Offensive security assessments

Core Concepts

OSINT (Open Source Intelligence) is the practice of collecting and analyzing publicly available information about a target (organization, domain, person, or asset) without touching the target directly. The goal is to map the attack surface and human footprint that an adversary c…

Why it matters

OSINT (Open Source Intelligence) is the practice of collecting and analyzing publicly available information about a target (organization, domain, person, or asset) without touching the target directly. The goal is to map the attack surface and human footprint that an adversary could exploit, before any active testing begins. Methodology - Scope and seed data: confirm authorized targets and gather starting points (company name, domains, key people, brands). - Passive collection: search engines, social media, public records, and metadata, leaving no trace on the target. - Infrastructure and footprint mapping: domains, subdomains, IP ranges, exposed services, certificates, and cloud assets. - People and credential exposure: employees, emails, usernames, roles, and breach/leak data tied to the org. - Leak and code search: paste sites, public repos, and document metadata for secrets or sensitive disclosure. - Triage and report: validate findings, remove noise, and prioritize what feeds the active assessment. What to look for - Externally exposed hosts, forgotten subdomains, and shadow IT not in official inventory. - Leaked credentials, API keys, and tokens in breaches, pastes, and source code. - Employee details usable for phishing or social engineering (emails, titles, tech stack hints). - Sensitive metadata in public documents (usernames, software versions, internal paths). - Misconfigured or public cloud storage and services tied to the organization.

How we test it

Our operators follow a structured checklist for this topic, adapted to your API surface and authentication model.

Testing approach

  • Structured validation of Core Concepts during scoped assessment.
  • Evidence captured with reproducible steps for your engineering team.

What we look for

  • Misconfigurations and control gaps related to Core Concepts.
  • Exploitable paths that could affect confidentiality, integrity, or availability.

Related topics

TopicSummary
Dark WebWe validate this area during scoped assessments, documenting impact and remediation guidance.
Information GatheringWe validate this area during scoped assessments, documenting impact and remediation guidance.
Online SourcesWe validate this area during scoped assessments, documenting impact and remediation guidance.
Social EngineeringWe validate this area during scoped assessments, documenting impact and remediation guidance.
VerificationWe validate this area during scoped assessments, documenting impact and remediation guidance.