🌍 Open Source Intelligence (OSINT)
Publicly Available Information, Systematically Collected
General
Sources
2
2 no-auth
Mission domains
2
reach
Data points
1
covered
Related INT
1
disciplines
🔌 Sources for Open Source Intelligence (2)
| Source | Category | Auth | Format | |
|---|---|---|---|---|
| MetaMask eth-phishing-detect Community crypto-phishing domain blocklist (100k+ domains). | Crypto Phishing | NONE | json | home↗ api↗ |
| ScamSniffer scam domains Community crypto scam / drainer domains. | Crypto Phishing | NONE | json | home↗ api↗ |
🎯 Mission Domains served
🎫 Data Points
🔍 Lookup
📊 Pre-built Queries · Open Source Intelligence
🔄 Live Datasets & APIs (2 key-free · ingestible)
📜 Playbook — Open Source Intelligence collection
- Direction — frame the requirement for Open Source Intelligence: what decision does this support, by when?
- Collection — collect from the 2 mapped sources (2 free) — filter the catalog by OSINT; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
🔗 Pivot to related disciplines
✨ Enrichment pathways
🎯 Mission
Open Source Intelligence collects publicly available web, social, and technical data to build a picture of targets from freely accessible footprints. It answers who owns an identity or infrastructure, where a person or asset is located, and how disparate public breadcrumbs connect into a single entity.
📡 Collection methods
- Domain and infrastructure footprinting (WHOIS, DNS, ASN mapping)
- Username enumeration across platforms
- Breach-data correlation and credential exposure checks
- Geolocation and chronolocation of imagery
- Reverse image search and EXIF metadata extraction
- Advanced search-operator (dorking) discovery
- Certificate-transparency subdomain harvesting
📚 Key sources & datasets
🎫 Data points produced
🔧 Tools & frameworks
- Maltego
- SpiderFoot
- Amass
- theHarvester
- Sherlock
- ExifTool
- Recon-ng
- Photon
📜 Open Source Intelligence Tradecraft
- Collect selectors (domains, emails, handles) and expand via footprinting and enumeration tools
- Deduplicate and enrich results, resolving domains to IPs, ASNs, and certificates
- Analyze links across breach data, social profiles, and infrastructure to cluster one identity
- Attribute the cluster to a real person or org using corroborating imagery, metadata, and reuse patterns
- Compile a sourced dossier with pivot chains and confidence ratings
- Hand selectors to specialist disciplines and monitor for changes on key assets
📊 Dashboard KPIs
Selectors enrichedIdentities resolvedBreach exposures foundSubdomains discoveredPivot depth achieved
🔍 Pre-built queries
🔗 Cross-discipline pivots
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron