OSINT & Attack Surface Assessment
OSINT attack surface assessment mapping everything an attacker can see: exposed assets, leaked credentials and shadow IT, found without touching a system.
An OSINT attack surface assessment maps everything an attacker can learn about your organization from the outside, before they ever send a packet at your systems. We use only public and passive sources, so nothing we do touches your infrastructure, yet the picture we build is exactly the one a determined intruder starts from.
What an OSINT attack surface assessment covers
Companies grow faster than their asset inventories. A marketing team spins up a landing page, a developer pushes a test API to a cloud account nobody tracks, an old subdomain keeps pointing at a service that was decommissioned two years ago. Every one of those is a door, and most organizations cannot list their own doors. This assessment finds them the way an attacker would, using open-source intelligence rather than intrusive scanning.
We look across the full external footprint: internet-facing hosts and services, domains and subdomains, cloud storage, code repositories, exposed credentials in breach data, and the human and technical signals that reveal shadow IT. The output is a ranked map of your external attack surface, with the genuinely dangerous exposures separated from the noise.
How we build your external picture
The discipline in open-source intelligence is not finding data, it is finding the data that matters and confirming it is really yours. Our attack surface assessment follows a structured passive methodology so nothing is missed and nothing false makes it into the report.
Seed and expand
We start from what you own: primary domains, brand names, known IP ranges, acquired companies. From those seeds we expand outward through passive DNS, WHOIS history, autonomous-system lookups and certificate transparency, pulling in every asset that traces back to your organization. Acquisitions and old brands are a common source of surprises here.
Enumerate and fingerprint
With the domain space mapped, we enumerate subdomains and fingerprint the services behind them using passive sources such as Shodan and Censys. This tells us what technology is exposed, which software versions are running, and where an old appliance or a forgotten staging server is quietly listening on the internet. We never actively exploit anything at this stage; the point is visibility.
Hunt for leaks
People leak more than infrastructure does. We search public code repositories for hardcoded API keys, cloud credentials and connection strings, comb breach and combolist data for employee logins tied to your domains, and check for open cloud storage that indexes itself to the world. A single valid credential in a paste site can undo an otherwise solid perimeter.
Correlate and rank
Raw findings are only useful once they are prioritized. We correlate the discovered assets, flag the ones that represent real risk such as an exposed admin panel or a leaked live credential, and rank them by how easily an attacker could turn them into access. The result is a shortlist you can act on this week, not a data dump.
The exposures we typically surface
Every organization is different, but certain findings come up again and again in the assessments we run across Europe.
Shadow IT and forgotten assets
The single most common finding is an asset nobody remembered. A demo environment left running, a subdomain from a campaign that ended, an old mail server that never got decommissioned. These sit outside patching and monitoring, which is precisely why attackers love them.
Leaked credentials and secrets
Employee passwords appear in breach dumps constantly, and people reuse them. We match leaked credentials to your domains so you know which accounts to force-reset. In parallel we look for developer secrets committed to public repositories, where an AWS key or a database password can open a direct path in.
Subdomain takeover and dangling DNS
When a service is retired but its DNS record is left pointing at the now-free cloud resource, an attacker can claim that resource and serve content from your domain. We flag every dangling record so you can clean them up before someone hosts a phishing page on your own brand.
Exposed panels and misconfigured storage
Admin interfaces, database consoles and monitoring dashboards routinely end up reachable from the internet by mistake. Publicly listable cloud storage is just as common. Both are catalogued with enough detail for your team to lock them down fast.
Metadata and document leakage
Public documents give away more than their contents. File metadata reveals internal usernames, software versions and folder paths, and it accumulates in PDFs and office files published on your own site. We surface this leakage because it hands an attacker the naming conventions and internal detail that make later social engineering far more convincing.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
What you receive
The deliverable is a working document, not a certificate to file away. It is meant to drive a remediation sprint.
A ranked external asset inventory
You get a complete list of the internet-facing assets we tied to your organization, each with its discovery source, the technology fingerprint, and a risk rating. For many clients this is the first accurate inventory of their own perimeter they have ever held.
Prioritized findings with remediation
Each exposure comes with a plain description, the evidence, the likely impact, and a specific fix. Leaked credentials get a reset list. Dangling records get the exact DNS entries to remove. Exposed services get a decommission or restrict recommendation. A free re-scan afterward confirms the surface has actually shrunk.
A basis for deeper testing
An attack surface assessment pairs naturally with a penetration test. Once you know what is exposed, an active test can safely probe the assets that matter most. Many clients use this engagement to scope a follow-on external network or web application pentest with confidence.
Compliance and governance value
Knowing your attack surface is not just good hygiene, it underpins several obligations European organizations carry.
ISO 27001 asset management
ISO 27001:2022 controls A.5.9 and A.8.1 expect a maintained inventory of information and associated assets. An external attack surface assessment gives you evidence that internet-facing assets are identified and managed, including the ones outside your official register.
GDPR, NIS2 and continuous monitoring
The GDPR’s article 32 calls for appropriate technical measures to secure personal data, and you cannot protect an asset you do not know exists. For entities under NIS2, understanding and reducing the external attack surface directly supports the risk-management and asset-visibility duties the directive imposes. Where clients want ongoing assurance, we run external attack surface management on a recurring basis so new exposures are caught as they appear.
Why analyst-led OSINT beats an automated scan
Automated attack-surface tools are fast, and they miss the things that matter. They struggle to attribute an asset to the right owner, they flood you with low-value alerts, and they cannot judge whether a leaked credential is live or a decade old. An analyst can. Our engineers confirm ownership, weed out false positives, and connect separate findings into a real attack path, such as a leaked key that unlocks a bucket that reveals more infrastructure. You get a short list of genuine problems instead of a dashboard full of maybes.
How we work, and where we draw the line
Open-source intelligence sits close to a legal and ethical boundary, and staying the right side of it is part of doing the job properly.
Passive means passive
Throughout the assessment we only observe. We query public records, indexes and datasets that anyone could reach, and we never log in, exploit, or send traffic designed to trigger a system. That is what makes the engagement safe to run against production without a maintenance window, and it is why we can start without a long authorization chain.
Confirmed ownership, no collateral targets
Attribution errors are a real risk in this work, because a subdomain or an IP can look like yours without being yours. We confirm ownership before anything lands in the report, so you are not chasing an asset that belongs to a neighbor on shared hosting or a former supplier. Anything we cannot confirm is flagged as unverified rather than asserted.
Handled under NDA
The findings from this work are a map of exactly how to attack you, so they are sensitive by nature. We handle everything under NDA, deliver through secure channels, and can destroy our copy of the data on request once you have the report. Leaked credentials are shared in a form your team can act on without exposing them further.
Pricing
Pricing depends on the size of your footprint: how many domains and brands, how large the IP space, and whether you want a one-off map or continuous monitoring. Because this work is fully passive, it is one of the most cost-effective ways to understand your risk.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Essential map | Single primary domain, subdomain enumeration, exposed-service fingerprinting, breach-credential check, ranked report | 3–5 working days | from €1,800 |
| Standard assessment | Multiple domains and brands, cloud-storage and public-repo secret hunting, subdomain-takeover checks, exec + technical report | 5–8 working days | €2,800–€6,000 |
| Advanced discovery | Large footprint with acquisitions, deep leaked-credential correlation, shadow-IT hunting, attack-path narrative | 8–12 working days | €6,000–€12,000 |
| Continuous monitoring | Ongoing external attack surface management with alerting on new or changed exposures | monthly | from €450/month |
| Custom / large estate | Global brand portfolio, multiple business units, blended with red-team objectives | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, and a re-scan is included after you remediate. Get a fixed quote
FAQ
How much does an OSINT attack surface assessment cost?
Will this touch or disrupt our live systems?
How is this different from a penetration test?
Can you find our leaked passwords and exposed secrets?
What about assets we don’t even know we own?
Do you offer continuous external attack surface management?
How long does the assessment take?
What do we get at the end?
Related services
Organizations that have grown through cloud adoption or acquisition and lost track of their real perimeter, security leads who need an accurate external asset inventory, and any European business scoping a penetration test or hardening its ISO 27001 asset management.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.