redteam-recon-person

Automate OSINT reconnaissance and generate structured profiles for targeted individuals.

1|1|Updated Apr 25, 2026
One-click install
npx skills add https://github.com/chenchunrun/onyx-soc --skill redteam-recon-person
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: redteam-recon-person
Source: https://github.com/chenchunrun/onyx-soc/tree/main/skills/redteam-recon-person
Command: npx skills add https://github.com/chenchunrun/onyx-soc --skill redteam-recon-person

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires requests, rich, and includes scripts (resource) components.

What problem does it solve?

个人目标情报收集与社工画像分析的自动化能力。针对特定个人进行开源情报收集,整合跨平台信息,生成可直接使用的个人档案与风险评估材料。

Core Features & Use Cases

  • OSINT收集与人像画像分析
  • 跨平台账户推断与关联
  • 风险评估、社工策略与报告生成
  • 适用于授权测试、 VIP 安全评估、 高管风险分析等场景

Quick Start

Provide target's name and optional email/username, then run the skill to generate a profile.

Frequently Asked Questions about redteam-recon-person

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate OSINT reconnaissance for a targeted individual?

OSINT reconnaissance for a targeted individual is automated by aggregating publicly available data across platforms into a structured profile. You provide a target's name and optional email or username to generate a comprehensive personal profile and risk assessment.

What is OSINT profiling and how does cross-platform username discovery work?

OSINT profiling collects publicly available data to build a structured personal dossier. Cross-platform username discovery works by inferring usernames and checking email registrations across multiple platforms to link targeted accounts together.

Can I use this for VIP risk assessments and executive security evaluations?

VIP risk assessments and executive security evaluations are supported through targeted OSINT investigations. The tool aggregates publicly available data to evaluate an individual's exposure and generate a social search matrix risk report.

Do I need to install holehe and blackbird to perform mailbox and username checks?

Mailbox checks via holehe and cross-platform username discovery via blackbird are orchestrated internally by the skill. You do not need to manually configure these dependencies; the script automates the checks and aggregates the results into a report.

What is the best way to generate a social search matrix for a person investigation?

The best way to generate a social search matrix is to provide a target's name and optional email, letting the skill automate cross-platform data aggregation. It auto-generates the matrix alongside breach checks and a structured profile report.

What are the limitations of using automated breach check stubs for social engineering profiling?

Automated breach check stubs provide preliminary data leak indications rather than full breach dataset access. The profiling relies on publicly available data, meaning private or secured accounts will yield limited cross-platform information for social engineering.