IT Forensics · OSINT
Profiling threat actors using OSINT – forensically categorising publicly documented methods
For certain threat actors who are actively operating on a recurring basis, there are publicly available specialist publications detailing their characteristic modus operandi and technical characteristics, which may be helpful in classifying an incident.
As part of existing incident response cases, we carry out a structured assessment to determine whether any identified characteristics can be linked to publicly documented methods used by known threat actors.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
Our OSINT investigations are always carried out as a complementary component to existing IT forensic, legal or internal corporate enquiries. Every step of the investigation and every piece of digital evidence found is documented and, where technically possible, archived to ensure traceability even if the original online content is subsequently altered or deleted.
Our services
As part of an ongoing case, we compare the methods and technical characteristics identified with publicly available specialist publications on known threat actors and document the results in a manner that is forensically verifiable.
Typical areas of application
This is how threat actor profiling works
The methods and technical characteristics identified in the course of the investigation are systematically cross-referenced against publicly available specialist publications on known threat actors; any discernible similarities are documented, with reference to the source.
Why is threat actor profiling relevant from a forensic perspective?
A plausible assessment can help to gauge an attacker’s likely next steps and the risk to the affected company more realistically.
The documented evidence also makes the classification transparent to third parties, such as insurers or public authorities.
Frequently Asked Questions
LanCologne – IT Forensics OSINT Cologne
Do you require a professional OSINT investigation into „OSINT-based profiling of threat actors"? LanCologne can assist you with the transparent, documented analysis of publicly available digital sources to complement your IT forensic, legal or internal corporate enquiries.
Related to this topic
- Detecting cyberattack early warnings using OSINT – Forensically documenting early public warning signs
- Using Google Dorking in a forensically traceable manner – utilising advanced search operators in a forensically documented way
- Command-and-Control Server: OSINT-based detection – forensic documentation of publicly visible control servers
- Researching malware indicators using OSINT – utilising publicly documented malware characteristics in a forensic context