Disciplines

🌍 Open Source Intelligence (OSINT)

Publicly Available Information, Systematically Collected
General

Sources

2
2 no-auth

Mission domains

2
reach

Data points

1
covered

Related INT

1
disciplines

🔌 Sources for Open Source Intelligence (2)

SourceCategoryAuthFormat
MetaMask eth-phishing-detect
Community crypto-phishing domain blocklist (100k+ domains).
Crypto PhishingNONEjsonhome↗ api↗
ScamSniffer scam domains
Community crypto scam / drainer domains.
Crypto PhishingNONEjsonhome↗ api↗

🎫 Data Points

domain (2) →

🔍 Lookup

📜 Playbook — Open Source Intelligence collection

  1. Direction — frame the requirement for Open Source Intelligence: what decision does this support, by when?
  2. Collection — collect from the 2 mapped sources (2 free) — filter the catalog by OSINT; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🔗 Pivot to related disciplines

CRYPTINT Cryptocurrency Intelligence →

🎯 Mission

Open Source Intelligence collects publicly available web, social, and technical data to build a picture of targets from freely accessible footprints. It answers who owns an identity or infrastructure, where a person or asset is located, and how disparate public breadcrumbs connect into a single entity.

📡 Collection methods

  • Domain and infrastructure footprinting (WHOIS, DNS, ASN mapping)
  • Username enumeration across platforms
  • Breach-data correlation and credential exposure checks
  • Geolocation and chronolocation of imagery
  • Reverse image search and EXIF metadata extraction
  • Advanced search-operator (dorking) discovery
  • Certificate-transparency subdomain harvesting

🔧 Tools & frameworks

  • Maltego
  • SpiderFoot
  • Amass
  • theHarvester
  • Sherlock
  • ExifTool
  • Recon-ng
  • Photon

📜 Open Source Intelligence Tradecraft

  1. Collect selectors (domains, emails, handles) and expand via footprinting and enumeration tools
  2. Deduplicate and enrich results, resolving domains to IPs, ASNs, and certificates
  3. Analyze links across breach data, social profiles, and infrastructure to cluster one identity
  4. Attribute the cluster to a real person or org using corroborating imagery, metadata, and reuse patterns
  5. Compile a sourced dossier with pivot chains and confidence ratings
  6. Hand selectors to specialist disciplines and monitor for changes on key assets

📊 Dashboard KPIs

Selectors enrichedIdentities resolvedBreach exposures foundSubdomains discoveredPivot depth achieved
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php