IT Forensics · OSINT
Detecting cyberattack early warnings using OSINT – Forensically documenting early public warning signs
Upcoming or ongoing cyberattacks are sometimes foreshadowed by publicly visible warning signs, such as mentions in underground forums, newly registered phishing domains or exposed test systems.
As part of existing security investigations, we carry out structured research into such publicly visible warning signs relating to the company in question.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
Our OSINT investigations are always carried out as a complementary component to existing IT forensic, legal or internal corporate enquiries. Every step of the investigation and every piece of digital evidence found is documented and, where technically possible, archived to ensure traceability even if the original online content is subsequently altered or deleted.
Our services
We search publicly available sources for identifiable warning signs relating to a relevant organisation and document our findings in a manner that is forensically verifiable.
Typical areas of application
This is how an investigation into early warnings of cyber-attacks is carried out
Relevant public sources, such as underground forums, newly registered domains and compromised systems, are systematically scanned using SpiderFoot and Shodan for mentions relating to the organisation in question, and any findings are documented.
Why is the investigation of early warnings of cyber attacks relevant from a forensic perspective?
Identifying warning signs at an early stage can enable a company to take protective measures before an attack has its full impact.
Furthermore, the forensic documentation of such warning signs may prove relevant in retrospect when reconstructing the chronology of an incident.
Frequently Asked Questions
LanCologne – IT Forensics OSINT Cologne
Do you require a professional OSINT investigation into „Identifying early warnings of cyberattacks using OSINT"? LanCologne can assist you with the transparent, documented analysis of publicly available digital sources to complement your IT forensic, legal or internal corporate enquiries.
Related to this topic
- Using Google Dorking in a forensically traceable manner – utilising advanced search operators in a forensically documented way
- Command-and-Control Server: OSINT-based detection – forensic documentation of publicly visible control servers
- Researching malware indicators using OSINT – utilising publicly documented malware characteristics in a forensic context
- Profiling threat actors using OSINT – forensically categorising publicly documented methods