We collect everything that is publicly known about your company — before attackers do. Subdomains, leaks, credentials, S3 buckets, social profiles.
Task: assess what an attacker could learn about the company from open sources. We worked only with the client's domain name — no internal data.
A complete profile of the company's digital presence
Subdomain enumeration, DNS records, ASN, IP ranges, historical data, reverse DNS.
Search across leak databases, pastebin, GitHub, public dumps. Emails, passwords, API keys, tokens.
S3 buckets, Azure Blob, GCP Storage — open or misconfigured storages.
LinkedIn, social networks, public employee profiles. Company structure, roles, contacts.
Used technologies, software versions, Shodan/Censys data, open ports and services.
GitHub, GitLab, Bitbucket — accidentally committed secrets, internal tools, architecture.
Methodical collection, analysis, report
We fix what we investigate: domains, brands, key people. NDA before we start. We define the depth of reconnaissance.
Collection from open sources without direct contact with the client's infrastructure: DNS, WHOIS, Shodan, search engines, social networks.
Subdomain enumeration, checking open ports and services, analyzing public repositories, hunting for leaks.
A structured report: what was found, where the risk is, how to close it. Prioritized by criticality.
Write to us — we'll run the reconnaissance before someone does it for you.