OSINT Cybersecurity Work: Estate, Vendors and Lookalikes
Security teams already do this work. What is usually missing is not capability, it is the record: a collection you can date, re-run next quarter and hand to somebody outside the team without translating it first.
Passive throughout, which is what makes it usable on assets you do not have authorization to test.
- Authorized use only.
- Domains only, never a person.
- Every finding sourced and timestamped.
- Passive collection only.
The four jobs this actually covers.
Not a platform strategy. These are the four requests that arrive repeatedly and get answered with browser tabs.
Own-estate external surface review
What do we expose, what changed since last quarter, and is it worse. Dated findings that subtract cleanly. Covered at length on attack surface management.
Vendor and supplier assessment
A per-counterparty artifact that goes in a file and satisfies an auditor, produced before a contract exists and without touching their systems.
Acquisition target infrastructure check
Registration age, hosting concentration, mail posture, certificate surface. Passive, so it works before the deal is announced and leaves nothing in anyone's logs.
Brand and lookalike monitoring
Typosquats and phishing infrastructure targeting your own name, with the registration evidence attached in a form a complaint can actually use.
The capability is not the gap. The record is.
Any competent security engineer can pull DNS, read a DMARC policy and search a certificate transparency log. The work is not hard. What breaks is everything after collection.
The findings live in a Slack thread and a screenshot. Nobody can say which day the record was retrieved, so next quarter's review cannot produce a diff and starts over. When procurement asks for the vendor assessment in a form they can file, an engineer spends an afternoon rewriting it into a document. And when somebody asks why the team was assessing a third party, the scope exists only in the memory of whoever ran it.
None of those are collection problems. They are record problems, and they are why the same estate gets re-enumerated from scratch every year.
The derived findings a security reader cares about.
Records in the first column, the derivation in the second, the thing you actually report in the third.
SPF qualifier and DMARC policy
- Derivation
- Rules published, enforcement level read from the policy tag
- The finding
- Whether the domain can be spoofed in practice, not just on paper
MX hostnames
- Derivation
- Provider attribution from the hostname set
- The finding
- Mail vendor concentration and the phishing surface it implies
RDAP events and status codes
- Derivation
- Age against claimed history, locks present or absent, expiry window
- The finding
- Hijacking exposure, lapse risk, and counterparty age inconsistencies
NS set and apex addresses
- Derivation
- Vendor attribution and redundancy read from delegation
- The finding
- Which external accounts can change your zone, and how many
CAA records
- Derivation
- Issuer restriction present or absent
- The finding
- Whether any public CA may issue certificates for the domain
Common-label resolution
- Derivation
- Which administrative labels answer publicly
- The finding
- Discoverable administrative and pre-production surface
Run it against a domain you own.
Pick "Own estate review", tick the authorization box, and run one of your own domains. Everything is passive: no packet reaches the subject and nothing appears in their logs.
-
It runs in your browser. Queries go to public DNS and RDAP endpoints, not through us.
-
Nothing reaches the subject. The domain you enter is never contacted, probed or scanned.
-
A domain, never a person. There is no input on this panel that accepts an individual.
-
Findings carry their evidence. Raw record, source endpoint and the UTC moment of retrieval.
Domain footprint sweep
passive collection only
Every finding will carry four things
- 1 Severity. What the record means for the decision in front of you.
- 2 The raw record. Exactly as the source returned it, unedited.
- 3 The source endpoint. The request that produced it, so it can be re-run.
- 4 The UTC retrieval time. Records change. Without this it is an assertion.
Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.
Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.
[]
Scope:
Analyst summary
This is not a threat intelligence feed, and does not replace one.
Feed-shaped questions need feed-shaped products.
If you need to know what is happening globally, which campaigns target your sector and which technologies are under active exploitation, keep your threat intelligence platform. This does not do that and will disappoint you if you expect it to.
What it does is the entity-shaped question: tell me about this specific domain or organization, defensibly, with the collection dated. The two run together well and the split is covered on threat intelligence platforms.
More from Osintpro
- Attack surface management
- Best OSINT tools
- Censys alternative
- Competitive intelligence
- Cybersecurity due diligence
- DNS lookup tool
- Free OSINT tools
- Investigators
- Maltego alternative
New to the category? Start with open source intelligence, then see how a scoped case runs or read the analyst notes on the blog.
Run one scoped sweep and see what a sourced finding looks like.
The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.
- Passive collection only, from public sources.
- A domain, never a person. There is no input for one.
- Your case data stays yours. No card required.