Infrastructure pivoting
From one domain, IP address or certificate to the wider set of servers, domains and accounts the attacker is using.
OSINT cyber investigations give your SOC and incident response team the view from outside the network: who set up the attacking infrastructure, what else it connects to, what has leaked and where the attackers are talking about it. We work under your incident lead and hand over findings to act on and evidence for the police.
OSINT cyber investigations use public and commercially available data, such as domain records, certificate logs, hosting data, criminal forums and leak sites, to explain an attack your internal tools have already detected. They support SOC and incident response work by mapping attacker infrastructure, analyzing phishing kits and leaks, observing extortion sites and preparing evidence. They complement forensics on your own systems; they do not replace it.
Your SOC sees what happened inside your environment; open-source investigation explains the attacker's side of the same event and what else they are running.
Telemetry tells you which host was touched and when. It rarely tells you who registered the phishing domain, which other brands the same kit targets, or whether your files are already on an extortion site. Those questions sit outside your perimeter.
NIST's current incident response recommendations are written as a Cybersecurity Framework 2.0 community profile, treating response as part of ongoing risk management rather than a one-off emergency (NIST SP 800-61 Rev. 3, April 2025). SOC OSINT investigations fit that cycle at three points: enriching an alert during triage, scoping the attacker's wider activity during response, and watching for follow-on activity after recovery.
Attackers increasingly come in through vulnerabilities and suppliers, and extortion crews publish victims at record rates, so the evidence often sits outside your network.
Six types of support, each tied to a question your incident lead needs answered.
From one domain, IP address or certificate to the wider set of servers, domains and accounts the attacker is using.
How the kit works, where stolen data is sent, which other organizations it imitates and whether it is sold as a service.
Whether data claimed by an attacker is real, which system it probably came from and where it is being shared.
Dark web monitoring →Observation of leak sites and actor channels, verification of claims and early warning of publication.
Linking activity to a known group, alias or toolset, with a stated confidence level and the evidence behind it.
Preserved, timestamped captures and a clear narrative for police, regulators, insurers and counsel.
Each indicator your SOC already has is a starting point; we follow it through public records to the rest of the attacker's setup.
| Starting point | Open sources we pivot through | What it can reveal |
|---|---|---|
| Domain | Registration data and history, passive DNS, name servers, registrar | Sister domains registered the same way, timing of set-up, reused registrant details |
| TLS certificate | Certificate Transparency logs, which publicly record certificates as they are issued (RFC 6962) | Look-alike domains issued before a campaign launches, shared certificate details |
| IP address and hosting | Hosting provider and network records, internet scan data, co-hosted sites | Other services on the same server, a provider to send an abuse report to |
| Phishing page or kit | Page source, kit files, exfiltration endpoints, kit advertisements | Where credentials go, the kit's seller, other targets of the same kit |
| Alias or handle | Forum and channel posts, archived pages, code repositories | The actor's history, other operations, language and working patterns |
| Crypto wallet | Public blockchain data and attribution resources | Payment flows and links to exchanges; see crypto investigations |
Pivoting stops at public and commercially available data; we never log into attacker panels or probe servers that are not yours.
Usually to a known group, an alias or a shared toolset; occasionally further. Every attribution comes with a confidence level and the evidence behind it.
Linking an incident to a known campaign or previously seen infrastructure is often possible within days. Linking an alias to a real person needs several independent points of evidence and is sometimes impossible from open sources alone.
We report what we know, what we assess and how strongly. No one is named on a single coincidence such as a reused username. Identifications go to your counsel and law enforcement; we do not publish attributions or contact suspects.
We observe leak sites and actor channels, verify what the attacker claims and warn you before publication. We do not negotiate with or pay criminals.
Leadership needs facts quickly: is the group real, does its sample come from our systems, has anything gone live? We watch the group's leak site and channels, compare published samples with what your team knows and track whether data spreads to forums or mirrors.
Decisions on payment belong to you, your counsel and specialist negotiators. The FBI does not support paying a ransom and asks victims to contact a field office or report at IC3 (FBI). The US Treasury strongly discourages ransom payments and treats a prompt, complete report to law enforcement as a significant mitigating factor in its sanctions enforcement (OFAC advisory, September 2021).
We access only as much leaked material as verification needs and handle personal data in it under the data protection rules that apply to you.
Scope, agree the rules, collect with preservation, analyze, review, hand over; most engagements follow these steps whatever their size.
Short indicator notes for urgent questions, focused reports from 10 business days and full campaign investigations in about a month.
| Deliverable | What it contains | Typical timing |
|---|---|---|
| Indicator note | Answers to one or two narrow questions, plus new indicators to block | Small tasks sometimes within one business day |
| Focused investigation | Infrastructure map, kit or leak analysis, confidence-rated findings | From 10 business days |
| Campaign or actor investigation | Full infrastructure and actor picture, attribution assessment, evidence pack | Up to about a month |
| Post-incident watch | Analyst-reviewed alerts on new infrastructure, leaks or mentions | Ongoing, platform updated hourly |
Urgent delivery adds 50% to the fee. The quote is fixed after written scoping, and if we miss the agreed date the fee goes down. Work is confidential and covered by an NDA on request.
We do not hack back, buy stolen data or infiltrate closed forums with fake identities, and we are not a substitute for forensic analysis of your own systems.
Accessing a computer without authorization is a crime even when the computer belongs to an attacker, under laws such as the US Computer Fraud and Abuse Act (18 U.S.C. § 1030). So we do not hack back, log into criminal panels, buy leaked data or use fake profiles to enter closed communities.
Open-source work is the wrong tool for questions inside your network, such as how the attacker moved and what was taken. That needs a forensics provider with access to your systems; we work alongside one. If you need continuous coverage rather than incident support, look at OSINT threat intelligence; if the case turns into a fraud or insider matter, our OSINT investigations team can take it further. Cyber investigation is one of the OSINT services we run as a single team, so cyber findings can be followed into the people and companies behind them.
Focused versions of cyber investigations for specific subjects, deals and situations.
Outside-in answers for a live incident: attacker infrastructure, leak claims, chatter and exposure, delivered to your incident lead within hours.
Read more →Lawful, HR- and counsel-led insider cases: leaked documents, access offered for sale and outside links, checked in open sources only.
Read more →Send the indicators, the timeline and the questions your incident lead needs answered. We confirm scope, timing and a fixed quote in writing.
Usually as soon as scope is agreed in writing, often the day you send the brief. A narrow question, such as finding sister domains registered alongside the one you caught, can sometimes be answered within one business day; a full infrastructure map with kit analysis takes from 10 business days. Urgent delivery costs an extra 50%, and new indicators to block are sent as we find them.
Often, yes. We compare file names, structure, dates and internal references in the sample with what your team knows about its systems, and check the group's record of real and exaggerated claims. We then watch the leak site and related channels for publication or resale. We do not negotiate or communicate with the attackers; payment decisions stay with you, your counsel and specialist negotiators.
Neither guesswork nor guaranteed. Linking an incident to a known group, alias or toolset is often achievable. Linking an alias to a real person needs several independent pieces of evidence and is sometimes impossible from open sources. Every attribution carries a confidence level and its evidence, and identifications go to your counsel or law enforcement, not to the public.
Yes. We preserve the relevant open-source material with timestamps and source URLs and write a short narrative: what happened, which infrastructure and accounts were used and where money or data went, if that is visible. The same pack can serve your insurer and counsel. In the US the FBI asks victims to report at IC3 or to a field office.
No. Your authorization covers your own systems, not the attacker's, and unauthorized access to someone else's computer is a crime under laws such as the Computer Fraud and Abuse Act. What we can do lawfully is identify the hosting provider and registrar, prepare abuse and takedown reports with evidence, and pass findings to law enforcement.
The overlap is small. The forensics firm examines your systems: what was accessed and how the attacker moved. We look outside: attacker infrastructure, kits, leak sites and actor history. We coordinate through your incident lead or counsel so nothing is done twice. If your insurer runs a provider panel, check its rules before adding anyone.
Sources checked 7 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.