Skip to content
Back to skills

Osint Investigator

ASecurity

Conduct ethical open-source intelligence investigations using public data — for due diligence, incident enrichment, and brand protection.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 29, 2026
ai-agentsrustgoawsgitapisecuritydocumentation

Works with

  • api

Security analysis

A100/100

Scanned September 29, 2026

npx -y skills add aicodedecode/awesome-muse-skills --skill osint-investigator --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Osint Investigator?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Osint Investigator
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-osint-investigator/badge)](https://www.skillsdirectory.com/skills/aicodedecode-osint-investigator)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: osint-investigator
description: Conduct ethical open-source intelligence investigations using public data — for due diligence, incident enrichment, and brand protection.
category: security
---

## Overview

OSINT (open-source intelligence) is the collection and analysis of **publicly available** information: DNS and certificate records, public code repos, social media, breach datasets, company filings, and more. Defenders use it for incident enrichment, executive due diligence, brand/typosquat monitoring, and third-party risk — all without touching anyone's private systems.

This skill covers ethical OSINT methodology: passive collection, source verification, and documentation. It explicitly excludes accessing non-public data, pretexting, or any technique that crosses into unauthorized access.

OSINT is a tradecraft of patience: the answer is usually public, but buried under noise, misdirection, and stale data. Professionals distinguish themselves through source criticism — asking of every find who published this, when, why, and what would disprove it — and through disciplined documentation that lets others verify the trail.

## When to use

- Enriching an incident: is this domain/IP known-malicious? Who registered it?
- Executive and vendor due diligence from public records.
- Brand protection: typosquat domains, fake social profiles, leaked credentials.
- Attack-surface discovery on your *own* assets (cert transparency, exposed repos, public buckets).
- Background research for hiring, partnerships, or journalism — within legal bounds.

## Core concepts

- **Passive first:** OSINT should not alert or touch the subject. Use cached/historical sources (certificate transparency logs, DNS history, archives) before any direct interaction.
- **Public means public:** if it requires credentials you do not legitimately hold, bypassing access controls, or deception to obtain — it is not OSINT, it is unauthorized access.
- **Verify across sources:** single-source "facts" are rumors. Corroborate identities, dates, and relationships across independent sources before acting on them.
- **Document everything:** URLs, timestamps, screenshots, and search queries. OSINT findings need provenance to be trustworthy and defensible.
- **Know your jurisdiction:** privacy laws (GDPR and equivalents), terms of service, and sector regulations constrain even public-data collection. When in doubt, legal review.
- **Operational hygiene:** separate research identities and browsers from personal ones; be aware that your queries can be logged by the services you use.

- **Historical sources beat live ones.** Archives, certificate history, and DNS history reveal what the subject tried to erase — always check the past, not just the present.
- **Pivot systematically.** One identifier (domain, email, handle) leads to infrastructure, which leads to related entities. Map the graph; do not just collect points.
- **Research-identity hygiene.** If your work requires viewing restricted-but-public content, use dedicated research accounts separated from personal identity — and never to deceive.

## Practical workflow

1. **Define the question:** "Is domain X malicious?" beats "research X." Scope the questions, the subject, and what is off-limits — in writing.
2. **Start with infrastructure:** for domains/IPs — WHOIS history, passive DNS, certificate transparency, ASN and hosting reputation, threat-intel reputation checks.
3. **Check exposure:** certificate transparency for rogue subdomains; public code search for leaked secrets tied to your org; breach datasets for executive/vendor emails (via legitimate lookup services).
4. **Public profile review:** company registries, press, social profiles *as publicly visible* — no connection-request pretexting, no fake accounts to bypass privacy settings.
5. **Corroborate and assess:** cross-check key claims across sources; grade confidence (confirmed / likely / uncorroborated); note what you could *not* verify.
6. **Report with provenance:** findings, confidence levels, source list with access dates, and recommended defensive actions (takedown requests, monitoring, credential resets).

### Defensive OSINT checklist (your own org, quarterly)

- [ ] Certificate transparency: unknown subdomains or certs
- [ ] Typosquat/lookalike domain registrations near your brands
- [ ] Public code and paste sites for leaked secrets/keys
- [ ] Executive names in breach datasets (credential-reset prompts)
- [ ] Fake social profiles impersonating brand or executives
- [ ] Exposed cloud storage and public repos under org accounts

### Sustaining the practice

- Maintain watchlists for brand, executive, and infrastructure indicators
- Refresh key investigations quarterly — public data changes
- Build a trusted source list per investigation type to speed future work
- Debrief false leads: what misled you, and what check would have caught it?

### Metrics that prove it works

- Turnaround per investigation question
- Source corroboration rate (multi-source confirmed vs single-source)
- False-lead rate (findings later disproven)
- Defensive action rate (takedowns filed, exposures remediated)

## Common pitfalls

- **Crossing into unauthorized access.** "It was on the internet" does not make bypassing logins or exploiting an exposed endpoint acceptable. If it is not public, stop.
- **Pretexting and fake personas.** Creating false identities to extract information is deception, not research — and often illegal.
- **Single-source conclusions.** Acting on one unverified post or record. Corroborate or label confidence honestly.
- **Doxxing-adjacent behavior.** Publishing or circulating personal data about individuals, even if public, can violate policy and law. Keep a strict need-to-know.
- **No documentation.** "I saw it somewhere" is useless in an incident review or legal matter. Capture provenance as you go.
- **Ignoring ToS and local law.** Scraping in violation of terms or collecting personal data unlawfully creates liability for the investigator and the org.
- **Attribution overconfidence.** OSINT suggests; it rarely proves. Grade confidence honestly — "likely" is not "confirmed," especially when actions depend on it.
- **Collecting beyond the question.** Scope creep into personal data creates legal exposure and noise. Answer the defined questions, document, stop.
- **Confusing data volume with insight.** A 200-page dump of unanalyzed records is not intelligence. Analyze, assess confidence, and answer the question asked.
- **Neglecting your own exposure.** Investigators get investigated. Practice good OPSEC on your research infrastructure and identities.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…