OSINT — Inteligencia de Fuentes AbiertasOSINT — Open Source Intelligence
Leaks, credenciales filtradas, info sensible en redes.Leaks, exposed credentials and sensitive information on social networks.
¿Qué es este servicio?What is this service?
Es la recolección y el análisis de información pública sobre la organización y sus personas: credenciales en filtraciones, datos en redes sociales, documentos con metadatos, infraestructura expuesta y menciones en foros.
The collection and analysis of public information about the organisation and its people: credentials in leaks, social media data, documents with metadata, exposed infrastructure and forum mentions.
¿Para qué se usa?What is it used for?
Permite ver qué material tiene disponible un atacante antes de empezar. La fase de reconocimiento de cualquier ataque dirigido es exactamente esto, y buena parte de lo que se encuentra es información que la propia organización publicó sin darse cuenta de que servía para atacarla.
It shows what material an attacker has available before starting. The reconnaissance phase of any targeted attack is exactly this, and much of what turns up is information the organisation itself published without realising it could be used against it.
Qué beneficios traeBenefits it delivers
- Encuentra credenciales corporativas en filtraciones de terceros, que se reutilizan y son entrada directa.
- Detecta información sensible publicada por descuido: documentos internos, credenciales en repositorios públicos, capturas con datos.
- Mapea a las personas objetivo de un ataque dirigido, que son las que necesitan protección adicional.
- Se hace sin tocar los sistemas del cliente, así que no tiene riesgo operativo alguno.
- Finds corporate credentials in third-party leaks, which get reused and are a direct way in.
- Detects sensitive information published carelessly: internal documents, credentials in public repositories, screenshots with data.
- Maps the people who would be targeted in a directed attack, the ones needing extra protection.
- It is performed without touching the systems of the client, so it carries no operational risk at all.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No hay obligación legal de hacer OSINT.
- Sí hay límites: la investigación trata datos personales de empleados y de terceros, así que la Ley 8968 aplica al tratamiento que hace el propio investigador.
- Conviene acotar por escrito qué se investiga y con qué finalidad, y no derivar hacia la vida privada de las personas.
- There is no legal obligation to perform OSINT.
- There are limits: the research processes personal data of employees and third parties, so Law 8968 applies to the processing carried out by the investigator.
- The subject and purpose of the research should be defined in writing, without drifting into the private lives of individuals.
InternacionalInternational
- Ningún marco lo exige por nombre.
- El RGPD limita el tratamiento de datos personales durante la investigación, incluso si la fuente es pública: que sea accesible no lo hace libre de reglas.
- Es un insumo estándar de las pruebas dirigidas por amenazas bajo marcos como TIBER-EU.
- No framework requires it by name.
- The GDPR limits the processing of personal data during the research, even where the source is public: accessible does not mean rule-free.
- It is a standard input to threat-led testing under frameworks such as TIBER-EU.
Requisitos mínimosMinimum requirements
- Definir por escrito el alcance: qué dominios, marcas y perfiles entran, y dónde está el límite con la vida privada.
- Autorización de la organización, aunque no se toquen sus sistemas.
- Claridad sobre qué se hace con lo hallado, sobre todo si aparecen datos personales de terceros.
- Un canal seguro para entregar el informe, que contendrá material sensible.
- Defining scope in writing: which domains, brands and profiles are included, and where the line with private life sits.
- Authorisation from the organisation, even though its systems are not touched.
- Clarity on what happens with what is found, especially if third-party personal data appears.
- A secure channel to deliver the report, which will contain sensitive material.
Plazo típico de entregaTypical delivery time
El rango habitual del mercado va de una a tres semanas según el tamaño de la organización y la cantidad de personas en alcance. Una investigación acotada a infraestructura y credenciales filtradas se entrega en cinco días; una que incluya perfilado de personal directivo se va a tres o cuatro semanas.
The usual market range runs from one to three weeks depending on organisation size and the number of people in scope. Research limited to infrastructure and leaked credentials is delivered in five days; one including executive profiling stretches to three or four weeks.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.