| name | collecting-open-source-intelligence |
| description | Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using publicly available data sources, passive reconnaissance tools, and dark web monitoring. Use when investigating external threat actor infrastructure, performing pre-engagement reconnaissance for authorized red team assessments, or enriching CTI reports with publicly available adversary context. Activates for requests involving Maltego, Shodan, OSINT framework, SpiderFoot, or infrastructure reconnaissance.
|
| domain | cybersecurity |
| subdomain | threat-intelligence |
| tags | ["OSINT","Maltego","Shodan","Recon-ng","SpiderFoot","threat-intelligence","ATT&CK-T1591","NIST-CSF"] |
| version | 1.0.0 |
| author | mahipal |
| license | Apache-2.0 |
| nist_csf | ["ID.RA-01","ID.RA-05","DE.CM-01","DE.AE-02"] |
Collecting Open-Source Intelligence
When to Use
Use this skill when:
- Investigating external infrastructure associated with a phishing campaign targeting your organization
- Enriching threat actor profiles with publicly observable indicators (WHOIS, ASN data, SSL certificates)
- Conducting authorized attack surface discovery to understand your organization's external exposure
Do not use this skill for active scanning against targets without explicit written authorization — OSINT collection must remain passive (no packets sent to target systems) unless scope permits active recon.
Detection Gaps & Validation
- Coverage gaps from a single source: Shodan, crt.sh, and passive DNS each see only a slice. A C2 behind Cloudflare shows the CDN IP, not origin; cert transparency misses some wildcard certs. Cross-check at least three independent sources before concluding infrastructure is mapped.
- False attribution from shared infrastructure: co-hosted domains on a bulletproof/shared host, or a reused Cobalt Strike watermark, do not establish a single actor. Treat each Maltego pivot as a hypothesis and verify the link independently.
- Stale data treated as live: 6-month-old passive DNS or expired WHOIS still resolves in the graph. Stamp every indicator with collection date and source, and discard pivots whose timestamps predate the campaign window.
- OPSEC leakage is also a coverage problem: directly visiting a target's site or actively probing its IP can tip off the adversary and crosses into active recon. Keep collection passive (cached/third-party data) unless scope authorizes active probing.
- Validate before reporting: confirm a candidate IOC against an independent enrichment (VirusTotal/OTX/PassiveTotal), record a confidence score, and explicitly note remaining collection gaps rather than presenting partial coverage as complete.
Prerequisites
- Maltego CE or commercial license for graph-based link analysis
- Shodan API key (https://shodan.io) for internet-wide device/service discovery
- OSINT Framework familiarity (https://osintframework.com) for tool selection
- SpiderFoot HX or open-source SpiderFoot for automated OSINT correlation
Workflow
Step 1: Define Collection Requirements
Establish the intelligence requirement (IR) before collecting. Document:
- Target: threat actor group, malicious domain, IP range, or organization
- Priority Intelligence Requirements (PIRs): What specific questions need answering?