offensive-osint

Enumerate domains and analyze external data for vulnerability discovery during red-team assessments.

1|Updated May 20, 2026
One-click install
npx skills add https://github.com/Magnatrix-Lab/MAGNATRIX-OS --skill offensive-osint-magnatrix-lab
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offensive-osint
Source: https://github.com/Magnatrix-Lab/MAGNATRIX-OS/tree/main/osint/Claude-OSINT/skills/offensive-osint
Command: npx skills add https://github.com/Magnatrix-Lab/MAGNATRIX-OS --skill offensive-osint-magnatrix-lab

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires shodan, censys, hunterio, intelx, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a comprehensive toolkit for external red-team OSINT and bug-bounty reconnaissance, enabling efficient and effective security auditing.

Core Features & Use Cases

  • OSINT Tools: Offers a curated collection of OSINT tools and resources for various reconnaissance activities.
  • Data Extraction: Performs deep analysis of domain records, network data, and social media profiles.
  • Use Case: A security auditor is tasked with auditing a client's external-facing assets. The auditor uses this Skill to uncover potential security vulnerabilities by leveraging the extensive toolset provided.

Quick Start

Load the offensive-osint skill and run the following command to enumerate all public subdomains for the target domain "example.com":

offensive-osint list-subdomains example.com

Frequently Asked Questions about offensive-osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enumerate subdomains for external red-team reconnaissance?

Subdomain enumeration for external red-team reconnaissance is executed via a dedicated command to list all public subdomains for a target domain. It leverages OSINT data sources to map the external attack surface and identify potential vulnerabilities.

What OSINT data sources are needed for bug bounty security auditing?

Bug bounty security auditing requires API access to external OSINT data sources like Shodan, Censys, and Hunterio. These services provide the network data, domain records, and intelligence required for deep analysis and vulnerability discovery.

Can I use this OSINT toolkit to find data leakage on client assets?

Yes, you can use this OSINT toolkit to find data leakage on client assets. It performs deep analysis of domain records and network data, uncovering exposed information and potential security vulnerabilities during external-facing asset audits.

What is the best way to discover vulnerabilities in external-facing assets?

The best way to discover vulnerabilities in external-facing assets is using a curated collection of OSINT tools for reconnaissance. By analyzing data leakage and network records from public sources, security auditors can efficiently uncover external weaknesses.

Do I need paid API keys to run external red-team OSINT scans?

Running external red-team OSINT scans emphasizes public and free tools, but dependencies like Shodan and Censys typically require API keys for deep data extraction. Providing these keys enables full vulnerability discovery and domain enumeration.