Case Study - Digital Footprint Discovery (Map Before You Test)
We found the phishing domain 3 days before the attackers used it. Takedown took 6 hours.
Client Context
Large public institution — 30+ official domains, 200+ work units publishing their own sites, citizen e-services. Rising phishing using look-alike domains + leaked employee creds.
Challenge
Security testing kept missing assets because no one knew the full digital footprint. Requirement: identify all organization-linked domains, subdomains, IPs, and technologies before any testing, plus early phishing detection.
Scope - Snipeyes Digital Footprint Discovery
- Organization-linked enumeration: domains, subdomains, IPs, netblocks, ASNs, cloud tenants, technologies (CMS, frameworks, third-party scripts)
- Look-alike / typo-squat monitoring + certificate transparency watch
- Credential & document leak correlation (public breaches, exposed docs)
- Pre-test scoping pack: which footprint entries enter vulnerability scanning vs monitor-only
Key Findings (redacted)
- 214 official + 89 unofficial linked hosts; 12 typo-squat domains registered in 30 days (2 already serving phishing kits)
- Technology debt: 27 sites on EOL CMS, 11 with exposed
.git/ backup files - Leak: 1,400+ employee emails in public breach corpora, 3 with reused admin passwords
- Phishing domain reported → takedown in 6 hours via registrar + Kominfo channel
Outcome
- Single footprint registry adopted as pre-test gate: no testing starts without footprint sign-off
- Phishing reports dropped 70% after takedown SOP + citizen advisory banner
- Quarterly footprint delta now feeds BSSN-style compliance evidence pack
Relevance for you: If your brand is phishable and your units publish freely — map the footprint first.