What is publicly findable about you
Domains, credentials from data breaches, metadata and what job adverts give away. Gathered without touching your systems.
What an attacker knows about you before they start
An OSINT analysis gathers what can be found about your company without a single access to your systems. OSINT stands for open source intelligence, the evaluation of open sources: domain names, certificate transparency logs, job adverts, published documents, profiles in networks, credentials from other people's data breaches.
The service appears twice with us, and that is not a contradiction. It is the first step of every external test, every red teaming and every social engineering exercise; there it decides where to start. And it is bookable on its own, when you first want to know how large your attack surface is at all.
We work exclusively passively. Your systems are not touched, there is no request that appears in your logs, and no release is needed for an access that does not happen.
Five sources that regularly yield something
The division follows what actually holds up in our analyses. Which source yields most in your case depends on sector and size.
Names and addresses
Domains and subdomains, entries in the certificate transparency logs, IP ranges and who owns them, DNS records. This is where the environments turn up that nobody thinks about any more: the test system from the year before last, the subdomain of a finished project.
Credentials from data breaches
Addresses of your company that appear in published data sets, along with the question of whether the password still works elsewhere. We name the accounts concerned, not passwords in the clear.
People and roles
Who works where, in what function, and to what pattern the email addresses are built. That is the basis of every pretext, and it therefore appears in a report that prepares no exercise.
Technology from public statements
Job adverts name the firewall in use with its version, tenders name the software landscape, talks name the architecture. This source is underestimated and is often the most productive.
Files, code and configuration
Metadata of published documents with user names and internal paths, public repositories with keys in the version history, open container registries.
The job advert that describes the maintenance access
An administrator is sought for a named firewall in a named version, experience with a particular VPN product desirable, a site with on-call duty. Three sentences, and the attack surface is described: the product, the version, the way in, and the fact that outside business hours somebody works remotely.
Alongside it a subdomain from the certificate transparency log that points at the same address and appears in no documentation, and an account from a four-year-old data breach whose password pattern matches the current scheme. All three are public, all three are found in a morning, and none of them leaves a trace with you.
Beside each, the report says what can be stopped. A job advert does not have to name the version; a subdomain nobody needs any more does not have to resolve.
A machine can gather; connecting is another matter
Tools deliver lists: subdomains, addresses, hits from data sets. We use them, among them our own, YekIntel. But the list is not the result; it is the material.
What counts is the connection: that the address from the breach belongs to the person whose role appears in the job advert, and that the remote maintenance named there runs on the subdomain nobody knows about any more. Each piece on its own sits low in any tool report. Together they are a way in.
So an analysis with us does not end with the list but with the connections inside it, and the rating follows what would have been reachable in the end.
How an OSINT analysis works
The effort follows the size of the company and the number of brands and sites. The work is passive throughout, with no access to your systems.
Fix the scope
Which brands, domains and legal entities belong to you. That is the question most often underestimated: subsidiaries, acquired companies and agencies bring addresses with them that cannot be told from yours from the internet.
Gather
Public registers, certificate transparency logs, DNS, published data sets, networks, job adverts, documents and public repositories. Tool-assisted, but read by hand.
Connect and assess
What belongs together, what is still valid, what is a route and what is only a find. Every item gets its source, so that you can check it.
Report
The finds with source and date, the connections between them, and per finding the way to stop it. On request as the basis for a test that follows.
A report your team can work from.
Every finding comes placed: with risk, effort and the route to a fix.
Management summary
The position on one page, readable for management and the board.
Finds with their source
Every item with source and date, so that you can check it yourself.
Risk rating to BSI
A traceable rating of every find against a recognised scheme.
Prioritised recommendations
Concrete recommendations in the order in which they take effect.
Closing meeting
On request, a joint walk-through of the results with your teams.
Repeat
On request, a fresh survey after an agreed period, compared against the last one.
What we need, and what is not included
From you we need the list of your brands, domains and legal entities, and a written engagement. Nothing more: there is no access to set up and no window to agree, because nothing happens to your systems.
Personal data is unavoidable in this: names, roles and addresses. We collect only what is publicly available and necessary for the engagement, build no profiles beyond that, and delete the working data on completion. That is in the contract, not only here.
Not included is every active step: no port scan, no login attempt, no phone call. What follows from the finds is tested by the external penetration test; whoever wants to approach the people found books social engineering or a phishing simulation. Over weeks and with an objective it becomes a red teaming engagement.
Common questions about OSINT analysis
No, and that is the point. The analysis reads what is publicly available and makes no request to your systems. Nothing of it appears in your logs. That is exactly how an attacker works before making the first visible move.
What we evaluate is published. We bypass no access control, sign in nowhere under a false name, and buy no data sets from doubtful sources. For credentials from known breaches we use services that name those affected without handing out passwords.
Then it is the first step within it and not a second invoice. On its own it is worth it when you want to know how large the attack surface is before commissioning, or when you want to watch regularly what has been added: after an acquisition, a new brand, a relaunch.
Once as a baseline, then annually or after every larger change: acquisitions, new sites, a change of service provider. Between the dates one thing changes regularly above all, namely the list of subdomains.
No. We name the accounts concerned and the source they come from, so that you can reset them specifically. Passwords in the clear do not belong in a report that then gets distributed by mail.
Certifications and memberships.
Talk to us.
A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.