We investigate exposure beyond the organisation's perimeter: public assets, leaked credentials, impersonation and signals that may anticipate or explain an incident.
Brands with a digital presenceCompanies exposed to phishingOrganisations investigating a potential leakTeams that need to understand their public attack surface
Services
What we do within Intelligence.
Every service is adapted to the asset, the required depth and the decision you need to make. The details below explain what each service covers before scope is agreed.
01
Intelligence
Footprinting and OSINT
We identify public information that an attacker could use to prepare an intrusion or social-engineering campaign and relate it to the organisation's real assets.
When it fits
Companies that want to understand what is visible from the Internet before an assessment, launch or exposure review.
What it includes
Domains, subdomains, IP addresses and exposed services
Relevant email addresses, profiles and public relationships
Technologies, metadata and accessible documents
Leaked credentials within legal limits
Attack-surface map
What the client receives
Validated exposure inventory
Source and confidence level for each finding
Risks and attack-surface reduction actions
02
Intelligence
Deep Web and Dark Web investigation
We search specialist sources, forums and markets for indications of credentials, data or references to the organisation, validating the information without unauthorised access to systems or accounts.
When it fits
Organisations responding to leak suspicions, external alerts or a need to determine whether specific information is circulating.
What it includes
Search for credentials and sensitive data
Review of mentions, samples and context
Correlation with known assets and dates
Authenticity validation within safe limits
Impact and urgency assessment
What the client receives
Documented evidence and sources
Impact analysis and confidence level
Containment, monitoring or escalation recommendations
03
Intelligence
Brand protection and fraudulent domains
We detect lookalike domains, pages, profiles and other impersonation signals that may target a brand's customers, employees or suppliers.
When it fits
Brands with online sales, support or account access that need to detect phishing, typosquatting and fraudulent use of their identity.
What it includes
Lookalike domains and registration patterns
Content, infrastructure and relationship with the brand
Associated profiles or public assets
Signal prioritisation and false-positive review
Technical support for blocking, monitoring or takedown requests when agreed
What the client receives
Validated and classified findings
Indicators for blocking and monitoring
Response and follow-up recommendations
Before
Scope and authorisation
Included assets, accounts and environments
Objective and depth of the work
Testing windows, contacts and stop criteria
Handling of information and evidence
Delivery
What the client receives
Agreed hypotheses and reference assets
Sources, evidence and confidence level
Impact and priority for each signal
Indicators for blocking or monitoring
Containment, communication or escalation recommendations
Limits
What remains out of scope
Unauthorised access to sources, systems or accounts
Conclusive attribution without sufficient evidence
Legal action on the client's behalf
Takedown or continuous monitoring unless explicitly included
First step
Tell us what you need to protect.
You do not need to select a service in advance. We will review the context and define the smallest engagement that can answer your need.