osint-gathering

Collect passive OSINT data on target domains via public sources.

7|Updated Feb 11, 2026
One-click install
npx skills add https://github.com/valITino/blhackbox --skill osint-gathering
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: osint-gathering
Source: https://github.com/valITino/blhackbox/tree/main/.claude/skills/osint-gathering
Command: npx skills add https://github.com/valITino/blhackbox --skill osint-gathering

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Passive open-source intelligence collection against a target domain to build situational awareness without triggering active defenses.

Core Features & Use Cases

  • Domain registration and WHOIS intelligence for ownership and history
  • DNS and subdomain discovery with passive sources
  • Infrastructure mapping including hosting, email, and cloud indicators
  • Consolidated OSINT reporting and risk signal identification

Quick Start

Provide a target domain to start OSINT gathering.

Frequently Asked Questions about osint-gathering

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform passive OSINT gathering against a target domain without triggering defenses?

Passive OSINT gathering against a target domain uses publicly accessible sources to build situational awareness without active probing. It aggregates domain reconnaissance, subdomain discovery, and DNS mapping into a structured intelligence payload for reporting.

Can I map subdomains and DNS infrastructure using only passive reconnaissance?

Yes, passive reconnaissance maps subdomains and DNS infrastructure by querying publicly accessible sources. This approach discovers subdomains and maps infrastructure without sending active probing requests to the target domain.

What is the best way to consolidate OSINT reporting for domain registration and hosting indicators?

Consolidated OSINT reporting aggregates domain registration, WHOIS intelligence, and hosting indicators into a structured payload. This identifies risk signals and builds infrastructure profiles without requiring active scanning.

Does passive domain reconnaissance require any active scanning tools to map email and cloud indicators?

No, passive domain reconnaissance requires zero active scanning tools. It uses public sources to map email and cloud indicators, ensuring infrastructure profiling occurs without triggering target defenses.

Why use passive OSINT collection instead of active probing for infrastructure profiling?

Passive OSINT collection avoids triggering active defenses by relying on public sources rather than active probing. It maps infrastructure and identifies risk signals while maintaining zero interaction with the target domain.

When should I not use passive recon for subdomain discovery?

Passive recon should not be used when you need real-time target responses or guaranteed complete subdomain discovery. It relies on cached public sources, which may lack the most recent infrastructure changes.