Reconnaissance & OSINT: we analyse what can be found publicly about your company, your employees and your systems. Purely passive, without a single access to your infrastructure.
Noise out, connections in: for every IP, every host and every finding we explain why it matters to you.
Risk rating, prioritisation and concrete recommendations instead of a list of data.
Tokens, logins or session IDs that turn up on GitHub, in pastebins or in public archives.
Old hosts, development instances and unsecured services that should have been taken offline long ago.
Roles, tools, presentations and document metadata that make precisely targeted pretexts possible.
Typosquatting domains that are being prepared for phishing campaigns or for fraud in your name.
Entries in public dumps that give away password reuse and account takeovers.
Plans, photos and geodata from which your physical security measures can be read off.
A complete picture of your domains, subdomains, systems and digital traces
Every finding documented with screenshot, timestamp and exact location
A risk rating with prioritisation: what would an attacker make use of first?
Concrete recommendations, including removal requests to third parties and awareness measures
Tools such as SpiderFoot or theHarvester deliver lots of data and just as many false positives. Our work starts after that: we cluster, verify manually, use advanced Google dorking and search paste sites and forums in a targeted way. We also include historical snapshots from the Wayback Machine, because earlier versions of your website often give away more than the one online today.
No active scan and no access to your systems. If you want to see vulnerabilities exploited, you also need an Infrastructure or Web-App Pentest.
No guarantee of completeness: we find what is publicly available at the time of the analysis. What leaks tomorrow, nobody can see today.
No removal by us. We document the locations so that you can file removal requests with third parties yourself.
The results feed straight into other modules: better pretexts for social engineering, hidden endpoints for the Web-App Pentest, known vulnerabilities for the Infrastructure Pentest and the preparation of a Physical Pentest. That is why we recommend OSINT as the base module for every assessment.
No. We do not access your infrastructure, we analyse third-party sources instead. Since there are no requests to your servers, there are no alerts in your firewall or IDS either.
Up to date on the day of the analysis. We also include historical data, for example from the Wayback Machine, because the internet forgets nothing.
Indirectly, yes. A freshly registered lookalike domain can be blocked before the phishing wave gets going. A leaked admin password can be changed before someone uses it in a credential stuffing attack. OSINT gives you exactly that head start.
Yes. Geodata, satellite images and photos from social media or job portals often reveal locking systems, camera types, supplier entrances or even employee badges. This shows how well a break-in could be prepared remotely.
Yes. Publicly readable S3 buckets and Azure Blobs are part of the standard scope, as are subdomain enumeration and the analysis of Certificate Transparency logs.
Publicly accessible PDFs often carry printer names, software versions and local paths in their file header. From that, one can work out what you use internally.
In a free initial call we clarify scope and questions. After that you receive a written proposal.