osint-footprinting

Map an organization's external attack surface from public DNS, WHOIS, and scan datasets.

6|Updated May 30, 2026
One-click install
npx skills add https://github.com/jassics/awesome-claude-security --skill osint-footprinting
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: osint-footprinting
Source: https://github.com/jassics/awesome-claude-security/tree/main/plugins/osint/skills/osint-footprinting
Command: npx skills add https://github.com/jassics/awesome-claude-security --skill osint-footprinting

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps identify and visualize an organization's external attack surface, revealing domains, services, technologies, and organizational details from public sources.

Core Features & Use Cases

  • External Footprint Mapping: Identifies domains, subdomains, IP ranges, and exposed services.
  • Public Source Analysis: Utilizes public DNS records, WHOIS data, and internet-wide scan datasets.
  • Use Case: Begin an engagement by mapping the target's external footprint to understand potential attack vectors.

Quick Start

Run the osint-footprinting skill to start the footprinting process for the target organization.

Frequently Asked Questions about osint-footprinting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map an organization's external attack surface using public DNS and WHOIS data?

To map an external attack surface, you analyze public DNS records, WHOIS data, and internet-wide scan datasets to identify target domains, subdomains, IP ranges, and exposed services.

What is OSINT footprinting for security assessments?

OSINT footprinting is the process of discovering and visualizing an organization's external attack surface from public sources to reveal domains, services, technologies, and organizational details.

Can I use OSINT footprinting for initial engagement preparation?

Yes, you can use OSINT footprinting for initial engagement preparation by mapping the target's external footprint to understand potential attack vectors before active testing begins.

How do I find exposed services and subdomains for ongoing attack-surface management?

You find exposed services and subdomains by analyzing internet-wide scan datasets and public DNS records, which identify active IP ranges and external technologies for ongoing attack-surface management.

Does footprinting an external attack surface require specialized scanning tools or dependencies?

No specialized dependencies are required to footprint an external attack surface, as the process utilizes publicly available DNS records, WHOIS data, and existing internet-wide scan datasets.

Related Skills