top of page

What is OSINT?

OSINT (Open-Source Intelligence) is the process of collecting and analyzing publicly available information.

Originally, the term was used in intelligence operations, where spies gathered information from public sources such as newspapers, television broadcasts, and official publications to understand activities in target countries.

Other forms of intelligence include:

  • HUMINT (Human Intelligence): Information gathered directly from target people.

  • SIGINT (Signals Intelligence): Information analized by obtained electronic communications and signals.

Today, the Internet has made vast amounts of corporate information publicly accessible. Rather than launching attacks blindly, cybercriminals first conduct thorough reconnaissance using OSINT.

For example, they may investigate:

  • What operating system does the company's website use (Windows or Linux)?

  • What middleware and software are running?

  • Are there any critical vulnerabilities affecting those products?

  • Have confidential files, such as employee credentials, been accidentally exposed online?

 

Completely hiding a company's online presence is nearly impossible in this era.

Our OSINT service identifies what information an attacker could discover about your organization using only publicly available sources, helping you visualize the potential risks.

Advantages and disadvantages
of our OSINT service

• No system implementation or frequent meetings are required .

(You only need to provide information such as the domain name.)

• We will deliver a monthly OSINT report, eliminating the need for your team to spend time and resources on continuous monitoring.

・Since we are not carrying out hacking or similar activities, it is unlikely to put a load on our company's systems or leave attack logs in our WAF or firewall.

(Some logs, such as those from port scans, will remain.)

・By viewing your organization from an attacker's perspective, you can identify security weaknesses and prioritize your security improvement efforts.

・Vulnerabilities are identified through broad reconnaissance rather than in-depth testing.
This service does not include active vulnerability assessment or penetration testing.​

(For example, if we identify a Fortinet VPN server along with version, we may report publicly known vulnerabilities. However, we do not attempt to verify exploitability through methods such as exploitation or brute-force attacks.)

​*Vulnerability assessment are available separately.

・A minimum contract term of six months is required. Cancellation is not permitted during the initial six-month period.

・If any third-party tools used to provide our OSINT services are discontinued or undergo significant price increases, we reserve the right to discontinue the affected services.

In such cases, we will terminate the service agreement, cease charging any fees from the date the service ends, and refund any prepaid fees for the unused service period.

Announcement

28 June 2026 Announcement of company establishment
bottom of page