OSINT

Conduct structured OSINT investigations across people, companies, domains, and organizations.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/julianobarbosa/.claude --skill osint-julianobarbosa
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: OSINT
Source: https://github.com/julianobarbosa/.claude/tree/main/skills/OSINT
Command: npx skills add https://github.com/julianobarbosa/.claude --skill osint-julianobarbosa

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps you perform structured open-source intelligence (OSINT) investigations for authorized research by organizing tasks into reliable phases and producing evidence-based outputs with clear guardrails.

Core Features & Use Cases

  • Multi-domain OSINT workflows: Run dedicated flows for people lookup, company lookup, investment due diligence, entity/threat intel, domain/subdomain investigation, and organization research.
  • Domain-first enumeration & quality gates: Enforces blocking domain discovery steps (where applicable) and uses confidence/verification thresholds to reduce gaps.
  • Ethics and authorization enforcement: Requires explicit authorization and uses an OSINT ethical framework to prevent prohibited or out-of-scope collection.
  • Multi-source verification & synthesis: Uses a structured intelligence cycle (planning → collection → processing → analysis → dissemination) and consolidates findings into a report-ready structure.

Quick Start

Tell the OSINT skill: "Run an OSINT investigation on example.com to map subdomains, technology stack, and security/threat indicators with authorization and a written scope statement."

Frequently Asked Questions about OSINT

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct open-source intelligence investigations for due diligence?▼

To conduct open-source intelligence investigations for due diligence, use structured workflows that route tasks through planning, collection, processing, and analysis phases. This synthesizes evidence from authorized public sources into verified, report-ready intelligence outputs.

What is the structured intelligence cycle for threat intelligence gathering?▼

The structured intelligence cycle for threat intelligence gathering is a multi-source workflow progressing from planning to collection, processing, analysis, and dissemination. It applies confidence thresholds to reduce gaps and ensure accurate infrastructure context.

Do I need explicit authorization to run domain reconnaissance?▼

Yes, explicit authorization is required to run domain reconnaissance. The ethical framework enforces mandatory authorization and a written scope statement to prevent prohibited collection before initiating subdomain discovery and technology stack mapping.

Can I use this approach for company background research and entity lookup?▼

Yes, you can use this approach for company background research and entity lookup. Dedicated multi-domain workflows support people lookup, company profiling, investment due diligence, and organization research by consolidating findings into a report-ready structure.

What is the best way to map subdomains and technology stacks using public sources?▼

The best way to map subdomains and technology stacks using public sources is through domain-first enumeration. This enforces blocking domain discovery steps and applies verification thresholds to accurately map security and threat indicators within an authorized scope.

When should I not use OSINT methodologies for entity research?▼

You should not use OSINT methodologies for entity research when you lack explicit authorization or a defined written scope statement. The ethical framework prevents executing prohibited collection or out-of-scope investigations without proper guardrails.