| name | osint-recon |
| description | OSINT investigation and reconnaissance workflows. Username enumeration, domain intelligence, dark web monitoring, social media analysis, and structured investigation methodology. Use for authorized OSINT research, threat intelligence, and security investigations.
|
OSINT Recon
Open Source Intelligence investigation and reconnaissance workflows.
how to use
-
/osint-recon
Apply OSINT methodology to the current investigation.
-
/osint-recon <target-type>
Plan an OSINT investigation for username, domain, email, or organization.
when to apply
Reference these guidelines when:
- investigating usernames or email addresses
- performing domain intelligence gathering
- conducting threat intelligence research
- analyzing social media footprints
- mapping organizational structure
- participating in OSINT CTF challenges
investigation methodology
OSINT Cycle
- Planning: Define objectives, scope, legal constraints
- Collection: Gather raw data from open sources
- Processing: Clean, normalize, deduplicate data
- Analysis: Correlate findings, identify patterns
- Dissemination: Report findings with confidence levels
- Feedback: Refine collection based on gaps
Evidence Classification
| Level | Description | Example |
|---|
| Confirmed | Multiple independent sources | Username + email + profile photo match |
| Probable | Strong single source or partial corroboration | Username match + similar bio |
| Possible | Single weak source | Username exists on platform |
| Doubtful | Contradictory or unreliable | Common username, no distinguishing info |
username enumeration
Sherlock-Style Patterns
import asyncio
import aiohttp
from typing import TypedDict
class UsernameResult(TypedDict):
platform: str
url: str
status: str
response_time_ms: float
PLATFORMS = {
"github": "https://github.com/{username}",
"twitter": "https://x.com/{username}",
"instagram": "https://instagram.com/{username}",
"reddit": "https://reddit.com/user/{username}",
"linkedin": "https://linkedin.com/in/{username}",
"medium": "https://medium.com/@{username}",
"dev.to": "https://dev.to/{username}",
"hackernews": "https://news.ycombinator.com/user?id={username}",
}
async def check_username(
session: aiohttp.ClientSession,
platform: str,
url: str,
) -> UsernameResult:
"""Check if username exists on a platform."""
try:
async with session.get(url, timeout=aiohttp.ClientTimeout(total=10)) as resp:
return {
"platform": platform,
"url": url,
: resp.status == ,
: ,
}
Exception:
{: platform, : url, : , : }
Key Tools
- Sherlock: Username enumeration across 400+ sites
- WhatsMyName: Web-based username search
- Namechk: Domain + username availability
domain intelligence
DNS & WHOIS
dig +short A example.com
dig +short MX example.com
dig +short TXT example.com
dig +short NS example.com
whois example.com
subfinder -d example.com -silent
curl -s "https://crt.sh/?q=%25.example.com&output=json" | jq '.[].name_value'
Technology Fingerprinting
- Wappalyzer: Browser extension for tech stack detection
- BuiltWith: Historical technology data
- Shodan: Internet-connected device search
- Censys: Certificate and host search
email intelligence
Email Verification Patterns
def email_osint(email: str) -> dict:
"""Gather intelligence from an email address."""
local_part, domain = email.split("@")
return {
"email": email,
"domain_info": {
"mx_records": dns_lookup(domain, "MX"),
"spf_record": dns_lookup(domain, "TXT", filter="spf"),
"dmarc_record": dns_lookup(f"_dmarc.{domain}", "TXT"),
},
"breach_check": "Use HaveIBeenPwned API",
"social_profiles": "Cross-reference with username enumeration",
"domain_age": "WHOIS creation date",
}
Tools
- theHarvester: Email, subdomain, name harvesting
- Hunter.io: Email pattern discovery
- HaveIBeenPwned: Breach exposure check
dark web intelligence
CTI Feed Sources (from DeepDarkCTI)
| Source Type | Examples | Use Case |
|---|
| Paste sites | Pastebin, GhostBin | Credential leaks, data dumps |
| Forums | Monitored via threat intel platforms | Threat actor discussion |
| Marketplaces | Tracked by law enforcement | Compromised data sales |
| Telegram | Public channels | Real-time threat chatter |
| Discord | Public servers | Community threat intel |
CTI Integration Pattern
from dataclasses import dataclass
from datetime import datetime
from enum import Enum
class ThreatLevel(Enum):
LOW = "low"
MEDIUM = "medium"
HIGH = "high"
CRITICAL = "critical"
@dataclass
class ThreatIndicator:
ioc_type: str
ioc_value: str
source: str
threat_level: ThreatLevel
first_seen: datetime
context: str
confidence: float
social media analysis
Profile Analysis Framework
- Account metadata: Creation date, follower/following ratio, posting frequency
- Content analysis: Topics, sentiment, language patterns
- Network analysis: Connections, group memberships, interactions
- Temporal analysis: Activity patterns, time zones, posting schedules
- Cross-platform correlation: Matching profiles across platforms
OSINT Workflow Template (from Obsidian OSINT Templates)
## Investigation: {{target}}
**Date**: {{date}}
**Objective**: {{objective}}
**Scope**: {{scope}}
### Findings
| Source | Data Point | Confidence | Notes |
|--------|-----------|------------|-------|
### Timeline
| Date | Event | Source |
### Connections Map
[Graph of relationships between entities]
### Assessment
**Confidence Level**: Confirmed / Probable / Possible / Doubtful
**Summary**:
**Recommendations**:
data correlation techniques
Entity Resolution
def correlate_entities(sources: list[dict]) -> list[dict]:
"""Match entities across different OSINT sources."""
...
Pivot Points
- Username → email → real name → address
- Domain → IP → other domains (reverse DNS)
- Phone → social media → real identity
- Image → EXIF data → GPS coordinates → other photos
integration with the operator's environment
| Component | Integration |
|---|
memory MCP server | Store entities, relations, observations as investigation graph |
security-auditor agent | Automate reconnaissance for security assessments |
PostToolUse hook | All OSINT commands logged in audit.log |
sequential MCP | Step-by-step reasoning for complex correlations |
CoreMind security layer | Hash chain audit trail for investigation activities |
Using Memory MCP for Investigations
# Store investigation entities
mcp__memory__create_entities: [{name: "target_user", entityType: "person", observations: ["..."]}]
mcp__memory__create_relations: [{from: "target_user", to: "target_domain", relationType: "owns"}]
mcp__memory__search_nodes: {query: "target investigation"}
legal and ethical guidelines
- Only use publicly available information
- Never access private accounts or systems without authorization
- Respect robots.txt and rate limits (see
browser-automation-safety skill)
- Document your methodology for reproducibility
- Report findings responsibly (coordinated disclosure)
- Comply with local privacy laws (GDPR, CCPA, etc.)
- Never harass or stalk individuals
cross-references
- offensive-security skill: Full penetration testing methodology
- security-review skill: Code-level security analysis
- browser-automation-safety skill: Rate limiting, robots.txt compliance
- research-methodology skill: Source credibility assessment
- SECURITY_ARSENAL.md: Complete tool inventory