IT Forensics · OSINT

Profiling threat actors using OSINT – forensically categorising publicly documented methods

For certain threat actors who are actively operating on a recurring basis, there are publicly available specialist publications detailing their characteristic modus operandi and technical characteristics, which may be helpful in classifying an incident.

Enquire without obligation

As part of existing incident response cases, we carry out a structured assessment to determine whether any identified characteristics can be linked to publicly documented methods used by known threat actors.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

Our OSINT investigations are always carried out as a complementary component to existing IT forensic, legal or internal corporate enquiries. Every step of the investigation and every piece of digital evidence found is documented and, where technically possible, archived to ensure traceability even if the original online content is subsequently altered or deleted.

Our services

As part of an ongoing case, we compare the methods and technical characteristics identified with publicly available specialist publications on known threat actors and document the results in a manner that is forensically verifiable.

Typical areas of application

Classification of an incident based on publicly documented procedures
Supplementing incident response investigations
Support with risk assessment for the company concerned
Documentation for communication with IT security service providers
Judicial and non-judicial expert reports
Collaboration with IT security teams

This is how threat actor profiling works

The methods and technical characteristics identified in the course of the investigation are systematically cross-referenced against publicly available specialist publications on known threat actors; any discernible similarities are documented, with reference to the source.

Why is threat actor profiling relevant from a forensic perspective?

A plausible assessment can help to gauge an attacker’s likely next steps and the risk to the affected company more realistically.

The documented evidence also makes the classification transparent to third parties, such as insurers or public authorities.

Frequently Asked Questions

Can an attack be attributed beyond doubt to a specific threat actor?+
No, publicly supported profiling provides plausible clues, not a definitive identification; we communicate this transparently.
What sources is the profiling based on?+
Publicly available specialist publications and reports from recognised security research organisations and IT security firms.
Is the profile updated on an ongoing basis?+
In the course of an ongoing case, we take into account any new public information that comes to light, where relevant.

LanCologne – IT Forensics OSINT Cologne

Do you require a professional OSINT investigation into „OSINT-based profiling of threat actors"? LanCologne can assist you with the transparent, documented analysis of publicly available digital sources to complement your IT forensic, legal or internal corporate enquiries.

Get in touch now