Skip to content

Cyber investigations that connect infrastructure to the people and organizations behind it.

OSINTTotal Cyber correlates domains, IPs, certificates, historical infrastructure, breached credentials, dark-web exposure and organizational relationships into a single investigation graph with source-backed evidence.

From a domain to the people behind it

An attack-surface inventory stops at the asset. A cyber investigation keeps going: from infrastructure to accounts, to the people and companies that own them, and back to the next asset. An illustrative pattern:

  1. Suspicious domainLookalike of the client's domain, registered recentlyInfrastructure
  2. Registration and DNSRDAP record and passive DNS historyInfrastructure
  3. IP and certificateShared hosting, ASN and certificate-transparency entriesInfrastructure
  4. Email and accountRegistrant email reused on a public code accountInfrastructure
  5. IndividualAccount attributed to a named person, namesakes excludedPerson
  6. CompanyPerson appears as an officer in a company registryCompany
  7. Related directorSecond officer of the same companyPerson
  8. Second domainDomain on the company's own certificateInfrastructure
  9. Credential exposureSecond domain's staff emails in breach and stealer-log indexesInfrastructure
  10. Cloud and code exposurePublic storage bucket and repository named after the brandInfrastructure

Every hop cites the record it came from. A link inferred rather than recorded is labelled as an assessment, with its confidence.

External exposure

  • Domains and subdomains from certificate logs, DNS and web archives
  • Web interfaces reached with one ordinary request, as a browser would
  • Cloud storage and SaaS tenants tied to the brand
  • Mobile apps and browser extensions naming the organization
  • Public code platforms, code search and deleted repositories

Infrastructure intelligence

  • DNS records and passive DNS history
  • WHOIS and RDAP registration data
  • IP ownership, hosting and ASN
  • Certificate-transparency relationships
  • Infrastructure reuse across domains

Breach and credential exposure

  • Staff and executive identifiers in public breach indexes
  • Infostealer-log exposure, reported as metadata only
  • Secrets exposed in public code, reported without the secret itself

Dark web

  • Mentions of the organization, its domains and people in public onion-search indexes
  • RoadmapRansomware and extortion leak-site monitoring
  • RoadmapCriminal-forum monitoring

Brand and impersonation

  • Registered lookalike and typosquat domains
  • Mail posture (SPF, DKIM, DMARC) and what each gap lets an impersonator do
  • Mobile apps and browser extensions that use the brand

Executive exposure

  • Executives' public contact data and accounts relevant to corporate risk
  • Breached accounts and impersonation of named executives
  • Links between executives' identities and company infrastructure

Threat-infrastructure investigation

  • Domains, IPs and certificates connected to a suspicious asset
  • Reputation and IOC context from public threat feeds
  • Accounts, people and companies behind the infrastructure, where evidence supports the link

Incident enrichment

  • External context and infrastructure history for a domain or IP from an incident
  • A relationship graph from the indicator to the organizations and people around it
  • Evidence that supports, or argues against, an attribution hypothesis

Supply-chain intelligence

  • Customers, integrators and vendors that name the organization on their own public footprint
  • Third-party data exposure involving the organization
  • Selected suppliers investigated with the same modules

Passive collection, defensive output

OSINTTotal Cyber is not a vulnerability scanner or a penetration test. It does not exploit, test credentials, scan ports or guess paths. Collection is passive and public, plaintext secrets are kept out of the report, and every finding ends in a mitigation the client’s IT team can act on.

One-time investigation or continuous intelligence

Managed Cyber Investigation
A defined scope, investigated once, delivered as a signed-off report. From $2,990
What the report covers
Continuous External Intelligence
Monitored domains, executives and key suppliers re-investigated on a daily, weekly or monthly cadence, with what changed since the previous version. From $2,500/month, scope dependent

Enterprise Cyber: larger monitored scope, API access and recurring analyst support on an annual contract. Talk to sales.

Questions

What is a cyber intelligence investigation?

An investigation of an organization's or person's external digital exposure, built from passive public sources, that connects infrastructure to the people and companies behind it and ends in mitigations.

When should an organization use it?

Before an acquisition, after a phishing or impersonation campaign, when an executive is targeted, during incident response to understand an indicator, or to see what an attacker sees before they do.

What is not included?

Exploitation, credential testing, port scans or any intrusive testing, and reading the contents of exposed storage or code beyond what proves the exposure.

Is there a sample?

Yes. Open the sample reports and read how evidence is graded in the methodology.

Start from the asset. Finish with who is behind it.

Discuss a cyber investigationView the cyber sample

  • Screen

    Fast, repeatable intelligence screening of people and companies.

  • Investigate

    Deep investigations across people, companies, assets and networks.

  • Intelligence Services

    Finished reports, delivered by our analysts.

Sample reportsMethodologyPricingAcceptable use

Cyber Investigation & Digital Risk Intelligence | OSINTTotal