Logo webu

Introduction to OSINT: techniques and applications in cybersecurity

17.6. 2024 | 10 min read | author: Marek Malcovský

OSINT (Open Source Intelligence) is a technique for gathering information from publicly available sources. These sources include various types of media, the internet, social networks, government publications, academic papers, and other freely accessible information.

Marek is an ethical hacker with a keen eye for detail. Throughout his career, he has uncovered vulnerabilities in several respected software products and systems used by companies worldwide. At Axelum, his primary role involves identifying security vulnerabilities in complex systems, making him a key member of the Red Team.
Marek holds the globally recognized Offensive Security Certified Professional (OSCP) certification for ethical hacking. Among his accomplishments, Marek also developed the Perimeter Guard service, which actively protects our clients' perimeters.

What specific techniques are part of the use of OSINT in cybersecurity?

Threat Identification


OSINT enables security teams to monitor and identify potential threats that are publicly discussed on forums, social networks, or other online platforms. Information about new vulnerabilities, exploits, or hacker activities can be detected in real-time.

Tracking Attackers


Using OSINT, security experts can track the activities of known attackers or groups. By analyzing their online presence and communication, they can gather valuable information about their methods, motives, and planned attacks.

Incident Response


In the event of a cyber attack, OSINT can provide rapid information about the nature of the attack, its scope, and possible mitigation methods. It also assists in gathering evidence for forensic analysis.

Security Awareness


Organizations can leverage OSINT to monitor mentions of their brand, products, or key employees on public forums and social media. This enables them to respond promptly to potential risks, such as phishing campaigns or social engineering attempts.

Monitoring Supply Chain


OSINT can help monitor and assess security risks associated with suppliers and partners. Information about security incidents in the supply chain can be critical for ensuring the overall security of the organization.

How do we leverage OSINT in offensive security?

OSINT (Open Source Intelligence) is an integral part of Red Team operations because it provides valuable information about the company and specific targets, such as organizational infrastructure, applications, employees, or other specific assets. OSINT allows gathering a wide range of information from publicly available sources, which is crucial for effectively identifying potential vulnerabilities and risks. Here are a few examples of the information we can obtain about your organization.

Mapping the online perimeter

Thanks to available registries like RIPE NCC (Réseaux IP Européens Network Coordination Centre and others), DNS databases, and projects such as Shodan or Censys, we can gather information not only about your ranges of IP addresses but also about the services operated and the configuration of your network.

  • RIPE NCC: Provides detailed information about assigned IP addresses and AS (autonomous systems). We can determine to whom the IP address belongs, its geolocation, and other technical details.

  • DNS databases: Through DNS records, we can find out which domains are assigned to your IP addresses, what A (address) and MX (mail exchange) records exist, and more. This helps us understand the structure of your network and the services you operate.

  • Shodan: It's a search engine that scans the internet and indexes information about connected devices and their services. With Shodan, we can obtain information about open ports, running services, and software versions, which can help identify potential vulnerabilities.

  • Censys: Similar to Shodan, Censys scans and indexes publicly accessible devices and services on the internet. It provides detailed analysis and allows searching according to various parameters, helping us map out infrastructure and identify risks.

LinkedIn as a database for phishing

There's no need to explain what LinkedIn is and what it's used for. However, we use it for identifying targets for spear phishing or gaining insights into technologies. Everyone likes to brag about what they do or what certifications they have. We are particularly interested in technologies like IBM-i and other obscure matters, which often indicate that an employee works, for example, with transaction systems in a bank and probably has some service access.

Mobile Applications - a package full of surprises

If you've ever subjected mobile applications to penetration tests, you've surely encountered findings such as access points, keys, test environment addresses, and more. Since mobile applications are available on the App Store or Google Play, we can download them, decompile (unpack) them, and even read the original source code. And if you think that sensitive information disappears with the release of a new version, you're mistaken. Thanks to servers like APKPure and others, historical versions of applications can also be obtained.

Photographs with a cup of coffee

When a new employee arrives and is excited, they often take photos of their workplace, a cup of coffee, and sometimes even their access card.

We love those photos, especially when they show the workstation. You might wonder, what's the point? The design of the card is crucial for us during physical penetrations, to convince your employees that we belong there. The workstation sometimes reveals the applications being used or even antivirus solutions.

Google Street View - our invisible agent

Street View regularly maps streets and offers a 360-degree view of the surroundings. Naturally, it also captures your headquarters and branches. What's the use for us?

Without having to travel to your location, we can explore where you have rear entrances, cameras, or what card readers you use. Sometimes, on Street View, we can see what employees wear or where they go to smoke.

Metadata not only in documents

Although data may not always be public, we can focus on so-called metadata. These metadata may include information about deployment windows or frequency and timing of outages. You might wonder how to obtain this information: we continuously monitor the availability of your services and deduce when we can launch attacks based on detected patterns. The ideal time is when a new version of a system is being deployed.


Metadata can also be stored in documents. Your organization sometimes publishes dozens of documents online, containing metadata about who created them, in which software and its version, and sometimes even the email of the person. We obtain such documents, for example, using a technique called dorking, which involves utilizing search engines like Google. We then download all documents and extract metadata, for instance, using tools like FOCA.

We know what WiFi you have!

There are several projects that map available WiFi networks using a large community of people. Whether it's for finding Free WiFi or simply gathering information, these projects provide valuable data. One of the most well-known projects is WiGLE.


WiGLE is a platform that collects and publishes information about WiFi networks worldwide. Anyone who joins this community contributes data about WiFi networks they encounter in their daily movements. The result is a massive database containing information about millions of WiFi networks, including their names (SSIDs), security settings, and locations.


For us, this means one thing – we can easily find out which WiFi networks are available within the perimeter of your building.

Public repositories

Several file storage services operated on the Czech internet, many of which have recently disappeared, such as ulozto.cz.

However, we remember a time when we frequently downloaded sensitive documents from these services. These documents contained passwords or internal IT documentation, which we used as a basis for phishing. One of the last websites where sensitive documents can still be found is webshare.cz.

Would you like to find out what sensitive data attackers can learn about you? Utilize our Red Team and gain important security insights about your organization!

Right in Your Inbox

Stay up to date and get the newsletter. Every month, you can look forward to exclusive educational content and news from the infosec world.

All infosec
We are an information security company. Our purpose is to safeguard the clients' most valuable information and protect their business.

© 2026 Axelum s.r.o.

Contact

Axelum s.r.o.

CIN: 25639056

VAT ID: CZ699004029

V Kapslovně 2767/2

130 00 Prague CZ

info@axelum.eu

+420 221 400 111


Created by uuWebKit
document_check.svg
We use cookies on this website to ensure its functionality and to personalise ads, solely with your consent and in accordance with our Cookies Policy.

By clicking on the "Accept cookies" button, you consent to the use of selected cookies and agree to the transfer of behavioural data for the display of targeted advertising on social and advertising networks. You can choose which information you want to share with us by clicking on the Cookie settings button.