Disciplines

📧 Email Intelligence (EMAILINT)

Email Addresses, Headers, and Mail Infrastructure
Identity

Sources

0
0 no-auth

Mission domains

0
reach

Data points

0
covered

Related INT

0
disciplines

🔍 Lookup

📜 Playbook — Email Intelligence collection

  1. Direction — frame the requirement for Email Intelligence: what decision does this support, by when?
  2. Collection — collect from the 0 mapped sources (0 free) — filter the catalog by EMAILINT; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎯 Mission

EMAILINT collects intelligence from email addresses, message headers, mail infrastructure, and breach corpora to resolve digital identities, map account footprints, and assess exposure. It answers who owns an address, where else that identity is registered, and whether its credentials are compromised.

📡 Collection methods

  • Non-invasive SMTP RCPT-TO/VRFY handshakes and catch-all detection to verify deliverability without sending
  • Received-chain and header forensics to recover originating IP, mail path, mailer fingerprint, and timezone
  • Breach corpus correlation to map credential reuse and account age across dumps
  • Username/pattern permutation (first.last, f.last) against corporate MX to infer valid addresses
  • Gravatar MD5-hash lookup and platform account-existence (password-reset) probing for profile linkage
  • SPF/DKIM/DMARC and MX enumeration to fingerprint the hosting provider and spoofability

🔧 Tools & frameworks

  • Holehe
  • GHunt
  • Mosint
  • h8mail
  • theHarvester
  • Maltego
  • SpiderFoot

📜 Email Intelligence Tradecraft

  1. Collect: enumerate the target address across breach indexes and platform account-existence checks
  2. Process: parse mail headers and normalize breach records into a unified identity table
  3. Analyze: correlate password and username reuse with registration timestamps to cluster accounts
  4. Attribute: pivot the Gravatar hash and reused handles to a named person and real-world profile
  5. Disseminate: publish an identity dossier with per-source confidence scores and provenance
  6. Action: flag exposed credentials for takedown, reset enforcement, or a monitoring watchlist

📊 Dashboard KPIs

Addresses enrichedBreach hitsAccounts linkedVerified deliverable %Reuse clusters
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php