OSINT: what public information reveals about your organisation
Searching, cross-checking and analysing publicly available information, within an engagement defined with you: technical exposure, credentials in circulation, domains imitating your brand.
In short. OSINT — open-source intelligence — means searching, cross-checking and analysing information that is already publicly available: domain registrations, certificates, services visible from the internet, code repositories, indexed documents, posts. At Cyber Praxis SRL this research is carried out under a written engagement, on a scope defined with you, and results in a report that separates established facts, hypotheses and limitations.
What is OSINT in practice?
It is the collection and analysis of publicly available information, without access to anyone's systems: no password is used, no vulnerability is exploited, no account is approached. We read what is already exposed, cross-check it, then explain what it means for your organisation.
The value is not in the isolated data point, it is in the correlation. A forgotten subdomain, a certificate that reveals an internal server name and a business address found in an old breach together describe a path that none of them showed on its own. An OSINT engagement therefore serves first to see your organisation the way an attacker sees it — and then to reduce what is useful to them.
Who it is for
For companies and organisations that want to know what they expose: before an audit or a certification, after an incident, before opening a new service, or because a doubt has appeared. For lawyers and their clients, as technical support: examination and preservation of public content specifically identified in a case file, with the documentation that goes with it. Cyber Praxis SRL works from Lasne, in Walloon Brabant, for clients in Belgium and France.
The services
1. External attack surface mapping
An inventory of what your organisation exposes on the internet: domain names and subdomains, IP addresses and reachable services, TLS certificates — including those that reveal internal host names —, administration or remote access portals left open, public code repositories and the configuration files sitting in them. The result is a list of assets ranked by exposure, which almost always contains items nobody in the organisation knew were online.
2. Credential leak research
Business addresses and credentials appearing in publicly documented breaches. We assess the real risk — age of the breach, nature of the exposed secret, likely reuse, accounts concerned — and set out remediation recommendations: targeted resets, two-factor authentication, review of mailbox rules, monitoring of sign-ins. We never test a credential, neither on your systems nor on anyone else's.
3. Impersonation and phishing detection
Lookalike domains — substituted letters, neighbouring extensions, misleading prefixes —, fake websites reusing your visual identity, fake login pages, profiles and adverts using your brand. Every finding is documented — URL, date and time of consultation, screen capture, domain registration data — in a form usable for a takedown request or for your counsel.
4. Threat monitoring
Monitoring of the public information relevant to your technologies: newly published vulnerabilities in the products you actually run, malicious campaigns active in your sector, methods reported by CERTs and vendors. The point is filtering: you receive what concerns your estate, not a news feed.
5. Incident response support
During or after an incident, we look for the public indicators matching what you observed — domains, addresses, file hashes, infrastructure already documented — and correlate them with the technical material you provide. This work complements the analysis of your own systems, which belongs to cyber investigation.
6. Data exposure research
Documents and data of the organisation made publicly accessible by mistake: open storage buckets, reachable backups, documents indexed by search engines, files dropped on sharing services, files published together with their metadata. We describe what is exposed, what can be inferred from it, and the steps that reduce the exposure — takedowns, de-indexing, corrected permissions.
7. Technical analysis of identified public content
At the request of a client or their lawyer, we examine and preserve pages, files or posts that are specifically identified: documentation of the URLs, of the dates and times of consultation, screen captures, copies of the files and cryptographic hashes where relevant. We describe what the content shows and the conditions under which it was collected. We do not claim that a screen capture on its own establishes the identity of the author of a piece of content or its authenticity: those are two separate questions, and the report says so.
8. Cyber due diligence on a supplier
Before entrusting data to a provider, or during a tender: the supplier's technical exposure, the hygiene of its domains and certificates, the security information it documents publicly — certifications, security page, incidents it has published itself. The analysis relies on public sources and on what the supplier publishes; it does not replace a contractual questionnaire, it lets you complete one knowingly.
What we do not do
Our OSINT engagements are cybersecurity and technical analysis work. Cyber Praxis SRL is not a private detective agency and does not accept research intended to establish a person's behaviour — a partner, an employee, a neighbour, an opposing party — in a dispute. In Belgium the classification of an engagement depends among other things on its purpose: relying solely on public sources does not remove the rules on private investigation. That is why the scope is put in writing before a case is accepted.
For the analysis of content intended for proceedings, describe the scope and send over the material already identified — URLs, screen captures, references. We then state what is feasible, what is not, and subject to what reservations, before accepting the engagement. A technical finding is not presented as proof: assessing the evidential weight of an item is for the court seised of the matter.
Our method
Six stages, from scope to recommendations
-
1
Scope and purpose
We write down with you what is being looked for, on which assets, and for what use. A clear scope is what distinguishes a technical engagement from open-ended collection.
-
2
Proportionate collection
Publicly available sources only, and only what the purpose requires. Anything not useful to the engagement is not collected.
-
3
Verification and cross-checking
Each item is confirmed by another source where possible. Anything that remains unconfirmed is flagged as such, never presented as established.
-
4
Preservation of material
URLs, dates and times of consultation, screen captures, copies of the files and SHA-256 hashes where the nature of the content justifies it.
-
5
Report
Three separate headings: established facts, hypotheses, limitations. The reader sees what is verified, what is likely and what could not be established.
-
6
Recommendations
Actionable steps, ranked by effect and effort, distinguishing what is yours to do from what depends on a third party — host, registrar, platform.
Frequently asked questions
Is OSINT lawful?
Consulting publicly available information raises no difficulty in itself. What matters is the purpose of the engagement, the data processed and the use made of the result: analysing an organisation's technical exposure and researching a person's behaviour are not governed by the same rules. Every request is therefore scoped in writing before it is accepted.
Do you touch our systems?
No. An OSINT engagement involves no penetration test, no login attempt and no exploitation of a vulnerability: we look at what is already exposed. Where an active test is advisable, it is a separate engagement, with written authorisation from the party responsible for the systems.
Does a screenshot prove who published a piece of content?
No. A screen capture shows what a page displayed at a given moment, from a given machine. The identity of the author and the authenticity of the content are two separate questions, which require other material and sometimes steps reserved to the judicial authorities. The report states what the item establishes and what it does not.
What does the report contain?
The method and the sources consulted, an inventory of the findings with dates and times, the separation between established facts, hypotheses and limitations, then recommendations ranked by priority. It is written to be read by a management team, a DPO, an insurer or a lawyer.
Do you accept research on an individual?
Not where the purpose is to establish a person's behaviour — a partner, an employee, a neighbour, an opposing party — in a dispute. Cyber Praxis SRL is not a private detective agency. In Belgium the classification of an engagement depends among other things on its purpose, and relying solely on public sources does not remove the rules on private investigation.
Describe your need and the assets or items concerned
A first conversation is free and confidential. Tell us what you want to know and on what scope: we will tell you what is feasible, subject to what reservations, and at what cost.