OSINT assessment

Attackers Start With What You Already Made Public.

Before any exploit, adversaries build a picture of your organisation from public sources. Nuclisafe reconstructs that view — exposed assets, leaked data and human-layer exposure — so you can reduce it before it is used against you.

What we test

Testing coverage across the attack surface

Coverage is tailored to your application. The areas below are assessed where applicable to the agreed scope.

External Attack Surface MappingExposed CredentialsData Leak DiscoveryEmployee ExposureSocial Engineering ExposureDomain EnumerationSubdomain EnumerationShadow IT DiscoveryExposed Cloud AssetsDigital Footprint ReviewBrand Exposure ReviewMetadata & Document Exposure

Common weaknesses

Issues we frequently look for

Leaked Credentials

Corporate credentials appearing in public breach data and reused against your login surfaces.

Forgotten Subdomains

Stale DNS records and abandoned hosts that still resolve to reachable, unmaintained services.

Shadow IT

Unsanctioned tools, environments and cloud assets standing outside your security controls.

Exposed Cloud Storage

Publicly listable buckets, backups and artefacts discoverable without authentication.

Employee Exposure

Role, email-format and technology details that make targeted phishing materially easier.

Code & Document Leakage

Secrets in public repositories, pastes and document metadata referencing internal systems.

How we test

A manual-first testing approach

  • Passive collection first — public sources only, with no interaction that falls outside the agreed scope.
  • Domain, subdomain and IP correlation to build a verified inventory of internet-facing assets.
  • Breach and leak review to identify exposed credentials and data attributable to your organisation.
  • Human-layer exposure analysis to quantify realistic social engineering and phishing risk.
  • Prioritised exposure report distinguishing confirmed assets from likely but unverified attribution.

Aligned frameworks

OSINT FrameworkMITRE ATT&CK (Reconnaissance)

Assessments are mapped to these industry frameworks and testing methodologies. This does not imply certification by, or partnership with, any of these organisations.

Example tools

ShodantheHarvesterMaltegoRecon-ngSpiderFootHave I Been Pwned

Illustrative only — tooling is selected per engagement and is not a guarantee of full coverage. Manual testing remains central to every assessment.

Deliverables

What you receive

Executive Summary

Business-level view of risk posture, key themes and priorities for leadership and stakeholders.

Technical Report

Detailed findings with affected endpoints, reproduction steps, evidence and references.

Proof of Concept

Validated demonstration of exploitability within the authorized scope, so nothing is theoretical.

Risk Rating

Severity based on impact and likelihood, supporting prioritization and remediation planning.

Remediation Guidance

Specific, actionable fix recommendations written for the developers who will implement them.

Retest Report

Post-fix verification confirming which findings are closed and which need further work.

Ready to start scoping?

Every assessment is scoped according to application complexity, attack surface and testing requirements.