What problem does it solve?
Security teams need to map threat actor infrastructure and enrich threat intelligence reports without tipping off adversaries or crossing legal boundaries, but manual OSINT collection across dozens of sources is slow and error-prone.
Core Features & Use Cases
- Passive Infrastructure Mapping: Query passive DNS, WHOIS history, certificate transparency logs (crt.sh), and Shodan to cluster malicious domains, IPs, and ASNs without sending packets to targets.
- Graph-Based Link Analysis: Use Maltego transforms to pivot from a known malicious domain through registrant emails, shared hosting, and reverse DNS to expand infrastructure attribution.
- Dark Web and Paste Monitoring: Automate collection from paste sites, breach data, and forums using SpiderFoot modules for leaked credentials and IOCs.
- Use Case: While investigating a phishing campaign, an analyst starts with one malicious domain, cross-checks Shodan, crt.sh, and passive DNS, then builds a Maltego graph that reveals the actor's broader C2 cluster with confidence-scored IOCs.
Quick Start
Use the collecting-open-source-intelligence skill to map the infrastructure behind the domain evil-domain.com using passive sources only.