OSINT
In offensive security, OSINT (open source intelligence) is the gathering of information about a target from publicly available sources: registration records, code repositories, social media, leaked data and the wider web. It is the first move of almost every engagement and the shared vocabulary of several of the firm’s services.
How it works
OSINT collects what is already public. For a target organisation that includes domain and certificate registration records, the DNS footprint, the technologies its sites reveal, the accounts and email formats visible on professional networks, code and configuration accidentally published in public repositories, documents with revealing metadata, and credentials exposed in past leaks. None of it touches the target’s own systems, so it is entirely passive and leaves no trace on them. Its purpose is to build a picture before any active work begins: what the organisation looks like from outside, who works there, what it runs, and where it has already leaked something useful. It is the intelligence half of reconnaissance, the part done from open sources rather than by probing.
What goes wrong
Organisations underestimate how much of their attack surface is assembled entirely from public information, and how directly it fuels an attack. A published email format plus a name from a professional network gives an attacker valid usernames; a repository left public leaks a credential or an internal hostname; a document’s metadata names an internal server. From the attacker’s side, hours of quiet collection produce the material for a targeted phishing message, a password-spraying list, or a route into the perimeter, without a single packet sent to the target. The exposure grows continuously as employees post, as code is pushed, and as old data leaks accumulate on the dark web, and the organisation usually has no view of it.
Where this shows up in an audit
We begin an external engagement with OSINT and report the exposure it finds as its own set of findings: the leaked credentials still valid, the public repository with a secret, the metadata or DNS record that reveals internal detail, each with the source and the risk it creates. It is passive, so it also frames what the active testing should target. Continuous collection of this kind is the basis of digital risk protection and feeds threat intelligence. This is part of how we map a target before touching it.