Mapping Threat Patterns Using Publicly Available Data

Written by Blogger

July 23, 2026

Guest Blogger: Ruqaya Osman

Cybersecurity teams have long operated in two distinct lanes: those who investigate incidents after they occur, and those who gather intelligence to anticipate future threats. Digital Forensics and Incident Response (DFIR) practitioners focus on what happened inside the network, while Open-Source Intelligence (OSINT) analysts look outward at publicly available data to understand the threat landscape.

But in today’s environment, this separation is no longer practical. Attackers move fast, reuse infrastructure, and leave traces across public sources long before, and after they strike. Organizations that treat OSINT and DFIR as separate disciplines miss critical opportunities to connect the dots earlier and respond more effectively.

This article explores how combining OSINT with DFIR enables security teams to shift from purely reactive investigations to proactive threat pattern mapping, and why this integration is no longer optional for modern security operations.

What Is Threat Pattern Mapping?

Threat pattern mapping is the process of identifying recurring behaviors, infrastructure, and techniques used by threat actors across multiple incidents or targets. Rather than treating each alert or incident in isolation, pattern mapping allows analysts to build a broader picture of who is attacking, how they operate, and what they are likely to do next.

At the core of this approach is the distinction between Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs). IOCs, such as IP addresses, domain names, and file hashes, are useful but short-lived. Threat actors rotate infrastructure frequently, making IOC-based detection alone insufficient. TTPs, on the other hand, describe how attackers behave, and these patterns tend to be far more stable over time.

Effective threat pattern mapping focuses on TTPs while using IOCs as entry points for deeper investigation. This is where the combination of OSINT and DFIR becomes particularly powerful.

OSINT Sources for Threat Pattern Mapping

Publicly available data provides a surprisingly rich foundation for identifying and mapping threat patterns. Key sources include:

Passive DNS & Domain Registration Records

Attackers often register domains with similar naming patterns, use the same registrars repeatedly, or rely on the same hosting providers. Tools like SecurityTrails, RiskIQ, and Whoxy can reveal historical DNS data that connects seemingly unrelated infrastructure. A domain registered just days before an attack, pointing to an IP with a history of abuse, is a strong pre-attack signal.

Exposed Repositories

GitHub and similar code-hosting platforms frequently contain attacker tools, scripts, leaked credentials, or configuration files accidentally committed to public repositories. Searching for specific strings, project names, or code patterns can surface early-stage attack preparation, sometimes before the attacker has deployed anything.

Sandbox Submissions

Platforms such as VirusTotal, Any.run, and Hybrid Analysis receive malware samples submitted from around the world. Analyzing submission patterns, file metadata, behavioral reports, and network indicators can reveal shared code, infrastructure overlaps, and campaign timelines often linking incidents across different organizations or regions.

Shodan & Censys

These internet-wide scanners continuously index exposed services, banners, and TLS certificates. Searching for specific configurations, software versions, or certificate patterns can identify attacker-controlled servers before they are used in active operations. A C2 server with a distinctive banner or self-signed certificate is often detectable weeks before a campaign begins.

Dark Web & Telegram Monitoring

Threat actors communicate, sell access, and share tools across dark web forums and encrypted messaging channels. Monitoring these sources provides early warning of targeting intent, leaked credentials, and initial access listings. When correlated with internal data, these signals can help organizations respond before an active intrusion escalates.

The DFIR Perspective: From Evidence to Pattern

When a DFIR investigation begins, analysts typically start with internal artifacts, logs, memory dumps, network captures, and endpoint telemetry. The goal is to reconstruct what happened, establish a timeline, and contain the damage. OSINT enhances this process at every stage:

  • Enriching IOCs: A suspicious IP address found in logs can be cross-referenced against AbuseIPDB, Shodan, and passive DNS records to determine whether it belongs to known malicious infrastructure, a recently registered domain, or a previously unseen threat actor cluster.
  • Validating Attribution: Behavioral patterns observed during an investigation, such as specific command-and-control communication styles, tooling, or staging techniques, can be matched against publicly documented threat actor profiles on platforms like MITRE ATT&CK or OpenCTI.
  • Expanding Scope: OSINT can reveal whether the same attacker infrastructure was used against other organizations, helping teams understand whether they are dealing with a targeted attack or a broader campaign affecting multiple entities.

Challenges and Limitations

Combining OSINT and DFIR is powerful, but it is not without challenges. Analysts must navigate several practical limitations:

  • Data noise and false positives: Public sources are full of misleading information. Not every flagged IP is malicious, and not every domain registration is suspicious. Correlation requires careful analysis and multiple data points before drawing conclusions.
  • Infrastructure overlap with legitimate services: Attackers frequently use shared hosting, cloud providers, or CDNs that also serve legitimate traffic. Blocking based on infrastructure alone can cause collateral damage.
  • Timeliness of public data: Sandbox reports, passive DNS records, and dark web postings may lag behind active campaigns. Analysts should treat OSINT as a complement to real-time detection, not a replacement.
  • Legal and ethical boundaries: OSINT must remain within legal limits. Accessing private systems, even inadvertently, or using data obtained through unauthorized means can expose organizations to legal risk.

Practical Workflow: A Phishing-Based Example

Consider a scenario where a financial organization receives a phishing email containing a link to a credential harvesting page. The internal investigation identifies the domain and the hosting IP. At this point, many teams stop, they block the IOCs and close the ticket.

An OSINT-enriched DFIR workflow goes further:

  1. Domain Analysis: The phishing domain was registered three days before the attack. WHOIS history reveals the same registrant email was used for five other domains registered over the past month, all targeting financial institutions.
  2. Infrastructure Mapping: Shodan shows the hosting server runs an uncommon web framework configuration previously observed in similar campaigns. Passive DNS links this IP to two additional domains targeting organizations in the same sector.
  3. Sandbox Correlation: A malware sample submitted to VirusTotal from a different country uses the same command-and-control domain, confirming this is part of a coordinated, multi-target campaign.
  4. Pattern Documentation: The combined findings are mapped to MITRE ATT&CK techniques — phishing (T1566), credential harvesting (T1056), and infrastructure reuse (T1583) — creating a reusable threat profile that can be shared with trusted partners and used to improve detection rules.

This workflow transforms a single incident into actionable threat intelligence that extends far beyond the original alert and benefits the broader security community.

Recommendations for Security Teams

Organizations looking to integrate OSINT into their DFIR practice should consider the following steps:

  • Build OSINT into IR playbooks: Define which external data sources to query at each stage of an investigation, and automate lookups where possible to reduce analyst burden.
  • Use a structured framework: Map findings to MITRE ATT&CK from the beginning of each investigation to enable consistent pattern tracking across incidents.
  • Share intelligence responsibly: Participate in ISACs, trusted sharing communities, or platforms like MISP to contribute findings and benefit from others’ observations.
  • Invest in analyst training: OSINT is a skill. Analysts should be trained not only in the tools but in source evaluation, bias recognition, and legal boundaries.

Conclusion

OSINT and DFIR are not competing disciplines,  they are complementary capabilities that, when combined, significantly improve an organization’s ability to detect, understand, and respond to cyber threats.

By integrating publicly available data into forensic investigations, security teams gain external visibility that internal telemetry alone cannot provide. And by grounding OSINT analysis in real incident data, threat intelligence becomes more accurate, contextual, and actionable.

As threat actors continue to evolve, the organizations that will stay ahead are those that stop treating investigations as isolated events and start mapping the patterns that connect them. The data is out ther,e the question is whether your team is equipped to use it.

About the Author: Ruqaya Osman is a cyber threat intelligence and OSINT analyst with a regional focus on the MENA region, specializing in threat pattern mapping, digital forensics, and incident response.

Forensic-Impact Articles

Investigative Perspective Claude Mythos AI

Investigative Perspective Claude Mythos AI

Guest Blogger: Sheetal Kumari At: MAD Forensics With the new age of AI, which has already arrived , showing continuous growth has introduced the world to a technology that is making advancements towards making human life easier yet also creating new dilemmas with...

The Recipe for the American Dream: Lessons from a 3 AM Workbench

The Recipe for the American Dream: Lessons from a 3 AM Workbench

I was born into a family of immigrants who followed their own dream to the United States to build a business from scratch. When I was a little girl, my mom and I lived with her parents after her divorce. That cozy house was the backdrop for the first years of my life,...