Service Overview
The OSINT (Open Source Intelligence) service of Dognet Technologies collects, analyzes and publicly available information on an organization, an individual, a domain or technological infrastructure, with the aim of mapping the external attack surface, identifying unconscious exposures and supporting threat intelligence activities, two diligence and security investigations. The OSINT is the first stage of any sophisticated attack: attackers spend weeks or months collecting information before launching an operation. Knowing what is visible from the outside is the first step to reduce the exposed surface.
OSINT

Our service is applicable in three distinct contexts: Defensive OSINT (analysis of its public exposure to reduce the attack surface), investigative OSINT (collection of information about third parties for two diligence, security investigations or legal support), and OSINT as a preparatory phase to a penetration test or Red Team operation.
Sources and Technics
The OSINT process adjusts the collection from heterogeneous sources, organizing them in functional categories:
- Technical infrastructure: DNS enumeration (A, MX, TXT, SPF, DMARC, DKIM), certified transparency logs (crt.sh, Censys), Shodan and FOFA for the mapping of services on public IPs, Wayback Machine for site history analysis, meta-data analysis of published documents to identify technical information (software versions, user names, internal paths).
- Digital presence: website analysis, corporate and personal social media, LinkedIn profiles of employees (organizational structure, technological stack, key roles), GitHub and other public repository for source code, credentials and accidentally committed secrets, job offers that reveal technologies in use.
- Data breach and credential exposure: search in public breach databases (HaveIBeenPwned, DeHashed, Leak-Lookup) to identify email addresses and corporate credentials compromised in previous breaches, still usable for credential stuffing if not changed.
- Dark web and underground forums: search on marketplaces and forums of the dark web to verify the presence of company data on sale, discussion about specific vulnerabilities of the products in use, or mentions of the organization in criminal contexts.
- Geospatial and physical: analysis of satellite images, Street View and public photographs to identify information about the physical location, externally visible infrastructure, badges and accidentally photographed access.
Tools and Workflow
The process uses consolidated tools in the OSINT community: Maltego for graphic visualization of relationships between entities, theHarvester, Recon-ng and SpiderFoot for automated collection, Amass for advanced enumeration of domains, Shodan and Censys for the search of exposed assets, OSINT Framework as a methodological reference, and custom tools developed by Dognet for specific use cases. All the data collected is arranged in a graph of reports that makes the connection structure visible immediately.
Main Use Cases
Two pre-acquisition or pre-partnership diligence: analysis of public exposure and the digital reputation of a subject before tightening business relationships or investing. External attack surface analysis: full mapping of everything an attacker can see of his organization, the basis for prioritization of surface reduction interventions. Support for incident response: collection of information about the attacker, the domains of C2 used and malicious infrastructure to support the response to the incident and potentially attribution. VIP protection and brand protection: continuous monitoring to detect attempts at impersonation, typosquatting domains, fraudulent social accounts and negative mentions.
Deliverable
OSINT report structured with: executive summary of the identified exposure; graph of relationships between entities; detailed findings by category (structure, people, breach, dark web); risk rating for each exposure; and remediation actions specific and actionable to reduce the identified surface.


