offensive-osint

Featured

Comprehensive OSINT methodology skill for offensive security, red team intelligence gathering, and bug bounty reconnaissance. Covers domain recon, email harvesting, social media profiling, GitHub/code leaks, Shodan/Censys enumeration, breach data lookup, employee profiling, infrastructure mapping, cryptocurrency tracing, geospatial intelligence, and AI-assisted analysis workflows. Use when performing reconnaissance against a target domain or organization, investigating a person or entity, tracing cryptocurrency flows, geolocating images or events, or building an attack-surface map.

DevOps & Infrastructure 719 stars 91 forks Updated 1 months ago MIT

Install

View on GitHub

Quality Score: 87/100

Stars 20%
95
Recency 20%
75
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Offensive OSINT Methodology ## Workflow 1. Define target scope (domain, org, person, crypto address, or geo subject) 2. Select applicable categories below based on scope 3. Work top-down within each category; pivot on discovered artifacts 4. Archive every key artifact: URL + timestamp + screenshot (PNG) + hash (SHA-256) 5. Log findings in JSONL with a `run_id` and tool versions for reproducibility 6. Suggest next steps based on what each tool returns --- ## General OSINT - [Bookmarks](https://tools.myosint.training/) — Comprehensive OSINT bookmarks - [OSINT Framework](https://osintframework.com/) — Tool/resource directory - [IntelTechniques Tools](https://inteltechniques.com/tools/) — Suite of investigative tools - [Bellingcat Toolkit](https://www.bellingcat.com/resources/2024/09/24/bellingcat-online-investigations-toolkit/) — Investigative journalism tools - [CyberSudo OSINT Toolkit](https://docs.google.com/spreadsheets/d/1EC0sKA_W9znzsxUt0wye9UYtyATXw5m8) — OSINT websites list - [Google Dorks](https://dorksearch.com/) — Efficient Google searching - [Distributed Denial of Secrets](https://ddosecrets.com/) — Leaked data - [Country-Specific Resources](https://digitaldigging.org/osint/) — Country-targeted OSINT ### Search Engines | Tool | Notes | |------|-------| | [Carrot2](https://search.carrot2.org/#/search/web) | Clusters results by topic | | [etools](https://www.etools.ch/) | Metasearch engine | | [Kagi](https://kagi.com/) | Privacy-first, non-personalized results...

Details

Author
0xwilliamortiz
Repository
0xwilliamortiz/claude-red
Created
1 months ago
Last Updated
1 months ago
Language
JavaScript
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

DevOps & Infrastructure Featured

offensive-osint

Comprehensive OSINT methodology skill for offensive security, red team intelligence gathering, and bug bounty reconnaissance. Covers domain recon, email harvesting, social media profiling, GitHub/code leaks, Shodan/Censys enumeration, breach data lookup, employee profiling, infrastructure mapping, cryptocurrency tracing, geospatial intelligence, and AI-assisted analysis workflows. Use when performing reconnaissance against a target domain or organization, investigating a person or entity, tracing cryptocurrency flows, geolocating images or events, or building an attack-surface map.

3,234 Updated 1 weeks ago
SnailSploit
AI & Automation Listed

osint

Open Source Intelligence expert methodology for pre-engagement reconnaissance. Covers target profiling, email harvesting, subdomain enumeration, technology fingerprinting, employee reconnaissance, and dark web monitoring.

1 Updated 3 weeks ago
sunilgentyala
DevOps & Infrastructure Listed

osint-methodology

Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers the 5-stage recon pipeline, asset-graph discipline, severity rubric, confidence upgrade workflows, time budgeting, identity-fabric mapping, breach×identity correlation, detectability tagging, detection-aware probing, WAF/CDN bypass, vulnerability prioritization, phishing infrastructure planning, bug bounty submission, and client deliverable templates. Use when planning or executing reconnaissance against authorized targets, mapping an organization's external attack surface, investigating a person/entity, or producing client deliverables.

12 Updated today
Ap6pack