Services Who We Are Resources Success Stories Contact Speak to a consultant
OSINT & Cyber Investigations

See your footprint the way an attacker does.

Before an attacker ever touches your network, they build a picture of it: domains, exposed services, leaked credentials, cloud storage left open, employee details scattered across breach data. None of this requires them to interact with a single live system, and none of it requires your permission. We reproduce that reconnaissance under controlled conditions, and provide investigative support when something has already happened.

TYPE
Black Box

Zero disclosure

TURNAROUND
7 Days

Retesting not required

APPROACH
Passive

Entirely non-intrusive

What the review covers

Nine assessment areas, all passive and non-intrusive

No live systems are engaged. We gather only what is already publicly available.

01

Domains and subdomains

Mapping every domain and subdomain tied to the organisation, including forgotten or shadow assets.

02

DNS and infrastructure enumeration

Resolving DNS records and hosting infrastructure to build a picture of what is externally reachable.

03

Certificate transparency log review

Mining public CT logs for certificates that reveal hidden hosts and internal naming conventions.

04

Cloud asset exposure checks

Searching for misconfigured or forgotten cloud storage, buckets and services left publicly accessible.

05

Publicly accessible services discovery

Identifying externally facing services and applications visible without authentication.

06

Technology stack fingerprinting

Profiling the software, frameworks and versions in use to flag known vulnerabilities.

07

Metadata leakage assessment

Extracting metadata from public documents and files that can reveal usernames, software and internal paths.

08

Public credential exposure and dark net assessment

Checking for exposed credentials and mentions across paste sites and dark web sources, where legally accessible.

09

Historical breach data review

Cross-referencing employee and domain data against known breach datasets, where lawfully available.

Passive by design, and stated as such. Because no live system is engaged, some findings cannot be confirmed without active testing. Where that is the case the report says so explicitly, and recommends penetration testing to verify the finding and rule out false positives.

Cyber investigations

Reactive support when something has already happened

Not every engagement is proactive. When an organisation or individual is already dealing with online harassment, a targeted intrusion, or a suspected compromise, the priority shifts from finding exposure to understanding what has actually occurred.

ONLINE HARASSMENT & TARGETED ATTACKS

Investigative support to understand who is behind a targeted campaign and put a plan in place to address it, with clear communication throughout.

SUSPECTED COMPROMISE

Establishing what happened, what was accessed, and what needs to be done next, brought together with the same evidence-first approach as every other engagement.

If it needs to be found, we find it. Cyber investigations get the same intensity as every other engagement we run: manual, evidence-first, and pursued until you have an answer you can act on, not just a summary of what is still unclear.

Common questions

What people ask before an OSINT review or investigation

What is an OSINT review?

Open-Source Intelligence review is a passive, non-intrusive assessment of your organisation's publicly exposed digital footprint: domains, exposed services, leaked credentials, cloud storage left open and breach data, run the way an attacker would during reconnaissance.

Do you need access to our systems to run an OSINT review?

No. The review is entirely passive and non-intrusive. No live systems are engaged and no access, credentials or internal information are required.

What is a cyber investigation?

Reactive investigative support when something has already happened: online harassment, targeted intrusion, or a suspected compromise, where you need to understand what occurred and who may be responsible.

How long does an OSINT review take?

A standard OSINT review turns around in seven days. Investigative engagements are scoped individually depending on the nature of the incident.

Get started

Find out what you're already showing

An OSINT review needs no access, no credentials and no downtime. If you're already dealing with an incident, tell us what's happened and we'll scope the right response.

Book a scoping call with our team

Confidential, and handled with discretion from the first conversation.

+44 20 7862 3837 [email protected] cyberarmedsecurity.com