IT Forensics · OSINT
Researching malware indicators using OSINT – utilising publicly documented malware characteristics in a forensic context
Known malware is often described in publicly accessible threat databases and specialist publications using characteristic technical indicators, which can be helpful in classifying an incident.
As part of existing incident response cases, we carry out a structured investigation to determine whether, and if so which, publicly documented indicators match the characteristics identified in the case.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
Our OSINT investigations are always carried out as a complementary component to existing IT forensic, legal or internal corporate enquiries. Every step of the investigation and every piece of digital evidence found is documented and, where technically possible, archived to ensure traceability even if the original online content is subsequently altered or deleted.
Our services
As part of an existing case, we cross-reference technical characteristics identified with publicly available threat databases and document the results in a manner that is forensically verifiable.
Typical areas of application
This is how a malware indicator investigation works
Technical characteristics identified during the system analysis are systematically cross-referenced against publicly available threat databases and specialist publications, and any documented matches are recorded for forensic purposes.
Why is malware indicator research relevant in a forensic context?
Comparing an incident with publicly documented cases can help to classify it more quickly and determine appropriate countermeasures.
Distinguishing between this and previously known, documented waves of attacks can also provide forensically relevant clues.
Frequently Asked Questions
LanCologne – IT Forensics OSINT Cologne
Do you require a professional OSINT investigation into „Researching malware indicators using OSINT"? LanCologne can assist you with the transparent, documented analysis of publicly available digital sources to support your IT forensic, legal or internal corporate investigations.
Related to this topic
- Profiling threat actors using OSINT – forensically categorising publicly documented methods
- Detecting cyberattack early warnings using OSINT – Forensically documenting early public warning signs
- Using Google Dorking in a forensically traceable manner – utilising advanced search operators in a forensically documented way
- Command-and-Control Server: OSINT-based detection – forensic documentation of publicly visible control servers