Notice: Die Funktion wp_register_script wurde fehlerhaft aufgerufen. Nicht erkannte(r) Schlüssel im Parameter $args: defer. Unterstützte Schlüssel: strategy, in_footer, fetchpriority, module_dependencies Weitere Informationen: Debugging in WordPress (engl.). (Diese Meldung wurde in Version 7.0.0 hinzugefügt.) in /var/www/vhosts/mgm-sp.217-154-231-6.plesk.page/httpdocs/wp-includes/functions.php on line 6170

Notice: Die Funktion wp_register_script wurde fehlerhaft aufgerufen. Nicht erkannte(r) Schlüssel im Parameter $args: defer. Unterstützte Schlüssel: strategy, in_footer, fetchpriority, module_dependencies Weitere Informationen: Debugging in WordPress (engl.). (Diese Meldung wurde in Version 7.0.0 hinzugefügt.) in /var/www/vhosts/mgm-sp.217-154-231-6.plesk.page/httpdocs/wp-includes/functions.php on line 6170
Open Source Intelligence / OSINT – mgm security partners
Notice: The wp_enqueue_script function was incorrect Called. Unrecognized key(s) in the $args parameter: async. Supported keys: strategy, in_footer, fetchpriority, module_dependencies. For more information: Debugging in WordPress. (This message was added in version 7.0.0.) in /var/www/vhosts/mgm-sp.217-154-231-6.plesk.page/httpdocs/wp-includes/functions.php online 6170

Open Source Intelligence / OSINT

With Open Source Intelligence (OSINT), you gain a realistic assessment of your public attack surface – from the perspective of a potential attacker.

Every company leaves digital traces on the internet: domains, subdomains, servers, used technologies, metadata, or publicly accessible files. This information provides valuable starting points for attackers to prepare attacks.

OSINT analyses offer a fast and efficient way to visualize your own attack surface – without performing active attacks. With the help of our in-house mgm tool „recon me“, we combine various methods to systematically collect, correlate, and process publicly available information. The result: a transparent overview of potential risks and concrete recommendations for action.

Our Services

Offer

We conduct comprehensive OSINT analyses for you – passively or actively, depending on the desired depth. Typical components:

  • Passive Scan: Querying public directory services (e.g., Whois, DNS, MX), identification of servers, subdomains, email addresses, technologies, and operators (e.g., Amazon, Akamai).
  • Active Scan: Direct investigation of the target domain without attacks, e.g., to identify further services, technologies, or unintentionally publicly accessible files.
  • Tool-Supported Analysis: Use of our automated OSINT tool „recon me“ for structured collection and evaluation.
  • Reporting & Consulting: Preparation of all results with evaluation, problem areas, and prioritized recommendations for action.

Approach

Approach

Our OSINT audits follow a clearly structured process:

  1. Scoping: Definition of the target domain and desired scan depth (passive or active).
  2. Data Collection: Cascading application of automated tools combined with manual expertise.
  3. Analysis: Evaluation of the found services, technologies, operators, and metadata.
  4. Risk Assessment: Derivation of the potential attack surface from an attacker's perspective.
  5. Reporting: Delivery of a detailed report with technical findings and recommendations.

Checkpoints

Approach

We specifically audit the publicly visible elements of your infrastructure:

  • Whois data, DNS and mail servers
  • Subdomains and associated services
  • Location and operator of external servers (e.g., cloud providers)
  • Web technologies and versions in use
  • Publicly accessible files and metadata
  • Identified vulnerabilities and misconfigurations

Your Benefit

With OSINT analyses, you see your company through the eyes of an attacker – and can proactively reduce risks.

The results provide you with a clear assessment of your technical IT security from an external perspective. You gain transparency over your public attack surface and receive concrete recommendations for effectively closing vulnerabilities.

  • Clear assessment of the public attack surface
  • Choice between passive or active scan
  • Structured analysis with mgm tool „recon me“
  • Transparent report with findings and measures
  • Detection of unintentionally published information
  • Improvement of IT security from an attacker's perspective
  • Basis for further security tests (e.g. pentests)
  • Early warning system for digital attack surfaces

Take the first step and get in touch.

Your contact person for Open Source Intelligence / OSINT:

First name, Last name

Thomas Schönrich

Take the first step and get in touch.