Target OSINT

Enumerate people and probe account-existence oracles from Attacks → Phishing → Target OSINT.

Attacks → Phishing → Target OSINT is the Praetorian-only tab for tenant-wide people research. Connect GitHub or Microsoft Teams, run a collection, and review the roster. This guide walks you through opening the tab, storing a credential, and launching a run.

This is not Integrations → SaaS Security (secrets scanning) and not Integrations → Workplace Messaging → Microsoft Teams (risk notifications).

Open Target OSINT

  1. Go to Attacks → Phishing.
  2. Open the Target OSINT sub-tab.

The heading is Tenant-wide target research. The count is all collected people for the tenant you are viewing.

Selecting people here does not add recipients to a campaign draft. Add targets manually in the campaign builder.

Connect an integration

  1. Click Integrations.
  2. Choose GitHub or Microsoft Teams.
  3. Click Continue.

Impersonate the customer tenant before connecting or removing a credential.

GitHub

Paste a classic personal access token with the repo scope into Personal access token. Fine-grained tokens are not supported. Guard uses the token to map emails to GitHub accounts. Click Continue, then test and save.

Microsoft Teams

  1. Click Start device sign-in.
  2. Open https://microsoft.com/devicelogin and enter the code Guard shows.
  3. Click Continue, then test and save.

Guard stores a per-tenant token from Microsoft Entra's device-code flow. No password is retained. Re-authenticate only if the token is revoked or can no longer refresh.

The Microsoft Teams oracle in a collection run stays locked until this connection exists.

Start a collection run

  1. Click New collection run.
  2. Identity anchor — enter a Known-valid email at the target org, pick the email format (default first.last@), and confirm the mailbox is real and active.
  3. Passive sources — toggle Hunter, Lusha, Apollo.io, and Dehashed. A source that shows NOT CONFIGURED needs a key in Customer Management → Operations. Lusha and Apollo consume paid credits per contact revealed.
  4. LinkedIn — coming soon. Nothing on this step contributes to the run.
  5. Account Enumeration — leave Statistical enumeration on to generate candidate addresses and probe oracles, or turn it off for passive collection only. Open Advanced to toggle Google Workspace, Microsoft 365, and Microsoft Teams.
  6. Review the selection. Click Launch collection.

Active probes are observable: they land in the tenant's sign-in logs. Google Workspace and Microsoft 365 do not need a stored integration. Microsoft Teams does.

Results stream into the roster. Search by name, email, title, or department. Export downloads the filtered roster as CSV.

Support

If the Target OSINT tab is missing, you are not on a Praetorian operator account. If a run returns nothing, reach out to support@praetorian.com.