Open Source Intelligence Analysis
An attacker-minded review of public information that could be used to profile the firm, target employees or prepare a broader attack.
Know when to bring this work into the program.
Use OSINT analysis to see the firm through an attacker’s eyes before a penetration test, social engineering exercise or executive-protection review.
A scope built around the risk.
An attacker-minded review of public information that could be used to profile the firm, target employees or prepare a broader attack.
- Domains, infrastructure and technology exposure
- Employee roles, contact data and relationships
- Leaked documents, metadata and credentials
- Information that supports convincing pretexts
Useful output for the people who must act.
- Curated exposure report
- Likely attacker profiles and targeting opportunities
- Recommendations to reduce unnecessary exposure
- Intelligence for authorized follow-on testing
A process designed for open source intelligence analysis.
Define the targets
Begin with domains, infrastructure and technology exposure and confirm the systems, people and evidence needed to answer the client’s specific questions.
Collect public exposure
Review employee roles, contact data and relationships. Then evaluate leaked documents, metadata and credentials to determine whether the relevant controls operate as intended.
Build the adversary view
Assess information that supports convincing pretexts and connect the result to credible security, operational and business impact.
Reduce the footprint
Provide curated exposure report and likely attacker profiles and targeting opportunities, then align responsible parties around the next actions.
Move from activity to clarity.
What can an attacker learn without touching the environment?
To answer this, Elteni analyzes domains, infrastructure and technology exposure together with employee roles, contact data and relationships. The client receives curated exposure report, with the evidence, context and next steps needed to act.
Which people or vendors are easiest to impersonate?
To answer this, Elteni analyzes employee roles, contact data and relationships together with leaked documents, metadata and credentials. The client receives likely attacker profiles and targeting opportunities, with the evidence, context and next steps needed to act.
Does public information reveal technology or security clues?
To answer this, Elteni analyzes leaked documents, metadata and credentials together with information that supports convincing pretexts. The client receives recommendations to reduce unnecessary exposure, with the evidence, context and next steps needed to act.
The result does not have to live in another report.
Relevant findings, evidence, owners and remediation status can be centralized in the Elteni Platform as part of an ongoing relationship.
Explore the Elteni Platform →