Target profiling via OSINT

Target profiling relies heavily on open-source intelligence (OSINT). Organisations routinely publish significant amounts of information about their workforce, enabling passive reconnaissance before any direct engagement.

Role disclosures

Individual public data sources expose operational details. Job postings may disclose managed systems, performance metrics, reporting chains, technical stacks, and required certifications. Professional networks like LinkedIn can, for example, reveal employee tenure, career history, and recent onboarding dates. And conference talks and public posts can be useful for identifying specific technical expertise and projects, providing natural talking points for engagement.

Individually, these are standard corporate communications. Correlated, they can establish expected communication norms and allow precise mapping of the target environment, including vendors, software versions, and network topology.

Target selection criteria

Optimal targets are rarely senior executives, who face higher security scrutiny, rely on executive assistants to screen incoming communications, and often hold fewer administrative credentials than org charts suggest.

More fruitful target selection focuses on high system access paired with high operational accessibility like new hires holding full system privileges but lacking baseline familiarity with normal operational procedures, support and helpdesk staff who are incentivised by resolution speed metrics and inherently structured to assist unfamiliar requesters, and third-party contractors and integrators who are frequently granted remote access, expected to operate on-site, and rarely recognised personally by local staff.

Pretext design and validation

A pretext provides operational justification for contact rather than a complex persona. Highly effective pretexts blend seamlessly into routine workflows. Mundane scenarios, a pending delivery, a vendor following up on a ticket number, an internal system verification request, or an enquiry from an out-of-office colleague, are far more resilient than complex scripts, which fail during unscripted interactions.

An effective pretext requires target specificity, meaning a clear justification for contacting this specific individual. And it requires verification resistance, resilience against simple peer-checking, which is the most common immediate validation method used by targets.

Operational risk of direct engagement

Direct engagement introduces exposure that passive collection does not. Human memory acts as an unalterable log. A target may recall an interaction, discuss it casually with peers, or report it to security, either immediately or weeks later. Consequently, every direct interaction carries operational risk and potential detection.