Services / Open source reconnaissance

Everything they need is already published.

We build the same dossier a real attacker would build on your organization, using nothing but public sources. Then we show you where every single item came from, so you can take it down, lock it down, or plan around it.

No access required. No permission asked. That is the point.

COLLECTION LOG / SAMPLE PASSIVE ONLY

What we collect

Six categories, each one a step toward a convincing phone call.

Reconnaissance is not a list of scary facts. Every finding is graded by what it enables, because a leaked org chart matters only in terms of what someone can now say to your receptionist.

People and structure

  • Employee roster, titles, tenure, and reporting lines
  • Who is new, since new hires are the softest targets
  • Who is out of office, traveling, or publicly on leave
  • Owner and executive exposure, including personal accounts tied to the business

Identity and access

  • Email address format and validated live addresses
  • Credentials appearing in public breach corpora
  • Reused personal accounts that share a password pattern
  • Single sign-on provider, visible from your login endpoints

Technology and vendors

  • Platforms named outright in job postings and hiring ads
  • Domains, subdomains, mail records, and exposed services
  • Remote access endpoints reachable from the internet
  • Third parties with standing access to your data

Language and documents

  • What staff call the help desk, the DMS, the portal, the shared drive
  • Document metadata: authors, internal paths, software versions
  • Files published on your own site that should not be public
  • Photos revealing badges, screens, whiteboards, or building access

The deliverable

A sourced dossier you can actually act on.

Every finding carries three things: where it came from, what an attacker does with it, and what you do about it.

01

The dossier

The full collection, organized the way an attacker would organize it rather than the way a scanner would. Each item cites its source URL or corpus so your team can verify it independently.

02

Pretext projection

The specific stories this material makes possible, written out as scripts. This is the section clients read twice. It is one thing to hear that your DMS vendor is public knowledge, and another to read the call that vendor name enables.

03

Remediation queue

A prioritized list with an owner and an action for each item: request a takedown, change a posting, rotate a credential, remove a file, adjust a privacy setting, or accept the risk deliberately.

04

Executive readout

A live walkthrough with leadership. Thirty minutes, no jargon, focused on the handful of findings that actually change what you should do this quarter.

Scope and limits

Passive collection only.

We read what is published. We do not touch what is not.

We do not authenticate anywhere

No logging into anything, no using found credentials, no accessing an account to see what is inside it. Discovered credentials are reported, never tested.

We do not scan or probe

Standard OSINT engagements are entirely passive. Active scanning and exploitation belong in a penetration test with its own separate authorization.

Personal lives stay out of scope

We collect on individuals only where their exposure creates organizational risk. Home addresses, family members, and personal matters that do not touch the business do not go in the report.

Findings are handled as sensitive

The dossier is the most dangerous document your organization will own that quarter. Encrypted delivery, defined retention, and destruction on request.

Common questions

Before you scope it.

How long does an engagement take?

Most organizations under 200 people take one to two weeks from authorization to readout. The collection itself is faster than that. The time goes into verification, because a dossier full of maybes is worse than no dossier at all.

Do you need anything from us to start?

A signed authorization and a list of the legal entities, domains, and locations in scope. That last part matters more than people expect. Organizations routinely forget a subsidiary, an old domain, or an acquired location, and those are exactly where exposure accumulates.

Will our employees know?

Not unless you tell them. Passive collection is invisible to the target. Many clients prefer to keep it quiet so the follow-on phone and email tests stay honest.

What if you find our credentials in a breach dump?

We report the account, the source corpus, and the exposure date, and we recommend rotation. We never attempt the credential. If we find something that suggests an active compromise, we stop and call you the same day.

Should we do this before or after the phone and email tests?

Before. Reconnaissance is what makes the other two realistic. A phishing campaign built from a stock template tests whether your staff can spot a stock template. One built from your actual vendor relationships tests something worth knowing.

Request a scope

Find out what is already out there.

Tell us your entities and domains. We come back with a scope, a fixed price, and the authorization paperwork. No obligation to run it.

Or call 888.788.ZERO
An Espyonaj engagement is delivered by Nwaj Tech.

We reply within one business day. Nothing runs without a signed authorization.

Request captured. Connect this form to your backend to deliver it.