OSINT Threat Intelligence Services

OSINT threat intelligence is only useful if it changes what you do on Monday morning. We turn open-source signals about attackers, campaigns and exposure into short, specific advice for your security team and your board.

  • Threat actors and campaigns
  • Phishing and impersonation
  • Credentials and leaks
  • Supply chain and vulnerabilities
Short answer

OSINT threat intelligence is cyber threat intelligence built from open and commercially available sources: criminal forums and channels, leak sites, technical data, vulnerability disclosures, social media and research. It tells you who is likely to target you, how, and what to do about it. OSINT-S delivers it as an initial threat assessment, ongoing alerts and regular briefings, scoped to your organization and sector.

What Is OSINT Threat Intelligence?

Evidence-based knowledge about threats to your organization, collected from open sources and analyzed so you can decide what to defend first.

The US intelligence community defines OSINT as intelligence derived exclusively from publicly or commercially available information that addresses specific requirements (IC OSINT Strategy 2024–2026). In cyber security, those requirements are questions such as: who targets companies like ours, which of our systems are exposed, and which vulnerabilities are being exploited right now?

Much of the raw material is public. ENISA, the EU cyber security agency, builds its annual threat landscape on open sources together with information shared by member states (ENISA Threat Landscape 2026). The value an analyst adds is relevance: separating the threats that matter to you from the thousands that do not.

Why Threat Intelligence Matters in 2026

Attackers are exploiting vulnerabilities, suppliers and stolen credentials faster than most teams can patch, and most security leaders still struggle to turn intelligence into decisions.

  • Exploitation of vulnerabilities was the top way in, at 31% of breaches, and third parties were involved in 48% (Verizon DBIR 2026).
  • ENISA recorded 8,257 incidents in 2025; where the intrusion vector was known, vulnerability exploitation accounted for 60.4% of unauthorized access (ENISA 2026).
  • One in four malicious breaches used AI, and those breaches cost $6 million on average (IBM 2026).
  • 91% of CISOs say they value threat intelligence, but only 26% say it drives their decisions (SANS 2026 CTI Survey).

That last gap is the one we work on. Intelligence that is not tied to your assets, your suppliers and your decisions becomes another feed nobody reads.

What Our OSINT Threat Intelligence Covers

Six areas, following Molfar's cyber threat intelligence practice.

Actors

Threat actors and campaigns

Groups targeting your sector, region or technology, their methods, and campaigns that are active now.

Dark web

Dark web and criminal channels

Mentions of your organization, assets and employees on forums, markets, leak sites and channels.

Dark web monitoring →
Exposure

Credentials and leaks

Compromised accounts, stealer logs, session cookies, API keys and leaked documents linked to you.

Fraud

Phishing and impersonation

Look-alike domains, fake login pages, fraudulent social accounts and executive impersonation.

Third parties

Supply-chain risk

Breaches, leaks and exposure at the suppliers and partners that hold your data or access.

Vulnerabilities

Exploited vulnerabilities

Which vulnerabilities in your technology stack are being exploited or discussed, so you can patch in the right order.

Scope areas as published on Molfar's cyber threat intelligence services page.

Strategic, Operational and Tactical Threat Intelligence

Three levels for three audiences: the board, the security leadership and the people who defend systems day to day.

LevelAudienceQuestions answeredTypical output
StrategicBoard, executives, risk committeeWhich threats could hurt the business, and how is the landscape changing?Quarterly briefing, threat landscape report
OperationalCISO, security managersWho is likely to target us, and with which campaigns?Actor profiles, campaign alerts, priorities
TacticalSOC, IT and fraud teamsWhat should we block, patch or reset today?Verified alerts with specific actions

How an OSINT Threat Intelligence Engagement Works

Requirements first, then a baseline assessment, then ongoing alerts and briefings that are reviewed against your changing priorities.

  1. Set intelligence requirementsWe agree the questions that matter: your crown-jewel assets, your sector, your suppliers, your executives and your technology stack.
  2. Baseline threat assessmentA first report on your current exposure and the actors and campaigns most relevant to you.
  3. CollectionContinuous collection from criminal sources, leak sites, technical data, vulnerability disclosures and research.
  4. Analysis and verificationAnalysts check what is real and relevant, and connect it to your assets and decisions.
  5. Alerts and briefingsVerified alerts with recommended actions, plus regular briefings for security leadership and, if you want, the board.
  6. ReviewRequirements are revisited as your business, suppliers and threats change.

Cyber Security Assessment: Your Exposure Seen From Outside

A one-off review of how your organization looks to an attacker: attack surface, leaked credentials and how easily staff can be socially engineered.

Many clients start with an assessment rather than an ongoing service. Molfar's cyber security assessment covers the attack surface, leaked credentials and controlled social-engineering testing (risk and security). A focused review may take several working days. The result is a prioritized list of fixes and a baseline for any monitoring that follows.

Threat Intelligence Platform or Managed OSINT Service?

Platforms suit large security teams with analysts to use them; a managed service suits organizations that need the answers without building a CTI team.

OptionPublished or reported priceBest for
Recorded Future$281,250 for 36 months, threat intelligence module, two users (AWS); buyer median $72,703 a year (Vendr)Large SOCs and CTI teams
Flashpoint Ignite$100,000 a year for cyber threat intelligence (AWS)Teams focused on criminal communities
SOCRadar CTI$14,750 a year, discounted to $11,950 (SOCRadar)Smaller teams wanting a platform
OSINT-S managed threat intelligenceQuoted on scopeOrganizations without a dedicated CTI team, or teams that need analyst support

Recorded Future's 2025 survey found that 91% of organizations planned to increase threat intelligence spending in 2026 (Recorded Future). The question is not only how much to spend, but whether you have the people to use what you buy. Compare vendors in our ranking of the best OSINT companies.

Who Delivers Our Threat Intelligence?

Molfar's cyber team, led by Global Head of Cyber Maksym Zrazhevskyi, working with the company's investigators and analysts.

Threat intelligence is one of the OSINT services run by Molfar's teams. It sits in the risk management practice, next to cyber security assessments, sanctions screening and adverse media work, so a cyber finding can be followed into an investigation of the people or companies behind it. Our work supports your security operations; it does not replace your internal security ownership or a managed security provider.

Get a Baseline Threat Assessment

Tell us your sector, key assets and suppliers. We start with a baseline of who is likely to target you and what is already exposed.

OSINT Threat Intelligence FAQ

What is OSINT threat intelligence?

OSINT threat intelligence is cyber threat intelligence built from open and commercially available sources, such as criminal forums, leak sites, technical data and vulnerability disclosures, and analyzed to tell you who may target you and what to do.

What is the difference between OSINT and threat intelligence?

OSINT is a source discipline: intelligence from publicly or commercially available information. Threat intelligence is a purpose: understanding threats to an organization. Most threat intelligence draws heavily on OSINT, alongside technical telemetry and shared data.

What are OSINT threat intelligence feeds?

OSINT feeds are streams of indicators and reports collected from open sources, such as malicious domains, IP addresses and leaked credentials. They are useful when someone filters them for relevance; unfiltered feeds often create more noise than value.

What does CTI stand for?

CTI stands for cyber threat intelligence: evidence-based knowledge about cyber threats that helps an organization decide how to defend itself.

Do we need a threat intelligence platform?

Only if you have analysts to use it. Platforms such as Recorded Future and Flashpoint are powerful but cost tens to hundreds of thousands of dollars a year. A managed service gives smaller teams the answers without the overhead.

How quickly can you start?

A baseline assessment can usually begin as soon as the requirements are agreed. A focused cyber security review may take several working days.

Do you share indicators we can load into our tools?

Where relevant, alerts include the technical details your team needs to act, such as domains, accounts or affected systems, in a format agreed at the start.

Is OSINT threat intelligence legal?

Yes. We collect from open and commercially available sources, do not hack or access systems without authorization, and handle personal data in leaks proportionately.