
15 June 2026
Swarmer and Molfar Partner to Integrate Verified Intelligence Data for Autonomous Systems
Partnership connects combat-proven drone autonomy software with verified intelligence data sets to improve AI decision-making.
A cyberattack does not always begin with malware or an attempted login. It may start with a job advertisement that names the company’s software, an exposed development subdomain, an employee’s public profile or credentials disclosed in an earlier breach.
Attackers use such information to understand a target before approaching its systems or people. Cyber security teams use open-source intelligence, or OSINT, to examine the same external footprint, identify material exposure and act before a public clue becomes an incident.
OSINT is intelligence produced from publicly or commercially available information to answer a defined requirement, as described in the US Intelligence Community’s OSINT Strategy.
In cyber security, the requirement might be to identify an organisation’s internet-facing assets, credential exposure, the operator of a phishing domain or public information that could support impersonation.
A search result is not intelligence by itself. Analysts must verify the source, connect identifiers and explain what a finding means for a security decision. An open port may be expected, a lookalike domain may be inactive and an exposed password may already have been reset. Context determines the risk.
OSINT is also a dual-use capability. Defenders and threat actors can inspect much of the same public environment. The difference lies in their purpose, authority and actions.
Internal logs show activity within known systems. OSINT provides an external view and may reveal forgotten domains, public cloud assets, leaked documents, exposed contacts or lookalike websites.
Attackers use public websites, social platforms, search engines, code repositories and technical databases during reconnaissance. MITRE ATT&CK documents these behaviours because the information can support phishing, account compromise and exploitation of public-facing services.
Security teams can reverse that perspective. They can use OSINT to:
OSINT does not predict every attack and cannot prove that a threat actor will act. It helps teams identify, validate and prioritise indicators earlier.
The relevant source depends on the intelligence question. Common categories include the following.
Corporate websites, job advertisements, conference biographies and professional profiles can reveal locations, suppliers, team structures and technologies. Combined, these details may help an attacker select a target or make a fraudulent request more convincing.
Social platforms and public forums can expose travel, reporting lines or work routines. Security reviews should focus on organisational risk rather than unrestricted profiling. Employee research, including social media background screening, must remain relevant, proportionate and lawful.
DNS and RDAP records, certificate logs, code repositories, indexes of internet-facing services and web archives help analysts connect domains, hosts and software. Vendor advisories and vulnerability catalogues add context.
A certificate does not prove that a host remains active, and a service banner does not prove vulnerability. Domain research, archives, metadata and other OSINT techniques still require validation.
Analysts can use authorised breach-notification services to identify account or domain exposure without retrieving stolen passwords. Public malware repositories and indicator feeds can help connect suspicious files, domains and infrastructure.
The deep web includes ordinary content that search engines do not index. The dark web includes services reached through networks such as Tor and is not inherently criminal. Closed communities, stolen datasets and purchased access do not automatically qualify as open sources; collection requires lawful authority and controls for sensitive material.
Business registries, procurement records and regulatory materials may connect infrastructure to companies or individuals. Access rules vary by jurisdiction.
Analysts use public reporting, malware data and infrastructure records to enrich indicators. Where lawful, they also monitor public threat-actor channels and ransomware leak sites, treating claims as leads until independently confirmed. A domain or IP address becomes useful when its timing, associations and independent corroboration are known.
OSINT can identify likely domains, cloud services or test environments missing from an asset inventory. Ownership must be confirmed before remediation. CISA’s internet-exposure guidance recommends identifying internet-accessible assets, deciding which must remain exposed and protecting or removing the rest.
Approved sources may indicate that corporate emails, documents, API keys or credentials were disclosed. Teams should verify the alert through authorised systems, reset affected credentials, revoke sessions and review logs—not test leaked passwords against live accounts.
Lookalike domains, copied websites and fake executive profiles can indicate fraud or phishing preparation. Analysts use OSINT to link the infrastructure, preserve evidence and support blocking or takedown requests.
During an incident, open sources add ownership, infrastructure and timeline context to internal telemetry. In transactions and vendor onboarding, OSINT supports cybersecurity due diligence by testing claims against evidence about breaches, exposed assets and security history.
No single platform provides a complete or verified picture. Common tools serve different parts of the process:
Tool lists change quickly. Twint, included in many older guides, has been archived. Dark-web indexes also change or disappear. Record the source, query date and what each result established.
Passive collection uses existing public or authorised third-party data without sending purpose-built queries to the target’s infrastructure or contacting its people. A search engine, certificate log or existing Shodan index can fit this category.
Port scans, vulnerability checks, DNS brute-force enumeration, authentication tests and direct contact generate new interactions. They are active reconnaissance or security testing and require written authorisation, a defined scope and rules of engagement. NIST’s technical testing guidance treats planning and authorisation as core controls.
Red teams may use OSINT before a penetration test, but public information is not permission to access a system. Analysts must stop when validation crosses the approved boundary.
A public fact does not have the same significance in every context. Security teams can prioritise it through five questions:
This prevents teams from treating every public detail as critical or dismissing small signals that become material when connected.
Start with a defined question and a list of assets in scope. Begin with passive collection, correlate identifiers and confirm ownership. Validate important findings independently, then record confidence, impact and limitations.
Assign an action and an owner to each material finding. Responses may include blocking a lookalike domain, closing an exposed service, resetting credentials or introducing out-of-band verification for sensitive requests.
AI can accelerate translation, clustering and triage. However, AI-assisted OSINT workflows can conflate different entities, repeat poisoned data and amplify false positives. Human verification remains necessary. Teams also need training in source validation, legal boundaries and evidence handling.
OSINT gives an organisation evidence about what outsiders can learn before interacting with its network or employees. It complements vulnerability management, internal telemetry, incident response and security awareness. It does not replace them.
Molfar Intelligence combines open-source research, technical context and human-factor analysis in cyber security risk management. Our reports identify exposed assets, data and behavioural signals, cite the supporting sources and prioritise each finding by its relevance to operations, compliance and business continuity.
Author

15 June 2026
Partnership connects combat-proven drone autonomy software with verified intelligence data sets to improve AI decision-making.

2 March 2026
A €900M EU real estate deal under investigation shows why institutional reputation cannot replace structured due diligence.
Behind every case is a client who needed clarity in uncertainty. Browse our work to see how we uncover what others miss — and what that means in practice for businesses and decision-makers.
Revealed how a high-stakes Defence Tech investment was halted after OSINT-driven due diligence uncovered a co-founder’s links to Russian-origin money laundering and a seized 2.6 billion UAH gambling enterprise, protecting a global firm from severe reputational and regulatory fallout.
Investment
Conducted a full pre-employment background investigation for a high-security aerospace role, covering court registry checks, financial record verification, ideological risk assessment, and social media OSINT analysis across relevant jurisdictions.
Space
Revealed how Russian drone manufacturers circumvent international sanctions by exploiting a critical design flaw (sanctions applied to company names rather than underlying legal entity identifiers), enabling Supercam to increase production tenfold despite being designated.
Finance
Conducted a comprehensive cybersecurity audit of a long-standing European IT infrastructure, identified critical internal data leaks involving financial plans and performance reviews, and implemented high-level security protocols to mitigate regulatory and operational risks.
Cybersecurity
Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.
Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.