osint-recon-automation
Installation
SKILL.md
OSINT Recon Automation
Authorization Boundary
- Restrict to your own assets, bug bounty programs with explicit scope, or assignments with written authorization.
- No social engineering, doxing, harassment, or targeting individuals.
- Respect rate limits and provider terms; never weaponize discovered credentials.
Recon Workflow
- Seed: registered domains, ASNs, org names, GitHub orgs, app store handles.
- Expand passively: cert transparency, passive DNS, reverse WHOIS, ASN ranges, code search, leaked credential repos, archive snapshots.
- Resolve and validate:
dnsx,httpx, screenshot withgowitnessoraquatone. - Pivot: shared favicons (
favfreak), Google Analytics IDs, S3 bucket naming, JS endpoints, ASN neighbors. - Dedupe and graph: build a node-edge model
(asset)-[relation]->(asset)and store in Neo4j or JSONL. - Monitor: diff snapshots; alert on new subdomain, new exposed service, leaked secret, or impersonation domain.