• SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Call us today! 844-OCD-TECH

Find our Location
OCD TechOCD Tech
  • SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us
Open Source Intelligence

Won’t You Be My Neighbor?

June 14, 2022 Posted by Emily Connolly IT Security

Conducting Old School OSINT

A man bumps into you in a crowded café and almost immediately his eyes light up. You raise your eyebrows as he says your name, before telling you he used to be your neighbor back when you were a child, living in the house next door to yours. He remembers when your father built the addition on the house and the fact that you won an award for community service in third grade. He even remembers the year you moved, when your parents sold the house shortly after the recession.

You’ve never seen this man in your life, but he seems to know you. He asks you how work is going, and you tell him about your job working security at the bank, thinking nothing of it. After all, you must know him, right? How else could he know so much about you?

In a previous blog post, we discussed the history of open-source intelligence (OSINT) and how this field can be split into two lanes: old school OSINT and new school OSINT. In this context, old school OSINT refers to information and intelligence that can be easily accessed and collected before the digital age, such as public records, newspapers, and broadcasts.

Before the internet, collecting information through open-source intelligence was much trickier. It required tenacity and parsing through hours of extraneous details to find the one name, location, or date one was looking for. It could even require travel, such as searching town records, only held in a town hall on the other side of the country. Things like newspapers, land deeds, and broadcasts were allowed to be accessed by any member of the public, but that did not mean they always could be easily accessed.

Now, however, with the internet, the process has been streamlined. In Massachusetts, for example, an online portal gives researchers a way to request access to a subject’s birth, death, and marriage certificates, with only a few restrictions for subjects born to unwed parents. The use of sites such as netronline.com has also streamlined the process of accessing public records, property data, and environmental records.

In the case of your would-be neighbor, he found your parents’ property records online, combing through data on their mortgage and the deed’s history. He even searched through old newspaper archives stored carefully online by your public library to find the small article about your elementary school award.

All of this, so that he could get you talking about security at your bank. After all, you’d be more willing to open up to an old neighbor.

As discussed in the previous blog post , we reviewed how limiting the number of public records available on you or your organization can be difficult, as often these same records exist for legal and transparency purposes. It is important to remember that just because someone knows where you live or where you work doesn’t mean they’re a legitimate party. Whether it’s through email, phone, or in person, you must verify these individuals as you would anyone else , even if they seem to know everything about you; otherwise they could be phishing.

Share
1
Avatar photo

About Emily Connolly

Emily is an IT Security Analyst at OCD Tech, joining the team in 2020. Previously, she had a year of experience in cybersecurity training of students and faculty at the University of Vermont’s information security office, as well as experience in incident response and network monitoring.

You also might be interested in

NCSAM – Week 2 – Cyber from the Break Room to the Board Room

Oct 12, 2016

Week 2: October 10-14, 2016 – Topic: Cyber from the[...]

OCD TECH XSS HUNTING USING GOOGLE DORKING

XSS Hunting using Google Dorking

Jun 22, 2023

Summary Generally, vulnerability scanning work is done by having a[...]

The Most Vulnerable – Smartphones

Jul 13, 2016

Pokemon Go is just the latest example in a growing[...]

Find us on

Contact Us

We're not around right now. But you can send us an email and we'll get back to you, asap.

Send Message
OCD Tech logo Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

  • OCD Tech
  • 25 BHOP, Suite 407, Braintree MA, 02184
  • 844-623-8324
  • https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®

IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review

IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO

Industries

  • Financial Services
  • Government
  • Enterprise
  • Auto Dealerships

© 2025 — OCD Tech: IT Audit - Cybersecurity - IT Assurance

  • OCD Tech
  • About Us
  • Contact Us
Prev Next