IT Forensics · OSINT
Identifying attackers’ infrastructure using OSINT – Forensically documenting attackers’ technical infrastructure
Attackers frequently use a reused technical infrastructure comprising Servern, domains and certificates for their activities, some of which can be traced via publicly available sources.
As part of existing incident response cases, we systematically identify publicly visible components of this infrastructure and their discernible interrelationships.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
Our OSINT investigations are always carried out as a complementary component to existing IT forensic, legal or internal corporate enquiries. Every step of the investigation and every piece of digital evidence found is documented and, where technically possible, archived to ensure traceability even if the original online content is subsequently altered or deleted.
Our services
We investigate publicly available technical characteristics of a known attacker infrastructure and document any discernible correlations in a manner that is forensically verifiable.
Typical areas of application
This is how an attacker infrastructure investigation is carried out
Using Shodan and SpiderFoot, publicly visible, connected systems are identified on the basis of known technical indicators such as IP addresses or certificates, and these findings are consolidated into a comprehensive picture that can be analysed forensically.
Why is attacker infrastructure research relevant from a forensic perspective?
Knowledge of the infrastructure used can help to assess the scale of an attack and identify other potential targets.
The documented correlations may also be relevant when classifying an attack according to known methods.
Frequently Asked Questions
LanCologne – IT Forensics OSINT Cologne
Do you require a professional OSINT investigation into „Identifying attacker infrastructure using OSINT"? LanCologne can assist you with the transparent, documented analysis of publicly available digital sources to complement your IT forensic, legal or internal corporate enquiries.
Related to this topic
- Verdächtige Zahlungsabwicklung OSINT-gestützt recherchieren – Auffällige Zahlungswege forensisch nachvollziehen
- Datenlecks im Dark Web OSINT-gestützt identifizieren – Veröffentlichte Datenlecks forensisch nachvollziehbar recherchieren
- Gestohlene Zugangsdaten OSINT-gestützt aufspüren – Kompromittierte Zugangsdaten forensisch nachvollziehbar recherchieren
- Untergrundforen OSINT-gestützt auswerten – Einschlägige Foren für die Cybersicherheitsrecherche forensisch nutzen