IT Forensics · OSINT

Identifying IoT devices using OSINT – Forensically tracing publicly accessible connected devices

Connected devices such as cameras, routers or control systems are sometimes accessible via the internet without adequate protection and can act as a gateway for attackers.

Enquire without obligation

As part of existing security investigations, we carry out a structured analysis to identify which publicly accessible networked devices can be linked to a relevant organisation.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

Our OSINT investigations are always carried out as a complementary component to existing IT forensic, legal or internal corporate enquiries. Every step of the investigation and every piece of digital evidence found is documented and, where technically possible, archived to ensure traceability even if the original online content is subsequently altered or deleted.

Our services

We use Shodan to investigate publicly accessible networked devices linked to a relevant organisation and document the results in a manner that is forensically verifiable.

Typical areas of application

Identification of publicly accessible networked devices
Supplementing IT security audits
Support in assessing a company’s attack surface
Documentation for internal security reports
Judicial and non-judicial expert reports
Collaboration with IT security teams

How an IoT device search works

Shodan is used to identify publicly accessible networked devices with a recognisable link to the relevant organisation; the device type, visible configuration and recognisable vulnerability indicators are documented.

Why is IoT device investigation relevant in a forensic context?

Insufficiently protected connected devices pose a significant security risk and are specifically targeted by attackers.

Forensic documentation may also prove useful retrospectively in reconstructing a possible point of entry in the event of a security incident.

Frequently Asked Questions

Are any devices that are detected actively attacked or tested?+
No, our research is limited to the passive analysis of publicly available scan data.
Does LanCologne resolve the configuration issues with the devices?+
No, we document the findings for forensic purposes; the technical resolution is the responsibility of the client’s relevant IT team.
Is this research combined with the analysis of exposed databases?+
Yes, the two methods often complement each other as part of a comprehensive security assessment of the publicly visible attack surface.

LanCologne – IT Forensics OSINT Cologne

Do you require a professional OSINT investigation into „identifying IoT devices using OSINT"? LanCologne can assist you with the transparent, documented analysis of publicly available digital sources to support your IT forensic, legal or internal corporate enquiries.

Get in touch now