Skip to content
Osintpro

OSINT Cybersecurity Work: Estate, Vendors and Lookalikes

Security teams already do this work. What is usually missing is not capability, it is the record: a collection you can date, re-run next quarter and hand to somebody outside the team without translating it first.

Passive throughout, which is what makes it usable on assets you do not have authorization to test.

See pricing
  • Authorized use only.
  • Domains only, never a person.
  • Every finding sourced and timestamped.
  • Passive collection only.

The four jobs this actually covers.

Not a platform strategy. These are the four requests that arrive repeatedly and get answered with browser tabs.

Own-estate external surface review

What do we expose, what changed since last quarter, and is it worse. Dated findings that subtract cleanly. Covered at length on attack surface management.

Vendor and supplier assessment

A per-counterparty artifact that goes in a file and satisfies an auditor, produced before a contract exists and without touching their systems.

Acquisition target infrastructure check

Registration age, hosting concentration, mail posture, certificate surface. Passive, so it works before the deal is announced and leaves nothing in anyone's logs.

Brand and lookalike monitoring

Typosquats and phishing infrastructure targeting your own name, with the registration evidence attached in a form a complaint can actually use.

The capability is not the gap. The record is.

Any competent security engineer can pull DNS, read a DMARC policy and search a certificate transparency log. The work is not hard. What breaks is everything after collection.

The findings live in a Slack thread and a screenshot. Nobody can say which day the record was retrieved, so next quarter's review cannot produce a diff and starts over. When procurement asks for the vendor assessment in a form they can file, an engineer spends an afternoon rewriting it into a document. And when somebody asks why the team was assessing a third party, the scope exists only in the memory of whoever ran it.

None of those are collection problems. They are record problems, and they are why the same estate gets re-enumerated from scratch every year.

The derived findings a security reader cares about.

Records in the first column, the derivation in the second, the thing you actually report in the third.

SPF qualifier and DMARC policy

Derivation
Rules published, enforcement level read from the policy tag
The finding
Whether the domain can be spoofed in practice, not just on paper

MX hostnames

Derivation
Provider attribution from the hostname set
The finding
Mail vendor concentration and the phishing surface it implies

RDAP events and status codes

Derivation
Age against claimed history, locks present or absent, expiry window
The finding
Hijacking exposure, lapse risk, and counterparty age inconsistencies

NS set and apex addresses

Derivation
Vendor attribution and redundancy read from delegation
The finding
Which external accounts can change your zone, and how many

CAA records

Derivation
Issuer restriction present or absent
The finding
Whether any public CA may issue certificates for the domain

Common-label resolution

Derivation
Which administrative labels answer publicly
The finding
Discoverable administrative and pre-production surface

Run it against a domain you own.

Pick "Own estate review", tick the authorization box, and run one of your own domains. Everything is passive: no packet reaches the subject and nothing appears in their logs.

  • It runs in your browser. Queries go to public DNS and RDAP endpoints, not through us.

  • Nothing reaches the subject. The domain you enter is never contacted, probed or scanned.

  • A domain, never a person. There is no input on this panel that accepts an individual.

  • Findings carry their evidence. Raw record, source endpoint and the UTC moment of retrieval.

Domain footprint sweep

passive collection only

stamped on the report
Samples:

Every finding will carry four things

  • 1 Severity. What the record means for the decision in front of you.
  • 2 The raw record. Exactly as the source returned it, unedited.
  • 3 The source endpoint. The request that produced it, so it can be re-run.
  • 4 The UTC retrieval time. Records change. Without this it is an assertion.

Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.

Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.

This is not a threat intelligence feed, and does not replace one.

Feed-shaped questions need feed-shaped products.

If you need to know what is happening globally, which campaigns target your sector and which technologies are under active exploitation, keep your threat intelligence platform. This does not do that and will disappoint you if you expect it to.

What it does is the entity-shaped question: tell me about this specific domain or organization, defensibly, with the collection dated. The two run together well and the split is covered on threat intelligence platforms.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.