OSINT
OSINT (Open Source Intelligence) is the practice of collecting and analyzing publicly available information about a target (organization, domain, person, or asset) without touching the target directly. The goal is to map the attack surface and human footprint that an adversary could exploit, before any active testing begins.
What we assess
Coverage areas included in this engagement. Select a topic for methodology depth and business impact.
| Topic | Summary |
|---|---|
| Core Concepts | OSINT (Open Source Intelligence) is the practice of collecting and analyzing publicly available information about a target (organization, domain, person, or asset) without touching the target directly. The goal is to map the attack surface and human footprint that an adversary c… |
| Dark Web | We validate this area during scoped assessments, documenting impact and remediation guidance. |
| Information Gathering | We validate this area during scoped assessments, documenting impact and remediation guidance. |
| Online Sources | We validate this area during scoped assessments, documenting impact and remediation guidance. |
| Social Engineering | We validate this area during scoped assessments, documenting impact and remediation guidance. |
| Verification | We validate this area during scoped assessments, documenting impact and remediation guidance. |
How we run it
Documented phases aligned to industry frameworks. Every step produces evidence your engineering team can replay.
Information Gathering
- [ ] Clearly define the objectives and scope of the OSINT investigation. - [ ] Ensure compliance with legal and ethical guidelines. - [ ] Respect privacy and t
- Clearly define the objectives and scope of the OSINT investigation.
- Ensure compliance with legal and ethical guidelines.
- Respect privacy and terms of service.
- Identify the target(s) or subject(s) of the investigation.
Online Sources
- [ ] Explore relevant forums, discussion boards, and online communities. - [ ] Look for blogs and personal websites related to the target. - [ ] Search for new
- Explore relevant forums, discussion boards, and online communities.
- Look for blogs and personal websites related to the target.
- Search for news articles or mentions related to the target.
- Access public records, such as property records, court documents, and business registrations.
- Use WHOIS databases to gather information about domain registrations.
- Enumerate DNS records to identify subdomains and related services.
- Search for email addresses associated with the target.
Social Engineering
- [ ] Use ethical phishing techniques to gather information (obtain informed consent). - [ ] Attend events, conferences, or gatherings where the target may be p
- Use ethical phishing techniques to gather information (obtain informed consent).
- Attend events, conferences, or gatherings where the target may be present.
Dark Web
- [ ] If relevant, monitor dark web marketplaces and forums for mentions of the target. - [ ] Explore Tor network (.onion) sites for hidden information.
- If relevant, monitor dark web marketplaces and forums for mentions of the target.
- Explore Tor network (.onion) sites for hidden information.
Verification
- [ ] Verify information from multiple sources to ensure accuracy. - [ ] Assess the reliability and credibility of information sources.
- Verify information from multiple sources to ensure accuracy.
- Assess the reliability and credibility of information sources.
Certification spotlight
Our operators hold industry-recognized offensive security credentials. For this engagement we lean on the certification below.
Primary certification
PenTest+
CompTIA
Why this matters for your engagement
CompTIA PenTest+ validates hands-on offensive methodology across networks, applications, and cloud targets. We apply this framework to scope, execute, and report findings with reproducible evidence your engineering team can action.
Risk areas we cover
High-level risk themes for this engagement. Cards with an arrow open the matching topic page.
Core Concepts
OSINT (Open Source Intelligence) is the practice of collecting and analyzing publicly available information about a target (organization, domain, person, or asset) without touching the target directly. The goal is to map the attack surface and human footprint that an adversary c…
Dark Web
We validate this area during scoped assessments, documenting impact and remediation guidance.
Information Gathering
We validate this area during scoped assessments, documenting impact and remediation guidance.
Online Sources
We validate this area during scoped assessments, documenting impact and remediation guidance.
Social Engineering
We validate this area during scoped assessments, documenting impact and remediation guidance.
Verification
We validate this area during scoped assessments, documenting impact and remediation guidance.
What you receive
Every engagement concludes with actionable output your security and engineering teams can operationalize.
Findings report
Documented vulnerabilities with severity ratings, affected assets, and reproducible evidence your team can action.
Remediation guidance
Prioritized recommendations mapped to risk and effort, with clear ownership for engineering and operations teams.
Retest scope
Defined retest window for critical and high findings so you can confirm fixes before auditors or leadership review.
Compliance and trust
Findings are mapped to severity frameworks and can support SOC 2, ISO 27001, HIPAA, and GDPR evidence requests. Review our security practices and subprocessors in the Trust Center.