Decision hub
Cybersecurity OSINT should triage risk without crossing into unauthorized testing.
Security teams can use public sources to inspect domains, certificates, malware context, exposed services, reputation labels, and breach signals. The discipline is to stay passive unless authorized and to avoid turning overlap into attribution.
- Best for: SOC analysts, threat-intel teams, journalists covering cyber incidents, and researchers scoping public exposure.
- Avoid when: a workflow requires scanning, exploitation, authentication bypass, credential use, or sensitive victim data without authority.
- Risks to control: false positives, stale threat labels, shared infrastructure, victim exposure, and unsupported attribution language.
Cybersecurity decision map
Infrastructure and exposure
Shodan, Censys, SecurityTrails
Use to understand public exposure, certificates, services, banners, DNS history, and internet-facing context without active probing.
Next route: infrastructure comparison
URL and domain triage
urlscan.io, VirusTotal, AlienVault OTX
Use for redirects, page-load behavior, reputation context, community signals, and indicator enrichment.
Compare with: URLhaus, PhishTank, Cisco Talos, and direct archive captures.
Breach and exposure context
Have I Been Pwned, Hudson Rock, EmailRep.io
Use cautiously for exposure signals. These can be sensitive and should never become public blame or identity proof.
Next route: breach and exposure toolkit
Indicator handling
CyberChef, MISP, Mitaka
Use when indicators need decoding, enrichment, sharing, or repeatable pivots across public sources.
Compare with: internal logs and case-specific evidence.
Passive-first workflow
- Define authorization and scope before collecting technical context.
- Prefer passive lookups and public records unless active testing is explicitly authorized.
- Record indicator, source, timestamp, visibility, and access level.
- Separate reputation labels, infrastructure overlap, exploitability, compromise, and attribution.
- Protect victim, employee, credential, and incident-response details.
Attribution boundary
A shared certificate, ASN, hosting provider, malware label, or exposed service is not actor attribution. Keep public language tied to observed evidence.
Next routes
Use domain and DNS investigation tools, threat-intelligence triage stack, or breach and attack-surface toolkit.