What problem does it solve? Reconnaissance and investigations require knowing which of hundreds of OSINT tools to use for each target type, and how to preserve evidence reproducibly. This Skill provides a structured methodology and curated tool directory so analysts can systematically investigate domains, organizations, people, crypto addresses, and geospatial subjects without missing key pivots. ## Core Features & Use Cases - Comprehensive Tool Directory: Curated tables of tools for domain recon, email harvesting, social media profiling, breach data lookup, Shodan/Censys enumeration, GitHub leaks, and employee profiling. - Specialized Intelligence Tracks: Dedicated workflows for cryptocurrency tracing (blockchain explorers, Arkham, bridge monitoring), geospatial intelligence (satellite imagery, flight/maritime tracking), media forensics, and Telegram/messaging intelligence. - Evidence Preservation Workflow: Standardized archiving with URL, timestamp, screenshot, SHA-256 hashing, and JSONL logging with run IDs for reproducible investigations. - Use Case: During a bug bounty engagement against a target organization, work top-down through infrastructure OSINT (crt.sh, Shodan, Amass) to map the attack surface, then pivot to breach data and employee profiling to identify exposed credentials. ## Quick Start Use the offensive-osint skill to build an attack-surface map and reconnaissance plan for the target domain example.com.