recon-osint

Perform OSINT reconnaissance to build target profiles from public sources.

60|14|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/brucesongs/kali-claw --skill recon-osint-brucesongs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-osint
Source: https://github.com/brucesongs/kali-claw/tree/main/skills/recon-osint
Command: npx skills add https://github.com/brucesongs/kali-claw --skill recon-osint-brucesongs

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Publicly available information about a target is scattered across many sources, making it hard to assemble a coherent picture for security assessments.

Core Features & Use Cases

  • Passive and active OSINT gathering across multiple sources to surface comprehensive target profiles
  • Subdomain enumeration, domain metadata extraction, and asset discovery for accurate attack surface mapping
  • Threat intelligence synthesis and cross-source correlation to support red-team planning and risk assessment

Quick Start

Trigger the OSINT workflow for a target domain to identify subdomains, exposed data, and public indicators.

Frequently Asked Questions about recon-osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I gather publicly available information to build a target profile for security assessments?

OSINT reconnaissance coordinates passive and active information gathering across multiple sources to surface comprehensive target profiles, consolidating scattered public data into structured intelligence for security assessments.

What is subdomain enumeration and how does it map an attack surface?

Subdomain enumeration discovers underlying domains and assets associated with a target to accurately map its attack surface. It extracts domain metadata and identifies exposed assets for comprehensive security testing.

Can I use this for both passive and active threat intelligence collection?

Yes, threat intelligence collection applies both passive and active gathering techniques. It synthesizes cross-source correlation to support red-team planning and risk assessment by building structured target profiles.

Does technology fingerprinting work across multiple data sources and formats?

Technology fingerprinting analyzes target profiles by correlating data gathered across multiple sources and formats. This cross-tool correlation satisfies structured reporting requirements to identify exposed technologies and public indicators.

What is the best way to start an OSINT workflow for a target domain?

Trigger the OSINT workflow directly for a target domain to identify subdomains, exposed data, and public indicators. This initiates asset discovery and technology fingerprinting to build a coherent intelligence picture.

When should I not use active reconnaissance for domain metadata extraction?

Active reconnaissance directly interacts with the target, which may trigger alerts or violate engagement rules. Use passive gathering instead when stealth is required or when assessing external assets without explicit authorization.