Loading...
Loading...
Found 846 Skills
Enumerate an organization's subdomains and sibling domains from Certificate Transparency logs and passive DNS. Use when looking for hidden, staging, dev, or VPN hosts, querying crt.sh or CT logs, reading certificate SAN fields, running subfinder or amass, doing subdomain enumeration or DNS brute-forcing, checking newly issued TLS certificates, or mapping the full hostname footprint of a domain.
Geolocate and chronolocate a photo or video from visual evidence alone — license plate and phone number formats, road markings, utility poles, bollards, signage typefaces, architecture and vegetation for place; shadow direction and length with SunCalc for time and date. Use for GEOINT and chronolocation work, verifying a claimed location without GPS or EXIF, matching a scene to Google Earth, Street View, Yandex Panoramas, Mapillary or KartaView, or estimating when a picture was taken from shadows, foliage and weather archives.
Establish who registered and who operates a domain using WHOIS, RDAP, and DNS. Use when running a whois lookup, querying RDAP, digging A/AAAA/MX/NS/TXT/SOA/CAA records, reading SPF includes, DKIM selectors or DMARC rua addresses, finding the registrar, registrant, or nameservers, doing reverse DNS/PTR or ASN and netblock lookups, or hunting historical WHOIS and passive DNS for a domain.
Find internet-exposed hosts, ports, services and devices using third-party internet-scan data. Use when searching Shodan or Censys, writing Shodan filter queries, reading service banners, checking open ports on an IP or netblock, pivoting on favicon hashes or TLS certificate fingerprints, hunting origin IPs behind Cloudflare or a CDN, or looking for exposed databases, dashboards, cameras and ICS devices without scanning the target.
Start-here router and tradecraft baseline for any OSINT investigation. Sets authorized scope, turns a vague request into an answerable intelligence question, writes a collection plan, picks the right workflow skill for the starting selector, and applies source grading and competing-hypothesis discipline. Use for "investigate this person/company/domain", "do OSINT on X", "where do I start", or any open-source intelligence, due diligence, or attribution task.
End-to-end passive reconnaissance workflow for a domain, website, or IP — builds an asset inventory covering registration, DNS, subdomains, infrastructure, tech stack, history and ownership without sending traffic to the target.
Investigate a phone number — E.164 normalisation with libphonenumber, phoneinfoga scanning, carrier and line-type identification, VoIP and burner detection, messaging-app registration checks, and reverse-lookup and caller-ID sources. Use for phone OSINT, reverse phone lookup, "who owns this number", identifying a burner or VoIP number, or checking whether a number is on WhatsApp, Telegram, or Signal.
Use people-search aggregators and primary public records to find addresses, phone numbers, relatives, age, and background on a person, and to audit and remove your own exposure. Covers Spokeo, BeenVerified, Whitepages, TruePeopleSearch, FastPeopleSearch, That'sThem, Radaris, Intelius, Pipl, voter files, county court and property records, FCRA and non-FCRA limits, GDPR position, and broker opt-out.
Research companies, directors, shareholders, and ultimate beneficial ownership in official corporate registries, filings, and offshore datasets. Covers OpenCorporates, UK Companies House and the PSC register, SEC EDGAR, US Secretary of State registries, EU business registers, GLEIF LEI records, OpenOwnership, OpenSanctions, and the ICIJ Offshore Leaks database. Use for KYB, entity resolution, group structure, nominee and shell detection, or finding a person's other directorships.
Recover deleted, edited, or historical web content from web archives using the Wayback Machine, its CDX API, archive.today, Common Crawl, and Memento/Timetravel. Use when a page is deleted, changed, or 404s, checking what a site used to say, finding old team or staff pages, prior pricing, removed posts, pre-redaction wording or old contact details, enumerating every archived URL for a domain, retrieving a raw archived snapshot, or preserving evidence before it disappears.
Build an entity-relationship link-analysis graph of an investigation — nodes, typed edges with source and confidence, aliases, and temporal validity — to expose shared infrastructure, bridging nodes, and the real principal behind a frontman. Use for link analysis, network mapping, Maltego graphs, Neo4j/Cypher or Gephi work, centrality and community detection, entity resolution and deduplication, or visualising how selectors and pivots connect.
Workflow to build a sourced, corroborated profile of a named individual from public records, social platforms, professional networks, court and property filings, licensing boards, patents, papers, and obituaries. Use for due diligence, background and fraud investigation, journalism, skip tracing, missing persons, hiring integrity checks, or auditing your own exposure.