Skip to main content

Service

OSINT Assessments

What an attacker can learn about you before touching a single system.

Targeted attacks begin with research, and the research is free. Before anyone sends a message or probes a host they know your staff names, your email format, your suppliers, your technology and often your internal processes, all from sources you published. This engagement does that research and hands you the result, which is normally the first time an organisation sees itself the way an attacker does.

How this works

People and structure

Who works there, in what roles, reporting to whom, and which of them are worth impersonating or targeting. Public profiles, conference talks, job adverts and press releases assemble an organisational chart, and job adverts in particular are unusually generous: they name the exact technologies, versions and tooling a team runs.

Technical footprint

Domains and subdomains from certificate transparency and passive DNS, cloud resources, mail configuration, and the technology fingerprint of what is exposed. This regularly surfaces hosts the organisation had forgotten, which are the ones nobody is patching.

Leaked and exposed material

Credentials appearing in breach corpora against your domains, secrets committed to public repositories, internal documents indexed by search engines, and files in misconfigured storage. Anything found is reported to you and not retained beyond what is needed to evidence the finding.

What it enables, not just what exists

A list of exposures is a starting point. The report explains the attack each exposure enables: this email format plus these names plus this supplier relationship produces a credible pretext, and this forgotten host plus this technology version produces an entry point.

What we look for

  • Staff names, roles and reporting lines assembled from public sources
  • Email address format, and which addresses are already public
  • Subdomains and hosts absent from your own inventory
  • Technologies, versions and tooling named in job adverts and engineering blogs
  • Credentials for your domains appearing in known breach data
  • Secrets and internal references in public code repositories
  • Documents indexed by search engines that were never intended to be
  • Supplier and partner relationships usable as a pretext, since a message from a real supplier defeats reputation-based filtering

What you get

  • The picture an attacker would assemble, presented as they would use it
  • Each exposure tied to the specific attack it enables
  • A removal and reduction list, ordered by what actually reduces risk rather than by what is easiest to delete
  • Sources for every finding, so anything you dispute can be checked

What this does not include

  • Any interaction with your systems: this is passive collection only
  • Purchasing data from criminal marketplaces
  • Investigation of individuals' personal lives beyond what is professionally relevant to the organisation
  • Takedown services, though the report identifies what should be removed and where

Questions people ask

Is this legal?
Everything collected is publicly available and gathered passively, with no access to your systems and no interaction with anyone. The engagement is scoped to the organisation rather than to individuals' private lives, and material about staff is limited to what is professionally relevant.
We are a small company. Is there anything to find?
Usually more, proportionally. Smaller organisations publish the same job adverts and use the same public repositories with less review, and are less likely to have anyone monitoring what leaves. The volume is smaller and the density is often higher.
What do we do with the results?
Some of it is removable and some is not, and the report separates them. Staff names and technology choices are largely unremovable, so those inform the pretexts to train against. Leaked credentials, exposed documents and forgotten hosts are actionable immediately.