September 29, 2026

Edition 10: Blue Team OSINT Agents, The Future of Human Threat Intel

By Jeremy Banon, Founder & CEO

← Back to The Cyber Health Journal

Devices and digital products are data vacuums. By using them, individuals create an expansive footprint. This data is both re-sold and exposed via breaches, getting into the hands of criminals who use it to compromise accounts and conduct social engineering. Managing this footprint is cumbersome for busy executives. The Dynamic Bio is a blue team personal wiki that tracks what criminals can surmise about an individual executive. It keeps an executive acutely aware of the public/private boundary and issues alerts to remediate new exposures.

Data is Wildfire and Feeds Attacker Pipelines

Anyone with an internet connection and a couple of hours can assemble a targeting-quality file on one of your executives. Consider what happened around Sam Altman: in the days after he was fired as OpenAI's CEO in November 2023, journalists at every major outlet published deep profiles of him. Within a week, they had surfaced his relationship history, his family's involvement in his companies, his real estate footprint, and long-forgotten interviews from a decade earlier, all from purely public sources. News outlets did it because they determined it was in the public interest. A motivated adversary could have done the same, more thoroughly, at any point in the years before the crisis, and no one would have noticed.

Some of that public data is voluntary. Much of it isn't. Elon Musk's private jet broadcasts its position in real time on the FAA's public ADS-B feed, which he cannot opt out of. That's how a nineteen-year-old built @elonjet in 2020: pull the FAA data, filter for tail numbers Musk owned, publish the result. Musk offered the student money to take it down and, when that failed, banned the account outright in 2022 citing his family's safety. Every executive who flies private is in the same position, and the same principle covers property deeds and SEC filings: public infrastructure that names executives whether they want it named or not.

Voluntary disclosure fills in what public infrastructure misses. In December 2015, Mark Zuckerberg and Priscilla Chan published a widely-shared open letter to their newborn daughter Max on Zuckerberg's Facebook page. Since then, all three of their daughters (Max, August, and Aurelia) have been publicly named across a decade of family coverage. If the CEO of the world's largest social media company uses his own platform to name his own child, so does everyone else's spouse.

These are three different exposure vectors, but the output is the same: an executive-shaped file that social engineers, private investigators, and increasingly automated adversaries assemble before every high-quality attack. That's the file behind an executive-impersonation call that convinces a finance director to move money, or a spear-phishing email that opens with a family detail the recipient thought only a handful of people knew.

Management and Remediation Are Too Cumbersome For Executives

Try to monitor the information that exists online about one of your executives and you'll realize you're in a cat and mouse game that's impossible to keep up with. Google Alerts can find a weak majority of pages that reference a person or a search term directly but, in our experience, miss a lot of content. Manually reviewing pages (in addition to being hopelessly time consuming and impractical) can result in crucial information hidden in metadata being overlooked. What these methods do surface is mostly noise, with unrelated hits outnumbering the useful ones many times over. Even if you had the patience to visit every data broker site, whatever picture you assemble this week is outdated by next.

And if you try it for a whole executive suite, the problem gets even harder. Each additional executive multiplies the work rather than adding to it. Families overlap in ways that matter: a data broker page listing an executive's spouse will often name the executive too. Building the capacity internally requires a specialist skillset that most security teams don't have and can't quickly hire for. Additionally, doing this work thoroughly and well often exposes someone on your team to sensitive information about the executive they're protecting that the executive would rather keep private from their organization.

Many of the out-of-the-box online tools currently available to track information about a person or organization are aimed at sales teams and headhunters. They exist to extract and provide maximum useful information about individuals to third parties, not to monitor an individual's online presence through an exhaustive scan of all the locations on the internet where information about them lives.

These are the problems the Dynamic Bio was built to solve.

We Scan, Deliver Alerts Based on Net New Info and Concrete Remediation Steps

The Dynamic Bio itself is the engineering, not the product. It runs in the background, maintaining a running record of every member's public exposure (though it can be accessed and viewed by members). What actually lands in your team's inbox is smaller and more useful: an alert, generated only when something changes that running record in a way that matters, paired with a specific next step.

Monitoring services tend to deliver a firehose of raw hits and leave the interpretation to the reader. Our approach is different: everything the pipeline finds is captured silently in the record; only when a change is both new (not already indexed) and materially exposing (enough to move the member's Cyber Health Score) does it become an alert to your team.

A typical alert reads like this: the PTA at the school of the member's child posts its new leadership committee to the school's public Facebook page, complete with each committee member's personal email and cell phone number. The member's spouse chairs the committee. The spouse's personal contact details, along with confirmation of the child's specific school, were not previously in the Dynamic Bio. Within hours of the post going live, our pipeline surfaces it and extracts the new facts. The member receives an alert with the source link and an updated Cyber Health Score, along with a proposed Cyber Health Care Plan item as a next step. In this case, we draft a takedown request to the PTA and the school's administrator, and route it to the member for one-click approval before it goes out.

Suggested actions come in two shapes. Some are automations we can run on the member's behalf with a single click. Others are content takedowns handled directly by our team. Every alert is always paired with an actionable next step.

Every mention runs the same pipeline before it moves a Cyber Health Score

The record itself is a structured, living profile drawn from the entire public record of an individual member. The closest analog is the executive medical record. A physician assembles a picture of a patient's health from labs, imaging, family history, and physical exams to catch what would otherwise go undetected, and we build the same kind of picture of a member's public exposure for the same reason.

Every day we sweep public sources (Google Alerts, Exa Search and other feeds) for new material referencing a member. Each new mention runs through our proprietary classifier that uses a combination of LLM queries and plaintext searches to decide whether it's actually about the right person. Once confirmed, mentions are handed to our extraction tool, which pulls out structured information. In some cases, that includes thousands of characters of detail-rich page content from sites that don't load in a normal browser. A deduplication and merging pass reconciles those facts against everything we've ever seen for that member and folds them into their current bio. Nothing is discarded silently: extractions carry their provenance, and every merge is auditable.

The Dynamic Bio monitors twelve categories per member, from name variants to life events. Every fact is annotated with the specific source or sources that surfaced it, so a reviewer can always trace an item back to the articles, filings, or posts that revealed it.  Each update is evaluated automatically against a member's Cyber Health Score. When a change would materially move that score, an internal alert fires so our team can step in to provide recommendations or correct misinformation.

A completed Dynamic Bio is sensitive data, and we treat it that way

The dynamic bio is built entirely from information that already exists in full public view: news articles, corporate filings, podcast interviews and public social media posts. But synthesizing all of this information into a structured profile creates something that individual fragments do not: a comprehensive view of an individual's attack surface. We therefore treat each completed dynamic bio as private, sensitive data and take steps to make sure it stays secure.

Each bio is scoped strictly to the member it describes and the small number of Cyber Health Company reviewers whose job requires access. All data is encrypted in transit and at rest, and we routinely reevaluate our cloud service providers and preferred tech services to ensure they live up to our strict standards for privacy and security.

Because prompt injection to LLMs represents a small but nonzero risk, we rely on publicly accessible LLM endpoints only for the purpose of evaluating and extracting information from a single mention at a time. Because the work of deduping information and structuring the completed dynamic bio also relies on LLM calls, we've set up our own physical infrastructure in-house in order to run smaller, open-source models ourselves, ensuring that sensitive information stays firmly within our digital ecosystem and never passes through anything accessible to third parties.

We will retain a bio only as long as members are actively enrolled and will honor any deletion requests promptly. Our position is simple: if a piece of information would help someone target a member, it should help us defend them first, and should live nowhere else.

The internet keeps changing, and so does our pipeline

The internet is always changing: as websites take new steps to prevent their content from being extracted, as organizations do everything in their power to keep their data inaccessible to others while finding as much as they can for themselves, we keep improving our processes to ensure that anytime information about a member appears on the internet, we find it first.

We’re also continuously expanding our scope: right now, our monitoring pipeline focuses on named mentions of our members.  We’re expanding this to track down harder to find information by searching via common misspellings, facial recognition, social media handles we find and other associations and identifying information. Right now, our OSINT researchers routinely find information about our members that casual sleuths can't: social security numbers, detailed contact information, etc. Our ultimate goal is to expand our automated pipeline to find everything that advanced researches are capable of tracking down.

The Dynamic Bio, in its fully realized form, will be a thorough report of everything about a member that exists publicly online, organized into a clear and convenient schema. It's a defender's-eye view of the target every member is to an attacker, and an inventory we build so that our team can shrink it.

‍

Subscribe

Oops! Something went wrong while submitting the form.