IT Forensics · OSINT

Identifying attackers’ infrastructure using OSINT – Forensically documenting attackers’ technical infrastructure

Attackers frequently use a reused technical infrastructure comprising Servern, domains and certificates for their activities, some of which can be traced via publicly available sources.

Enquire without obligation

As part of existing incident response cases, we systematically identify publicly visible components of this infrastructure and their discernible interrelationships.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

Our OSINT investigations are always carried out as a complementary component to existing IT forensic, legal or internal corporate enquiries. Every step of the investigation and every piece of digital evidence found is documented and, where technically possible, archived to ensure traceability even if the original online content is subsequently altered or deleted.

Our services

We investigate publicly available technical characteristics of a known attacker infrastructure and document any discernible correlations in a manner that is forensically verifiable.

Typical areas of application

Identification of further Server or domains associated with an attack
Supplementing incident response investigations
Support in assessing the severity of an attack
Documentation for communication with IT security service providers
Judicial and non-judicial expert reports
Collaboration with IT security teams

This is how an attacker infrastructure investigation is carried out

Using Shodan and SpiderFoot, publicly visible, connected systems are identified on the basis of known technical indicators such as IP addresses or certificates, and these findings are consolidated into a comprehensive picture that can be analysed forensically.

Why is attacker infrastructure research relevant from a forensic perspective?

Knowledge of the infrastructure used can help to assess the scale of an attack and identify other potential targets.

The documented correlations may also be relevant when classifying an attack according to known methods.

Frequently Asked Questions

Can the identified infrastructure be linked to a specific attacker?+
Only to a limited extent based on publicly available information; an unequivocal attribution often requires additional, non-public information.
Are the attacker’s active systems still being monitored?+
Only as part of publicly accessible, passive research within the existing case.
Is this investigation being carried out in conjunction with forensic system analyses?+
Yes, it often complements the technical analysis of the systems concerned in the context of incident response cases.

LanCologne – IT Forensics OSINT Cologne

Do you require a professional OSINT investigation into „Identifying attacker infrastructure using OSINT"? LanCologne can assist you with the transparent, documented analysis of publicly available digital sources to complement your IT forensic, legal or internal corporate enquiries.

Get in touch now