logo

OSINT for Incident Response (Part 1)

ID: 81e67a08-e9fc-5b30-bc67-97dc87f00ea9

STIX ID: report--81e67a08-e9fc-5b30-bc67-97dc87f00ea9

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2023-12-07

Date Updated: 2026-04-27

Author: BHIS

...
...

This practitioner blog demonstrates how quick OSINT sweeps (nslookup, DNSDumpster, Shodan, Censys, LeakIX) can accelerate DFIR: in the featured case a firewall migration introduced a NAT misconfiguration that exposed RDP/SMB to the internet, enabling attackers to install remote-access software and deploy ransomware. The author shows using external scans and screenshots plus internal logs (e.g., Windows 4625 events) to establish timelines, identify patient zero, and support remediation and vendor accountability, and advocates making OSINT a routine part of incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.