offensive-osint

Automate OSINT collection for offensive security reconnaissance across domains and targets.

1|1|Updated Mar 4, 2026
One-click install
npx skills add https://github.com/erkanrzgc/cyberm4fia-scanner --skill offensive-osint
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offensive-osint
Source: https://github.com/erkanrzgc/cyberm4fia-scanner/tree/main/core/ai_skills/offensive-osint
Command: npx skills add https://github.com/erkanrzgc/cyberm4fia-scanner --skill offensive-osint

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Automates and orchestrates comprehensive OSINT collection to rapidly assemble target intelligence for offensive security engagements. It reduces manual gathering across domains, emails, social profiles, breach data, and infrastructure mapping by providing a repeatable reconnaissance workflow.

Core Features & Use Cases

  • Domain reconnaissance and infrastructure mapping across public sources.
  • Social media profiling and breach data lookup for target artifacts.
  • Artifact archiving with timestamped URLs, screenshots, and SHA-256 hashes, plus JSONL logs for reproducibility.
  • Pivoting across tools and datasets to build a comprehensive attack surface map.

Quick Start

Initiate an OSINT session on a target to begin collecting domain and social-identity artifacts and archive evidence automatically.

Frequently Asked Questions about offensive-osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate OSINT collection for offensive security reconnaissance?

OSINT collection for offensive security is automated by orchestrating reconnaissance workflows across domains, organizations, and social profiles to rapidly assemble target intelligence and map infrastructure.

What is the best way to map an organization's attack surface using public sources?

Mapping an organization's attack surface involves pivoting across public OSINT datasets and tools to gather domain reconnaissance, social media profiling, and breach data lookup results into a comprehensive intelligence profile.

Can I archive OSINT artifacts with timestamps and hashes for reproducibility?

Yes, OSINT artifacts are archived with timestamped URLs, screenshots, and SHA-256 hashes, while JSONL run logs capture run_id and tool versions to ensure full investigative reproducibility.

Does offensive OSINT support investigations targeting crypto addresses and persons?

Offensive OSINT supports investigations targeting domains, organizations, persons, and crypto addresses, applying reconnaissance and profiling techniques to gather actionable intelligence across these target types.

Do I need external OSINT tools to use this reconnaissance and profiling workflow?

The workflow uses a modular toolkit that can integrate multiple OSINT sources, allowing you to pivot across external tools and datasets to build your attack surface map without rigid dependencies.