offensive-osint

Identify target-domain OSINT artifacts and assemble a structured reconnaissance plan.

2|Updated Apr 21, 2026
One-click install
npx skills add https://github.com/din4e/Skills4RedTeam --skill offensive-osint-din4e
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offensive-osint
Source: https://github.com/din4e/Skills4RedTeam/tree/main/skills/offensive-osint
Command: npx skills add https://github.com/din4e/Skills4RedTeam --skill offensive-osint-din4e

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

OSINT workflows are often chaotic and time-consuming; this skill provides a structured methodology to gather, categorize, and analyze open-source intelligence for offensive security, red team engagement, and bug bounty reconnaissance.

Core Features & Use Cases

  • Domain reconnaissance, social media profiling, GitHub/code leaks discovery, Shodan/Censys enumeration, breach data lookup, and infrastructure mapping for attack-surface development.
  • AI-assisted analysis workflows and geospatial/infrastructure context to prioritize targets and track findings across engagements.
  • Use Case: When performing reconnaissance against a target domain or organization, an investigator can systematically collect artifacts, timestamp them, and build a reproducible attack surface map.

Quick Start

Initiate the OSINT workflow for a target domain or entity and begin archiving artifacts (URL + timestamp + screenshot (PNG) + hash (SHA-256)) for reproducible investigations.

Frequently Asked Questions about offensive-osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the best way to structure an OSINT reconnaissance workflow for a target domain?

To perform domain reconnaissance, profile social media, discover code leaks, query breach data, and map infrastructure, you enforce scope selection and archive artifacts with timestamps, screenshots, and SHA-256 hashes to build a reproducible attack surface map.

How do I archive and log OSINT artifacts during an investigation?

You archive OSINT artifacts by recording the URL, timestamp, screenshot (PNG), and hash (SHA-256) for each finding, and logging the data in JSONL format to ensure end-to-end reproducible investigations across red team engagements.

What subjects can I investigate using an offensive OSINT methodology?

You can investigate domains, organizations, individuals, crypto addresses, and geo subjects. The methodology covers social media profiling, infrastructure mapping, breach data lookups, and code leaks discovery to develop a comprehensive attack surface.

How does infrastructure mapping work in threat intelligence gathering?

Infrastructure mapping in threat intelligence works by enumerating exposed assets and services using Shodan and Censys, integrating geospatial context to prioritize targets, and assembling the results into a structured reconnaissance plan.

Can I use this OSINT workflow for bug bounty reconnaissance?

Yes, you can use this workflow for bug bounty reconnaissance. It systematically collects and categorizes open-source intelligence artifacts, allowing investigators to build a reproducible attack surface map tailored for bug bounty target scopes.

Do I need specialized tools to perform GitHub code leak discovery?

GitHub code leak discovery requires tool-compatible JSONL logging and artifact archiving to track findings, but relies on systematically applying structured OSINT workflows rather than any specific proprietary platform dependency.