techstack-identification

Identify company technology stacks via passive OSINT across 17 intelligence domains.

7|1|Updated Apr 14, 2026
One-click install
npx skills add https://github.com/ArianHobson333/claude-bug-bounty-stack --skill techstack-identification-arianhobson333
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: techstack-identification
Source: https://github.com/ArianHobson333/claude-bug-bounty-stack/tree/main/vendor/communitytools/projects/pentest/.claude/skills/techstack-identification
Command: npx skills add https://github.com/ArianHobson333/claude-bug-bounty-stack --skill techstack-identification-arianhobson333

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires python, requests, tldextract, tldextract, asnlookup, ipwhois, whois, socket, json, yaml, markdown, pandas, scikit-learn, networkx, matplotlib, and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides passive OSINT-based reconnaissance to identify a target's technology stack, including frontend, backend, infrastructure, and security technologies, without credentials or active scanning.

Core Features & Use Cases

  • Passive OSINT Reconnaissance: Discovers company tech stacks using publicly available signals across 17 intelligence domains.
  • Automated Analysis: Infers frontend, backend, infrastructure, and security technologies using signals like domain records, code repositories, job postings, and web archives.
  • Use Case: Given a company name and domain, the Skill can identify their technology stack and potential vulnerabilities by analyzing signals from various sources like DNS records, TLS certificates, code repositories, and job postings.

Quick Start

Run the skill with the following command:

techstack-identification --company <company_name> --domain <domain_hint>

Frequently Asked Questions about techstack-identification

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I identify a company's tech stack using passive OSINT without active scanning?

Passive OSINT reconnaissance identifies a target's tech stack by extracting and analyzing public signals from domain records, code repositories, job postings, and web archives without active scanning or credentials.

What OSINT intelligence domains can I use for technology mapping?

Technology mapping across 17 intelligence domains analyzes DNS records, TLS certificates, code repositories, and job postings to infer frontend, backend, infrastructure, and security technologies used by the target.

Can I find potential vulnerabilities by analyzing a target's technology stack from DNS and TLS records?

Yes, analyzing DNS records and TLS certificates can identify a target's technology stack and potential vulnerabilities by inferring infrastructure and security technologies from publicly available signals.

Do I need Python and network libraries to run passive reconnaissance for tech stack identification?

Yes, tech stack identification requires Python and various libraries including requests, tldextract, socket, pandas, scikit-learn, and networkx for DNS querying, web scraping, and data analysis across multiple intelligence domains.

What is the best way to discover a target's frontend and backend technologies for competitive analysis?

The best way to discover frontend and backend technologies for competitive analysis is passive OSINT reconnaissance, which infers technologies from public signals like code repositories and web archives without active scanning.

Why does passive reconnaissance matter for due diligence and pentesting preparation?

Passive reconnaissance matters for due diligence and pentesting preparation because it identifies a target's infrastructure and security technologies using public signals, avoiding detection while gathering actionable intelligence.

Related Skills