What is OSINT?
OSINT (Open Source Intelligence) is the collection and analysis of public information —websites, social media, registries, forums, leaks— to draw useful conclusions.
In cybersecurity it lets you see the same thing an attacker sees before attacking you: your exposed surface, your employees, your suppliers and what has already leaked. All without entering any system.
What is it for?
- Your company's digital footprint: what's visible about you from the internet.
- Leaked credentials of your employees in third-party breaches.
- Brand impersonation: lookalike domains, fake profiles, cloned sites.
- Executive exposure, a classic target for CEO fraud.
- Leaked information on projects, code or documents.
- Incident investigation: what was published and where after an attack.
When does it make sense?
OSINT is an add-on service that fits well:
- Before a security project, to know how they see you.
- After an incident, to know what got out and where it ended up.
- On a regular basis, if you're an exposed brand or an attractive target.
- As support for incident investigation and crisis management.
How we do it
- Scope. What we look for and over which assets.
- Collection. Open sources, leaks and registries.
- Analysis. What's noise and what's real risk.
- Report with prioritised findings.
- Action plan: what to close, what to take down, what to monitor.
OSINT is an add-on to Plan Tria. We integrate it with your security: findings don't stay in a report, they enter your plan and get closed.
Frequently asked questions
Is OSINT legal?
Yes. Only publicly accessible information is used, without entering any system or breaching anything. It isn't hacking: it's analysis of what's already out there.
How is it different from a pentest?
A pentest tries to get into your systems with permission. OSINT only observes from outside, touching nothing. They complement each other.
Can you tell if my credentials have leaked?
Yes, we look for leaks affecting your company's domains and email addresses in third-party breaches.
How often should it be done?
It depends on your exposure. For visible brands or targeted sectors, regularly; otherwise, at least once and after any incident.