What attackers know about you before they attack

Reconnaissance & OSINT: we analyse what can be found publicly about your company, your employees and your systems. Purely passive, without a single access to your infrastructure.

  • No scan of your systems
  • Every finding with source and timestamp
  • The foundation for every further test

How open sources turn into a rated report

Scope Domains, IP ranges, brand terms, roles of your employees, platforms
1 · Passive information gathering
  • Search engines
  • Certificate Transparency logs
  • GitHub
  • Shodan / Censys
  • Archive.org
  • Social media
  • Pastebins
  • Leak dumps
  • Job portals
  • Geodata and photos
2 · Clustering and manual verification

Noise out, connections in: for every IP, every host and every finding we explain why it matters to you.

3 · Rated report

Risk rating, prioritisation and concrete recommendations instead of a list of data.

What we typically find

Credentials

Credentials and API keys

Tokens, logins or session IDs that turn up on GitHub, in pastebins or in public archives.

Subdomains

Forgotten systems

Old hosts, development instances and unsecured services that should have been taken offline long ago.

Employees

Material for phishing

Roles, tools, presentations and document metadata that make precisely targeted pretexts possible.

Domains

Lookalike domains

Typosquatting domains that are being prepared for phishing campaigns or for fraud in your name.

Leaks

Leaked passwords

Entries in public dumps that give away password reuse and account takeovers.

Physical

Site and building information

Plans, photos and geodata from which your physical security measures can be read off.

What you have in hand at the end

  • A complete picture of your domains, subdomains, systems and digital traces

  • Every finding documented with screenshot, timestamp and exact location

  • A risk rating with prioritisation: what would an attacker make use of first?

  • Concrete recommendations, including removal requests to third parties and awareness measures

What happens when nobody is looking

  • Leaked passwords lead to account takeovers
  • Attackers quietly gather information about your employees
  • Old subdomains become entry points for exploits
  • Lookalike domains enable deceptively real phishing
  • Exposed systems stay undiscovered for months
  • Exposed documents hand internal structures to attackers

Who this is worth it for

  • Companies that want to know how an attacker sees them before a pentest or red teaming
  • Organisations with many domains, sites or shadow IT that has grown over the years
  • Teams that want to assess the phishing and social engineering risks of their workforce
  • Operators who need to protect their brand against lookalike domains and misuse

People, not tool exports

Tools such as SpiderFoot or theHarvester deliver lots of data and just as many false positives. Our work starts after that: we cluster, verify manually, use advanced Google dorking and search paste sites and forums in a targeted way. We also include historical snapshots from the Wayback Machine, because earlier versions of your website often give away more than the one online today.

What this analysis is not

  • No active scan and no access to your systems. If you want to see vulnerabilities exploited, you also need an Infrastructure or Web-App Pentest.

  • No guarantee of completeness: we find what is publicly available at the time of the analysis. What leaks tomorrow, nobody can see today.

  • No removal by us. We document the locations so that you can file removal requests with third parties yourself.

Strongest in combination

The results feed straight into other modules: better pretexts for social engineering, hidden endpoints for the Web-App Pentest, known vulnerabilities for the Infrastructure Pentest and the preparation of a Physical Pentest. That is why we recommend OSINT as the base module for every assessment.

Frequently asked questions

Will our admins notice the analysis?

No. We do not access your infrastructure, we analyse third-party sources instead. Since there are no requests to your servers, there are no alerts in your firewall or IDS either.

How current are the results?

Up to date on the day of the analysis. We also include historical data, for example from the Wayback Machine, because the internet forgets nothing.

Can this help us stop attacks before they start?

Indirectly, yes. A freshly registered lookalike domain can be blocked before the phishing wave gets going. A leaked admin password can be changed before someone uses it in a credential stuffing attack. OSINT gives you exactly that head start.

Do you also look at our sites?

Yes. Geodata, satellite images and photos from social media or job portals often reveal locking systems, camera types, supplier entrances or even employee badges. This shows how well a break-in could be prepared remotely.

Do you also find files in cloud storage that has been misconfigured?

Yes. Publicly readable S3 buckets and Azure Blobs are part of the standard scope, as are subdomain enumeration and the analysis of Certificate Transparency logs.

What do the metadata in our documents give away?

Publicly accessible PDFs often carry printer names, software versions and local paths in their file header. From that, one can work out what you use internally.

Do you want to know how an attacker sees you?

In a free initial call we clarify scope and questions. After that you receive a written proposal.