OSINT – Open Source Intelligence

OSINT (Open Source Intelligence), which is open source intelligence, is the analysis of information available in open sources, aimed at identifying data that may be relevant to an organization’s security.

The analysis may include information about infrastructure, domains, technologies, employees, data leaks, and other elements of an organization’s digital footprint.

We check what information a potential attacker can find, how they can combine it, and how it can support further reconnaissance or attack preparation.

What does OSINT analysis involve?

OSINT analysis involves collecting, verifying, and combining information about an organization available from external sources.

A single piece of information often isn’t a problem. Only by combining data concerning employees, infrastructure, technologies, or business partners can a picture useful to an attacker be created.

OSINT therefore allows you to check what can be determined about an organization without gaining access to its internal systems.

What do we check during OSINT analysis?

The scope may include information about infrastructure, employees, domains, technologies, data leaks, and other elements of an organization’s digital footprint.

Depending on the project’s goal, we analyze, among other things:

  • internet-facing infrastructure – domains, subdomains, IP addresses, publicly available services, and information about technologies used,
  • information about employees and organizational structure – positions, contact details, and information useful for social engineering activities,
  • data and credential leaks related to the organization,
  • social media, forums, and other public sources where information about the company or its employees appears,
  • public registries and historical sources that may reveal additional connections or context,
  • sources related to leaks and cybercrime, if covered by the agreed project scope.

The goal is not merely to collect a large amount of data. The most important thing is to determine which information may be relevant from a security perspective and how it can be used in further reconnaissance.

How do attackers use OSINT?

OSINT is often used during the reconnaissance phase, which precedes the actual technical or social engineering attack.

Publicly available information can help determine what technologies a company uses, who is responsible for specific processes, or what infrastructure elements are visible from the Internet.

Data about employees, business partners, or current projects, in turn, can increase the credibility of phishing, spear phishing, or vishing.

OSINT analysis allows identifying some of this information before it is used against the organization.

How is OSINT analysis performed?

OSINT analysis includes defining the scope, collecting information, verifying and correlating it, and assessing its significance from a security perspective.

1. Defining the objective and scope

We determine whether the analysis should cover the entire organization, a specific area, infrastructure, or selected individuals.

2. Information collection and verification

We analyze open sources and identify information related to the organization and the defined project scope.

3. Data correlation

We combine information from various sources and check if, together, they can reveal additional context about the organization.

4. Exposure assessment

We assess which information can support further reconnaissance, social engineering activities, or attack scenario preparation.

What do you get after the analysis?

After OSINT analysis, you receive a summary of identified information, an assessment of its security relevance, and recommendations for reducing exposure.

The analysis results help to:

  • identify information available about the organization from external sources,
  • indicate data that may be useful during attack preparation,
  • define areas requiring exposure reduction,
  • plan further security-related actions.

Thanks to this, OSINT gives the organization a picture of what a person conducting reconnaissance might see before a potential attack.

When is it worth conducting OSINT analysis?

OSINT analysis is worth conducting when an organization wants to check its digital footprint and assess what information is available about it from an external perspective.

It is especially worth considering analysis:

  • before Red Teaming or social engineering tests,
  • after an incident or data breach,
  • after major organizational or technological changes,
  • as part of a periodic assessment of the organization’s exposure.

OSINT vs. Red Teaming and Penetration Tests

OSINT can be a standalone analysis, but it is also used as a reconnaissance element during Red Teaming and other offensive security activities.

In Red Teaming, information gathered during reconnaissance can help prepare a realistic scenario and identify potential entry points.

In penetration tests, OSINT can support the reconnaissance phase by gathering information about the target environment before commencing the actual technical tests.

The scope of the analysis depends on the project’s objective.

What sources are used in OSINT?

OSINT uses many open sources, including websites, social media, public registries, web archives, and technical data regarding infrastructure.

Depending on the scope of the analysis, specialized tools supporting infrastructure search and correlation analysis, such as Shodan, Censys, Maltego, or SpiderFoot, may also be used.

Tools support the analyst’s work, but the verification of information, its correlation, and assessment in the context of a specific organization are crucial.

FAQ

Is OSINT legal?

OSINT can be conducted legally if it relies on permitted sources and methods and is carried out in accordance with applicable regulations and data usage policies. OSINT analysis should not involve bypassing security measures or obtaining information unlawfully.

Does an OSINT analysis require access to the company’s systems?

OSINT analysis primarily focuses on information available from an external perspective. However, the project scope may require providing basic information needed to properly define the analyzed organization or environment.

Can OSINT analysis include specific employees?

Yes, if it results from the agreed project scope. The analysis may include, for example, individuals holding key positions or those particularly vulnerable to social engineering activities.

Does OSINT cover the dark web?

The scope of the analysis may include checking sources related to data leaks and cybercrime for information concerning the organization. The detailed scope is determined before the project begins.

How often should OSINT analysis be performed?

The frequency depends on the organization and changes in its environment. Analysis should be reconsidered after an incident, major organizational or technological changes, and as part of a periodic exposure assessment.

Can the information found through an OSINT analysis be restricted?

The possibility of limiting exposure depends on the source and type of information. The analysis results help identify areas where it is worth changing the way data is published, service configuration, or information management policies.

Inquire about OSINT analysis

Contact Details

TestArmy Group S.A. ul. Petuniowa 9/5 53-238 Wrocław Poland

Zgoda na przetwarzanie danych

Privacy policy acceptance

Testuj.pl jest teraz częścią CyberForces

Trafiasz tu z testuj.pl? Spokojnie, jesteś we właściwym miejscu. Po zmianach w naszych markach oferta szkoleń B2B oraz usług z obszaru cyberbezpieczeństwa jest dostępna na CyberForces.

Zespół pozostaje ten sam, zmieniło się miejsce, w którym znajdziesz naszą ofertę.