OSINT Cyber Investigations and SOC Support

OSINT cyber investigations give your SOC and incident response team the view from outside the network: who set up the attacking infrastructure, what else it connects to, what has leaked and where the attackers are talking about it. We work under your incident lead and hand over findings to act on and evidence for the police.

  • Infrastructure pivoting
  • Phishing kit and leak analysis
  • Ransomware leak-site observation
  • Evidence for law enforcement
Short answer

OSINT cyber investigations use public and commercially available data, such as domain records, certificate logs, hosting data, criminal forums and leak sites, to explain an attack your internal tools have already detected. They support SOC and incident response work by mapping attacker infrastructure, analyzing phishing kits and leaks, observing extortion sites and preparing evidence. They complement forensics on your own systems; they do not replace it.

What OSINT Cyber Investigations Add to a SOC

Your SOC sees what happened inside your environment; open-source investigation explains the attacker's side of the same event and what else they are running.

Telemetry tells you which host was touched and when. It rarely tells you who registered the phishing domain, which other brands the same kit targets, or whether your files are already on an extortion site. Those questions sit outside your perimeter.

NIST's current incident response recommendations are written as a Cybersecurity Framework 2.0 community profile, treating response as part of ongoing risk management rather than a one-off emergency (NIST SP 800-61 Rev. 3, April 2025). SOC OSINT investigations fit that cycle at three points: enriching an alert during triage, scoping the attacker's wider activity during response, and watching for follow-on activity after recovery.

Why Outside-In Investigation Matters in 2026

Attackers increasingly come in through vulnerabilities and suppliers, and extortion crews publish victims at record rates, so the evidence often sits outside your network.

  • For the first time in 19 years, vulnerability exploitation overtook stolen credentials as the main way in, starting 31% of breaches; third parties were involved in 48% (Verizon DBIR 2026).
  • Ransomware groups publicly posted 7,515 victims in 2025, up 58% on the year before, across 124 tracked groups (GuidePoint GRIT 2026).
  • The global average cost of a data breach reached $4.99 million (IBM 2026).

SOC OSINT Investigation Support We Provide

Six types of support, each tied to a question your incident lead needs answered.

Infrastructure

Infrastructure pivoting

From one domain, IP address or certificate to the wider set of servers, domains and accounts the attacker is using.

Phishing

Phishing kit analysis

How the kit works, where stolen data is sent, which other organizations it imitates and whether it is sold as a service.

Leaks

Leak and exposure analysis

Whether data claimed by an attacker is real, which system it probably came from and where it is being shared.

Dark web monitoring →
Extortion

Ransomware and extortion support

Observation of leak sites and actor channels, verification of claims and early warning of publication.

Attribution

Actor attribution

Linking activity to a known group, alias or toolset, with a stated confidence level and the evidence behind it.

Evidence

Evidence packs

Preserved, timestamped captures and a clear narrative for police, regulators, insurers and counsel.

Infrastructure Pivoting: From One Indicator to a Campaign

Each indicator your SOC already has is a starting point; we follow it through public records to the rest of the attacker's setup.

Starting pointOpen sources we pivot throughWhat it can reveal
DomainRegistration data and history, passive DNS, name servers, registrarSister domains registered the same way, timing of set-up, reused registrant details
TLS certificateCertificate Transparency logs, which publicly record certificates as they are issued (RFC 6962)Look-alike domains issued before a campaign launches, shared certificate details
IP address and hostingHosting provider and network records, internet scan data, co-hosted sitesOther services on the same server, a provider to send an abuse report to
Phishing page or kitPage source, kit files, exfiltration endpoints, kit advertisementsWhere credentials go, the kit's seller, other targets of the same kit
Alias or handleForum and channel posts, archived pages, code repositoriesThe actor's history, other operations, language and working patterns
Crypto walletPublic blockchain data and attribution resourcesPayment flows and links to exchanges; see crypto investigations

Pivoting stops at public and commercially available data; we never log into attacker panels or probe servers that are not yours.

How Far Can OSINT Attribution Go?

Usually to a known group, an alias or a shared toolset; occasionally further. Every attribution comes with a confidence level and the evidence behind it.

Linking an incident to a known campaign or previously seen infrastructure is often possible within days. Linking an alias to a real person needs several independent points of evidence and is sometimes impossible from open sources alone.

We report what we know, what we assess and how strongly. No one is named on a single coincidence such as a reused username. Identifications go to your counsel and law enforcement; we do not publish attributions or contact suspects.

Ransomware and Extortion Incident Support

We observe leak sites and actor channels, verify what the attacker claims and warn you before publication. We do not negotiate with or pay criminals.

Leadership needs facts quickly: is the group real, does its sample come from our systems, has anything gone live? We watch the group's leak site and channels, compare published samples with what your team knows and track whether data spreads to forums or mirrors.

Decisions on payment belong to you, your counsel and specialist negotiators. The FBI does not support paying a ransom and asks victims to contact a field office or report at IC3 (FBI). The US Treasury strongly discourages ransom payments and treats a prompt, complete report to law enforcement as a significant mitigating factor in its sanctions enforcement (OFAC advisory, September 2021).

We access only as much leaked material as verification needs and handle personal data in it under the data protection rules that apply to you.

How a Cyber Investigation Runs With Your Team

Scope, agree the rules, collect with preservation, analyze, review, hand over; most engagements follow these steps whatever their size.

  1. Brief and scopeYour incident lead sends indicators, the timeline and the questions. We confirm scope, deadline and a fixed quote in writing.
  2. Agree the rulesWho directs the work, who receives findings, whether counsel instructs us and what is out of scope.
  3. Collect and preserveOpen-source collection with timestamps, source URLs and preserved captures, so findings can be relied on later.
  4. Pivot and analyzeInfrastructure, kits, leaks and actor activity are connected and checked against your own telemetry.
  5. Senior reviewA senior analyst reviews every finding and confidence level before it leaves us.
  6. Hand overIndicators your SOC can block, a written report and, if needed, an evidence pack for police, regulators or insurers.

What You Receive and How Quickly

Short indicator notes for urgent questions, focused reports from 10 business days and full campaign investigations in about a month.

DeliverableWhat it containsTypical timing
Indicator noteAnswers to one or two narrow questions, plus new indicators to blockSmall tasks sometimes within one business day
Focused investigationInfrastructure map, kit or leak analysis, confidence-rated findingsFrom 10 business days
Campaign or actor investigationFull infrastructure and actor picture, attribution assessment, evidence packUp to about a month
Post-incident watchAnalyst-reviewed alerts on new infrastructure, leaks or mentionsOngoing, platform updated hourly

Urgent delivery adds 50% to the fee. The quote is fixed after written scoping, and if we miss the agreed date the fee goes down. Work is confidential and covered by an NDA on request.

Legal Limits and When This Is the Wrong Tool

We do not hack back, buy stolen data or infiltrate closed forums with fake identities, and we are not a substitute for forensic analysis of your own systems.

Accessing a computer without authorization is a crime even when the computer belongs to an attacker, under laws such as the US Computer Fraud and Abuse Act (18 U.S.C. § 1030). So we do not hack back, log into criminal panels, buy leaked data or use fake profiles to enter closed communities.

Open-source work is the wrong tool for questions inside your network, such as how the attacker moved and what was taken. That needs a forensics provider with access to your systems; we work alongside one. If you need continuous coverage rather than incident support, look at OSINT threat intelligence; if the case turns into a fraud or insider matter, our OSINT investigations team can take it further. Cyber investigation is one of the OSINT services we run as a single team, so cyber findings can be followed into the people and companies behind them.

OSINT Cyber Investigations: Specialized Services

Focused versions of cyber investigations for specific subjects, deals and situations.

Cyber investigations

Incident response OSINT

Outside-in answers for a live incident: attacker infrastructure, leak claims, chatter and exposure, delivered to your incident lead within hours.

Read more →
Cyber investigations

Insider threat investigations

Lawful, HR- and counsel-led insider cases: leaked documents, access offered for sale and outside links, checked in open sources only.

Read more →

Bring Us In Before the Trail Goes Cold

Send the indicators, the timeline and the questions your incident lead needs answered. We confirm scope, timing and a fixed quote in writing.

OSINT Cyber Investigations FAQ

Our SOC flagged a phishing domain hitting finance staff, and we want OSINT cyber investigations to find the rest of the attacker's infrastructure before the next wave — how fast can you start?

Usually as soon as scope is agreed in writing, often the day you send the brief. A narrow question, such as finding sister domains registered alongside the one you caught, can sometimes be answered within one business day; a full infrastructure map with kit analysis takes from 10 business days. Urgent delivery costs an extra 50%, and new indicators to block are sent as we find them.

We received a ransom note and the group says it will publish our data on its leak site in five days — can you tell us whether the sample they posted is really ours?

Often, yes. We compare file names, structure, dates and internal references in the sample with what your team knows about its systems, and check the group's record of real and exaggerated claims. We then watch the leak site and related channels for publication or resale. We do not negotiate or communicate with the attackers; payment decisions stay with you, your counsel and specialist negotiators.

Can you actually name the person behind an attack on our company, or is attribution with open sources mostly guesswork?

Neither guesswork nor guaranteed. Linking an incident to a known group, alias or toolset is often achievable. Linking an alias to a real person needs several independent pieces of evidence and is sometimes impossible from open sources. Every attribution carries a confidence level and its evidence, and identifications go to your counsel or law enforcement, not to the public.

We want to report a business email compromise to the police, but our internal notes are a mess — can you prepare an evidence pack they will take seriously?

Yes. We preserve the relevant open-source material with timestamps and source URLs and write a short narrative: what happened, which infrastructure and accounts were used and where money or data went, if that is visible. The same pack can serve your insurer and counsel. In the US the FBI asks victims to report at IC3 or to a field office.

Our board asked whether we could just hack back and take down the attacker's server ourselves — would your team do that if we authorized it?

No. Your authorization covers your own systems, not the attacker's, and unauthorized access to someone else's computer is a crime under laws such as the Computer Fraud and Abuse Act. What we can do lawfully is identify the hosting provider and registrar, prepare abuse and takedown reports with evidence, and pass findings to law enforcement.

We already pay a forensics firm under our cyber insurance policy — is there any point adding OSINT investigators, or will we just pay twice for the same work?

The overlap is small. The forensics firm examines your systems: what was accessed and how the attacker moved. We look outside: attacker infrastructure, kits, leak sites and actor history. We coordinate through your incident lead or counsel so nothing is done twice. If your insurer runs a provider panel, check its rules before adding anyone.