What problem does it solve?
Red team operators need a structured methodology for gathering publicly available information about a target organization before an engagement, and ad-hoc reconnaissance often misses breach credentials, leaked secrets, and subdomains that provide the fastest path to initial access.
Core Features & Use Cases
- Four-Phase OSINT Workflow: Covers domain and network reconnaissance, personnel and social intelligence, credential and data leak discovery, and technology stack identification.
- MITRE ATT&CK Mapping: Aligns activities with reconnaissance techniques including T1595, T1589, T1590, T1591, and T1593 for standardized reporting.
- Commonly Missed Sources: Highlights breach dumps, GitHub dorking, certificate transparency logs, and document metadata extraction with confirmation steps before reporting.
- Use Case: During an authorized red team engagement, an operator follows the workflow to enumerate subdomains with Amass and Subfinder, harvest employee emails via LinkedIn and Hunter.io, and check HaveIBeenPwned for leaked credentials to build a spearphishing target profile.
Quick Start
Ask the AI to perform OSINT gathering against an authorized target domain, enumerating subdomains, employees, leaked credentials, and technology stack into a structured reconnaissance report.