Total 52,033 skills, Security & Compliance has 2053 skills
Showing 12 of 2053 skills
Enumerate a username or handle across hundreds of platforms and pivot from matched accounts to real-identity, contact, and content selectors.
Passive reconnaissance workflow for a domain, website, or IP — maps DNS, subdomains, infrastructure, tech stack, history, and ownership without touching the target.
Compile OSINT findings into a professional, sourced, and timestamped intelligence report that separates confirmed facts from inference.
Operational security for investigators — create and maintain research accounts and browse without exposing your identity. Use when setting up a sockpuppet or research persona, avoiding attribution while investigating, or hardening a browsing environment.
Organize investigation findings into an entity-relationship graph to reveal connections. Use when mapping links between people, accounts, and infrastructure, building a Maltego-style graph, visualizing selectors and pivots, or untangling a complex network.
Corporate intelligence and due-diligence workflow — map a company's legal structure, people, infrastructure, footprint, and risk from public records.
Find internet-exposed hosts, services, and devices from third-party scan data. Use when searching Shodan or Censys, finding open ports and banners, identifying an IP's tech stack, or discovering exposed databases, cameras, or industrial devices — without scanning the target yourself.
Workflow to build a sourced profile of a named individual from public sources, pivoting across identity, contact, social, and location selectors.
Mine GitHub, GitLab, and git history for people, infrastructure, and leaked secrets. Use when investigating a developer or org on GitHub, finding leaked API keys or credentials in code, or pivoting from commits, emails, and repos.
Start-here router for any OSINT investigation. Names the workflow and knowledge skills and picks the right one for a given starting selector.
Craft advanced search-engine queries to surface hidden or specific content. Use when building Google dorks, using search operators (site, filetype, intext, inurl), finding exposed files or documents, or narrowing searches for a name, email, or leak.
Search paste sites, forums, and text dumps for leaked or mentioned selectors. Use when searching Pastebin or paste sites, monitoring forums and Telegram for leaks, finding a name/email/domain in dumps, or tracking chatter about a target.