company-osint

Compare original and translation side by side

🇺🇸

Original

English
🇨🇳

Translation

Chinese

Company OSINT

企业OSINT

Profile an organization for due diligence, M&A, vendor risk, fraud, or competitive intelligence. Input: a company or brand name, or a domain.
为尽职调查、并购、供应商风险评估、欺诈排查或竞争情报需求,对组织进行画像分析。输入信息:公司或品牌名称,或域名。

Step 1 — Authorized scope

步骤1 —— 授权范围

Read ../../ETHICS.md. Corporate research on public records is broadly lawful; stay passive toward the company's private systems. Done when scope is noted.
阅读../../ETHICS.md。基于公开记录开展企业研究基本合法;请勿主动触碰公司的私有系统。完成标志:确认范围。

Step 2 — Establish the legal entity

步骤2 —— 确定法律实体

Resolve the brand to registered entities — the primary selector. Use
corporate-registries
(Companies House, SEC EDGAR, OpenCorporates, state registries) to get: legal name(s), registration number, incorporation date and jurisdiction, status, addresses, officers, and shareholders. Done when at least one canonical legal entity is identified with its registry ID.
将品牌名称关联至注册实体——这是核心检索对象。使用
corporate-registries
(英国公司注册处、美国SEC EDGAR、OpenCorporates、各州注册机构)获取:法定名称、注册号、成立日期及管辖区域、状态、地址、管理人员和股东信息。完成标志:至少识别出一个带注册ID的标准法律实体。

Step 3 — People

步骤3 —— 人员信息

Pivot from officers, directors, and key staff to individuals. Run
person-osint
on decision-makers; map staff and roles from LinkedIn, the team page (via
wayback-archives
for departed staff), and conference/press mentions. Done when leadership and relevant staff are listed with sources.
从管理人员、董事及核心员工拓展到具体个人。对决策者执行
person-osint
;通过LinkedIn、团队页面(若员工已离职,可借助
wayback-archives
获取)、会议/新闻提及内容梳理员工及职位信息。完成标志:列出领导层及相关员工信息并标注来源。

Step 4 — Digital infrastructure

步骤4 —— 数字基础设施

Pivot from the primary domain: run
domain-osint
,
whois-dns-recon
,
certificate-transparency
(subdomains/acquired brands), and
shodan-censys-recon
(exposed hosts and tech stack). Check
github-git-recon
for org repos and leaked secrets. Done when domains, subdomains, and exposed services are enumerated.
从主域名展开:执行
domain-osint
whois-dns-recon
certificate-transparency
(子域名/收购的品牌)以及
shodan-censys-recon
(暴露的主机和技术栈)。通过
github-git-recon
检查组织仓库及泄露的机密信息。完成标志:枚举所有域名、子域名及暴露的服务。

Step 5 — Footprint & risk

步骤5 —— 业务范围与风险

  • Financials/filings — SEC/regulatory filings, annual reports.
  • Litigation & sanctions — court records, OFAC/sanctions and PEP lists, adverse-media screening.
  • Reputation — news, reviews, breach exposure via
    breach-data-analysis
    .
  • Relationships — subsidiaries, parents, and shared officers across registries reveal group structure.
Done when legal, financial, infrastructure, and reputational dimensions each have sourced findings or a documented gap.
  • 财务/备案文件——SEC/监管备案、年度报告。
  • 诉讼与制裁——法院记录、OFAC/制裁名单及政治公众人物(PEP)名单、负面媒体筛查。
  • 声誉——新闻、评论、通过
    breach-data-analysis
    排查数据泄露情况。
  • 关联关系——子公司、母公司,以及跨注册机构的共享管理人员信息,可揭示集团架构。
完成标志:法律、财务、基础设施及声誉维度均有带来源的调查结果,或记录相关空白。

Step 6 — Report

步骤6 —— 生成报告

Run
osint-report
. Present an entity chart (parent → subsidiaries → key people), then findings by dimension, each claim cited and dated.
执行
osint-report
。呈现实体关系图(母公司→子公司→核心人员),然后按维度展示调查结果,每项结论均需标注来源及日期。