Security · OSINT · Training July 2026

Building a Security Awareness App
with OSINT Challenges

Security awareness training is usually a boring annual video that everyone clicks through without reading. I wanted something different: a short, interactive quiz with real OSINT spotting challenges that also produces clean audit evidence. This is how I built Aegis.

The Problem with Awareness Training

Most security awareness training fails for the same reason: it is passive. People watch a slideshow, click next until it ends, and retain almost nothing. Meanwhile ISO 27001 control A.6.3 requires evidence that staff actually receive and engage with security awareness training. The typical solution satisfies the auditor on paper while doing very little to change behavior.

I wanted to solve both sides at once: make the training genuinely engaging, and produce clean, automatic evidence of completion that maps directly to the compliance requirement.

What Aegis Does

Aegis is a lightweight web app that runs a training round of ten questions. Each round mixes two visual OSINT scenes with eight practical multiple-choice questions, drawn at random with no repeats and with the answer order shuffled every time. The pass mark is 80%.

→
Visual OSINT scenes ask the user to spot what is wrong or revealing in an image: information leaking in the background of a photo, a suspicious detail in a message, the kind of thing an attacker would notice first.
→
Practical multiple-choice questions cover everyday security habits and light ISO 27001 knowledge, pulled from a bank of over a hundred items so repeat takers keep seeing fresh content.
→
Every question has a short explanation shown after answering, so the training teaches rather than just tests. A wrong answer is a learning moment, not just a lost point.
→
Pass or retry logic means a passing score can be saved as evidence, while a failing score only offers a retry with feedback on the topics to review.

The Compliance Angle

This is where the app earns its place beyond being a fun quiz. When a user passes, the result is written automatically to a Google Sheet that serves as ISO 27001 evidence for the awareness training control. Each row records who took it, when, the score, the result, and which topics they should review.

Crucially, only passing results at or above the 80% threshold are written, and that rule is enforced in two places: in the app's own backend and again in the script that writes to the sheet. Defense in depth, even for something this small. The result is a living, timestamped training register that an auditor can review at any time, generated with zero manual effort.

Why this matters The best compliance tooling is the kind where the evidence is a natural byproduct of a process people actually want to use. Nobody has to remember to log anything. The act of completing the training is the act of creating the record.

The Stack

The whole thing is deliberately lightweight. The frontend is React built with Vite, styled with a small design-token object rather than a heavy CSS framework. No local storage, no client-side database, no unnecessary dependencies.

→
React + Vite for a fast, self-contained single-page app with the OSINT scene engine, scoring logic, and theming all in one place.
→
Serverless function receives the result, re-checks the pass mark, and forwards valid results onward, so the pass threshold is never trusted from the client alone.
→
Google Apps Script web app acts as the write endpoint to the sheet, running under the owner account so the hosting platform never needs any Google permissions of its own.
→
Optional fallback store using a hosted Redis, used only if the sheet endpoint is unavailable, so a passing result is never silently lost.

Architecture Decisions Worth Noting

A few choices shaped the design. Keeping the pass-mark check on the server side, not just in the browser, means the threshold cannot be bypassed by editing client code. Having the Google Apps Script run under the owner account means the hosting platform holds no Google credentials at all, which keeps the security surface small. And separating the question bank into its own file means content can grow over time without touching the app logic.

Design principle A security tool should not itself be a security liability. Every integration point was chosen to minimize the credentials and permissions the system holds. The app writes evidence without ever having write access to anything sensitive on its own.

What's Next

The roadmap is about depth and realism. The visual scene engine already supports images with clickable hotspot regions, so the next step is replacing illustrative scenes with real phishing screenshots and realistic workspace photos, making the OSINT challenges sharper. Beyond that: growing the question bank further so frequent takers never run out of new material, and adding simple reporting so pass rates across the team can be seen at a glance.

The broader lesson from building Aegis is that compliance and engagement are not opposites. A training tool people actually enjoy using produces better security behavior and better audit evidence at the same time. You just have to build it so that the useful record falls out of the process naturally.