Home/Services/OSINT & Attack Surface Assessment
security service

OSINT & Attack Surface Assessment

OSINT attack surface assessment mapping everything an attacker can see: exposed assets, leaked credentials and shadow IT, found without touching a system.

Manual, expert-ledEvidence-based findingsFree remediation retest

An OSINT attack surface assessment maps everything an attacker can learn about your organization from the outside, before they ever send a packet at your systems. We use only public and passive sources, so nothing we do touches your infrastructure, yet the picture we build is exactly the one a determined intruder starts from.

What an OSINT attack surface assessment covers

Companies grow faster than their asset inventories. A marketing team spins up a landing page, a developer pushes a test API to a cloud account nobody tracks, an old subdomain keeps pointing at a service that was decommissioned two years ago. Every one of those is a door, and most organizations cannot list their own doors. This assessment finds them the way an attacker would, using open-source intelligence rather than intrusive scanning.

We look across the full external footprint: internet-facing hosts and services, domains and subdomains, cloud storage, code repositories, exposed credentials in breach data, and the human and technical signals that reveal shadow IT. The output is a ranked map of your external attack surface, with the genuinely dangerous exposures separated from the noise.

Full subdomain enumeration across passive DNS and certificate transparency logs
Internet-exposed services fingerprinted through Shodan and Censys
Publicly readable S3 buckets, blob containers and other exposed cloud storage
Secrets and API keys leaked in public GitHub and GitLab repositories
Employee credentials surfaced in known breach and combolist dumps
Forgotten subdomains and dangling DNS records ripe for takeover

How we build your external picture

The discipline in open-source intelligence is not finding data, it is finding the data that matters and confirming it is really yours. Our attack surface assessment follows a structured passive methodology so nothing is missed and nothing false makes it into the report.

Seed and expand

We start from what you own: primary domains, brand names, known IP ranges, acquired companies. From those seeds we expand outward through passive DNS, WHOIS history, autonomous-system lookups and certificate transparency, pulling in every asset that traces back to your organization. Acquisitions and old brands are a common source of surprises here.

Enumerate and fingerprint

With the domain space mapped, we enumerate subdomains and fingerprint the services behind them using passive sources such as Shodan and Censys. This tells us what technology is exposed, which software versions are running, and where an old appliance or a forgotten staging server is quietly listening on the internet. We never actively exploit anything at this stage; the point is visibility.

Hunt for leaks

People leak more than infrastructure does. We search public code repositories for hardcoded API keys, cloud credentials and connection strings, comb breach and combolist data for employee logins tied to your domains, and check for open cloud storage that indexes itself to the world. A single valid credential in a paste site can undo an otherwise solid perimeter.

Correlate and rank

Raw findings are only useful once they are prioritized. We correlate the discovered assets, flag the ones that represent real risk such as an exposed admin panel or a leaked live credential, and rank them by how easily an attacker could turn them into access. The result is a shortlist you can act on this week, not a data dump.

100%
passive: we never touch your systems
3–7d
typical turnaround for a full external map
Free
re-scan after you remediate exposures

The exposures we typically surface

Every organization is different, but certain findings come up again and again in the assessments we run across Europe.

Shadow IT and forgotten assets

The single most common finding is an asset nobody remembered. A demo environment left running, a subdomain from a campaign that ended, an old mail server that never got decommissioned. These sit outside patching and monitoring, which is precisely why attackers love them.

Leaked credentials and secrets

Employee passwords appear in breach dumps constantly, and people reuse them. We match leaked credentials to your domains so you know which accounts to force-reset. In parallel we look for developer secrets committed to public repositories, where an AWS key or a database password can open a direct path in.

Subdomain takeover and dangling DNS

When a service is retired but its DNS record is left pointing at the now-free cloud resource, an attacker can claim that resource and serve content from your domain. We flag every dangling record so you can clean them up before someone hosts a phishing page on your own brand.

Exposed panels and misconfigured storage

Admin interfaces, database consoles and monitoring dashboards routinely end up reachable from the internet by mistake. Publicly listable cloud storage is just as common. Both are catalogued with enough detail for your team to lock them down fast.

Metadata and document leakage

Public documents give away more than their contents. File metadata reveals internal usernames, software versions and folder paths, and it accumulates in PDFs and office files published on your own site. We surface this leakage because it hands an attacker the naming conventions and internal detail that make later social engineering far more convincing.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

What you receive

The deliverable is a working document, not a certificate to file away. It is meant to drive a remediation sprint.

A ranked external asset inventory

You get a complete list of the internet-facing assets we tied to your organization, each with its discovery source, the technology fingerprint, and a risk rating. For many clients this is the first accurate inventory of their own perimeter they have ever held.

Prioritized findings with remediation

Each exposure comes with a plain description, the evidence, the likely impact, and a specific fix. Leaked credentials get a reset list. Dangling records get the exact DNS entries to remove. Exposed services get a decommission or restrict recommendation. A free re-scan afterward confirms the surface has actually shrunk.

A basis for deeper testing

An attack surface assessment pairs naturally with a penetration test. Once you know what is exposed, an active test can safely probe the assets that matter most. Many clients use this engagement to scope a follow-on external network or web application pentest with confidence.

Compliance and governance value

Knowing your attack surface is not just good hygiene, it underpins several obligations European organizations carry.

ISO 27001 asset management

ISO 27001:2022 controls A.5.9 and A.8.1 expect a maintained inventory of information and associated assets. An external attack surface assessment gives you evidence that internet-facing assets are identified and managed, including the ones outside your official register.

GDPR, NIS2 and continuous monitoring

The GDPR’s article 32 calls for appropriate technical measures to secure personal data, and you cannot protect an asset you do not know exists. For entities under NIS2, understanding and reducing the external attack surface directly supports the risk-management and asset-visibility duties the directive imposes. Where clients want ongoing assurance, we run external attack surface management on a recurring basis so new exposures are caught as they appear.

Why analyst-led OSINT beats an automated scan

Automated attack-surface tools are fast, and they miss the things that matter. They struggle to attribute an asset to the right owner, they flood you with low-value alerts, and they cannot judge whether a leaked credential is live or a decade old. An analyst can. Our engineers confirm ownership, weed out false positives, and connect separate findings into a real attack path, such as a leaked key that unlocks a bucket that reveals more infrastructure. You get a short list of genuine problems instead of a dashboard full of maybes.

How we work, and where we draw the line

Open-source intelligence sits close to a legal and ethical boundary, and staying the right side of it is part of doing the job properly.

Passive means passive

Throughout the assessment we only observe. We query public records, indexes and datasets that anyone could reach, and we never log in, exploit, or send traffic designed to trigger a system. That is what makes the engagement safe to run against production without a maintenance window, and it is why we can start without a long authorization chain.

Confirmed ownership, no collateral targets

Attribution errors are a real risk in this work, because a subdomain or an IP can look like yours without being yours. We confirm ownership before anything lands in the report, so you are not chasing an asset that belongs to a neighbor on shared hosting or a former supplier. Anything we cannot confirm is flagged as unverified rather than asserted.

Handled under NDA

The findings from this work are a map of exactly how to attack you, so they are sensitive by nature. We handle everything under NDA, deliver through secure channels, and can destroy our copy of the data on request once you have the report. Leaked credentials are shared in a form your team can act on without exposing them further.

Pricing

Pricing depends on the size of your footprint: how many domains and brands, how large the IP space, and whether you want a one-off map or continuous monitoring. Because this work is fully passive, it is one of the most cost-effective ways to understand your risk.

Engagement What’s included Timeline Price
Essential map Single primary domain, subdomain enumeration, exposed-service fingerprinting, breach-credential check, ranked report 3–5 working days from €1,800
Standard assessment Multiple domains and brands, cloud-storage and public-repo secret hunting, subdomain-takeover checks, exec + technical report 5–8 working days €2,800–€6,000
Advanced discovery Large footprint with acquisitions, deep leaked-credential correlation, shadow-IT hunting, attack-path narrative 8–12 working days €6,000–€12,000
Continuous monitoring Ongoing external attack surface management with alerting on new or changed exposures monthly from €450/month
Custom / large estate Global brand portfolio, multiple business units, blended with red-team objectives on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, and a re-scan is included after you remediate. Get a fixed quote

FAQ

How much does an OSINT attack surface assessment cost?
A single-domain map starts from €1,800, and the price rises with the number of domains, brands and cloud accounts in scope. You get a fixed quote after a free scoping call.
Will this touch or disrupt our live systems?
No. The assessment is entirely passive and uses public sources such as certificate transparency, Shodan, Censys, breach data and public code. We do not send exploit traffic or scan intrusively, so there is zero risk to availability.
How is this different from a penetration test?
An attack surface assessment maps what is exposed without touching it, while a penetration test actively probes and exploits chosen targets. They pair well: the assessment finds the doors, and a pentest checks which ones open. Many clients scope a follow-on test from the results.
Can you find our leaked passwords and exposed secrets?
Yes. We correlate employee credentials against known breach and combolist data tied to your domains, and we hunt public GitHub and GitLab for hardcoded API keys, cloud credentials and connection strings. Each finding comes with a reset or rotation recommendation.
What about assets we don’t even know we own?
Finding those is the core value. Shadow IT, forgotten staging servers, subdomains from old campaigns and assets inherited through acquisitions show up regularly, and they are usually the highest risk because nobody is patching them.
Do you offer continuous external attack surface management?
Yes. Beyond a one-off map we can monitor your footprint on a recurring basis from €450/month and alert you when a new host, subdomain or exposure appears, so your perimeter stays known as it changes.
How long does the assessment take?
A single-domain map typically takes three to five working days, and a large multi-brand footprint with deep credential correlation runs eight to twelve. You hear about anything critical, like a live leaked key, the moment we confirm it.
What do we get at the end?
A ranked inventory of your internet-facing assets, a prioritized list of exposures with evidence and specific fixes, and an executive summary of your external risk. A free re-scan afterward confirms the surface has shrunk.

Related services

Who needs this

Organizations that have grown through cloud adoption or acquisition and lost track of their real perimeter, security leads who need an accurate external asset inventory, and any European business scoping a penetration test or hardening its ISO 27001 asset management.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "OSINT & Attack Surface Assessment"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.