Skip to content

Cyber Intelligence Investigation report

A Cyber Intelligence Investigation maps an organization's or person's external digital exposure from passive, public collection: domains, infrastructure, certificates, exposed code and storage, breached credentials and lookalike domains. It then connects that infrastructure to the people and organizations behind it and turns each exposure into a mitigation step.

Who orders it

  • CISOs and security teams wanting an outside-in view
  • MSSPs, DFIR and CTI teams enriching a client engagement
  • Corporate security assessing executive exposure
  • Deal teams assessing a target's cyber posture before an acquisition

Questions it answers

What can an outsider see and use about this organization or person, and how does the infrastructure connect to the people and companies behind it?

  • Which domains, subdomains, cloud storage and SaaS tenants belong to this organization?
  • Are staff credentials in breach data or infostealer logs?
  • Is code or a secret belonging to the organization exposed on public code platforms?
  • Who registered these lookalike domains, and what else do they connect to?
  • Which exposures matter most, and what should IT do about them?

Scope

  • Asset inventory from certificate logs, DNS, passive DNS, WHOIS and web archives
  • Web interfaces, mobile apps and browser extensions tied to the organization
  • Code platforms, code search, secret findings and deleted repositories
  • Cloud storage and SaaS tenant exposure
  • Breach and infostealer exposure (public breach indexes and stealer-log sources)
  • Dark-web mentions from public onion-search indexes
  • Lookalike domains and mail posture (SPF, DKIM, DMARC)
  • IP, hosting and ASN context, with threat-feed reputation
  • Exposed people and contact data, as a defensive target bank
  • Mitigations for each finding
  • RoadmapRansomware and extortion leak-site monitoring
  • RoadmapCriminal-forum monitoring

Not every source applies to every subject; the report shows what was checked and what was not.

Not included

  • Exploitation, credential testing or login attempts
  • Port scanning, path guessing or any intrusive testing
  • Reading the contents of exposed storage or repositories beyond what proves the exposure
  • Disclosure of plaintext secrets or passwords in the report
  • A vulnerability scan or penetration test

Example table of contents

  1. 01Executive summary
  2. 02Asset inventory
  3. 03Web interfaces, mobile apps and browser extensions
  4. 04Code platforms and secret findings
  5. 05SaaS tenants and cloud storage
  6. 06Credential and data exposure
  7. 07Exposed people and contact data
  8. 08Target bank
  9. 09Mitigations
  10. 10Scope, method, limitations and evidence index

Evidence and confidence

How is evidence verified?

Each finding carries its source, an Admiralty grade (source reliability A to F, credibility from corroboration), the retrieval time and a SHA-256 hash of the captured page. Inferred links are labelled as assessments with their confidence.

What stops a weak finding getting through?

QA rules block findings without evidence, universal negatives and speculative language, and an analyst signs the report off before release.

Read the methodology

Price and process

From $2,990

Starting price. Scope, jurisdictions and data-provider costs set the final figure, which is confirmed before collection starts.

  1. 1. Your organization is vetted before its first case.
  2. 2. You state the requirement, purpose and lawful basis; we agree scope and price.
  3. 3. Collection, analysis, QA and analyst sign-off.
  4. 4. Delivery: PDF and DOCX report with an asset inventory, target bank and mitigations, signed off by an analyst.

Turnaround depends on scope and is agreed with the mandate.

Need this level of intelligence on a real case?

Runs on OSINTTotal Cyber. Published examples are on the samples page.

Discuss an investigation
  • Screen

    Fast, repeatable intelligence screening of people and companies.

  • Investigate

    Deep investigations across people, companies, assets and networks.

  • Cyber

    Infrastructure, exposure and the people and companies behind it.

Sample reportsMethodologyPricingAcceptable use

Cyber Intelligence Investigation | OSINTTotal