a significant part of the digital investigative landscape, but effective use requires more than familiarity with individual tools. Investigators must understand where AI can add value, how its outputs should be checked, and how to protect professional and evidential standards.
In today’s digital landscape, individuals and organisations leave behind vast amounts of publicly available data. When harnessed correctly, this data becomes a powerful tool for investigations, due diligence, risk management, and intelligence-led decision-making.
For practitioners who already understand the fundamentals of artificial intelligence, the next challenge is integrating it into structured and operational investigative workflows.
As digital investigations become more complex, professionals must move beyond basic search techniques and develop technical, scalable, and structured approaches to online intelligence gathering.
Cyber-enabled offenders present unique challenges for investigators. These individuals often possess a high level of technical competence and deliberately employ digital tools, obfuscation techniques, and technical narratives to frustrate investigations and undermine evidential integrity.
Digital fraud is an escalating threat, with criminals increasingly exploiting online presence and digital footprints to target individuals and organisations. A growing proportion of serious fraud begins or develops through digital channels, and criminals may disproportionately target people who are vulnerable or less confident online.
Effective evidence recovery is a cornerstone of successful investigations. For new investigators or digital intelligence practitioners, understanding how to collect, preserve, and present evidence to the required standard can be challenging.
In digital investigations, the one true constant is often the written word. Whether it is an email, social media post, forum message, threat communication, fraud correspondence, or even a username, language provides valuable intelligence about the person behind it.
Commercial organisations conducting digital investigations operate in an increasingly complex legal environment. While businesses do not work under formal investigative authorities in the same way as government agencies, there remains a critical requirement to understand where legal thresholds, privacy obligations, and potential authorisation issues may arise in order to avoid regulatory breaches, reputational damage, and adverse litigation.
Managing digital investigation teams requires more than traditional supervisory skills. Many managers and supervisors find themselves responsible for internet investigation staff, cyber investigators, and digital intelligence teams without having previously worked directly within the digital investigation environment themselves.
Managing digital investigation teams requires more than traditional leadership skills. Many managers and team leaders find themselves responsible for internet investigators, OSINT practitioners, fraud teams, cyber analysts, and digital intelligence staff without having previously worked directly within the digital investigation field themselves.
Professional development in the security industry cannot stand still. Threats evolve, operational environments change, and security professionals must continually maintain and enhance their skills to remain effective, compliant, and operationally ready.
The Certified Security Professional (CPSP) Programmeme is designed for individuals new to the security industry who wish to develop a professional, competent, and credible skill set.
Due diligence is a cornerstone of professional security provision. Understanding the people, organisations, and environments you operate around is critical to mitigating risk, verifying claims, and protecting assets.
Traditional security training often focuses exclusively on physical threats, while conventional cyber security courses target networks and IT systems. In today’s environment, security professionals must operate across both spheres, protecting physical assets, personnel, and digital footprints from malicious actors.
This five-day Level 3 qualification develops the knowledge and practical understanding needed to assess counter-terrorism risk and improve preparedness for venues, sites and organisations.
Current recognition, accreditation and endorsement arrangements are confirmed in the course information supplied during enquiry. Sorinteq will provide the relevant awarding and recognition details before enrolment.
Modern cyber reconnaissance increasingly requires practitioners to operate at scale, manage complex datasets, and identify subtle digital footprints across multiple platforms and infrastructures. At advanced levels, success depends on the ability to combine technical expertise, analytical judgement, and investigative tradecraft.
In advanced digital investigations and Technical Equipment Interference (TEI) operations, the ability to identify, attribute, and verify subjects through network interaction is a critical capability. Controlled infrastructure and specialist tooling can provide valuable intelligence opportunities where traditional investigative methods are limited.
In modern cyber-enabled and cyber-dependent investigations, critical intelligence and evidential opportunities are often contained within active online accounts rather than on physical devices alone. Email platforms, messaging services, social media accounts, cloud storage, and digital identities can provide decisive insight into criminality, intent, associations, and operational planning.
Cyber reconnaissance is a critical capability in modern intelligence, security, and investigative operations. As platforms, data volumes, and adversary techniques evolve, OSINT practitioners must move beyond purely manual and browser-based methods.
Linux is one of the most widely used operating systems in cyber security, digital investigations, intelligence operations, and technical research environments. Many investigative tools, automation platforms, and secure operational environments rely on Linux-based systems and command-line functionality.
As we move through the modern digital world, we are constantly surrounded by radio signals. Smartphones, Wi-Fi networks, Bluetooth devices, the Internet of Things (IoT), GPS, and near field communication (NFC) systems continuously interact with the radio frequency (RF) spectrum, often leaving behind valuable digital traces.
As digital investigations become increasingly complex, cyber reconnaissance practitioners must move beyond tool usage and begin to understand how to shape, adapt, and build investigative capability through code.
Modern investigations increasingly require the ability to lawfully obtain intelligence and evidential opportunities directly from digital devices and systems used by subjects of interest. Where conventional investigative methods are limited, Targeted Equipment Interference (TEI) provides a specialist capability to support operational objectives.