offensive-osint
覆盖多类来源与标准化日志,便于规模化与系统化侦查。
可用于敏感目标画像与追踪,存在隐私与合规风险。
面向渗透与情报的全方位 OSINT 收集、记录与关联指南。
面向红队和漏洞赏金的 OSINT 操作手册,覆盖域名侦察、邮箱收集、社媒画像、GitHub/code 泄露、Shodan/Censys 枚举、泄露数据查验、员工画像、基础设施映射、加密货币追踪和地理情报等。用在对某个域名、组织或个人做侦察、绘制攻击面或定位证据时。特色是强调可复现的证据归档(URL、时间戳、截图、SHA-256)并用 JSONL 记录整个发现链。
▸ 展开 SKILL.md 英文原文
Comprehensive OSINT methodology skill for offensive security, red team intelligence gathering, and bug bounty reconnaissance. Covers domain recon, email harvesting, social media profiling, GitHub/code leaks, Shodan/Censys enumeration, breach data lookup, employee profiling, infrastructure mapping, cryptocurrency tracing, geospatial intelligence, and AI-assisted analysis workflows. Use when performing reconnaissance against a target domain or organization, investigating a person or entity, tracing cryptocurrency flows, geolocating images or events, or building an attack-surface map.
帮我安装这个 skill:https://raw.githubusercontent.com/SnailSploit/Claude-Red/main/Skills/recon/offensive-osint/SKILL.mdcurl -fsSL "https://raw.githubusercontent.com/SnailSploit/Claude-Red/main/Skills/recon/offensive-osint/SKILL.md"# Offensive OSINT Methodology ## Workflow 1. Define target scope (domain, org, person, crypto address, or geo subject) 2. Select applicable categories below based on scope 3. Work top-down within each category; pivot on discovered artifacts 4. Archive every key artifact: URL + timestamp + screenshot (PNG) + hash (SHA-256) 5. Log findings in JSONL with a `run_id` and tool versions for reproducibility 6. Suggest next steps based on what each tool returns --- ## General OSINT - [Bookmarks](https://tools.myosint.training/) — Comprehensive OSINT bookmarks - [OSINT Framework](https://osintframework.com/) — Tool/resource directory - [IntelTechniques Tools](https://inteltechniques.com/tools/) —