What problem does it solve? Open source intelligence investigations often fail due to ad-hoc searching, missed pivots, and poor evidence handling. This Skill provides a systematic operational checklist that walks an analyst through target definition, collection, correlation, and reporting so nothing important is overlooked. ## Core Features & Use Cases - Full OSINT workflow checklist: Covers OpSec and sock puppets, image and video geolocation, chronolocation via shadow and astronomical analysis, people and social media investigation, and infrastructure OSINT with concrete tool links for each step. - Specialized investigation tracks: Includes cryptocurrency transaction and wallet tracing (including Layer 2 and bridge obfuscation challenges), threat actor attribution workflows with Russia- and China-specific pivots, and malware artifact triage. - Use Case: An analyst investigating a suspicious wallet address uses the cryptocurrency investigation section to trace fund flows through block explorers, then pivots to infrastructure OSINT to map associated domains via certificate transparency logs and passive DNS. ## Quick Start Use the osint-methodology skill to plan and execute a structured OSINT investigation against my target, tracking each checklist step as we go.