Skip to content
Osintpro

OSINT Investigation Use Cases

Each one below is a request that already lands on somebody's desk, answered today with six browser tabs and a spreadsheet. The change is not the collection. It is what you are holding at the end.

  • Six investigations, before and after.
  • The same collection in all six.
  • Domains only, never a person.
  • Authorized use only.

The request, and what comes back

Six investigations, with the before and the after.

Case 1 Third-party risk, procurement

Vendor due diligence before signature

Before
Three hours across six tabs, ending in a spreadsheet row that reads "checked, no issues, March". Nobody can say what was checked or on which day.
After
A scoped case and a sourced dossier filed against the vendor. Registration age, mail spoofability, infrastructure control, each with its record and UTC retrieval time. An artifact the auditor accepts.

Third party risk screening

Case 2 Security engineering, CISO

Own-estate attack surface review

Before
A subdomain list of unknown age. Next quarter nobody can tell what changed, so the review starts again from nothing.
After
Dated findings with the record attached, so the following quarter subtracts cleanly. What changed is the finding, and that is the slide leadership wanted.

Attack surface management

Case 3 Corp dev, security due diligence

Acquisition target infrastructure check

Before
Guesswork about what you are buying, assembled from the target's own marketing and a call with their CTO.
After
Registration age, hosting concentration, mail posture and certificate surface, cited and dated. Passive, so it runs before the deal is announced and leaves nothing in their logs.

OSINT for security teams

Case 4 Operations, legal, compliance

Authorized pre-engagement screening

Before
An unstructured look at a counterparty, with the reason for looking existing only in somebody's memory.
After
Consent-backed corporate screening with the basis recorded before collection. Never a consumer background check and never a people search.

Pre-engagement screening

Case 5 Strategy, corp dev, BD

Competitive infrastructure mapping

Before
A deck built from the competitor's marketing material, which describes what they want said about them.
After
Their public stack read from their own records: vendor verification strings, mail provider, DNS delegation, new hostnames in transparency logs. Observation separated from inference.

Competitive intelligence

Case 6 Security, brand protection, legal

Brand and lookalike domain monitoring

Before
A phishing report forwarded to legal with a screenshot attached and no registration evidence.
After
Typosquat registrations enumerated with dates, registrar of record and mail configuration attached, which is what a registrar complaint or a UDRP filing actually needs.

OSINT for investigators

The same collection, in every case above

One scoped sweep, six different questions.

What changes between the use cases is the scope you declare and what you do with the artifact. The collection itself is the same: passive, public sources, every finding carrying the raw record, the source endpoint and the UTC moment of retrieval.

Domains only. This tool has no input that accepts a person, which is a structural limit rather than a promise. Read the boundary we publish.

Domain footprint sweep

passive collection only

stamped on the report
Samples:

Every finding will carry four things

  • 1 Severity. What the record means for the decision in front of you.
  • 2 The raw record. Exactly as the source returned it, unedited.
  • 3 The source endpoint. The request that produced it, so it can be re-run.
  • 4 The UTC retrieval time. Records change. Without this it is an assertion.

Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.

Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.

Each written for the person who runs it

Use cases in depth.

New to the category? Start with open source intelligence, see how a scoped case runs, or compare the alternatives on best OSINT tools.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.