
Attacker Recon 2026: AI, OSINT and German Companies' Attack Surface
How AI simplifies OSINT work on the external attack surface: from attribution to shadow IT. And where it reaches its limits.
Topic
When & Where
Details
Format:
Technology lecture
Language:
German
Session description
Speaker: Frank Tiemann
Mapping a company's attack surface from the outside has so far been mostly manual craft: attributing domains and IP ranges, cross-checking certificates and registry data, telling subsidiaries and service providers apart, assessing reachable services, discarding false attributions. The technical scan is rarely the hard part – attribution and assessment are. And this is exactly where AI is changing OSINT work in a tangible way.
The talk takes the attacker's perspective: what is visible of German companies on the internet, without a single packet reaching an internal system? The focus is not on concepts but on results – shown using screenshots from our dashboards and analyses.
Two areas where AI makes technical reconnaissance concretely easier:
< ...
