pentest-osint-recon

Gather public OSINT data to map external attack surfaces.

299|56|Updated Jan 13, 2026
One-click install
npx skills add https://github.com/jd-opensource/JoySafeter --skill pentest-osint-recon
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pentest-osint-recon
Source: https://github.com/jd-opensource/JoySafeter/tree/main/skills/pentest-osint-recon
Command: npx skills add https://github.com/jd-opensource/JoySafeter --skill pentest-osint-recon

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Gathers publicly available information about target organizations to map external attack surfaces, enabling proactive defense and threat modeling.

Core Features & Use Cases

  • Domain enumeration, tech profiling, and OSINT collection to identify exposed assets and weaknesses.
  • Asset correlation and vulnerability intel checks to prioritize remediation.
  • Use Case: An incident responder quickly inventories external footprint after a new domain appears.

Quick Start

Run the OSINT reconnaissance workflow against the target domain to begin collection now.

Frequently Asked Questions about pentest-osint-recon

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map my organization's external attack surface using OSINT?

You map your external attack surface by gathering publicly available information to identify exposed assets and weaknesses. This OSINT workflow collects domain enumeration, tech profiling, and credential leakage checks to correlate assets with CVE data for proactive defense.

What's the best way to discover subdomains and profile technologies for threat intelligence?

The best way to discover subdomains and profile technologies is using standard OSINT tooling like amass, subfinder, httpx, whatweb, and theharvester. This structured workflow correlates discovered assets with vulnerability intel to prioritize threat intelligence remediation.

Can I check for credential leakage across my organization's domains and emails?

Yes, you can check for credential leakage across domains, emails, and assets. The OSINT reconnaissance workflow gathers publicly available information to identify exposed credentials and correlate them with your external attack surface for incident response.

Do I need standard OSINT tools like amass and subfinder to run this reconnaissance workflow?

Yes, you need standard OSINT tooling including amass, subfinder, httpx, whatweb, and theharvester. These tools enable domain enumeration, tech profiling, and information gathering required to map external attack surfaces and correlate assets with CVE data.

How does an incident responder inventory an external footprint after a new domain appears?

An incident responder inventories an external footprint by running the OSINT reconnaissance workflow against the new target domain. This collects publicly available information, maps exposed assets, and checks vulnerability intel to prioritize remediation actions.

When do I need OSINT collection and asset correlation with CVE data?

You need OSINT collection and asset correlation with CVE data when mapping external attack surfaces for proactive defense and threat modeling. This process identifies exposed assets, discovers weaknesses through tech profiling, and prioritizes remediation based on vulnerability intelligence.