Popular searches
Hamburger Menu
//

OSINT: identify your attack surfaces before attackers do

Open Source Intelligence (OSINT) is the structured analysis of publicly available information about your company – from DNS records and exposed systems to employee footprints. In short: we show you what attackers can already see. And what you should secure first.

Illustration: 3 Personen und Hund in relaxter Bürosituation, davor Ritter, der mit Schild einen Drachen abwehrt.
//

OSINT: what the internet reveals about your company

Sounds abstract? It isn't. What we see in practice: most companies have blind spots – not because they're careless, but because no one is systematically looking from the outside in.

The problem: lack of transparency into your external atteack surface

Your company leaves traces everywhere: DNS records, decommissioned legacy systems, code snippets in repositories, metadata in documents. Individually, these pieces of information seem harmless. But when correlated cleverly, they give hackers a perfect roadmap for a targeted attack.

The difficulty: without a systematic Open Source Intelligence analysis, you don't know which doors are actually open. That makes meaningful vulnerability management nearly impossible.

The solution: our structured OSINT analysis

We look at your company through a hacker's eyes. Through our structured collection and analysis of public sources, we uncover which systems, data, and organizational connections are externally visible – without any active interference with your infrastructure.

//

Our OSINT services

How your OSINT analysis works

  1. OSINT assessment: We gain visibility into publicly available information and evaluate your external attack surface.
  2. Structured summary: You receive a written summary of all relevant information we identified about your company online, including a criticality assessment.
  3. Debrief: We walk through the findings together and put them into practical context.
  4. Prioritized recommendations: You get concrete actions you can implement step by step – independently or together with us.
  5. Optional ongoing support: If needed we can support you beyond the initial OSINT analysis – flexibly ranging from targeted assistance to ongoing advisory.

//

Your value: security through visibility

OSINT isn't a theoretical concept. It delivers measurable results for your IT operations:

//

Visibility into public information – with OSINT

Marc Lenze

IT Security Business Development Lead

Forgotten subdomains, leaked data, open test systems. We find these in almost every OSINT project. External vulnerabilities – such as subdomains abused for phishing – often go undetected for a long time and are deliberately exploited by attackers.
Let's take a look together at what's visible on your end.

Marc Lenze

IT Security Business Development Lead

//

What does OSINT look like in practice?

Imagine this: A medium-sized software company is about to launch a new customer platform. Its internal IT infrastructure is well-established: firewalls, security mechanisms, and established processes are in place. Before the go-live, our team conducts an OSINT analysis to uncover potential risks beyond the scope of traditional security audits.

In the process, our analysts come across several pieces of seemingly harmless information:

  • Code snippets: A public repository contains code that was accidentally uploaded – including an internal hostname: “dev-stage-04.firma.de.”
  • DNS entries: Historical DNS queries show that this subdomain still points to a cloud IP address, even though the system should actually be shut down.
  • Certificate Transparency: Public certificate logs confirm that the test system is still accessible online.
  • Social Media: An employee posts a photo from the office on LinkedIn. In the background, a monitor is visible displaying a dashboard that reveals the database version being used.

It is only the combination of this information that reveals the actual risk.

A publicly accessible test system outside the company’s firewall – with outdated software and a potential attack surface.

The company’s production systems are secure. The forgotten test system, however, could serve as an entry point for attackers – even before the platform goes live.

The preventive measures are clear:

  • Isolate the cloud instance and clean up the public repository
  • Integrate secret scanning and code reviews into the development workflow
  • Raise employee awareness about the secure use of social media

This example illustrates why OSINT is an important component of modern IT security today:
Risks arise not only within a company’s own infrastructure, but often from publicly visible information outside the company’s boundaries.

//

Frequently asked questions about OSINT

Can my systems be compromised during the analysis?
No. OSINT analyses are conducted exclusively passively. This means we do not actively interact with your systems and do not perform any scans or attacks. Only publicly available information is analyzed.
What do I receive at the end of the analysis?
You'll receive a structured report covering all relevant findings along with prioritized recommendations. We then walk through the results together in a debrief and put them into practical context.
When is an OSINT analysis worth it?
An OSINT analysis is worthwhile for any company. In the digital world, publicly visible information is continuously generated and, if left unmonitored, can turn into security or reputational risks.
How can OSINT be integrated into existing security processes?
OSINT complements existing processes by identifying risks from publicly available sources at an early stage. This makes it a key component of your cyber resilience: it supports incident response, threat intelligence, and vulnerability management, helping you prioritize security measures effectively.
How does OSINT differ from Attack Surface Management (ASM)?
OSINT is a methodology – the systematic analysis of publicly available information, applicable across many areas such as threat intelligence, research, and security analysis. ASM is an ongoing process that specifically identifies and monitors an organization's exposed attack surface. OSINT techniques are often a core component within ASM, though ASM on its own only covers a subset of what OSINT makes possible.

Let's take a look through the hacker's eyes

Reach out and we'll show you in an initial call where your biggest blind spots are.

Marc Lenze

IT-Security Business Development Lead

Marc Lenze

IT-Security Business Development Lead