offensive-osint

Identify target-domain OSINT artifacts and assemble a structured reconnaissance plan.

2|Updated Apr 21, 2026
One-click install
npx skills add https://github.com/din4e/Skills4RedTeam --skill offensive-osint-din4e
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: offensive-osint
Source: https://github.com/din4e/Skills4RedTeam/tree/main/skills/offensive-osint
Command: npx skills add https://github.com/din4e/Skills4RedTeam --skill offensive-osint-din4e

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

OSINT workflows are often chaotic and time-consuming; this skill provides a structured methodology to gather, categorize, and analyze open-source intelligence for offensive security, red team engagement, and bug bounty reconnaissance.

Core Features & Use Cases

  • Domain reconnaissance, social media profiling, GitHub/code leaks discovery, Shodan/Censys enumeration, breach data lookup, and infrastructure mapping for attack-surface development.
  • AI-assisted analysis workflows and geospatial/infrastructure context to prioritize targets and track findings across engagements.
  • Use Case: When performing reconnaissance against a target domain or organization, an investigator can systematically collect artifacts, timestamp them, and build a reproducible attack surface map.

Quick Start

Initiate the OSINT workflow for a target domain or entity and begin archiving artifacts (URL + timestamp + screenshot (PNG) + hash (SHA-256)) for reproducible investigations.

Frequently Asked Questions about offensive-osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the best way to structure an OSINT reconnaissance workflow for a target domain?▼

To perform domain reconnaissance, profile social media, discover code leaks, query breach data, and map infrastructure, you enforce scope selection and archive artifacts with timestamps, screenshots, and SHA-256 hashes to build a reproducible attack surface map.

How do I archive and log OSINT artifacts during an investigation?▼

You archive OSINT artifacts by recording the URL, timestamp, screenshot (PNG), and hash (SHA-256) for each finding, and logging the data in JSONL format to ensure end-to-end reproducible investigations across red team engagements.

What subjects can I investigate using an offensive OSINT methodology?▼

You can investigate domains, organizations, individuals, crypto addresses, and geo subjects. The methodology covers social media profiling, infrastructure mapping, breach data lookups, and code leaks discovery to develop a comprehensive attack surface.

How does infrastructure mapping work in threat intelligence gathering?▼

Infrastructure mapping in threat intelligence works by enumerating exposed assets and services using Shodan and Censys, integrating geospatial context to prioritize targets, and assembling the results into a structured reconnaissance plan.

Can I use this OSINT workflow for bug bounty reconnaissance?▼

Yes, you can use this workflow for bug bounty reconnaissance. It systematically collects and categorizes open-source intelligence artifacts, allowing investigators to build a reproducible attack surface map tailored for bug bounty target scopes.

Do I need specialized tools to perform GitHub code leak discovery?▼

GitHub code leak discovery requires tool-compatible JSONL logging and artifact archiving to track findings, but relies on systematically applying structured OSINT workflows rather than any specific proprietary platform dependency.