IT Forensics · OSINT

Identifying exposed databases using OSINT – forensically tracing publicly accessible databases

Incorrectly configured databases are sometimes accessible via the internet without adequate access protection and may disclose sensitive data.

Enquire without obligation

As part of existing security investigations, we carry out a structured search to determine whether any publicly accessible databases relating to a relevant organisation can be found.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

Our OSINT investigations are always carried out as a complementary component to existing IT forensic, legal or internal corporate enquiries. Every step of the investigation and every piece of digital evidence found is documented and, where technically possible, archived to ensure traceability even if the original online content is subsequently altered or deleted.

Our services

We use Shodan to search publicly accessible systems linked to a relevant organisation for evidence of inadequately protected databases, and document the results in a manner that is forensically verifiable.

Typical areas of application

Identification of inadequately protected, publicly accessible databases
Supplementing IT security audits
Support with assessing a data protection risk
Documentation for internal security reports
Judicial and non-judicial expert reports
Collaboration with IT security teams

This is how a search of exposed databases works

Shodan is used to identify publicly accessible systems associated with the relevant organisation and to check them for typical characteristics of inadequately protected database services; the findings are documented.

Why is the investigation of exposed databases relevant from a forensic perspective?

Identifying a database that is inadequately protected at an early stage can help prevent a potential data breach before any data actually leaks out.

Forensic documentation of a discovery also helps to assess whether unauthorised access has already taken place.

Frequently Asked Questions

Is the content of any databases found analysed?+
Only to the extent strictly necessary for forensic documentation and risk assessment, in accordance with the relevant legal requirements.
Will LanCologne resolve the database configuration issue?+
No, we document the findings for forensic purposes; the technical resolution is the responsibility of the client’s relevant IT team.
Is this research combined with an analysis of public code repositories?+
Yes, the two methods often complement each other as part of a comprehensive security audit.

LanCologne – IT Forensics OSINT Cologne

Do you require a professional OSINT investigation into „Identifying exposed databases using OSINT"? LanCologne can assist you with the transparent, documented analysis of publicly available digital sources to complement your IT forensic, legal or internal corporate enquiries.

Get in touch now