Working area · A.05

    Cyber Intelligence

    Cyber intelligence is not information security. It is not about configuring defences, but about understanding the environment: what organisational information circulates outside the perimeter, what makes the organisation an attractive target, and which signals precede a targeted attempt.

    This area works the outer side of the problem — the side the organisation does not control and usually does not know about: domains resembling its own, credentials exposed in earlier breaches, executive profiles rich in detail, and suppliers who widen the surface without realising it.

    What the discipline covers

    • Analysis of the digital exposure surface: domains, subdomains, visible services, forgotten assets.
    • Brand impersonation monitoring: lookalike domains, fraudulent websites, fake profiles.
    • Exposure of corporate credentials and data appearing in third-party breaches.
    • Exposure profile of people with access or decision authority, the usual basis of targeted social engineering.
    • Threat context: tactics observed against the sector, not attribution of specific campaigns.

    Scope

    The assessment stays outside the perimeter. It documents what an external observer can establish and what that would enable, without ever testing a control.

    • External attack surface of the organisation, its brands and its publicly linked subsidiaries.
    • Exposure of named individuals only where a security purpose justifies it, with data minimisation.
    • Third-party exposure that reaches the organisation indirectly through a supplier or partner.
    • Explicit exclusions: no credential testing, no intrusion, no acquisition or storage of breach dumps.

    Main risks and threats

    • Targeted fraud built on published organisational detail: impersonation of executives, suppliers or payment instructions.
    • Reuse of leaked corporate credentials against internal services.
    • Fraudulent sites and lookalike domains used to harvest customer or employee credentials.
    • Forgotten infrastructure that remains reachable and unmonitored.
    • Suppliers whose own exposure becomes an entry route into the organisation.
    • Aggregation: individually harmless publications that together enable a credible pretext.

    Relevant indicators and warning signs

    • Recent registration of domains similar to the corporate one, a frequent precursor to fraud or impersonation.
    • Corporate credentials present in old breaches and reused across internal services.
    • Executives and finance staff with enough public exposure to support a believable pretext.
    • Orphaned digital assets: test environments, subdomains and panels with no assigned owner.
    • Publication of internal structure, approval chains or payment calendars in public sources.
    • Suppliers with public incidents that indirectly affect the organisation.

    Application of OSINT

    • Inventory of externally visible assets using public domain and certificate records.
    • Monitoring of new domain registrations and certificates showing similarity to the brand.
    • Exposure assessment of key individuals, with data minimisation and a strictly security-related purpose.
    • Reconstruction of the plausible attack scenario: what information would make a targeted attempt credible.
    • Prioritisation by impact on the organisation and by real ease of exploitation, not by number of findings.

    Zero101OSINT methodology

    • Agreement on the perimeter to be reviewed: brands, domains, subsidiaries and roles in scope.
    • Passive collection only: nothing is queried, tested or authenticated against the organisation's systems.
    • Corroboration of every finding with attached, reproducible evidence and its collection date.
    • Aggregation analysis, because the risk usually lies in the combination and not in any single item.
    • Prioritised remediation plan, distinguishing what can be withdrawn from what can only be mitigated.
    • Re-measurement after remediation, so the reduction in exposure can be demonstrated internally.

    Open sources used

    • Public domain records, certificate transparency logs and network range allocation data.
    • Public vulnerability advisories and official incident communications.
    • Published corporate content, professional networks and publicly accessible code repositories.
    • Verifiable information about already disclosed breaches, without acquiring or processing data dumps.
    • Reports with attached evidence, criticality classification and actionable reduction measures.

    Applications for companies, organisations and security decision-makers

    • Understand real exposure before investing in more defensive technology.
    • Reduce the viability of fraud based on impersonation of executives and suppliers.
    • Bring external judgement to third-party and acquisition due diligence.
    • Justify security priorities to management with verifiable evidence rather than hypotheses.
    • Give an awareness programme concrete, organisation-specific material instead of generic examples.

    Products or analytical outputs Zero101OSINT can provide

    • Corporate digital exposure report with findings, evidence and a prioritised reduction plan.
    • Individual exposure assessment for executives and staff with sensitive access.
    • Digital risk review of a third party before contracting or integrating it.
    • Periodic monitoring of lookalike domains and of newly appearing exposure.

    Legal, ethical and reliability limitations

    No third-party systems are accessed, no credentials are tested, no intrusion or aggressive scanning is carried out, and no material originating from breaches is acquired or stored. The existence of an exposed credential is documented as an indicator, never by verifying it.

    Exposure analysis of individuals is limited to public information, with data minimisation and an exclusively security-related purpose; no profiling is produced for any other purpose. An external exposure report does not replace a technical audit or an authorised penetration test.

    Related reports

    No intelligence report published in English is directly relevant to this area yet. The available analysis is covered by the related articles below.

    Related articles

    Article

    Executive digital exposure: a growing risk for companies

    The digital visibility of executives has become a corporate risk vector. Analysis of how public information can compromise business security.

    Read →
    Article

    The corporate digital footprint: what it really reveals about a company

    Analysis of the corporate digital footprint: what information it reveals about a company, how it is generated, and why it constitutes a strategic risk if not properly managed.

    Read →
    Article

    How cybercriminals use OSINT to prepare targeted attacks against companies

    The most effective attacks don't start with malicious code. They start with public information that no one controlled. Analysis of the reconnaissance process prior to a targeted cyberattack.

    Read →
    Article

    Advanced social engineering: how public information enables corporate attacks

    The most sophisticated attacks don't exploit technical vulnerabilities. They exploit trust built with information the organization itself left accessible.

    Read →
    Article

    Whaling: the cyberattack targeting senior management that companies must anticipate

    Whaling is a sophisticated phishing variant designed to compromise executive profiles such as CEOs, CFOs, or legal directors, leveraging their digital exposure.

    Read →
    Article

    The false sense of digital control in companies

    Most organizations believe they control their digital information. Analysis of the gap between perception and reality in corporate information exposure.

    Read →

    Need analysis in this area?

    Describe the scope, the deadline and the decision the analysis has to support. You will receive the proposed approach, the limits of the assessment and the deliverable that can realistically be produced.

    Get in touch