osint-methodology

Plan and execute OSINT collection with structured source selection and documentation.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill osint-methodology-liberty91ltd
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: osint-methodology
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/osint-methodology
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill osint-methodology-liberty91ltd

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Structured OSINT collection is often ad hoc and error-prone. This guide provides a repeatable methodology for planning, executing, and documenting OSINT investigations, ensuring thorough coverage and clear records.

Core Features & Use Cases

  • Planning and scoping: objectives, sources, keywords, and time constraints.
  • Technique catalog: search operators, operator examples, and source categories.
  • Documentation and reporting: structured notes and evidence tracking.
  • Use Case: Investigate a threat actor profile by mapping sources, IOCs, and a timeline to support decision making.

Ethical and Legal Boundaries

  • Only access publicly available information.
  • Do not engage in impersonation or illegal activity.
  • Respect privacy and data protection regulations.

Quick Start

Initiate an OSINT collection session following the planning, targeting the appropriate sources, and document findings.

Frequently Asked Questions about osint-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure an OSINT investigation to avoid missing critical sources?

Structure your OSINT investigation by applying a repeatable methodology for planning, executing, and documenting collection. This ensures thorough coverage across government advisories, vendor reports, and open sources while maintaining clear records.

What is the best way to document OSINT collection for threat intelligence?

The best way to document OSINT collection is using structured notes and evidence tracking practices. This methodology ensures your threat intelligence findings are repeatable, clearly recorded, and support decision making.

Which search operators should I use for open source intelligence gathering?

For open source intelligence gathering, use a technique catalog of search operators with applied examples. This guides structured source selection across public advisories and reports during your collection planning.

Can I use this methodology to profile threat actors and map IOCs?

Yes, you can use this methodology to profile threat actors by mapping sources, IOCs, and a timeline. It provides a structured framework for scoping objectives and executing targeted OSINT investigations.

What are the ethical boundaries when collecting publicly available information?

The ethical boundaries for collecting publicly available information require accessing only public data, avoiding impersonation or illegal activity, and respecting privacy and data protection regulations throughout the OSINT process.

Why does my ad hoc OSINT collection process often produce incomplete results?

Ad hoc OSINT collection produces incomplete results because it lacks structured planning and repeatable methodology. Implementing defined scoping, source categories, and keyword planning ensures thorough coverage and clear documentation.