Cyber investigations that connect infrastructure to the people and organizations behind it.
OSINTTotal Cyber correlates domains, IPs, certificates, historical infrastructure, breached credentials, dark-web exposure and organizational relationships into a single investigation graph with source-backed evidence.
From a domain to the people behind it
An attack-surface inventory stops at the asset. A cyber investigation keeps going: from infrastructure to accounts, to the people and companies that own them, and back to the next asset. An illustrative pattern:
- Suspicious domainLookalike of the client's domain, registered recentlyInfrastructure
- Registration and DNSRDAP record and passive DNS historyInfrastructure
- IP and certificateShared hosting, ASN and certificate-transparency entriesInfrastructure
- Email and accountRegistrant email reused on a public code accountInfrastructure
- IndividualAccount attributed to a named person, namesakes excludedPerson
- CompanyPerson appears as an officer in a company registryCompany
- Related directorSecond officer of the same companyPerson
- Second domainDomain on the company's own certificateInfrastructure
- Credential exposureSecond domain's staff emails in breach and stealer-log indexesInfrastructure
- Cloud and code exposurePublic storage bucket and repository named after the brandInfrastructure
Every hop cites the record it came from. A link inferred rather than recorded is labelled as an assessment, with its confidence.
External exposure
- Domains and subdomains from certificate logs, DNS and web archives
- Web interfaces reached with one ordinary request, as a browser would
- Cloud storage and SaaS tenants tied to the brand
- Mobile apps and browser extensions naming the organization
- Public code platforms, code search and deleted repositories
Infrastructure intelligence
- DNS records and passive DNS history
- WHOIS and RDAP registration data
- IP ownership, hosting and ASN
- Certificate-transparency relationships
- Infrastructure reuse across domains
Breach and credential exposure
- Staff and executive identifiers in public breach indexes
- Infostealer-log exposure, reported as metadata only
- Secrets exposed in public code, reported without the secret itself
Dark web
- Mentions of the organization, its domains and people in public onion-search indexes
- RoadmapRansomware and extortion leak-site monitoring
- RoadmapCriminal-forum monitoring
Brand and impersonation
- Registered lookalike and typosquat domains
- Mail posture (SPF, DKIM, DMARC) and what each gap lets an impersonator do
- Mobile apps and browser extensions that use the brand
Executive exposure
- Executives' public contact data and accounts relevant to corporate risk
- Breached accounts and impersonation of named executives
- Links between executives' identities and company infrastructure
Threat-infrastructure investigation
- Domains, IPs and certificates connected to a suspicious asset
- Reputation and IOC context from public threat feeds
- Accounts, people and companies behind the infrastructure, where evidence supports the link
Incident enrichment
- External context and infrastructure history for a domain or IP from an incident
- A relationship graph from the indicator to the organizations and people around it
- Evidence that supports, or argues against, an attribution hypothesis
Supply-chain intelligence
- Customers, integrators and vendors that name the organization on their own public footprint
- Third-party data exposure involving the organization
- Selected suppliers investigated with the same modules
Passive collection, defensive output
OSINTTotal Cyber is not a vulnerability scanner or a penetration test. It does not exploit, test credentials, scan ports or guess paths. Collection is passive and public, plaintext secrets are kept out of the report, and every finding ends in a mitigation the client’s IT team can act on.
One-time investigation or continuous intelligence
- Managed Cyber Investigation
- A defined scope, investigated once, delivered as a signed-off report. From $2,990
- What the report covers
- Continuous External Intelligence
- Monitored domains, executives and key suppliers re-investigated on a daily, weekly or monthly cadence, with what changed since the previous version. From $2,500/month, scope dependent
Enterprise Cyber: larger monitored scope, API access and recurring analyst support on an annual contract. Talk to sales.
Questions
What is a cyber intelligence investigation?
When should an organization use it?
What is not included?
Is there a sample?
Start from the asset. Finish with who is behind it.
Same engine, other ways in
- Screen
Fast, repeatable intelligence screening of people and companies.
- Investigate
Deep investigations across people, companies, assets and networks.
- Intelligence Services
Finished reports, delivered by our analysts.