Digital forensics and IT expertise — Belgium & France

OSINT: what public information reveals about your organisation

Searching, cross-checking and analysing publicly available information, within an engagement defined with you: technical exposure, credentials in circulation, domains imitating your brand.

Our method

Six stages, from scope to recommendations

  1. 1

    Scope and purpose

    We write down with you what is being looked for, on which assets, and for what use. A clear scope is what distinguishes a technical engagement from open-ended collection.

    Free

  2. 2

    Proportionate collection

    Publicly available sources only, and only what the purpose requires. Anything not useful to the engagement is not collected.

    Public sources

  3. 3

    Verification and cross-checking

    Each item is confirmed by another source where possible. Anything that remains unconfirmed is flagged as such, never presented as established.

    Two sources

  4. 4

    Preservation of material

    URLs, dates and times of consultation, screen captures, copies of the files and SHA-256 hashes where the nature of the content justifies it.

    Timestamped

  5. 5

    Report

    Three separate headings: established facts, hypotheses, limitations. The reader sees what is verified, what is likely and what could not be established.

    Signed report

  6. 6

    Recommendations

    Actionable steps, ranked by effect and effort, distinguishing what is yours to do from what depends on a third party — host, registrar, platform.

    Included

Frequently asked questions

Is OSINT lawful?

Consulting publicly available information raises no difficulty in itself. What matters is the purpose of the engagement, the data processed and the use made of the result: analysing an organisation's technical exposure and researching a person's behaviour are not governed by the same rules. Every request is therefore scoped in writing before it is accepted.

Do you touch our systems?

No. An OSINT engagement involves no penetration test, no login attempt and no exploitation of a vulnerability: we look at what is already exposed. Where an active test is advisable, it is a separate engagement, with written authorisation from the party responsible for the systems.

Does a screenshot prove who published a piece of content?

No. A screen capture shows what a page displayed at a given moment, from a given machine. The identity of the author and the authenticity of the content are two separate questions, which require other material and sometimes steps reserved to the judicial authorities. The report states what the item establishes and what it does not.

What does the report contain?

The method and the sources consulted, an inventory of the findings with dates and times, the separation between established facts, hypotheses and limitations, then recommendations ranked by priority. It is written to be read by a management team, a DPO, an insurer or a lawyer.

Do you accept research on an individual?

Not where the purpose is to establish a person's behaviour — a partner, an employee, a neighbour, an opposing party — in a dispute. Cyber Praxis SRL is not a private detective agency. In Belgium the classification of an engagement depends among other things on its purpose, and relying solely on public sources does not remove the rules on private investigation.

Describe your need and the assets or items concerned

A first conversation is free and confidential. Tell us what you want to know and on what scope: we will tell you what is feasible, subject to what reservations, and at what cost.