Intelligence That Gets Reused, Not Filed Away
A company is not just a domain. A person is not just an email. Pentesterra gathers company context, technology, exposed attack surface, and people intelligence into one reusable profile - passively - and feeds it into phishing, pentest, and reporting.
What the module does
Company-level intelligence
For a target organization Pentesterra builds one profile: what the company does, the products it ships, the technologies it likely runs, the infrastructure and attack surface it exposes, and its business and regulatory context. Passive and semi-passive collection - no active scanning required.
- →Business context, products, likely tech stack
- →Domains, subdomains, CIDR ranges, cloud footprint
- →Public signals: leaks, dark-web mentions, threat-actor interest
- →One deduplicated company record, updated on each run
People intelligence
Who the people are, what roles they hold, and the public professional context around them - down to a per-person deep profile on demand. This is what makes a social-engineering assessment realistic instead of a guess.
- →Roles, seniority, org structure
- →Professional context, interests, public footprint
- →Emails and identity data tied to the company record
- →On-demand deep profiling for named high-value individuals
Reusable, not a dead-end report
OSINT is gathered so it can be reused. The same intelligence layer feeds phishing scenario design, pentest prioritization, social-engineering validation, and the 'why this matters' section of the final report.
- →Feeds phishing and social-engineering simulation
- →Informs pentest scope, likely tech, and attack paths
- →Adds business-impact context to findings
- →Shared across modules, not siloed per assessment
Discovery and monitoring at scale
Add companies in bulk, discover related entities, and keep them monitored. When the knowledge base updates, added companies are re-checked automatically, and you get alerts on new exposure.
- →Bulk upload and company discovery
- →Near-real-time re-checks as intelligence updates
- →Monitoring and alerting for tracked organizations
- →Suited to supplier, portfolio, and M&A due-diligence use
FAQ
Is Pentesterra OSINT passive?
Collection is passive and semi-passive - public sources, certificate transparency, DNS, leak and dark-web data, and professional context. It does not require active scanning or any authenticated access to the target.
What is 'deep person profiling'?
An on-demand profile for a single named individual: role, seniority, professional context, public footprint, and identity data, assembled into one record. It is triggered per person rather than bundled into a whole-company scan.
How does OSINT connect to the rest of the platform?
It is the shared intelligence layer. Phishing simulation uses it to build context-aware scenarios, the pentest modules use it to prioritize and understand likely technology, and reporting uses it to explain business impact.
Can I use this to assess suppliers or acquisition targets?
Yes. You can upload companies in bulk, run passive checks quickly, and keep them monitored - which fits third-party risk, portfolio monitoring, and pre-acquisition due diligence without needing permission to scan.