Loading...
Loading...
Found 846 Skills
Passive reconnaissance workflow for a domain, website, or IP — maps DNS, subdomains, infrastructure, tech stack, history, and ownership without touching the target.
Operational security for investigators — create and maintain research accounts and browse without exposing your identity. Use when setting up a sockpuppet or research persona, avoiding attribution while investigating, or hardening a browsing environment.
Compile OSINT findings into a professional, sourced, and timestamped intelligence report that separates confirmed facts from inference.
Corporate intelligence and due-diligence workflow — map a company's legal structure, people, infrastructure, footprint, and risk from public records.
Craft advanced search-engine queries to surface hidden or specific content. Use when building Google dorks, using search operators (site, filetype, intext, inurl), finding exposed files or documents, or narrowing searches for a name, email, or leak.
Start-here router for any OSINT investigation. Names the workflow and knowledge skills and picks the right one for a given starting selector.
Investigate an email address — validate it, find linked accounts and breaches, and pivot to the owner's identity, usernames, and other contact selectors.
Organize investigation findings into an entity-relationship graph to reveal connections. Use when mapping links between people, accounts, and infrastructure, building a Maltego-style graph, visualizing selectors and pivots, or untangling a complex network.
Mine GitHub, GitLab, and git history for people, infrastructure, and leaked secrets. Use when investigating a developer or org on GitHub, finding leaked API keys or credentials in code, or pivoting from commits, emails, and repos.
Workflow to build a sourced profile of a named individual from public sources, pivoting across identity, contact, social, and location selectors.
Corporate due-diligence workflow — resolve a brand or website to its registered legal entity, map group structure and beneficial ownership, profile officers and directors, enumerate the digital estate, and screen litigation, insolvency, procurement, sanctions, PEP, and adverse media. Use for vendor and counterparty risk, KYC/KYB, M&A diligence, investor checks, or shell-company assessment.
Investigate an email address — MX and syntactic validation, Gravatar lookup, corporate email-format inference, breach exposure, and full mail-header analysis (Received chain, Message-ID, SPF/DKIM/DMARC). Use for email OSINT, verifying whether an address exists, finding accounts registered to an address, guessing a company's email format, or tracing where a message actually came from.