Offensive security assessments
Information Gathering
We validate this area during scoped assessments, documenting impact and remediation guidance.
Why it matters
- [ ] Clearly define the objectives and scope of the OSINT investigation. - [ ] Ensure compliance with legal and ethical guidelines. - [ ] Respect privacy and terms of service. - [ ] Identify the target(s) or subject(s) of the investigation.
How we test it
Our operators follow a structured checklist for this topic, adapted to your API surface and authentication model.
Testing approach
- Structured validation of Information Gathering during scoped assessment.
- Evidence captured with reproducible steps for your engineering team.
What we look for
- Misconfigurations and control gaps related to Information Gathering.
- Exploitable paths that could affect confidentiality, integrity, or availability.
Engagement checklist
Items we validate during scoping and execution for this topic.
What we assess
- Clearly define the objectives and scope of the OSINT investigation.
- Ensure compliance with legal and ethical guidelines.
- Respect privacy and terms of service.
- Identify the target(s) or subject(s) of the investigation.
Related topics
| Topic | Summary |
|---|---|
| Core Concepts | OSINT (Open Source Intelligence) is the practice of collecting and analyzing publicly available information about a target (organization, domain, person, or asset) without touching the target directly. The goal is to map the attack surface and human footprint that an adversary c… |
| Dark Web | We validate this area during scoped assessments, documenting impact and remediation guidance. |
| Online Sources | We validate this area during scoped assessments, documenting impact and remediation guidance. |
| Social Engineering | We validate this area during scoped assessments, documenting impact and remediation guidance. |
| Verification | We validate this area during scoped assessments, documenting impact and remediation guidance. |