Loading...
Loading...
Found 844 Skills
Compile OSINT findings into a professional, sourced, and timestamped intelligence report that separates confirmed facts from inference.
Corporate intelligence and due-diligence workflow — map a company's legal structure, people, infrastructure, footprint, and risk from public records.
Craft advanced search-engine queries to surface hidden or specific content. Use when building Google dorks, using search operators (site, filetype, intext, inurl), finding exposed files or documents, or narrowing searches for a name, email, or leak.
Start-here router for any OSINT investigation. Names the workflow and knowledge skills and picks the right one for a given starting selector.
Investigate an email address — validate it, find linked accounts and breaches, and pivot to the owner's identity, usernames, and other contact selectors.
Organize investigation findings into an entity-relationship graph to reveal connections. Use when mapping links between people, accounts, and infrastructure, building a Maltego-style graph, visualizing selectors and pivots, or untangling a complex network.
Mine GitHub, GitLab, and git history for people, infrastructure, and leaked secrets. Use when investigating a developer or org on GitHub, finding leaked API keys or credentials in code, or pivoting from commits, emails, and repos.
Workflow to build a sourced profile of a named individual from public sources, pivoting across identity, contact, social, and location selectors.
Corporate due-diligence workflow — resolve a brand or website to its registered legal entity, map group structure and beneficial ownership, profile officers and directors, enumerate the digital estate, and screen litigation, insolvency, procurement, sanctions, PEP, and adverse media. Use for vendor and counterparty risk, KYC/KYB, M&A diligence, investor checks, or shell-company assessment.
Investigate an email address — MX and syntactic validation, Gravatar lookup, corporate email-format inference, breach exposure, and full mail-header analysis (Received chain, Message-ID, SPF/DKIM/DMARC). Use for email OSINT, verifying whether an address exists, finding accounts registered to an address, guessing a company's email format, or tracing where a message actually came from.
Look up companies, officers, and ownership in official business registries and filings. Use when researching a company's legal entity, finding directors/shareholders/beneficial owners, checking incorporation records, or reading SEC/regulatory filings.
Find internet-exposed hosts, services, and devices from third-party scan data. Use when searching Shodan or Censys, finding open ports and banners, identifying an IP's tech stack, or discovering exposed databases, cameras, or industrial devices — without scanning the target yourself.