IT Forensics · OSINT

Searching public code repositories using OSINT – Forensically tracing accidentally published source code

Employees sometimes inadvertently publish source code containing sensitive information, such as login details or internal system details, on publicly accessible code platforms.

Enquire without obligation

As part of existing security investigations, we carry out a structured review to determine whether such sensitive information is publicly accessible.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

Our OSINT investigations are always carried out as a complementary component to existing IT forensic, legal or internal corporate enquiries. Every step of the investigation and every piece of digital evidence found is documented and, where technically possible, archived to ensure traceability even if the original online content is subsequently altered or deleted.

Our services

We search publicly accessible code repositories for mentions of a relevant organisation and document any sensitive information found in a manner that is forensically verifiable.

Typical areas of application

Detecting accidentally disclosed login details in the source code
Supplementing IT security audits
Support with the assessment of a data protection incident
Documentation for internal security reports
Judicial and non-judicial expert reports
Collaboration with IT security teams

This is how research in public code repositories works

Publicly accessible code platforms are searched using SpiderFoot and structured manual research for mentions of the relevant organisation and typical patterns of sensitive data; any findings are documented.

Why is searching public code repositories relevant from a forensic perspective?

Login details published by mistake pose a significant security risk and should be identified at an early stage.

Forensic documentation of a discovery also helps the affected company to take appropriate countermeasures promptly.

Frequently Asked Questions

Are any login details that are found tested?+
No, we document the discovery in a way that is forensically verifiable, without using the login details we have found ourselves.
Can private repositories also be viewed?+
No, we only search publicly accessible repositories.
Is a report submitted to the platform once the item has been found?+
The forensic documentation may serve as the basis for a report by the client.

LanCologne – IT Forensics OSINT Cologne

Do you require a professional OSINT investigation into „Searching public code repositories using OSINT"? LanCologne can assist you with the transparent, documented analysis of publicly accessible digital sources to support your IT forensic, legal or internal corporate enquiries.

Get in touch now