Case Study - Digital Footprint Discovery (Map Before You Test)

We found the phishing domain 3 days before the attackers used it. Takedown took 6 hours.

ILLUSTRATION — FOOTPRINT LAYERS
🏛️
DOMAINS
+ typo-squats
🌿
SUBDOMAINS
+ cert logs
📡
IPs / ASN
+ history
🧩
TECH STACK
CMS, JS, headers

Client Context

Large public institution — 30+ official domains, 200+ work units publishing their own sites, citizen e-services. Rising phishing using look-alike domains + leaked employee creds.

Challenge

Security testing kept missing assets because no one knew the full digital footprint. Requirement: identify all organization-linked domains, subdomains, IPs, and technologies before any testing, plus early phishing detection.

Scope - Snipeyes Digital Footprint Discovery

  • Organization-linked enumeration: domains, subdomains, IPs, netblocks, ASNs, cloud tenants, technologies (CMS, frameworks, third-party scripts)
  • Look-alike / typo-squat monitoring + certificate transparency watch
  • Credential & document leak correlation (public breaches, exposed docs)
  • Pre-test scoping pack: which footprint entries enter vulnerability scanning vs monitor-only

Key Findings (redacted)

  • 214 official + 89 unofficial linked hosts; 12 typo-squat domains registered in 30 days (2 already serving phishing kits)
  • Technology debt: 27 sites on EOL CMS, 11 with exposed .git / backup files
  • Leak: 1,400+ employee emails in public breach corpora, 3 with reused admin passwords
  • Phishing domain reported → takedown in 6 hours via registrar + Kominfo channel

Outcome

  • Single footprint registry adopted as pre-test gate: no testing starts without footprint sign-off
  • Phishing reports dropped 70% after takedown SOP + citizen advisory banner
  • Quarterly footprint delta now feeds BSSN-style compliance evidence pack

Relevance for you: If your brand is phishable and your units publish freely — map the footprint first.