External attack surface
Domains, subdomains from certificate logs, exposed services in internet scan databases and forgotten cloud assets.
OSINT reconnaissance shows you what an attacker can learn about your organization before sending a single packet: forgotten servers, staff names and email formats, leaked passwords, documents that give away internal details. We run it only under written authorization and agreed rules of engagement, and we deliver an exposure map with fixes in priority order.
OSINT reconnaissance is the information-gathering phase of a red team or penetration test, done from public and commercially available sources. It maps your external attack surface, the staff details that make social engineering believable and credentials already leaked. OSINT-S does this under written authorization and rules of engagement, reports findings against MITRE ATT&CK and gives you a prioritized list of fixes.
Everything an adversary needs to plan an attack: who works where, which systems face the internet and which secrets are already out.
MITRE ATT&CK lists Reconnaissance as its first tactic, TA0043: "The adversary is trying to gather information they can use to plan future operations." It currently holds twelve techniques, from Search Open Websites/Domains (T1593) and Search Open Technical Databases (T1596) to Gather Victim Identity Information (T1589) and Phishing for Information (T1598) (MITRE ATT&CK).
We run the passive parts of that list against you, with your permission, so you see the same picture an attacker would. Each finding is tagged with the technique it supports, which lets your red team, pentester or detection engineers use it directly.
Believable phishing and phone pretexts are built from public details about your people, and AI now makes that tailoring cheap.
Both routes begin with reconnaissance. A forgotten subdomain is found through certificate logs; a convincing text to the help desk is written from a staff profile and an org chart. Reducing what can be found makes both attacks harder.
Six areas, each linked to an ATT&CK technique and each with a fix you can own.
Domains, subdomains from certificate logs, exposed services in internet scan databases and forgotten cloud assets.
Email formats, reporting lines and roles that are easy to impersonate, such as finance, IT support and executive assistants.
Corporate accounts in breach data and infostealer logs, matched to current staff and reported for reset. We never test them.
Public files, job ads and code repositories that reveal usernames, software versions or internal hostnames.
Registered look-alike domains and fake profiles that could support a phishing campaign against your staff or customers.
Key vendors visible from public sources, plus office photos that show badges, screens or entry points.
Our default is passive: we read public sources and never touch your systems. Anything active happens only if your rules of engagement say so.
| Activity | Type | Default | Condition |
|---|---|---|---|
| Search engines, websites, social and professional networks | Passive | Included | Public content only; no fake profiles |
| Certificate Transparency logs (RFC 6962), DNS and registration records | Passive | Included | None beyond scope |
| Breach and infostealer data | Passive | Included | Matched and reported; never used to log in |
| Port and service scanning (T1595) | Active | Excluded | Only on IP ranges you confirm you own, in a separate authorized test |
| Phishing or phone pretext tests (T1598) | Active | Excluded | Separate written approval, named targets, agreed scenarios and stop rules |
We do not exploit anything we find. If a finding looks exploitable, we report it so your tester or vendor can verify and fix it.
No written authorization, no work. The letter names who approved it, what is in scope and what is not.
Unauthorized access to computer systems is a crime under the US Computer Fraud and Abuse Act (18 U.S.C. § 1030) and the UK Computer Misuse Act (section 1). Passive OSINT does not access your systems, but a good engagement is still written down. Before work starts we agree:
NIST's guide to security testing describes planning, execution and post-testing phases for assessments such as penetration tests (NIST SP 800-115); our reconnaissance slots into the planning and discovery work of that model.
Scope and authorize, collect passively, validate, map to ATT&CK, review and debrief.
A map of what is exposed, ranked by attacker value, with an owner and a fix for each item.
| Priority | Typical finding | Typical fix |
|---|---|---|
| High | Old subdomain with a login page on outdated software | Decommission or patch, then remove the DNS record |
| High | Staff credentials in recent infostealer logs | Reset passwords, revoke sessions, check the device |
| Medium | Email format, org chart and help desk number easy to find | Stronger identity checks for password and MFA resets |
| Medium | Documents with usernames and software versions in metadata | Strip metadata before publishing |
| Low | Office photos showing badge design | Review photo guidance for social media |
A focused external recon takes from 10 business days; a comprehensive assessment covering several brands or regions takes up to about a month. Urgent delivery adds 50%. The quote is fixed after scoping and goes down if we miss the agreed date.
Our findings become the target list and scenarios for your authorized tester, so the test reflects what a real attacker would see.
Many clients buy reconnaissance as the first phase of a test run by their own red team or an external penetration testing firm. We hand over a structured file of in-scope assets, roles and pretext themes tagged to ATT&CK, and your tester decides what to try. If you run phishing simulations, the same findings make them closer to real attacks: scenarios built on your actual suppliers, tools and public announcements rather than generic templates.
Repeating the recon after fixes shows whether the exposure really went down, which is a simple measure to report to leadership.
If you need proof that something can be exploited, a compliance pentest or internal testing, hire an accredited penetration tester.
OSINT reconnaissance tells you what is visible, not whether it can be broken into. For compliance testing, internal network tests or exploitation, use an accredited penetration testing provider; our report gives them a head start. If the concern is the personal exposure of executives rather than the company, a digital footprint assessment or executive protection is a better fit. For ongoing coverage of new exposure, see OSINT threat intelligence. Red team recon is one of several OSINT services for security teams, and it is often requested by corporate security and critical infrastructure operators.
Focused versions of red team recon for specific subjects, deals and situations.
Authorized OSINT reconnaissance before a pentest: scope-validated targets, ownership evidence and a handover pack your tester can use on day one.
Read more →Authorized phishing, phone and process tests built from your real public exposure, run with stop rules, staff welfare and no blame.
Read more →Send the domains, brands and business units you want assessed and who will sign the authorization. We reply with scope, timing and a fixed quote.
Usually, yes. A focused external recon takes from 10 business days once the authorization is signed, and urgent delivery is available for an extra 50%. We hand over a structured file of in-scope assets, roles and pretext themes tagged to MITRE ATT&CK, so your vendor can plan scenarios around your real suppliers and public announcements. Send the vendor's start date with your brief and we plan backwards from it.
Not by default. Our standard recon is passive: we show which public details, such as staff names, roles and the help desk number, would make that call convincing. A live phone test is active social engineering and needs separate written approval, named targets, agreed scripts and stop rules. Many clients run that test through their existing vendor using our findings.
No. We match leaked credentials to current accounts and report them for reset, but we never use them to log in, even to your own systems. Testing credentials is active intrusion and belongs in a separately authorized penetration test run by your tester. Our report gives them the list so they can decide, within their rules of engagement, whether testing is needed.
Only within limits. We note where public professional and social profiles expose company details, such as roles, travel or internal tools, but we do not build dossiers on staff, look into family members or access private content. Employee data is minimized and deleted at the end. Where an executive's personal exposure is the real concern, a separate digital footprint assessment, agreed with that person, is the right route.
It is useful on its own. Many findings, such as forgotten subdomains, leaked credentials and documents with revealing metadata, can be fixed without any further testing. The exposure map gives you a prioritized to-do list and a baseline to repeat after fixes. If something looks exploitable, we say so, and you can commission a targeted penetration test for that item only.
You need a signed authorization from someone with authority over the organization and the assets in scope, usually the CISO, CIO or general counsel, plus rules of engagement listing domains, brands, contacts, exclusions and escalation. If any active testing is added later, it needs its own written approval. The decision on scope always stays with you, and we confirm it back in writing.
Sources checked 7 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.