mcpbeat

Offensive Osint

snailsploit/offensive-osint

Comprehensive OSINT methodology skill for offensive security, red team intelligence gathering, and bug bounty reconnaissance. Covers domain recon, email harvesting, social media profiling, GitHub/code leaks, Shodan/Censys enumeration, breach data lookup, employee profiling, infrastructure mapping, cryptocurrency tracing, geospatial intelligence, and AI-assisted analysis workflows. Use when performing reconnaissance against a target domain or organization, investigating a person or entity, tracing cryptocurrency flows, geolocating images or events, or building an attack-surface map.

6k tokens
context cost
the whole folder, loaded on every use
1
files
instructions only
0
copies elsewhere
how many repositories repackaged it
2806
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/SnailSploit/Claude-Red --skill offensive-osint

The instruction itself

39 sections, as written by the author

Offensive OSINT Methodology

Workflow

  • Define target scope (domain, org, person, crypto address, or geo subject)
  • Select applicable categories below based on scope
  • Work top-down within each category; pivot on discovered artifacts
  • Archive every key artifact: URL + timestamp + screenshot (PNG) + hash (SHA-256)
  • Log findings in JSONL with a run_id and tool versions for reproducibility
  • Suggest next steps based on what each tool returns

General OSINT

Search Engines

| Tool | Notes |

|------|-------|

| Carrot2 | Clusters results by topic |

| etools | Metasearch engine |

| Kagi | Privacy-first, non-personalized results |

| Brave Search | Independent index; Goggles for custom ranking |

| PDF Search | Search PDF files and view table of contents |

| Google Fact Check Explorer | Cross-site fact-check search |


Username & Email Investigation

| Tool | Purpose |

|------|---------|

| Sherlock | Username search across social networks |

| Maigret | Collect profiles by username from many sites |

| What's My Name | Username search across platforms |

| Holehe | Check if email is registered on platforms |

| Epieos | Email address pivots and metadata |

| OSINT Industries | Email/username/phone lookups |

| Hunter.io | Find email addresses for a domain |

| EmailRep | Email reputation and associated data |

| Emailable | Verify email existence |

| Mugetsu | X/Twitter username history |

| RocketReach / Apollo | Email enrichment and pattern guessing |

| PhoneInfoga | Phone number intelligence framework |

Browser extensions: GetProspect, SignalHire



Phone Number OSINT


Social Media

| Platform | Tool |

|----------|------|

| Instagram | Picuki — view profiles without account |

| X/Twitter | snscrape — preferred CLI scraper; use Twint only as fallback |

| Facebook | Graph Search, sowsearch.info, lookup-id.com, whopostedwhat.com |

| Facebook (research) | Meta Content Library — CrowdTangle successor (researcher-gated) |

| YouTube/Twitch | Social Blade — analytics |

| TikTok | Tokboard — trend and profile analytics |

| Reddit | Reveddit — removed content; RedTrack.social — user history |

| Bluesky | Firesky — real-time firehose; SkyView — follower graphs |

| Mastodon | FediSearch — cross-instance search; Fedifinder — find Twitter users on Mastodon |

| Faces | Search4Faces |


Public Records & Company Information

RU/CN Registries

Russia: Rusprofile, Kontur.Focus (freemium), zakupki.gov.ru (procurement), EGRUL/EGRIP (official, captcha-gated)

China: GSXT (National Enterprise Credit), Qichacha/Tianyancha (freemium), MIIT ICP/Beian (ICP filings)

Sanctions & Compliance


Breach & Leak Data


Infrastructure & Attack-Surface OSINT

ASN/BGP & Internet Measurement

Certificates & CT Monitoring

  • crt.sh — Search Certificate Transparency logs
  • Censys Certificates — CT and x509 attribute pivots
  • CertStream — Real-time CT feed via WebSocket
  • Rapid7 Open Data — Sonar DNS/HTTP/SSL datasets
  • Cert Spotter [Freemium] — CT monitoring and alerts
  • Favicon hash (mmh3): cluster infrastructure; pair with Shodan/Censys favicon search

Threat Intel & IOCs

Malware Analysis & Sandboxes


Cryptocurrency OSINT

Blockchain Explorers

| Chain | Explorer |

|-------|---------|

| Bitcoin | Blockchain.com, Blockchair |

| Ethereum | Etherscan |

| BNB Chain | BSCScan |

| Polygon PoS | PolygonScan |

| Solana | Solscan |

| Multi-chain | OKLink Freemium], [Cielo |

L2 Explorers: Arbiscan, Optimistic Etherscan, BaseScan, zkSync Era, L2Beat (risk/TVL comparison)

Transaction Tracking & Analytics

NFT & Exchange Intelligence

Bridge Monitoring


Media Intelligence

Image Forensics

Video Analysis

Browser Extensions for Media


Geospatial Intelligence

Satellite Imagery & Mapping

Geolocation Tools

Street View: Google Street View, Apple Maps, Yandex Maps, Baidu Maps

Flight OSINT

Maritime OSINT


AI-Assisted OSINT

> Warning: Never paste PII, sensitive IOCs, or unique pivots into cloud LLMs. They log inputs and may use them for training. Use local models (Ollama, LM Studio) for sensitive analysis.

| Tool | Strength |

|------|---------|

| ChatGPT (paid) | Log parsing, dataset analysis, Code Interpreter for CSVs/JSON, GPT-4 Vision for image OCR |

| Claude (paid) | 200K token context for large document dumps and report synthesis |

| Gemini 1.5 Pro | 2M token context; Deep Research mode with citations |

| Perplexity Pro (paid) | Real-time web search + reasoning; multi-query synthesis |

Local/privacy-preserving: Ollama (Llama 3, Mistral), LM Studio, GPT4All

Commercial AI OSINT Platforms

Deepfake & Synthetic Media Detection


Archiving & Evidence Preservation

  • archive.today — One-page content archiver with screenshot
  • URLScan.io — On-demand webpage scan with resource map
  • ArchiveBox — Self-hosted archiving (HTML, PDF, screenshots, media)
  • Hunchly — Evidence capture for investigators (paid)
  • Wayback SavePageNow API v3 — On-demand archiving with job IDs
  • SingleFileZ — Browser extension for offline HTML archives
  • Kasm Workspaces — Containerized OSINT workspace/browser isolation

Evidence handling:

  • Capture: URL + timestamp + PNG screenshot + WARC/SingleFileZ archive
  • Hash all downloaded files (SHA-256) and record in case notes
  • Separate work profiles/containers per case; store evidence read-only
  • Use JSONL (NDJSON) logs with run_id and tool versions for reproducibility

Automation & Workflows

  • n8n — Self-hosted workflow automation (e.g., RSS → scrape → alert pipelines)
  • Huginn — Agent-based monitoring, scraping, alerting
  • Playwright — Headless browser automation with stealth plugins
  • Browsertrix Crawler — Archival crawling with WARC export
  • Prefect / Apache Airflow — Workflow orchestration for data pipelines

Regional Search Engines


Telegram & Messaging Intelligence

  • TGStat — Channel analytics and search
  • Telemetr — Channel growth, overlaps, forwards
  • Combot — Group analytics (partially paid)
  • TelegramDB Search Bot — Basic Telegram OSINT
  • Discord ID — Basic Discord account information
  • Sogou Weixin search — WeChat Official Accounts content search
  • View public Telegram channels: https://t.me/s/<channel>

How to use it

Copy the folder

Take snailsploit/offensive-osint from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.