Service

OSINT
and corporate
intelligence

We collect everything that is publicly known about your company — before attackers do. Subdomains, leaks, credentials, S3 buckets, social profiles.

Discuss your project Pentest →
OSINT Threat Intel Attack Surface Subdomain Enum Leak Search DNS Recon Shodan NDA
47
subdomains found
in one case
12
leaks in one case
6h
typical timeline
100%
NDA
Real case

Corporate reconnaissance — in 6 hours

Task: assess what an attacker could learn about the company from open sources. We worked only with the client's domain name — no internal data.

47subdomains discovered
12leaks with credentials
3open S3 buckets
6htime spent

What we collect

A complete profile of the company's digital presence

DNS

Infrastructure and domains

Subdomain enumeration, DNS records, ASN, IP ranges, historical data, reverse DNS.

Leaks

Leaks and credentials

Search across leak databases, pastebin, GitHub, public dumps. Emails, passwords, API keys, tokens.

Cloud

Exposed cloud resources

S3 buckets, Azure Blob, GCP Storage — open or misconfigured storages.

People

Employees and socials

LinkedIn, social networks, public employee profiles. Company structure, roles, contacts.

Tech

Technology stack

Used technologies, software versions, Shodan/Censys data, open ports and services.

Code

Public repositories

GitHub, GitLab, Bitbucket — accidentally committed secrets, internal tools, architecture.

How we work

Methodical collection, analysis, report

01

Scope and NDA

We fix what we investigate: domains, brands, key people. NDA before we start. We define the depth of reconnaissance.

02

Passive reconnaissance

Collection from open sources without direct contact with the client's infrastructure: DNS, WHOIS, Shodan, search engines, social networks.

03

Active collection

Subdomain enumeration, checking open ports and services, analyzing public repositories, hunting for leaks.

04

Analysis and report

A structured report: what was found, where the risk is, how to close it. Prioritized by criticality.

FAQ

What is OSINT reconnaissance for business?
Collection and analysis of publicly available information about the company — what an attacker can learn before the attack. Domains, employees, technologies, leaks, exposed resources.
Is this legal?
Yes. OSINT works only with publicly available data. No unauthorized access to systems — only what is already available to anyone on the internet.
How long does reconnaissance take?
Base OSINT for a single domain — 6–24 hours. A full audit of the company's digital presence — 2–5 business days.
What will this report give me?
An understanding of what a potential attacker knows about you. A list of concrete risks — leaked passwords, exposed services, public secrets — with recommendations on how to close them.

Find out what the internet knows about you

Write to us — we'll run the reconnaissance before someone does it for you.

Telegram: @FzControl Red Team →