OSINT: identify your attack surfaces before attackers do
Open Source Intelligence (OSINT) is the structured analysis of publicly available information about your company – from DNS records and exposed systems to employee footprints. In short: we show you what attackers can already see. And what you should secure first.
OSINT: what the internet reveals about your company
Sounds abstract? It isn't. What we see in practice: most companies have blind spots – not because they're careless, but because no one is systematically looking from the outside in.
The problem: lack of transparency into your external atteack surface
Your company leaves traces everywhere: DNS records, decommissioned legacy systems, code snippets in repositories, metadata in documents. Individually, these pieces of information seem harmless. But when correlated cleverly, they give hackers a perfect roadmap for a targeted attack.
The difficulty: without a systematic Open Source Intelligence analysis, you don't know which doors are actually open. That makes meaningful vulnerability management nearly impossible.
The solution: our structured OSINT analysis
We look at your company through a hacker's eyes. Through our structured collection and analysis of public sources, we uncover which systems, data, and organizational connections are externally visible – without any active interference with your infrastructure.
Our OSINT services
How your OSINT analysis works
- OSINT assessment: We gain visibility into publicly available information and evaluate your external attack surface.
- Structured summary: You receive a written summary of all relevant information we identified about your company online, including a criticality assessment.
- Debrief: We walk through the findings together and put them into practical context.
- Prioritized recommendations: You get concrete actions you can implement step by step – independently or together with us.
- Optional ongoing support: If needed we can support you beyond the initial OSINT analysis – flexibly ranging from targeted assistance to ongoing advisory.
Your value: security through visibility
OSINT isn't a theoretical concept. It delivers measurable results for your IT operations:
Visibility into public information – with OSINT
What does OSINT look like in practice?
Imagine this: A medium-sized software company is about to launch a new customer platform. Its internal IT infrastructure is well-established: firewalls, security mechanisms, and established processes are in place. Before the go-live, our team conducts an OSINT analysis to uncover potential risks beyond the scope of traditional security audits.
In the process, our analysts come across several pieces of seemingly harmless information:
- Code snippets: A public repository contains code that was accidentally uploaded – including an internal hostname: “dev-stage-04.firma.de.”
- DNS entries: Historical DNS queries show that this subdomain still points to a cloud IP address, even though the system should actually be shut down.
- Certificate Transparency: Public certificate logs confirm that the test system is still accessible online.
- Social Media: An employee posts a photo from the office on LinkedIn. In the background, a monitor is visible displaying a dashboard that reveals the database version being used.
It is only the combination of this information that reveals the actual risk.
A publicly accessible test system outside the company’s firewall – with outdated software and a potential attack surface.
The company’s production systems are secure. The forgotten test system, however, could serve as an entry point for attackers – even before the platform goes live.
The preventive measures are clear:
- Isolate the cloud instance and clean up the public repository
- Integrate secret scanning and code reviews into the development workflow
- Raise employee awareness about the secure use of social media
This example illustrates why OSINT is an important component of modern IT security today:
Risks arise not only within a company’s own infrastructure, but often from publicly visible information outside the company’s boundaries.
Frequently asked questions about OSINT
Let's take a look through the hacker's eyes
Reach out and we'll show you in an initial call where your biggest blind spots are.
IT-Security Business Development Lead
Marc Lenze
IT-Security Business Development Lead