Red Team OSINT Reconnaissance and Social Engineering Assessment

OSINT reconnaissance shows you what an attacker can learn about your organization before sending a single packet: forgotten servers, staff names and email formats, leaked passwords, documents that give away internal details. We run it only under written authorization and agreed rules of engagement, and we deliver an exposure map with fixes in priority order.

  • Written authorization first
  • Mapped to MITRE ATT&CK
  • Exposure map and fixes
  • Feeds your pentest or red team
Short answer

OSINT reconnaissance is the information-gathering phase of a red team or penetration test, done from public and commercially available sources. It maps your external attack surface, the staff details that make social engineering believable and credentials already leaked. OSINT-S does this under written authorization and rules of engagement, reports findings against MITRE ATT&CK and gives you a prioritized list of fixes.

What OSINT Reconnaissance Shows an Attacker

Everything an adversary needs to plan an attack: who works where, which systems face the internet and which secrets are already out.

MITRE ATT&CK lists Reconnaissance as its first tactic, TA0043: "The adversary is trying to gather information they can use to plan future operations." It currently holds twelve techniques, from Search Open Websites/Domains (T1593) and Search Open Technical Databases (T1596) to Gather Victim Identity Information (T1589) and Phishing for Information (T1598) (MITRE ATT&CK).

We run the passive parts of that list against you, with your permission, so you see the same picture an attacker would. Each finding is tagged with the technique it supports, which lets your red team, pentester or detection engineers use it directly.

Why Recon Is Where Social Engineering Starts

Believable phishing and phone pretexts are built from public details about your people, and AI now makes that tailoring cheap.

  • Social engineering on mobile devices succeeded 40% more often than traditional email phishing, and vulnerability exploitation started 31% of breaches (Verizon DBIR 2026).
  • One in four malicious breaches was AI-enabled, a 56% rise on the year before (IBM 2026).

Both routes begin with reconnaissance. A forgotten subdomain is found through certificate logs; a convincing text to the help desk is written from a staff profile and an org chart. Reducing what can be found makes both attacks harder.

What Our OSINT Penetration Testing Recon Covers

Six areas, each linked to an ATT&CK technique and each with a fix you can own.

T1596 · T1590

External attack surface

Domains, subdomains from certificate logs, exposed services in internet scan databases and forgotten cloud assets.

T1589 · T1591

People and roles

Email formats, reporting lines and roles that are easy to impersonate, such as finance, IT support and executive assistants.

T1589

Leaked credentials

Corporate accounts in breach data and infostealer logs, matched to current staff and reported for reset. We never test them.

T1593 · T1594

Documents and metadata

Public files, job ads and code repositories that reveal usernames, software versions or internal hostnames.

T1593

Look-alike domains and brand

Registered look-alike domains and fake profiles that could support a phishing campaign against your staff or customers.

T1591

Suppliers and physical clues

Key vendors visible from public sources, plus office photos that show badges, screens or entry points.

Passive Collection Versus Active Testing

Our default is passive: we read public sources and never touch your systems. Anything active happens only if your rules of engagement say so.

ActivityTypeDefaultCondition
Search engines, websites, social and professional networksPassiveIncludedPublic content only; no fake profiles
Certificate Transparency logs (RFC 6962), DNS and registration recordsPassiveIncludedNone beyond scope
Breach and infostealer dataPassiveIncludedMatched and reported; never used to log in
Port and service scanning (T1595)ActiveExcludedOnly on IP ranges you confirm you own, in a separate authorized test
Phishing or phone pretext tests (T1598)ActiveExcludedSeparate written approval, named targets, agreed scenarios and stop rules

We do not exploit anything we find. If a finding looks exploitable, we report it so your tester or vendor can verify and fix it.

Authorization and Rules of Engagement Come First

No written authorization, no work. The letter names who approved it, what is in scope and what is not.

Unauthorized access to computer systems is a crime under the US Computer Fraud and Abuse Act (18 U.S.C. § 1030) and the UK Computer Misuse Act (section 1). Passive OSINT does not access your systems, but a good engagement is still written down. Before work starts we agree:

  • A signed authorization from someone with authority over the organization and the assets in scope.
  • Rules of engagement: domains, brands and business units in scope; contacts; hours; how findings that need urgent action are escalated.
  • Clear exclusions: employees' personal accounts and family members, suppliers' systems and any third party that has not agreed.
  • Data handling: employee data is minimized, kept to what shows a risk, and deleted at the end as agreed.

NIST's guide to security testing describes planning, execution and post-testing phases for assessments such as penetration tests (NIST SP 800-115); our reconnaissance slots into the planning and discovery work of that model.

How a Red Team Recon Engagement Runs

Scope and authorize, collect passively, validate, map to ATT&CK, review and debrief.

  1. Scope and authorizeWe agree the questions, the assets and the exclusions, and receive a signed authorization and a fixed quote.
  2. Passive collectionOpen-source collection across websites, technical databases, certificate logs, breach data and public profiles.
  3. Validate ownershipEvery asset is confirmed as yours before it goes in the report, so your team does not chase someone else's server.
  4. Map and prioritizeFindings are tagged to ATT&CK techniques and ranked by how easily an attacker could use them.
  5. Senior reviewA senior analyst checks every finding, and removes personal details that are not needed to show the risk.
  6. Report and debriefAn exposure map, prioritized fixes and a walkthrough for your security team or red team lead.

The Exposure Map and Prioritized Fixes

A map of what is exposed, ranked by attacker value, with an owner and a fix for each item.

PriorityTypical findingTypical fix
HighOld subdomain with a login page on outdated softwareDecommission or patch, then remove the DNS record
HighStaff credentials in recent infostealer logsReset passwords, revoke sessions, check the device
MediumEmail format, org chart and help desk number easy to findStronger identity checks for password and MFA resets
MediumDocuments with usernames and software versions in metadataStrip metadata before publishing
LowOffice photos showing badge designReview photo guidance for social media

A focused external recon takes from 10 business days; a comprehensive assessment covering several brands or regions takes up to about a month. Urgent delivery adds 50%. The quote is fixed after scoping and goes down if we miss the agreed date.

Feeding OSINT Recon Into Your Pentest or Phishing Simulation

Our findings become the target list and scenarios for your authorized tester, so the test reflects what a real attacker would see.

Many clients buy reconnaissance as the first phase of a test run by their own red team or an external penetration testing firm. We hand over a structured file of in-scope assets, roles and pretext themes tagged to ATT&CK, and your tester decides what to try. If you run phishing simulations, the same findings make them closer to real attacks: scenarios built on your actual suppliers, tools and public announcements rather than generic templates.

Repeating the recon after fixes shows whether the exposure really went down, which is a simple measure to report to leadership.

When This Is Not the Right Test

If you need proof that something can be exploited, a compliance pentest or internal testing, hire an accredited penetration tester.

OSINT reconnaissance tells you what is visible, not whether it can be broken into. For compliance testing, internal network tests or exploitation, use an accredited penetration testing provider; our report gives them a head start. If the concern is the personal exposure of executives rather than the company, a digital footprint assessment or executive protection is a better fit. For ongoing coverage of new exposure, see OSINT threat intelligence. Red team recon is one of several OSINT services for security teams, and it is often requested by corporate security and critical infrastructure operators.

OSINT Red Team Recon: Specialized Services

Focused versions of red team recon for specific subjects, deals and situations.

Red team recon

OSINT penetration testing

Authorized OSINT reconnaissance before a pentest: scope-validated targets, ownership evidence and a handover pack your tester can use on day one.

Read more →
Red team recon

Social engineering assessment

Authorized phishing, phone and process tests built from your real public exposure, run with stop rules, staff welfare and no blame.

Read more →

See Your Organization the Way an Attacker Would

Send the domains, brands and business units you want assessed and who will sign the authorization. We reply with scope, timing and a fixed quote.

OSINT Reconnaissance FAQ

Our pentest vendor starts in three weeks and I want OSINT reconnaissance done first so their phishing scenarios look like a real attack — can you deliver in time?

Usually, yes. A focused external recon takes from 10 business days once the authorization is signed, and urgent delivery is available for an extra 50%. We hand over a structured file of in-scope assets, roles and pretext themes tagged to MITRE ATT&CK, so your vendor can plan scenarios around your real suppliers and public announcements. Send the vendor's start date with your brief and we plan backwards from it.

I'm the CISO and want to know how easy it would be to trick our help desk into resetting an executive's MFA — will you call our help desk as part of this?

Not by default. Our standard recon is passive: we show which public details, such as staff names, roles and the help desk number, would make that call convincing. A live phone test is active social engineering and needs separate written approval, named targets, agreed scripts and stop rules. Many clients run that test through their existing vendor using our findings.

We found our employees' passwords in a breach dump during your recon — will you try them against our VPN to prove the risk is real?

No. We match leaked credentials to current accounts and report them for reset, but we never use them to log in, even to your own systems. Testing credentials is active intrusion and belongs in a separately authorized penetration test run by your tester. Our report gives them the list so they can decide, within their rules of engagement, whether testing is needed.

Can your OSINT recon include our employees' personal social media and family members, since attackers would look there too?

Only within limits. We note where public professional and social profiles expose company details, such as roles, travel or internal tools, but we do not build dossiers on staff, look into family members or access private content. Employee data is minimized and deleted at the end. Where an executive's personal exposure is the real concern, a separate digital footprint assessment, agreed with that person, is the right route.

We are a mid-sized manufacturer without a red team — is an OSINT reconnaissance worth it on its own, or only as part of a penetration test?

It is useful on its own. Many findings, such as forgotten subdomains, leaked credentials and documents with revealing metadata, can be fixed without any further testing. The exposure map gives you a prioritized to-do list and a baseline to repeat after fixes. If something looks exploitable, we say so, and you can commission a targeted penetration test for that item only.

Which written documents do I need before your team starts reconnaissance on our company, and who in our organization has to sign them?

You need a signed authorization from someone with authority over the organization and the assets in scope, usually the CISO, CIO or general counsel, plus rules of engagement listing domains, brands, contacts, exclusions and escalation. If any active testing is added later, it needs its own written approval. The decision on scope always stays with you, and we confirm it back in writing.