Before an attacker ever touches your network, they build a picture of it: domains, exposed services, leaked credentials, cloud storage left open, employee details scattered across breach data. None of this requires them to interact with a single live system, and none of it requires your permission. We reproduce that reconnaissance under controlled conditions, and provide investigative support when something has already happened.
Zero disclosure
Retesting not required
Entirely non-intrusive
No live systems are engaged. We gather only what is already publicly available.
Mapping every domain and subdomain tied to the organisation, including forgotten or shadow assets.
Resolving DNS records and hosting infrastructure to build a picture of what is externally reachable.
Mining public CT logs for certificates that reveal hidden hosts and internal naming conventions.
Searching for misconfigured or forgotten cloud storage, buckets and services left publicly accessible.
Identifying externally facing services and applications visible without authentication.
Profiling the software, frameworks and versions in use to flag known vulnerabilities.
Extracting metadata from public documents and files that can reveal usernames, software and internal paths.
Checking for exposed credentials and mentions across paste sites and dark web sources, where legally accessible.
Cross-referencing employee and domain data against known breach datasets, where lawfully available.
Passive by design, and stated as such. Because no live system is engaged, some findings cannot be confirmed without active testing. Where that is the case the report says so explicitly, and recommends penetration testing to verify the finding and rule out false positives.
Not every engagement is proactive. When an organisation or individual is already dealing with online harassment, a targeted intrusion, or a suspected compromise, the priority shifts from finding exposure to understanding what has actually occurred.
Investigative support to understand who is behind a targeted campaign and put a plan in place to address it, with clear communication throughout.
Establishing what happened, what was accessed, and what needs to be done next, brought together with the same evidence-first approach as every other engagement.
If it needs to be found, we find it. Cyber investigations get the same intensity as every other engagement we run: manual, evidence-first, and pursued until you have an answer you can act on, not just a summary of what is still unclear.
Open-Source Intelligence review is a passive, non-intrusive assessment of your organisation's publicly exposed digital footprint: domains, exposed services, leaked credentials, cloud storage left open and breach data, run the way an attacker would during reconnaissance.
No. The review is entirely passive and non-intrusive. No live systems are engaged and no access, credentials or internal information are required.
Reactive investigative support when something has already happened: online harassment, targeted intrusion, or a suspected compromise, where you need to understand what occurred and who may be responsible.
A standard OSINT review turns around in seven days. Investigative engagements are scoped individually depending on the nature of the incident.
An OSINT review needs no access, no credentials and no downtime. If you're already dealing with an incident, tell us what's happened and we'll scope the right response.
Confidential, and handled with discretion from the first conversation.