Cybersecurity Reach Foundation
OPSEC Framework

L.A.Y.E.R.S

A practical six-step framework for investigators, researchers, and anyone who needs to protect themselves while working online. Each layer reduces your exposure — together, they make you a much harder target.

L

Limit Your Exposure

Use a fresh browser profile with no personal logins or extensions, and minimize your fingerprint before any research session begins.

Key Steps

  • Create a dedicated browser profile used only for research
  • Disable or remove all personal extensions
  • Never sign into personal accounts in your research environment
A

Anonymize Your Connection

Hide your real IP by routing through a VPN or Tor Browser, then verify anonymity with leak tests before proceeding.

Key Steps

  • Use a reputable no-log VPN or Tor for sensitive investigations
  • Run a DNS leak test after connecting — VPNs can leak even when 'on'
  • Confirm your visible IP matches your VPN exit node, not your ISP
Y

Yank Out Metadata

Images, PDFs, and documents carry hidden data — device names, GPS coordinates, author info. Strip it before sharing or using files in research.

Key Steps

  • Check all files received from unknown sources before opening
  • Strip metadata from your own files before publishing or submitting
  • GPS data in photos can pinpoint your exact location — always check
E

Establish Separation

Keep your research identity completely isolated from your real one. Overlap between accounts and devices is how investigators get burned.

Key Steps

  • Use burner email addresses for research account sign-ups
  • Run investigations inside a dedicated VM or isolated browser environment
  • Never use your real name, phone number, or primary email for research accounts
R

Research Safely

Investigate targets indirectly. Never load unknown sites or execute scripts in your real browser — use purpose-built tools that fetch content on your behalf.

Key Steps

  • Submit suspicious URLs to URLscan or VirusTotal before visiting
  • Use web archives to view pages without hitting live servers
  • WHOIS and passive DNS can reveal infrastructure without direct contact
S

Secure Your Environment

Your device is the last line of defense. Keep it hardened, encrypted, and clean — especially after a session ends.

Key Steps

  • Keep your OS and tools updated — unpatched systems are low-hanging fruit
  • Enable MFA on every account tied to your research identity
  • Encrypt research files and wipe VM snapshots or temp data when done

Apply these layers before every session.

OPSEC isn't a one-time setup — it's a habit. Run through the checklist before each investigation and after. The goal is to leave no trace that connects your research to your real identity.