osint

Map target organizations through passive OSINT sources with confidence scoring.

13|1|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/0x0pointer/skills --skill osint-0x0pointer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: osint
Source: https://github.com/0x0pointer/skills/tree/main/osint
Command: npx skills add https://github.com/0x0pointer/skills --skill osint-0x0pointer

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill enables comprehensive passive OSINT reconnaissance to map a target organization across people, infrastructure, technologies, and public footprints without touching the target's systems.

Core Features & Use Cases

  • Phase-based workflow covering domain/DNS intelligence, certificate history, email discovery, infrastructure mapping, subdomain takeover detection, and open-source intelligence from public sources.
  • Evidence-driven reporting with confidence scoring, diagrams, and narrative notes to support threat modeling and security assessments.
  • Operates with MCP-compatible clients and integrates into end-to-end engagements, chaining into active testing workflows when authorized.

Quick Start

Initiate a target domain and preferred depth to begin passive OSINT collection and mapping of external surface area.

Frequently Asked Questions about osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I gather passive OSINT reconnaissance data for a target organization?

Passive OSINT reconnaissance maps a target organization's people, infrastructure, and public exposure using public sources without touching the target's systems, providing evidence-driven reporting with confidence scoring for threat modeling.

What is subdomain enumeration and certificate transparency monitoring in threat intelligence?

Subdomain enumeration and certificate transparency monitoring map a target's external infrastructure and historical SSL/TLS certificate registrations, detecting public exposure and subdomain takeover risks for threat modeling.

Can I use Wayback Machine artifacts and Shodan data for social media footprinting?

Wayback Machine artifacts and Shodan/Censys data gather historical web snapshots and cloud asset intelligence, while social media footprinting maps people and public exposure, cross-referencing findings to provide comprehensive threat intelligence reporting.

How do I discover email addresses and DNS intelligence for domain reconnaissance?

Email discovery and domain/DNS intelligence use tools like dnsrecon and theHarvester to map a target organization's email addresses, DNS records, and infrastructure, generating evidence-driven reports with confidence scoring for security assessments.

Does passive OSINT reconnaissance require authorization before chaining into active testing?

Passive OSINT reconnaissance relies on public sources without touching target systems, but explicitly requires authorization before chaining into active penetration testing workflows with /pentester.

What are the limitations of passive OSINT for mapping cloud assets and subdomain takeovers?

Passive OSINT limitations include reliance on public source accuracy and historical data from certificate transparency and Wayback, meaning cloud asset mapping and subdomain takeover detection may miss recent infrastructure changes not yet indexed.