IT Forensics · OSINT

Researching malware indicators using OSINT – utilising publicly documented malware characteristics in a forensic context

Known malware is often described in publicly accessible threat databases and specialist publications using characteristic technical indicators, which can be helpful in classifying an incident.

Enquire without obligation

As part of existing incident response cases, we carry out a structured investigation to determine whether, and if so which, publicly documented indicators match the characteristics identified in the case.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

Our OSINT investigations are always carried out as a complementary component to existing IT forensic, legal or internal corporate enquiries. Every step of the investigation and every piece of digital evidence found is documented and, where technically possible, archived to ensure traceability even if the original online content is subsequently altered or deleted.

Our services

As part of an existing case, we cross-reference technical characteristics identified with publicly available threat databases and document the results in a manner that is forensically verifiable.

Typical areas of application

Classification of detected malware based on publicly available indicators
Supplementing incident response investigations
Support with the assessment of known attack patterns
Cross-referencing with publicly documented threat actors
Judicial and non-judicial expert reports
Collaboration with IT security teams

This is how a malware indicator investigation works

Technical characteristics identified during the system analysis are systematically cross-referenced against publicly available threat databases and specialist publications, and any documented matches are recorded for forensic purposes.

Why is malware indicator research relevant in a forensic context?

Comparing an incident with publicly documented cases can help to classify it more quickly and determine appropriate countermeasures.

Distinguishing between this and previously known, documented waves of attacks can also provide forensically relevant clues.

Frequently Asked Questions

Does this research replace technical malware analysis?+
No, it supplements the forensic system analysis with publicly available reference information.
What sources are used for the comparison?+
These include, amongst other things, publicly accessible threat databases, specialist publications and security research reports.
Can all malware be publicly categorised?+
No, in particular, new or specifically designed malware may not be publicly documented.

LanCologne – IT Forensics OSINT Cologne

Do you require a professional OSINT investigation into „Researching malware indicators using OSINT"? LanCologne can assist you with the transparent, documented analysis of publicly available digital sources to support your IT forensic, legal or internal corporate investigations.

Get in touch now