domain-intel

Performs passive domain reconnaissance including subdomain discovery, SSL inspection, WHOIS lookups, and DNS resolution.

Updated Jun 7, 2026
One-click install
npx skills add https://github.com/Chensihakniroth/ANAKOT-AGENT --skill domain-intel-chensihakniroth
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: domain-intel
Source: https://github.com/Chensihakniroth/ANAKOT-AGENT/tree/main/optional-skills/research/domain-intel
Command: npx skills add https://github.com/Chensihakniroth/ANAKOT-AGENT --skill domain-intel-chensihakniroth

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve? Gathering infrastructure intelligence about a domain—its subdomains, SSL certificate status, registration details, and DNS records—normally requires multiple paid tools or API keys. This Skill performs all of these passive OSINT checks using only the Python standard library, with zero dependencies and zero API keys. ## Core Features & Use Cases - Subdomain Discovery: Enumerate subdomains from Certificate Transparency logs via crt.sh, filtering out expired certificates. - SSL & WHOIS Inspection: Check TLS certificate expiry, cipher suites, and issuers, plus registrar, creation, and expiration dates across 100+ TLD WHOIS servers. - DNS & Availability Checks: Resolve A, AAAA, MX, NS, TXT, and CNAME records, and heuristically determine if a domain is available for registration using DNS, WHOIS, and SSL signals. - Bulk Analysis: Run multiple checks across up to 20 domains in parallel with structured JSON output. - Use Case: Before acquiring a domain for a new project, run the availability check on candidates like coolstartup.io, then inspect SSL expiry dates across your existing domain portfolio in one bulk command. ## Quick Start Ask the agent to find all subdomains of example.com and check when its SSL certificate expires using the domain intelligence skill.

Frequently Asked Questions about domain-intel

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find subdomains of a domain without API keys?▼

Query Certificate Transparency logs through crt.sh, which publishes all issued TLS certificates. The subdomains command fetches these entries over HTTPS, filters expired certificates, and returns a deduplicated list of subdomain names as JSON.

How to check SSL certificate expiration from the command line?▼

Connect to the host on TCP port 443 with Python's ssl module and parse the certificate's notAfter field. The ssl command reports days remaining, expiry status, TLS version, cipher suite, and subject alternative names.

Does this WHOIS lookup work on Windows and macOS?▼

Yes, the tool uses only Python standard library modules like socket, ssl, and urllib, so it runs identically on Linux, macOS, and Windows. Note that WHOIS queries use TCP port 43, which some restrictive networks block.

Why does WHOIS sometimes show no registrant information?▼

Many WHOIS servers redact registrant details due to GDPR privacy regulations. The lookup still returns registrar, creation date, expiration date, and name servers when available, but personal contact data may be omitted.

What are the limitations of passive domain availability checks?▼

The availability check is heuristic-based, combining DNS resolution, WHOIS responses, and SSL reachability signals. It is not authoritative like a registrar API, so results marked possibly available should be confirmed with an actual registrar before purchase.