IT Forensics · OSINT
Identifying phishing domains using OSINT – Forensically uncovering and documenting fraudulent domains
Phishing domains often mimic well-known brands or companies by using domain names that sound similar, and can be identified through systematic research into domain variations and certificate protocols.
This research may be useful for the early detection and documentation of fraudulent domains in the context of existing cyber-security incidents.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
Our OSINT investigations are always carried out as a complementary component to existing IT forensic, legal or internal corporate enquiries. Every step of the investigation and every piece of digital evidence found is documented and, where technically possible, archived to ensure traceability even if the original online content is subsequently altered or deleted.
Our services
We systematically search for phishing domains that impersonate a relevant brand or organisation, and document any domains found in a manner that is forensically traceable.
Typical areas of application
How a phishing domain search works
Starting with the target domain, a systematic search is carried out for domain variations that sound similar, as well as newly registered domains with certificates, and these are checked for characteristics typical of phishing.
Why is phishing domain research relevant from a forensic perspective?
Early identification can help to limit the damage caused by an ongoing phishing campaign by reporting it promptly to registrars and hosting providers.
The forensic documentation of identified phishing domains also forms an important basis for the subsequent legal investigation of an incident.
Frequently Asked Questions
LanCologne – IT Forensics OSINT Cologne
Do you require a professional OSINT investigation into „Identifying phishing domains using OSINT"? LanCologne can assist you with the transparent, documented analysis of publicly available digital sources to complement your IT forensic, legal or internal corporate enquiries.
Related to this topic
- Mapping IP addresses and network ranges using OSINT – Classifying technical infrastructure in a forensically traceable manner
- Forensic documentation of systems exposed via Shodan – Capturing publicly visible infrastructure in a forensically traceable manner
- Forensic analysis of website history using web archives – Forensic reconstruction of archived website versions
- Analysing email headers using OSINT – Conducting a forensic analysis of technical sender information