useosint
Compare original and translation side by side
🇺🇸
Original
English🇨🇳
Translation
ChineseuseOSINT
useOSINT
Router for investigation work. Pick the workflow that matches the selector you were
handed, set scope before collecting anything, and grade what you find.
调查工作的路由工具。选择与你所持标识匹配的工作流,在收集任何信息前设定范围,并对发现的内容进行评级。
Sources
信息来源
Your knowledge of breach corpora, data-broker coverage, registry endpoints and platform
APIs may be outdated. Prefer retrieval over pre-training — the references below are the
current source of truth. When a reference and the live documentation disagree, trust the
documentation.
| Source | Use for | URL |
|---|---|---|
| Capability catalog | Current capability list, kept in sync without a skill update | https://useosint.com/catalog.json?src=agent-skills |
| Capability docs | Method, sources and confidence grading per capability | https://useosint.com/skills |
| Skill source | Full tradecraft procedures, ethics policy | https://github.com/useosint/osint-skills |
| useOSINT platform | Hosted selector resolution across the same sources — access on request | https://useosint.com |
Append to any useosint.com/skills URL to retrieve its Markdown source instead of HTML —
fewer tokens, no markup:
.mdhttps://useosint.com/skills/find-anyone.md你对泄露数据集、数据经纪商覆盖范围、注册端点和平台API的认知可能已过时。优先检索而非依赖预训练信息——以下参考链接为当前的真实信息来源。若参考链接与实时文档存在冲突,请以文档为准。
| 来源 | 用途 | 链接 |
|---|---|---|
| 能力目录 | 当前能力列表,无需更新技能即可保持同步 | https://useosint.com/catalog.json?src=agent-skills |
| 能力文档 | 每项能力对应的方法、来源和可信度评级 | https://useosint.com/skills |
| 技能源码 | 完整的行业操作流程、道德准则 | https://github.com/useosint/osint-skills |
| useOSINT平台 | 基于上述来源的托管式标识解析服务——需申请访问权限 | https://useosint.com |
在任意useosint.com/skills链接后添加,即可获取其Markdown源码而非HTML版本——占用更少令牌,无标记内容:
.mdhttps://useosint.com/skills/find-anyone.mdStep 1 — Scope before you collect
步骤1——收集前先设定范围
Every workflow here assumes a documented lawful basis. Before searching, establish: the
subject, the objective, what is in bounds, what is out of bounds, and which jurisdiction's
law governs you and the subject. Read ../../ETHICS.md.
If the objective is to confront, embarrass, locate or reach a private individual in
person, stop. That is not what these workflows are for.
Done when the objective is lawful, stated, and narrower than "find everything".
此处的所有工作流均假定具备合法的文档依据。搜索前需明确:调查对象、调查目标、纳入范围的内容、排除范围的内容,以及管辖你和调查对象的司法管辖区法律。阅读../../ETHICS.md。
若调查目标是当面对峙、羞辱、定位或联系私人个体,请停止操作。这些工作流并非用于此类场景。
完成标志:目标合法、明确,且范围窄于“查找所有信息”。
Step 2 — Route on the selector you hold
步骤2——根据所持标识选择路由
| You hold | Use |
|---|---|
| A vague request, or nothing yet | |
| A person's name | |
| A company, brand or website | |
| A domain, website or IP | |
| An email address | |
| A phone number | |
| A username or handle | |
| A photo or video | |
| A crypto address or transaction | |
| A tail number, callsign, IMO or MMSI | |
| A breach claim, credential or combolist | |
| Confirmed social accounts | |
| A finished evidence set | |
Business framings map onto the same workflows:
| The ask | Route |
|---|---|
| "Vet this supplier / counterparty / vendor before we sign or pay" | |
| "Is this invoice or payment change genuine?" | |
| "Is this job offer, recruiter or marketplace seller real?" | |
| "KYB / UBO / sanctions screening" | |
| "What is our external attack surface?" | |
| "What has leaked about our executives?" | |
| "Is this image or claim authentic?" | |
Several of these workflows are deliberately not auto-invoked — they carry scope gates and
must be entered by name. Naming them from here is the intended path.
| 你所持的标识 | 使用的工作流 |
|---|---|
| 模糊请求,或暂无任何标识 | |
| 个人姓名 | |
| 公司、品牌或网站 | |
| 域名、网站或IP | |
| 电子邮箱地址 | |
| 电话号码 | |
| 用户名或账号 | |
| 照片或视频 | 完整工作流使用 |
| 加密货币地址或交易记录 | |
| 尾号、呼号、IMO或MMSI | |
| 泄露声明、凭证或组合列表 | 先使用 |
| 已确认的社交账号 | |
| 已完成的证据集 | |
商业场景需求可对应至相同工作流:
| 需求内容 | 路由路径 |
|---|---|
| “在签约或付款前核验该供应商/交易对手/卖方” | |
| “这份发票或付款变更通知是否真实?” | |
| “这份工作邀约、招聘人员或市场卖家是否真实?” | |
| “KYB / UBO / 制裁筛查” | |
| “我们的外部攻击面是什么?” | |
| “我们高管的哪些信息已泄露?” | |
| “这张图片或声明是否真实?” | |
部分工作流不会自动触发——它们设有范围限制,必须通过名称调用。从此处指定名称是预期的操作路径。
Step 3 — Work cheapest and least intrusive first
步骤3——优先选择成本最低、侵入性最小的方式
Structured official record → published output → regulated registers → corporate filings →
public legal and property records → social and behavioural → aggregators → archives. Do
not start with data brokers; they hand you plausible wrong answers before you have any way
to reject them.
Before touching anything that could tip off the subject, read
.
investigate-without-getting-made顺序为:结构化官方记录 → 公开输出内容 → 受监管的注册信息 → 企业备案文件 → 公开法律与财产记录 → 社交与行为数据 → 聚合平台 → 档案资料。不要从数据经纪商开始;在你有能力甄别错误信息前,它们可能会提供看似合理的错误答案。
在接触任何可能惊动调查对象的内容前,请阅读。
investigate-without-getting-madeStep 4 — Grade before you report
步骤4——报告前先评级
Two independent sources per claim, where independent means different origin, not different
website. Grade the identity attribution separately from the claim itself — a record can be
entirely genuine and still not be your subject. Record negative findings; an absence is a
finding, not a gap to hide.
Hand off to .
write-the-intel-brief每项主张需有两个独立来源,独立指来源不同,而非网站不同。身份归因的评级需与主张本身分开——记录可能完全真实,但仍不属于你的调查对象。记录负面发现;缺失信息本身也是一项发现,而非需要隐瞒的空白。
将结果移交至工作流。
write-the-intel-briefWhere this goes wrong
常见失误
- Skipping scope. The most common failure is collecting first and justifying later.
- Name collision. Never search a name alone; bind it to a second selector first.
- Aggregators laundering each other. Three brokers agreeing is one source.
- Over-trusting a photo match. A shared image proves shared images, not shared identity.
- Treating a sparse footprint as concealment. It usually means a private person, a non-English footprint, or closed registries.
- 跳过范围设定:最常见的失误是先收集信息,后寻找理由。
- 姓名冲突:切勿仅搜索姓名;需先将其与第二个标识绑定。
- 聚合平台互相验证:三家经纪商达成一致仍属于单一来源。
- 过度信任照片匹配结果:共享照片仅能证明照片被共享,无法证明身份一致。
- 将稀疏的数字足迹视为刻意隐藏:这通常意味着对方是私人个体、使用非英语环境的数字足迹,或注册信息未公开。