Threat actors and campaigns
Groups targeting your sector, region or technology, their methods, and campaigns that are active now.
OSINT threat intelligence is only useful if it changes what you do on Monday morning. We turn open-source signals about attackers, campaigns and exposure into short, specific advice for your security team and your board.
OSINT threat intelligence is cyber threat intelligence built from open and commercially available sources: criminal forums and channels, leak sites, technical data, vulnerability disclosures, social media and research. It tells you who is likely to target you, how, and what to do about it. OSINT-S delivers it as an initial threat assessment, ongoing alerts and regular briefings, scoped to your organization and sector.
Evidence-based knowledge about threats to your organization, collected from open sources and analyzed so you can decide what to defend first.
The US intelligence community defines OSINT as intelligence derived exclusively from publicly or commercially available information that addresses specific requirements (IC OSINT Strategy 2024–2026). In cyber security, those requirements are questions such as: who targets companies like ours, which of our systems are exposed, and which vulnerabilities are being exploited right now?
Much of the raw material is public. ENISA, the EU cyber security agency, builds its annual threat landscape on open sources together with information shared by member states (ENISA Threat Landscape 2026). The value an analyst adds is relevance: separating the threats that matter to you from the thousands that do not.
Attackers are exploiting vulnerabilities, suppliers and stolen credentials faster than most teams can patch, and most security leaders still struggle to turn intelligence into decisions.
That last gap is the one we work on. Intelligence that is not tied to your assets, your suppliers and your decisions becomes another feed nobody reads.
Six areas, following Molfar's cyber threat intelligence practice.
Groups targeting your sector, region or technology, their methods, and campaigns that are active now.
Mentions of your organization, assets and employees on forums, markets, leak sites and channels.
Dark web monitoring →Compromised accounts, stealer logs, session cookies, API keys and leaked documents linked to you.
Look-alike domains, fake login pages, fraudulent social accounts and executive impersonation.
Breaches, leaks and exposure at the suppliers and partners that hold your data or access.
Which vulnerabilities in your technology stack are being exploited or discussed, so you can patch in the right order.
Scope areas as published on Molfar's cyber threat intelligence services page.
Three levels for three audiences: the board, the security leadership and the people who defend systems day to day.
| Level | Audience | Questions answered | Typical output |
|---|---|---|---|
| Strategic | Board, executives, risk committee | Which threats could hurt the business, and how is the landscape changing? | Quarterly briefing, threat landscape report |
| Operational | CISO, security managers | Who is likely to target us, and with which campaigns? | Actor profiles, campaign alerts, priorities |
| Tactical | SOC, IT and fraud teams | What should we block, patch or reset today? | Verified alerts with specific actions |
Requirements first, then a baseline assessment, then ongoing alerts and briefings that are reviewed against your changing priorities.
A one-off review of how your organization looks to an attacker: attack surface, leaked credentials and how easily staff can be socially engineered.
Many clients start with an assessment rather than an ongoing service. Molfar's cyber security assessment covers the attack surface, leaked credentials and controlled social-engineering testing (risk and security). A focused review may take several working days. The result is a prioritized list of fixes and a baseline for any monitoring that follows.
Platforms suit large security teams with analysts to use them; a managed service suits organizations that need the answers without building a CTI team.
| Option | Published or reported price | Best for |
|---|---|---|
| Recorded Future | $281,250 for 36 months, threat intelligence module, two users (AWS); buyer median $72,703 a year (Vendr) | Large SOCs and CTI teams |
| Flashpoint Ignite | $100,000 a year for cyber threat intelligence (AWS) | Teams focused on criminal communities |
| SOCRadar CTI | $14,750 a year, discounted to $11,950 (SOCRadar) | Smaller teams wanting a platform |
| OSINT-S managed threat intelligence | Quoted on scope | Organizations without a dedicated CTI team, or teams that need analyst support |
Recorded Future's 2025 survey found that 91% of organizations planned to increase threat intelligence spending in 2026 (Recorded Future). The question is not only how much to spend, but whether you have the people to use what you buy. Compare vendors in our ranking of the best OSINT companies.
Molfar's cyber team, led by Global Head of Cyber Maksym Zrazhevskyi, working with the company's investigators and analysts.
Threat intelligence is one of the OSINT services run by Molfar's teams. It sits in the risk management practice, next to cyber security assessments, sanctions screening and adverse media work, so a cyber finding can be followed into an investigation of the people or companies behind it. Our work supports your security operations; it does not replace your internal security ownership or a managed security provider.
Tell us your sector, key assets and suppliers. We start with a baseline of who is likely to target you and what is already exposed.
OSINT threat intelligence is cyber threat intelligence built from open and commercially available sources, such as criminal forums, leak sites, technical data and vulnerability disclosures, and analyzed to tell you who may target you and what to do.
OSINT is a source discipline: intelligence from publicly or commercially available information. Threat intelligence is a purpose: understanding threats to an organization. Most threat intelligence draws heavily on OSINT, alongside technical telemetry and shared data.
OSINT feeds are streams of indicators and reports collected from open sources, such as malicious domains, IP addresses and leaked credentials. They are useful when someone filters them for relevance; unfiltered feeds often create more noise than value.
CTI stands for cyber threat intelligence: evidence-based knowledge about cyber threats that helps an organization decide how to defend itself.
Only if you have analysts to use it. Platforms such as Recorded Future and Flashpoint are powerful but cost tens to hundreds of thousands of dollars a year. A managed service gives smaller teams the answers without the overhead.
A baseline assessment can usually begin as soon as the requirements are agreed. A focused cyber security review may take several working days.
Where relevant, alerts include the technical details your team needs to act, such as domains, accounts or affected systems, in a format agreed at the start.
Yes. We collect from open and commercially available sources, do not hack or access systems without authorization, and handle personal data in leaks proportionately.
Sources checked 6 October 2026. OSINT-S is operated by Molfar Intelligence, a trading name of Molfar Limited (Companies House 13558891). Figures from Molfar are company statements, not independently audited.