osint-technique
Audited by Socket on Sep 5, 2026
5 alerts found:
Securityx5SUSPICIOUS. The skill is coherent as an OSINT/recon methodology guide, but its actual footprint is broader than passive research: it teaches credential discovery/validation, identity and tenant enumeration, exploit-adjacent probing, and extensive interaction with third-party services. It is not confirmed malware or covert exfiltration, yet it gives an AI agent offensive security capabilities and sensitive-data handling patterns that create high operational risk.
The provided fragment is not malware in the conventional sense, but it is a targeted, multi-source email harvesting and identity enumeration workflow for a specific domain, using certificate transparency data, theHarvester, and authenticated GitHub commit searches. It consolidates harvested PII into plaintext files and includes instructions for email pattern inference and deliverability checks, which together strongly indicate phishing/spam enablement potential. No obvious obfuscation or exploit/persistence primitives are present in the shown code, but the behavior is high-risk from an abuse-prevention perspective.
High likelihood of malicious/offensive use: the fragment is an explicit identity/tenant/user enumeration and misconfiguration reconnaissance playbook. It actively probes authentication-related endpoints (Microsoft GetCredentialType and Okta /api/v1/authn in deep mode) and performs crafted GraphQL queries/subscription probing to extract further attack surface. No meaningful obfuscation is present, but the operational intent is hostile (account/tenant enumeration and phishing-enabling discovery). Recommend treating as dangerous if encountered in a supply-chain context and avoid inclusion/use.
No classic malware or supply-chain compromise behavior is evident in the provided snippet (no exfiltration, persistence, credential theft, or obfuscation). However, the artifact is an end-to-end, operationally actionable tradecraft for reconstructing and refining an individual’s location from proximity/distance signals and photo/EXIF/sun/landmark evidence, including guidance to bypass common distance-privacy defenses. This presents a severe privacy/safety risk if distributed or used for non-consensual tracking/stalking.
This fragment is a highly actionable adversary-style OSINT and targeting playbook. It provides end-to-end instructions to enumerate LinkedIn employees, derive and validate likely corporate email addresses against breach/verification sources, prioritize high-value targets, and generate personalized pretext hooks. It also instructs stealth/evasion measures and uses job-posting tech/vendor details to support follow-on offensive recon. While not malware code itself, the content is strongly associated with phishing/BEC and credential/secret abuse facilitation and should be treated as high-risk supply-chain material if distributed as part of a package or repository.