Loading...
Loading...
Found 835 Skills
Discover subdomains and related domains from public TLS certificate logs. Use when enumerating subdomains, finding hidden or staging hosts, mapping an org's domains via crt.sh or Certificate Transparency, or spotting newly issued certificates.
Look up domain registration and DNS records. Use when running WHOIS/RDAP, querying DNS records (A, MX, TXT, NS, SPF, DKIM, DMARC), finding a domain's registrant, nameservers, or mail setup, or resolving IPs and ASNs.
Track aircraft and vessels from public ADS-B and AIS broadcasts using ADS-B Exchange, Flightradar24, FlightAware, MarineTraffic, VesselFinder and Equasis. Use when following a tail number or flight, looking up an ICAO 24-bit hex code, registration or callsign, tracing a ship by IMO number or MMSI, checking a flag of convenience or port-call history, investigating who owns a private jet or vessel, or analysing AIS gaps and dark-fleet behaviour.
Extract and interpret embedded file metadata with exiftool — EXIF GPS coordinates, camera make/model/serial, DateTimeOriginal and CreateDate timestamps, XMP and IPTC fields, and Office/PDF document properties like Author, Company, LastModifiedBy, template paths and revision counts. Use when reading EXIF from a photo, checking who wrote a document, dating a file, fingerprinting a camera or phone, or investigating file provenance in JPEG, HEIC, RAW, MP4, DOCX, XLSX and PDF files.
Mine GitHub, GitLab, and git history for identities, infrastructure, and leaked credentials using commit author emails, GitHub code search, the commit .patch endpoint, trufflehog, gitleaks, git log pickaxe, and full-ref history scans. Use when investigating a developer or organisation on GitHub, finding leaked API keys, AWS access keys or tokens in code, enumerating org members and their personal repos, recovering secrets deleted from HEAD but present in history or forks, or checking exposed .git directories, gists, and CI logs.
Craft advanced search-engine queries and Google dorks to surface hidden files, documents, and mentions. Use when building a Google dork, using search operators (site:, filetype:, inurl:, intitle:, intext:, before:/after:), forcing verbatim/exact-match search, finding exposed directory listings, config files, backups, or open S3 buckets, searching paste sites and document repositories for a name, email, or leaked selector, or comparing Google against Bing, DuckDuckGo, and Yandex operators.
Enumerate an organization's subdomains and sibling domains from Certificate Transparency logs and passive DNS. Use when looking for hidden, staging, dev, or VPN hosts, querying crt.sh or CT logs, reading certificate SAN fields, running subfinder or amass, doing subdomain enumeration or DNS brute-forcing, checking newly issued TLS certificates, or mapping the full hostname footprint of a domain.
Geolocate and chronolocate a photo or video from visual evidence alone — license plate and phone number formats, road markings, utility poles, bollards, signage typefaces, architecture and vegetation for place; shadow direction and length with SunCalc for time and date. Use for GEOINT and chronolocation work, verifying a claimed location without GPS or EXIF, matching a scene to Google Earth, Street View, Yandex Panoramas, Mapillary or KartaView, or estimating when a picture was taken from shadows, foliage and weather archives.
Trace cryptocurrency addresses and transactions on public blockchains using block explorers like Etherscan, Blockchair, mempool.space and Blockscout. Use when following a Bitcoin, Ethereum or EVM wallet, investigating a ransom or scam payment, clustering addresses with common-input heuristics, resolving an ENS name, identifying exchange deposit addresses, mixers, CoinJoin, Tornado-style pools or cross-chain bridges, or checking an address against OFAC sanctions listings.
Establish who registered and who operates a domain using WHOIS, RDAP, and DNS. Use when running a whois lookup, querying RDAP, digging A/AAAA/MX/NS/TXT/SOA/CAA records, reading SPF includes, DKIM selectors or DMARC rua addresses, finding the registrar, registrant, or nameservers, doing reverse DNS/PTR or ASN and netblock lookups, or hunting historical WHOIS and passive DNS for a domain.
Deep-dive a subject's social media presence — profile metadata, follower and mutual network, content analysis, and posting-time pattern of life across Instagram, Facebook, X/Twitter, TikTok, LinkedIn, Reddit, Telegram and Discord. Use when profiling a social account, mapping someone's friends and family, inferring a target's timezone, routine, home or workplace from their posts, or archiving a profile before it's deleted.
Find internet-exposed hosts, ports, services and devices using third-party internet-scan data. Use when searching Shodan or Censys, writing Shodan filter queries, reading service banners, checking open ports on an IP or netblock, pivoting on favicon hashes or TLS certificate fingerprints, hunting origin IPs behind Cloudflare or a CDN, or looking for exposed databases, dashboards, cameras and ICS devices without scanning the target.