Skip to content

Fictional sample.Every person, company, domain, account and wallet in this report is invented. It shows the format and depth of a real deliverable, abridged.

Cyber Investigation sample report

brindlecove-health.example

Regional clinic group, fictional organization

As of
Handling
Confidential. For the client and the stated purpose only.
Evidence items
5

Intelligence requirement

For the clinic group's security lead: what can an outsider see of our external footprint, which assets are forgotten, and is anyone impersonating us?

Lawful purpose recorded in the case gate: Security exposure review of your own organization and its staff (security_exposure).

Scope and exclusions

In scope

  • Domains and subdomains from certificate logs, DNS and web archives
  • Hosting, certificates and registrant links between assets
  • Mail posture: SPF, DKIM, DMARC and MTA-STS
  • Reported credential exposure for the organization's domains
  • Lookalike and impersonation domains

Not included

  • Non-public records, bank or account data, and anything behind a login we do not lawfully hold
  • Leaked credentials or breach contents: only the fact that an exposure was reported is recorded
  • Locating or contacting any person, pretexting or covert approaches
  • Health, religion, sexual life, ethnic origin or other protected traits
  • Port scans, vulnerability scans, exploitation or any active testing
  • Logging in with exposed credentials or testing whether they work

Executive intelligence assessment

Forty-one hostnames found, six not linked from any current page. One forgotten staging host still serves a login page. DMARC is set to monitor only. Exposure was reported for 12 staff accounts. Two lookalike domains were registered this year, one with a mail server.

Key findings

  • staging.brindlecove-health.example serves a login page on a certificate issued in 2026.

    FactConfidence: ConfirmedEvidence: E-Y-0001, E-Y-0002

  • DMARC policy is p=none, so spoofed mail is reported but not rejected.

    FactConfidence: ConfirmedEvidence: E-Y-0003

  • A breach notification service reports exposure for 12 accounts on the domain. Contents were not viewed.

    FactConfidence: MediumEvidence: E-Y-0004

  • brindlecove-heath.example, registered 2026-06, has an MX record and may be prepared for phishing.

    AssessmentConfidence: MediumEvidence: E-Y-0005

Chronology

DateEventEvidence
2026-02Certificate issued for the staging hostEvidence: E-Y-0001
2026-06Lookalike domain registered, MX record addedEvidence: E-Y-0005
2026-09DMARC record observed at p=noneEvidence: E-Y-0003

Contradictions and alternative hypotheses

  • The lookalike domain was registered defensively by a vendor or by the group itself.

    Open. The registrant is privacy-protected; the group's IT team can confirm.

Intelligence gaps

  • Internal assets and anything not visible from the internet.
  • Which of the 12 exposed accounts are still active.

Analyst assessment

Take the staging host offline or behind access control, move DMARC to quarantine, reset the reported accounts, and watch the lookalike domain.

Reviewer sign-off: a real report cannot be sent until it passes the QA rules and a second person, not the analyst, signs it off. Both names and the sign-off time go on the cover. This sample carries none.

Evidence index

IDSourceClassGradeRetrievedSHA-256
E-Y-0001Certificate transparency log entryAggregatorC22026-09-172e6ade3ee44c, truncated
E-Y-0002Page capture of the staging hostSelf-publishedD22026-09-17d0245c6d2b46, truncated
E-Y-0003DNS TXT record, _dmarcEstablishedB32026-09-17b66e98dbded6, truncated
E-Y-0004Breach notification service, domain summaryAggregatorC32026-09-17ee317d2a3c45, truncated
E-Y-0005WHOIS and DNS records for the lookalike domainEstablishedB32026-09-18990cbfd33769, truncated

Grade is the Admiralty code, set by rule: reliability A to F from the source class, credibility 1 to 6 from how many other independent sources support the same claim. Hashes in this sample are illustrative. In a real report each is the SHA-256 of the stored capture. How grading works

Cyber Investigation sample report (fictional) | OSINTTotal