Skip to content

Company OSINT

Before attacking the infrastructure it’s worth understanding the organization: how it’s structured, what subsidiaries and brands it has, what it acquired, which providers it uses, where it’s physically located, and what technologies it buys. That context defines the target’s true scope (a parent company can have dozens of domains and subsidiaries with forgotten infra) and provides pretexts and vectors that purely technical recon misses.

  • Corporate structure: parent, subsidiaries, brands, acquisitions → more domains/infra in scope.
  • Associated domains and brands: not just target.com, but all its properties.
  • Providers and technology: which SaaS, cloud, and software they use (supply-chain vectors).
  • Physical locations: offices, data centers (relevant for physical red team).
  • Financial/legal data: company registries, filings (context, pretexts).
  • Job ads: reveal the internal tech stack in detail.
# corporate registries (by country)
OpenCorporates, Crunchbase, company registries, SEC EDGAR (US)
# associated brands and domains
reverse WHOIS (by registrant organization/email)
whoxy, ViewDNS reverse whois -> all domains registered by the org
# certificates (reveal related brands/domains)
crt.sh by org name
# job ads (tech stack)
LinkedIn Jobs, job boards -> "seeking an expert in <technology X>"
# from the registrant email/organization, all their domains
# whoxy / ViewDNS / amass intel
amass intel -whois -d target.com # related domains by WHOIS
amass intel -org "Target Inc" # by organization name

This turns “one domain” into “the company’s full domain portfolio,” many with less-watched infra.

Acquired companies bring their own infra, often unintegrated and unhardened:

# Crunchbase/news: "Target Inc acquires Startup X"
# -> Startup X may have domains, ranges (recon-asn), and vulnerable systems
# now under Target's umbrella (and scope)
# an ad "Active Directory Administrator with Citrix and SAP experience"
# reveals: AD, Citrix, SAP in the internal infra -> concrete vectors to look for

Job ads are one of the most underrated sources of the internal stack.

1. Map the structure (parent, subsidiaries, brands, acquisitions)
2. Reverse WHOIS -> all the org's domains
3. Expand each domain (subdomains, ASN, technical recon)
4. Extract the stack from job ads
5. Identify providers/SaaS (supply chain)
6. Consolidate the target's real scope

An organization must know its own surface: inventory of domains/brands/subsidiaries, management of infra inherited from acquisitions (harden or retire), control of what job ads reveal about the stack, and continuous Attack Surface Management. What you discover as an attacker, defense should discover first.

  • Corporate structure mapped (parent/subsidiaries/brands)
  • Reverse WHOIS → all the org’s domains
  • Acquisitions identified (inherited infra)
  • Internal stack extracted from job ads
  • Providers/SaaS identified (supply chain)
  • Physical locations (if physical red team applies)
  • Each domain expanded with technical recon
  • Real scope consolidated