offensive-osint

Aggregate public data for OSINT reconnaissance in red-team workflows.

1|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/riparino/Claude-Cyber --skill offensive-osint-riparino
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offensive-osint
Source: https://github.com/riparino/Claude-Cyber/tree/main/Claude-Red/Skills/offensive-osint
Command: npx skills add https://github.com/riparino/Claude-Cyber --skill offensive-osint-riparino

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This OSINT methodology skill streamlines structured public-data gathering for offensive security, red-team intel, and bug bounty workflows, reducing noise and guiding targeted reconnaissance.

Core Features & Use Cases

  • Domain reconnaissance and infrastructure mapping
  • Email harvesting, social-media profiling, GitHub/code-leaks detection
  • Enumeration of Shodan/Censys assets, breach data lookups, and employee profiling
  • Geospatial intelligence, cryptocurrency tracing, and AI-assisted analysis workflows
  • Use Case: when assessing a target domain, a person, or an organization, assemble a comprehensive attack-surface map and risk profile.

Quick Start

Identify your target and start with General OSINT and Username/Email Investigation to begin collecting artifacts.

Frequently Asked Questions about offensive-osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform OSINT reconnaissance for red-team domain profiling?

OSINT reconnaissance for red-team domain profiling involves aggregating public data to map a target's attack surface. This skill orchestrates top-down categorization, artifact archiving, and iterative pivoting across infrastructure, breach data, and employee profiles.

Can I trace cryptocurrency flows and detect GitHub code leaks during an investigation?

Yes, cryptocurrency tracing and GitHub code-leaks detection are supported core features. The methodology aggregates public data to trace crypto flows and identify exposed source code, logging all artifacts to JSONL with run_id tracking.

What is the best way to enumerate Shodan and Censys assets for a bug bounty target?

Enumerating Shodan and Censys assets requires structured public-data gathering to discover exposed infrastructure. This skill guides targeted reconnaissance by orchestrating iterative pivoting across enumerated assets and logging tool versions.

How does structured OSINT categorization reduce noise during threat intelligence gathering?

Structured OSINT categorization reduces noise by applying a top-down methodology to public-data gathering. It streamlines artifact archiving and iterative pivoting, ensuring targeted reconnaissance rather than unstructured data collection.

Do I need specific tools to start email harvesting and social media profiling?

No specific external tools are required as dependencies. The skill provides the methodology for email harvesting and social-media profiling, orchestrating the workflow and archiving artifacts with JSONL logging and run_id tracking.

When should I not use a structured OSINT methodology for target reconnaissance?

A structured OSINT methodology is not suited for unstructured, ad-hoc data collection or non-offensive investigations. It is specifically designed for red-team recon, bug bounty workflows, and targeted infrastructure discovery requiring artifact archiving.