Company OSINT
Before attacking the infrastructure it’s worth understanding the organization: how it’s structured, what subsidiaries and brands it has, what it acquired, which providers it uses, where it’s physically located, and what technologies it buys. That context defines the target’s true scope (a parent company can have dozens of domains and subsidiaries with forgotten infra) and provides pretexts and vectors that purely technical recon misses.
What’s sought
Section titled “What’s sought”- Corporate structure: parent, subsidiaries, brands, acquisitions → more domains/infra in scope.
- Associated domains and brands: not just
target.com, but all its properties. - Providers and technology: which SaaS, cloud, and software they use (supply-chain vectors).
- Physical locations: offices, data centers (relevant for physical red team).
- Financial/legal data: company registries, filings (context, pretexts).
- Job ads: reveal the internal tech stack in detail.
Sources
Section titled “Sources”# corporate registries (by country)OpenCorporates, Crunchbase, company registries, SEC EDGAR (US)# associated brands and domainsreverse WHOIS (by registrant organization/email)whoxy, ViewDNS reverse whois -> all domains registered by the org# certificates (reveal related brands/domains)crt.sh by org name# job ads (tech stack)LinkedIn Jobs, job boards -> "seeking an expert in <technology X>"Reverse WHOIS: find all domains
Section titled “Reverse WHOIS: find all domains”# from the registrant email/organization, all their domains# whoxy / ViewDNS / amass intelamass intel -whois -d target.com # related domains by WHOISamass intel -org "Target Inc" # by organization nameThis turns “one domain” into “the company’s full domain portfolio,” many with less-watched infra.
Acquisitions and inherited infrastructure
Section titled “Acquisitions and inherited infrastructure”Acquired companies bring their own infra, often unintegrated and unhardened:
# Crunchbase/news: "Target Inc acquires Startup X"# -> Startup X may have domains, ranges (recon-asn), and vulnerable systems# now under Target's umbrella (and scope)Technology from job ads
Section titled “Technology from job ads”# an ad "Active Directory Administrator with Citrix and SAP experience"# reveals: AD, Citrix, SAP in the internal infra -> concrete vectors to look forJob ads are one of the most underrated sources of the internal stack.
Methodology
Section titled “Methodology”1. Map the structure (parent, subsidiaries, brands, acquisitions)2. Reverse WHOIS -> all the org's domains3. Expand each domain (subdomains, ASN, technical recon)4. Extract the stack from job ads5. Identify providers/SaaS (supply chain)6. Consolidate the target's real scopeFor the defense
Section titled “For the defense”An organization must know its own surface: inventory of domains/brands/subsidiaries, management of infra inherited from acquisitions (harden or retire), control of what job ads reveal about the stack, and continuous Attack Surface Management. What you discover as an attacker, defense should discover first.
Testing checklist
Section titled “Testing checklist”- Corporate structure mapped (parent/subsidiaries/brands)
- Reverse WHOIS → all the org’s domains
- Acquisitions identified (inherited infra)
- Internal stack extracted from job ads
- Providers/SaaS identified (supply chain)
- Physical locations (if physical red team applies)
- Each domain expanded with technical recon
- Real scope consolidated