IT Forensics · OSINT

Analysing phishing campaigns using OSINT – Conducting a forensic analysis of publicly visible phishing infrastructure

Phishing campaigns often leave publicly visible traces, such as fake domains, hosted landing pages or reused sender addresses, which can provide relevant clues in the context of existing security incidents.

Enquire without obligation

As part of existing incident response cases, we carry out a structured analysis of the publicly visible elements that form the basis of a phishing campaign and how these elements are linked.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

Our OSINT investigations are always carried out as a complementary component to existing IT forensic, legal or internal corporate enquiries. Every step of the investigation and every piece of digital evidence found is documented and, where technically possible, archived to ensure traceability even if the original online content is subsequently altered or deleted.

Our services

We investigate publicly available information relating to a relevant phishing campaign and document any identifiable infrastructure and connections in a manner that is forensically verifiable.

Typical areas of application

Analysis of a specific phishing campaign following a security incident
Supplementing incident response investigations
Identification of further, related phishing domains
Support in taking down phishing infrastructure
Judicial and non-judicial expert reports
Collaboration with IT security teams

This is how a phishing campaign analysis is carried out

Using a known phishing email or domain as a starting point, Maltego and SpiderFoot are used to systematically collect technical characteristics such as domain registration, hosting and reused resources, and to compile these into an overall picture.

Why is the analysis of phishing campaigns relevant from a forensic perspective?

Documented evidence of a campaign’s infrastructure can provide important clues as to the scale and origin of an attack.

The early identification of related phishing domains can also help to detect further attacks on the affected company.

Frequently Asked Questions

Can LanCologne have phishing domains taken down?+
We document the relevant facts using forensic methods; the site is taken offline via the relevant hosting providers or registries, in consultation with the client where necessary.
Are related campaigns also identified?+
Insofar as publicly available characteristics suggest a connection, yes, provided the link is properly documented.
Can the authorship of a campaign be established beyond doubt?+
Only to a limited extent via publicly available information; we communicate the existing limitations of our investigations transparently.

LanCologne – IT Forensics OSINT Cologne

Do you require a professional OSINT investigation into „analysing phishing campaigns using OSINT"? LanCologne can assist you with the transparent, documented analysis of publicly available digital sources to support your IT forensic, legal or internal corporate enquiries.

Get in touch now