osint

Conduct OSINT research on domains, IPs, social media, and documents.

1|Updated Jun 9, 2026
One-click install
npx skills add https://github.com/aivos-xie/hermes-skills --skill osint-aivos-xie
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: osint
Source: https://github.com/aivos-xie/hermes-skills/tree/main/security/osint
Command: npx skills add https://github.com/aivos-xie/hermes-skills --skill osint-aivos-xie

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires maltego, recon-ng, theharvester, shodan, censys, dnsrecon, and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill offers a robust toolkit for performing thorough Open Source Intelligence (OSINT) research, solving the challenge of uncovering relevant information across the web efficiently.

Core Features & Use Cases

  • Domain/IP Intelligence: Conduct comprehensive searches on domains and IPs to discover sensitive data and services.
  • Social Media and Document Intelligence: Extract metadata from social media, websites, and documents for valuable insights.
  • Geolocation Intelligence: Retrieve geographic data from various sources for spatial analysis.
  • Automated OSINT: Automate the collection process using various OSINT frameworks.

Quick Start

To gather domain intelligence on a target, run 'dnsrecon -d target.com -t brt'.

Frequently Asked Questions about osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I gather domain and IP intelligence for threat research?

Domain and IP intelligence gathering uses tools like dnsrecon and theHarvester to discover sensitive data and services. You can run 'dnsrecon -d target.com -t brt' to collect DNS records and enumerate subdomains for digital forensics or threat intelligence.

What is OSINT and how does automated collection work with Shodan and Censys?

OSINT is Open Source Intelligence retrieval from public web sources across domains, social media, and documents. Automated collection integrates Shodan and Censys to query internet-connected devices and services, streamlining information gathering for competitive analysis and security research.

Can I extract metadata from social media and documents for intelligence research?

Yes, social media and document intelligence extraction pulls metadata from websites, profiles, and files. This process retrieves valuable insights and hidden data from public sources, supporting comprehensive research for digital forensics and spatial analysis.

Does Maltego work with recon-ng for comprehensive information gathering?

Maltego and recon-ng are integrated to perform comprehensive information gathering and link analysis. Maltego provides graphical link analysis while recon-ng offers a framework for web-based reconnaissance, together enabling thorough Open Source Intelligence research workflows.

What's the best way to retrieve geolocation data for spatial analysis?

Geolocation intelligence retrieval extracts geographic data from various public sources for spatial analysis. By querying IP registries, metadata, and location-based services, you can map physical locations associated with target domains or social media profiles.

Why do I need multiple OSINT tools instead of a single framework?

Comprehensive OSINT research requires multiple tools like dnsrecon, Shodan, and theHarvester because each targets different data layers. DNS tools find records, Shodan scans services, and document analysis extracts metadata, ensuring full-spectrum coverage across domains, IPs, and social media.

Related Skills