OSINT (Open Source Intelligence)
OSINT in offensive security
Every penetration test and red team engagement begins with OSINT. The reconnaissance phase determines what an attacker can learn about the target before sending a single packet. This includes:
- Infrastructure discovery – identifying domains, subdomains, IP ranges, cloud services, and internet-facing systems through DNS records, certificate transparency logs, and services like Shodan (a search engine that indexes internet-connected devices)
- People and organisation mapping – harvesting employee names, email addresses, job titles, and reporting structures from LinkedIn, company websites, press releases, and data breach databases
- Credential exposure – checking whether employee credentials have appeared in previous data breaches using tools such as Have I Been Pwned and dark web monitoring services
- Technical fingerprinting – identifying software versions, frameworks, CMS platforms, and server configurations from HTTP headers, JavaScript files, and public code repositories
Common OSINT tools used in penetration testing include Maltego (for relationship mapping and visualisation), SpiderFoot (automated reconnaissance), theHarvester (email and subdomain enumeration), and Shodan (internet-connected device search). These same tools are available to attackers, which is precisely why organisations need to understand what they reveal.
OSINT in defensive security
Defensive OSINT – sometimes called threat intelligence – focuses on monitoring external sources for threats aimed at your organisation. This includes:
- Brand and executive monitoring – tracking mentions of your organisation, executives, and key personnel across social media, paste sites, dark web forums, and Telegram channels for signs of targeting or impersonation
- Attack surface monitoring – continuously scanning for exposed assets, misconfigured cloud storage, forgotten subdomains, and shadow IT that your security team may not know about
- Threat actor tracking – following known threat actor groups and their TTPs (tactics, techniques, and procedures) to anticipate attacks against your sector or supply chain
- Data leak detection – identifying when internal documents, credentials, or customer data appear on breach forums, dark web marketplaces, or public paste sites
Organisations in regulated sectors often integrate OSINT feeds into their MXDR or SIEM platforms, correlating external threat intelligence with internal security events.
OSINT and social engineering
OSINT is the enabler of effective social engineering. A phishing email that references a real project, names a real colleague, or impersonates a genuine supplier is far more convincing than a generic attempt. During crisis simulation exercises, OSINT-derived scenarios test whether staff can recognise highly targeted phishing – the kind built from real information about the organisation.
This is also why OSINT matters for business email compromise. Attackers use OSINT to identify finance teams, understand approval workflows, and impersonate senior executives. The more information publicly available about your organisation’s structure, the easier it is to craft a convincing BEC attack.
Cyberfort and OSINT
OSINT is embedded in every penetration testing engagement we deliver. Our CREST-certified testers conduct thorough open source reconnaissance to identify your external exposure before testing begins – the same methodology real attackers use, applied to strengthen your defences. Our crisis simulation exercises incorporate OSINT-derived scenarios to test your team’s response to realistic, targeted attacks.
Related glossary terms
- Red Teaming – adversarial simulation that relies heavily on OSINT during the reconnaissance phase
- [MITRE ATT&CK – framework documenting the reconnaissance tactics that OSINT supports
- BEC (Business Email Compromise) – attack type enabled by OSINT-gathered organisational intelligence
- Threat Modelling – structured process that uses OSINT findings to identify likely attack paths
- MXDR – managed detection and response services that integrate OSINT threat feeds
External references
- Wikipedia: Open-source intelligence – history and overview of OSINT as a discipline
- Wikidata: Q593370 – canonical entity identifier
- NCSC: Threat Assessment – NCSC guidance on threat assessment incorporating open source intelligence
- MITRE ATT&CK: Reconnaissance – MITRE’s taxonomy of reconnaissance techniques including OSINT methods
Frequently asked questions
What is OSINT in cyber security?
OSINT (Open Source Intelligence) is the collection and analysis of publicly available information to support security objectives. In cyber security, this means gathering data from sources such as domain records, social media, breach databases, code repositories, and internet-scanning services to identify an organisation’s external exposure, inform penetration testing, or detect threats. The same information is available to attackers, which is why understanding your OSINT footprint is a defensive priority.
What tools are used for OSINT?
Common OSINT tools include Shodan (searches for internet-connected devices and exposed services), Maltego (maps relationships between entities such as people, domains, and IP addresses), SpiderFoot (automates reconnaissance across dozens of data sources), and theHarvester (enumerates email addresses and subdomains). These are the same tools used by both penetration testers during reconnaissance and by threat actors during target research.
How can organisations reduce their OSINT exposure?
Start by auditing what is publicly visible. Review employee social media policies, remove unnecessary technical information from public-facing websites, monitor for leaked credentials in breach databases, and audit DNS records for forgotten subdomains or test environments. Regular OSINT assessments – ideally as part of a penetration testing programme – identify exposure before attackers exploit it. The goal is not to eliminate all public information, but to remove data that provides a direct advantage to an attacker.
Awards and Accreditations




















Contact Us
Cyberfort Ltd
Venture West,
Greenham Business Park, Thatcham,
Berkshire,
RG19 6HX
