IT Forensics · OSINT

Researching public security vulnerability reports using OSINT – Conducting a forensic analysis of disclosed vulnerability reports

Security researchers and security forums sometimes publish information about vulnerabilities in systems which may also affect a relevant company.

Enquire without obligation

As part of existing IT security investigations, we carry out a structured analysis to determine whether there are any publicly available vulnerability reports relating to the systems used by a relevant organisation.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

Our OSINT investigations are always carried out as a complementary component to existing IT forensic, legal or internal corporate enquiries. Every step of the investigation and every piece of digital evidence found is documented and, where technically possible, archived to ensure traceability even if the original online content is subsequently altered or deleted.

Our services

We search publicly available specialist publications and security databases for reports of vulnerabilities relating to a relevant organisation and document the results in a manner that is forensically verifiable.

Typical areas of application

Search for publicly known vulnerability advisories
Supplementing IT security audits
Support in prioritising security measures
Documentation for internal security reports
Judicial and non-judicial expert reports
Collaboration with IT security teams

This is how the investigation into publicly reported security vulnerabilities works

SpiderFoot is used to systematically scan publicly available vulnerability databases and specialist publications for references relating to the systems in use at the relevant organisation; any findings are documented.

Why is the investigation of publicly reported security vulnerabilities relevant from a forensic perspective?

Early detection of publicly known vulnerability reports can help to identify the urgent need for action before a vulnerability is actively exploited.

Forensic documentation also helps the relevant IT team to prioritise security measures.

Frequently Asked Questions

Are vulnerabilities technically tested by LanCologne itself?+
No, we research publicly available information; technical vulnerability assessments of our own systems are carried out through specialised penetration tests.
Are vulnerabilities in third-party software used also identified?+
Insofar as it is publicly available and relevant to the issue at hand, yes.
Will this search be combined with the IoT device search?+
Yes, the two methods often complement each other as part of a comprehensive security assessment of the publicly visible attack surface.

LanCologne – IT Forensics OSINT Cologne

Do you require a professional OSINT investigation into „Researching public security vulnerability reports using OSINT"? LanCologne supports you in the transparent, documented analysis of publicly available digital sources to complement your IT forensic, legal or internal corporate enquiries.

Get in touch now