OSINT: identify your attack surfaces before attackers do
Open source intelligence (OSINT) is the structured analysis of publicly available information about your company – from DNS records and exposed systems to employee footprints. In short: we show you what attackers can already see. And what you should secure first.
OSINT: what the internet reveals about your company
Sounds abstract? It isn't. What we see in practice: most companies have blind spots – not because they're careless, but because no one is systematically looking from the outside in.
The problem: lack of transparency into your external attack surface
Your company leaves traces everywhere: DNS records, decommissioned legacy systems, code snippets in repositories, metadata in documents. Individually, these pieces of information seem harmless. But when correlated cleverly, they give hackers a perfect roadmap for a targeted attack.
The difficulty: without a systematic open source intelligence analysis, you don't know which doors are actually open. That makes meaningful vulnerability management nearly impossible.
The solution: our structured OSINT analysis
We look at your company through hacker's eyes. With our structured collection and analysis of public sources, we uncover which systems, data, and organizational connections are externally visible – without any active interference with your infrastructure.
Our OSINT services
How your OSINT analysis works
- OSINT assessment: We gain visibility into publicly available information and evaluate your external attack surface.
- Structured summary: You receive a written summary of all relevant information we identified about your company online, including a criticality assessment.
- Debrief: We walk through the findings together and put them into practical context.
- Prioritized recommendations: You get concrete actions you can implement step by step – independently or together with us.
- Optional ongoing support: If needed we can support you beyond the initial OSINT analysis – flexibly ranging from targeted assistance to ongoing advisory.
Your value: security through visibility
OSINT isn't a theoretical concept. It delivers measurable results for your IT operations:
Visibility into public information – with OSINT
What does OSINT look like in practice?
Imagine this: A medium-sized software company is about to launch a new customer platform. Its internal IT infrastructure is well-established: firewalls, security mechanisms, and established processes are in place. Before the go-live, our team conducts an OSINT analysis to uncover potential risks beyond the scope of traditional security audits.
In the process, our analysts come across several pieces of seemingly harmless information:
- Code snippets: A public repository contains code that was accidentally uploaded – including an internal hostname: “dev-stage-04.firma.de.”
- DNS entries: Historical DNS queries show that this subdomain still points to a cloud IP address, even though the system should actually be shut down.
- Certificate transparency: Public certificate logs confirm that the test system is still accessible online.
- Social media: An employee posts a photo from the office on LinkedIn. In the background, a monitor is visible displaying a dashboard that reveals the database version being used.
It is only the combination of this information that reveals the actual risk.
A publicly accessible test system outside the company’s firewall – with outdated software and a potential attack surface.
The company’s production systems are secure. The forgotten test system, however, could serve as an entry point for attackers – even before the platform goes live.
The preventive measures are clear:
- Isolate the cloud instance and clean up the public repository
- Integrate secret scanning and code reviews into the development workflow
- Raise employee awareness about the secure use of social media
This example illustrates why OSINT is an important component of modern IT security today:
Risks arise not only within a company’s own infrastructure, but often from publicly visible information outside the company’s boundaries.
Frequently asked questions about OSINT
Let's take a look through hacker's eyes.
Reach out and we'll show you in an initial call where your biggest blind spots are.
IT-Security Business Development Lead
Marc Lenze
IT-Security Business Development Lead