What problem does it solve? Open-source intelligence investigations often fail due to ad-hoc workflows, missed pivots, and poor evidence handling. This Skill provides a structured, checklist-driven OSINT methodology so investigations are systematic, reproducible, and properly documented. ## Core Features & Use Cases - Full Investigation Checklists: Covers OpSec and sock puppets, cryptocurrency and Layer-2 tracing, image/video geolocation, chronolocation via shadow and astronomical analysis, threat actor attribution, and social media enumeration. - Tool and Platform Guidance: Recommends concrete tools per task, such as SunCalc for shadow analysis, crt.sh for certificate pivots, Sherlock for username enumeration, and Arkham or TRM for wallet tracing. - Attribution Discipline: Enforces confidence levels, rule-of-three corroboration, and MITRE ATT&CK mapping to avoid single-source attribution errors. - Use Case: An analyst investigating a suspicious crypto wallet uses the methodology to trace fund flows across bridges, profile the wallet, pivot to exchange accounts, and produce a documented report with hashed evidence artifacts. ## Quick Start Ask the assistant to walk you through an OSINT investigation of a target using the structured methodology checklist, starting with scoping and OpSec setup.