osint

Identify publicly visible assets, employees, and technologies using OSINT techniques.

60|14|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/brucesongs/kali-claw --skill osint-brucesongs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: osint
Source: https://github.com/brucesongs/kali-claw/tree/main/skills/osint
Command: npx skills add https://github.com/brucesongs/kali-claw --skill osint-brucesongs

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Gathers intelligence from publicly available sources to build a comprehensive view of an organization's digital footprint.

Core Features & Use Cases

  • Passive and semi-passive OSINT collection across domains, emails, subdomains, technologies, and breaches.
  • Automated correlation and reporting to map attack surfaces and identify risk hotspots.
  • Support for 13 OSINT workflows and 50+ data sources, enabling rapid red-team and defensive assessments.

Quick Start

To begin, trigger an OSINT workflow to collect public data and summarize the findings.

Frequently Asked Questions about osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map an organization's public attack surface using OSINT?

To map an attack surface using OSINT, you gather intelligence across domains, subdomains, and emails using passive and semi-passive techniques. This builds a comprehensive view of publicly visible assets and technologies.

Can I use passive reconnaissance to find exposed employee data and breaches?

Yes, passive reconnaissance can find exposed employee data by querying breach data and email addresses. It correlates public sources to identify risk hotspots without directly interacting with the target's network.

What's the best way to automate subdomain enumeration and fingerprinting for security assessments?

Automating subdomain enumeration and fingerprinting is best handled by triggering an OSINT workflow that integrates multiple data sources. This automatically correlates technologies and assets to produce structured reports for assessments.

How many data sources are supported for public data correlation?

The system supports 50+ data sources for public data correlation. These sources feed into 13 distinct OSINT workflows, enabling rapid data integration for red-team and defensive security assessments.

Does OSINT reconnaissance work for both red-team and defensive assessments?

Yes, OSINT reconnaissance works for both red-team and defensive assessments. It maps public digital footprints and identifies risk hotspots, informing proactive security strategies and threat modeling.

When should I use semi-passive OSINT techniques instead of active scanning?

You should use semi-passive OSINT techniques when you need to map public assets and technologies without alerting the target. This approach safely gathers domains and subdomain data while minimizing direct network interaction.