Offensive security assessments

Online Sources

We validate this area during scoped assessments, documenting impact and remediation guidance.

Why it matters

- [ ] Explore relevant forums, discussion boards, and online communities. - [ ] Look for blogs and personal websites related to the target. - [ ] Search for news articles or mentions related to the target. - [ ] Access public records, such as property records, court documents, and business registrations. - [ ] Use WHOIS databases to gather information about domain registrations. - [ ] Enumerate DNS records to identify subdomains and related services. - [ ] Search for email addresses associated with the target.

How we test it

Our operators follow a structured checklist for this topic, adapted to your API surface and authentication model.

Testing approach

  • Structured validation of Online Sources during scoped assessment.
  • Evidence captured with reproducible steps for your engineering team.

What we look for

  • Misconfigurations and control gaps related to Online Sources.
  • Exploitable paths that could affect confidentiality, integrity, or availability.

Engagement checklist

Items we validate during scoping and execution for this topic.

What we assess

  • Explore relevant forums, discussion boards, and online communities.
  • Look for blogs and personal websites related to the target.
  • Search for news articles or mentions related to the target.
  • Access public records, such as property records, court documents, and business registrations.
  • Use WHOIS databases to gather information about domain registrations.
  • Enumerate DNS records to identify subdomains and related services.
  • Search for email addresses associated with the target.

Related topics

TopicSummary
Core ConceptsOSINT (Open Source Intelligence) is the practice of collecting and analyzing publicly available information about a target (organization, domain, person, or asset) without touching the target directly. The goal is to map the attack surface and human footprint that an adversary c…
Dark WebWe validate this area during scoped assessments, documenting impact and remediation guidance.
Information GatheringWe validate this area during scoped assessments, documenting impact and remediation guidance.
Social EngineeringWe validate this area during scoped assessments, documenting impact and remediation guidance.
VerificationWe validate this area during scoped assessments, documenting impact and remediation guidance.