OSINT analysis: identifying your public attack surface
You want to know which digital traces your company leaves and which of them attackers could use? Our OSINT analysis examines publicly accessible information and assesses the findings in the context of your security situation.
OSINT analysis: seeing what attackers already know about you.
Your situation
You want to know what attackers can already find out about your organisation today?
Many cyberattacks do not begin in your systems but on the open internet. Even before a phishing e-mail is sent or a vulnerability is exploited, attackers collect freely available information: reachable systems, domains and services, public documents and their metadata, employee profiles and contact details on social networks, information on locations, technologies and partners.
An OSINT analysis is often prompted by one of these situations: you want to check your assumptions about your own attack surface, which may be outdated or wrong. You are planning red teaming or a TLPT according to TIBER-EU, which requires a reconnaissance phase. Or you need insights for requirements arising from DORA, NIS2 or the German critical infrastructure umbrella act (KRITIS-Dachgesetz).
Our OSINT analysis shows your publicly visible attack surface – systematically and without access to your systems. We assess the findings from an attacker’s perspective and evaluate how they affect your security situation. However, OSINT is no substitute for missing asset management; we tell you that openly in the initial consultation.
Services & results
OSINT analysis in six steps: from scope to situation report
You find out which publicly accessible information about your company attackers could use: domains, subdomains and reachable systems, documents and metadata, employee profiles, information on technologies and partners. The findings are assessed in the context of your security situation, without access to your systems. The analysis is also suitable as the reconnaissance phase for red teaming or a TLPT according to TIBER-EU.
We combine manual research with automated methods, including the open source tool BBOT. The approach is based on established OSINT methods and has been developed further from our many years of experience in penetration testing. Each analysis describes the methods, sources and tools used, so that you can trace the origin of every finding.
01
Agreeing objectives and scope
Together we define the analysis objectives, the environment considered and possible focus areas. We take specific topics, sector requirements or sources you prefer into account as early as the preliminary discussion and the proposal phase.
02
Collecting data from open sources
We systematically collect information from technical and non-technical sources – exclusively publicly accessible data from the web, DNS, social networks, forums, cloud services, paste sites, databases and other sources. Typical components:
Domains, subdomains and IP ranges that can be attributed to your organisation
Employee information: professional profiles, e-mail addresses and other data that facilitate social engineering
Technology stack: frameworks, server versions, libraries, exposed metadata
Cloud services and third-party providers: misconfigured storage, open APIs, external integrations
Data leaks: paste sites, data dumps, open databases and social media sources with indications of compromised credentials
03
Structuring and inventorying
From the findings, we build an inventory of your publicly visible infrastructure and relevant digital assets.
Inventory of your public traces
A structured overview of the visible infrastructure and relevant information.
04
Assessing risks and entry points
We classify each finding by relevance, impact and possible exploitation by attackers. Because our analysts come from penetration testing and red team exercises, we consistently look at the information from an attacker’s perspective and focus on how it could actually be used.
05
Situation report
You do not receive an automated OSINT report, but an individually and manually prepared, technically reviewed situation report. It presents traces, anomalies and observations in a structured way and in their overall context, and fully describes methods, sources and tools.
Your situation report
Traceably derived findings with an assessment and indications of where action is needed.
06
Final meeting
In a joint meeting, we present and explain the results. On request, we work out how the insights can feed into a penetration test, red teaming or WBRT® – White Box Red Teaming.
Our expertise
OSINT has been an integral part of our methodology for many years – as a stand-alone analysis and as a preparation phase in red teaming and WBRT®. It is carried out by penetration testers with years of practice in penetration testing and red team exercises. secuvera is a BSI-certified IT security service provider and has been carrying out penetration tests since 2000.
In our OSINT analyses, we use the open source tool BBOT, among others. Our colleague Danny Scherer showed how external attack surfaces can be captured in a structured way with it in the iX special “Security Tools” 2025 – with examples from real assessments.
We use OSINT where it gives you insight: to check assumptions about your attack surface or when red teaming requires a reconnaissance phase. In a conventional penetration test, we add a reconnaissance phase on request; usually we talk to you directly about your environment.
Getting started
Naming the organisation, domains and research focus areas
Narrow down the organisation and analysis objective
In the preliminary discussion, you name the organisation to be examined, known domains and particular focus areas. We take sector-specific requirements and preferred sources into account when planning the proposal.
Use the results for further tests
The insights gained can feed into red teaming, White Box Red Teaming or targeted penetration tests. This means the research can serve as a basis for subsequent attack simulations and improvement measures.
Publicly accessible information is analysed within the agreed scope. The research does not replace practical testing of whether the points of attack found can be exploited.
Questions about OSINT analysis
Do you need access to our systems for the OSINT analysis?
The analysis uses publicly accessible information and does not require internal system access. We agree on the organisation to be examined, known domains and particular research objectives.
Are the findings only compiled automatically?
No. Penetration testers with experience from red team exercises assess the information from an attacker’s perspective. The situation report is prepared individually and manually and is technically reviewed. What matters is the context and actual usability of the findings.
Does an OSINT finding already prove an exploitable vulnerability?
Not necessarily. The research assesses publicly visible information; practical exploitability may require a separate technical test. Results can feed into targeted pentests, White Box Red Teaming or a red team assessment.
Does an OSINT analysis replace our asset management?
No. If it is unclear which systems and applications exist in the first place, OSINT is no substitute for functioning asset management. OSINT cannot guarantee completeness; some targets can only be found with internal knowledge. The analysis is useful for checking existing assumptions about your attack surface.
Is OSINT part of every penetration test?
No. A reconnaissance phase is possible in a penetration test, but not standard. As your contractor, we can discuss your environment directly with you instead of researching it at great effort. Reconnaissance is necessary, however, when red teaming is required, for example.