Back to glossary

OSINT

2 min read

In offensive security, OSINT (open source intelligence) is the gathering of information about a target from publicly available sources: registration records, code repositories, social media, leaked data and the wider web. It is the first move of almost every engagement and the shared vocabulary of several of the firm’s services.

July 29, 2026
Compartir:

How it works

OSINT collects what is already public. For a target organisation that includes domain and certificate registration records, the DNS footprint, the technologies its sites reveal, the accounts and email formats visible on professional networks, code and configuration accidentally published in public repositories, documents with revealing metadata, and credentials exposed in past leaks. None of it touches the target’s own systems, so it is entirely passive and leaves no trace on them. Its purpose is to build a picture before any active work begins: what the organisation looks like from outside, who works there, what it runs, and where it has already leaked something useful. It is the intelligence half of reconnaissance, the part done from open sources rather than by probing.

What goes wrong

Organisations underestimate how much of their attack surface is assembled entirely from public information, and how directly it fuels an attack. A published email format plus a name from a professional network gives an attacker valid usernames; a repository left public leaks a credential or an internal hostname; a document’s metadata names an internal server. From the attacker’s side, hours of quiet collection produce the material for a targeted phishing message, a password-spraying list, or a route into the perimeter, without a single packet sent to the target. The exposure grows continuously as employees post, as code is pushed, and as old data leaks accumulate on the dark web, and the organisation usually has no view of it.

Where this shows up in an audit

We begin an external engagement with OSINT and report the exposure it finds as its own set of findings: the leaked credentials still valid, the public repository with a secret, the metadata or DNS record that reveals internal detail, each with the source and the risk it creates. It is passive, so it also frames what the active testing should target. Continuous collection of this kind is the basis of digital risk protection and feeds threat intelligence. This is part of how we map a target before touching it.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.