GlossaryAttack surface and pentesting

OSINT

Short answer

OSINT (Open Source Intelligence) is information collected from publicly available sources, such as websites, social networks, public records, code repositories and leaked data, and analysed for a purpose. Attackers use it to prepare attacks; defenders use it to see what their organisation exposes.

How attackers use it

Before an attack, criminals research their target: staff names and roles from LinkedIn to craft spear phishing, email address formats, technologies mentioned in job offers, subdomains and exposed services from DNS records and search engines like Shodan, credentials from previous leaks and secrets accidentally published in public code repositories.

How defenders use it

The same techniques show a company its own digital footprint: which systems are visible from the internet, which employee credentials appear in leaks, which documents are publicly indexed and which lookalike domains have been registered. This view is the basis of attack surface management and an input for threat intelligence. Our article on what your company exposes online shows typical findings.

Reducing exposure

Limit technical detail in job offers and public documents, train staff on what they share about their work, monitor leaked credentials and enforce MFA, remove forgotten subdomains and test environments, and register lookalike domains of the brand.

Limits

Information being public does not make every use of it lawful. OSINT on people must respect data protection law, and any testing beyond passive collection requires authorisation.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub