Insights

What is OSINT — and why should your business care?

OSINT — Open Source Intelligence — is the practice of collecting information from publicly available sources: websites, social media, public records, leaked databases, job postings, even photos your team shares online. No hacking involved. Just careful collection of what is already out there.

Why attackers love OSINT

Before any serious attack, adversaries research their target. An employee's LinkedIn reveals your tech stack. A job posting reveals the software you use internally. An old forum post by your developer reveals an email pattern. A photo from your office party reveals the badge design. Individually harmless — combined, they become an attack plan.

Why defenders need it more

The same techniques, used on yourself, show you exactly what an attacker would see. An OSINT assessment answers questions like: Which employee emails appear in known data breaches? What internal documents are accidentally indexed by Google? Which subdomains did your old vendors leave running? What does your digital footprint reveal that you never intended to publish?

What a professional assessment covers

At Karleesh, an OSINT engagement typically maps your external attack surface (domains, subdomains, exposed services), checks staff emails against breach databases, reviews what metadata your published files leak, and audits what social media reveals about your operations. You receive a prioritised report — what to remove, what to monitor, what to train your team about.

The internet never forgets, but you can control what it remembers next. If you have never seen your company through an attacker's eyes, that is the single most valuable security exercise you can do this quarter.

Free download

Website Security Checklist (PDF)

25 practical checks every business website should pass — from our security team.

← All articles