Definition · Subdomain Enumeration
What is OSINT?
OSINT is the practice of assembling a picture of a target from information that is already public. In a security context it is the passive half of reconnaissance: no packets are sent to the target’s systems, so there is nothing for the target to detect or block.
Sources that matter for attack surface work
- Certificate transparency logs — every publicly trusted certificate names its hostnames, so CT logs are a continuously published list of subdomains
- WHOIS and RDAP — registrant, registrar, name server, and IP allocation data
- Passive DNS — historical resolutions revealing names that no longer resolve and hosting that has moved
- Internet-wide scan datasets — third-party scan data about services and banners
- Code repositories and package registries — internal hostnames, endpoints, and occasionally secrets in commit history
- Corporate filings, job adverts, and staff profiles — subsidiaries, technology in use, and names for social engineering
Why OSINT drives external exposure risk
OSINT is how an outsider learns that a subsidiary you acquired still runs its own mail domain, that your naming convention makes internal hosts guessable, or that a developer published a config file with an API hostname in it. None of that requires touching your network, and none of it will show up in your logs.
Defensive OSINT
Running OSINT against yourself is cheap and repeatable, and it is the only way to see the version of your organisation that an attacker sees first. It routinely surfaces shadow IT and assets that never made it into any inventory.
Related concepts
OSINT findings become the seed list for active asset discovery and subdomain enumeration, and are the starting point for both threat actors and red teams.