Skip to main content

osint-investigator

Open-source intelligence gathering with theHarvester, recon-ng, Maltego, and SpiderFoot. Domain recon, email harvesting, DNS mapping, and threat actor profiling from BlackArch tools on ARGUS.

Aller à l'installation

Informations de source

Dépôt
RabbitAI-Lab/rabbit-plugins-upstream
Dernière activité de la source
26 juillet 2026 à 20:50
Langue détectée de SKILL.md
anglais
Étoiles
0
Forks
0

Options d'installation

Le prompt qui vérifie d'abord la source est sélectionné par défaut. Vous pouvez passer à une commande directe ou télécharger une copie locale.

Vérifiez les fichiers source

Lisez SKILL.md et les fichiers associés affichés par SkillsMP avant de décider de l'installer.

Explorateur de fichiers
4 fichiers

Affichage de SKILL.md

SKILL.md
Instructions source · Aperçu en lecture seule
name
osint-investigator
description
Open-source intelligence gathering with theHarvester, recon-ng, Maltego, and SpiderFoot. Domain recon, email harvesting, DNS mapping, and threat actor profiling from BlackArch tools on ARGUS.
homepage
https://github.com/nousresearch/argus
metadata
{"openclaw":{"requires":{"bins":"[Truncated]","mcps":"[Truncated]","optional_bins":"[Truncated]"},"os":["linux"]}}
# OSINT Investigator Open-source intelligence (OSINT) gathering and analysis pipeline using ARGUS BlackArch tools. Combines theHarvester for email/subdomain harvesting, recon-ng for web reconnaissance, Maltego for graphical link analysis, and SpiderFoot for automated data aggregation. Enriched with aynops for domain recon and CVE-MCP for threat intelligence context. Runs on ARGUS infrastructure with 11 installed BlackArch recon/OSINT tools. ## Prerequisites - **ARGUS host** with BlackArch tools installed - **theHarvester** 4.11.1+ — email and subdomain harvesting - **recon-ng** 5.1.2+ — web reconnaissance framework - **Maltego** 4.11.3+ — graphical link analysis - **aynops** MCP available on localhost — domain recon + scanning - `curl`, `jq` on PATH ## Infrastructure | Component | Location | Purpose | |-----------|----------|---------| | theHarvester | `/usr/bin/theHarvester` | Email, subdomain, and name harvesting | | recon-ng | `/usr/bin/recon-ng` | Web reconnaissance framework | | Maltego | `/usr/bin/maltego` | Graphical link analysis | | SpiderFoot | `/usr/bin/spiderfoot` | Automated OSINT platform | | aynops | localhost MCP | Domain recon: whois, DNS, ports, SSL | | CVE-MCP | localhost MCP | CVE intelligence enrichment | ## Core Commands ### Quick Domain Recon (theHarvester) Harvest emails, subdomains, IPs, and URLs for a target domain: ```bash TARGET="example.com" OUTDIR="/tmp/osint/$TARGET-$(date +%Y%m%d-%H%M%S)" mkdir -p "$OUTDIR" echo "=== theHarvester: Full Harvest ===" theHarvester -d "$TARGET" -b all -f "$OUTDIR/harvest.html" 2>&1 | \ tee "$OUTDIR/harvest-output.txt" # Extract emails echo "" echo "=== Extracted Emails ===" grep -E '[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}' "$OUTDIR/harvest-output.txt" | \ sort -u > "$OUTDIR/emails.txt" cat "$OUTDIR/emails.txt" # Extract subdomains echo "" echo "=== Extracted Subdomains ===" grep -E '^[*]?[a-zA-Z0-9.-]+\.'"$TARGET" "$OUTDIR/harvest-output.txt" | \ sort -u > "$OUTDIR/subdomains.txt" cat "$OUTDIR/subdomains.txt" # Extract IPs echo "" echo "=== Extracted IPs ===" grep -oE '\b([0-9]{1,3}\.){3}[0-9]{1,3}\b' "$OUTDIR/harvest-output.txt" | \ sort -u > "$OUTDIR/ips.txt" cat "$OUTDIR/ips.txt" ``` ### theHarvester — Targeted Source Selection Use specific data sources for focused harvesting: ```bash TARGET="example.com" # LinkedIn-focused (people, roles) echo "=== LinkedIn Harvest ===" theHarvester -d "$TARGET" -b linkedin 2>&1 # DNS brute-force echo "=== DNS Brute-Force ===" theHarvester -d "$TARGET" -b dnsdumpster,crtsh,certspotter 2>&1 # Search engines echo "=== Search Engine Discovery ===" theHarvester -d "$TARGET" -b google,bing,yahoo,duckduckgo 2>&1 # GitHub/code discovery echo "=== Code Repository Discovery ===" theHarvester -d "$TARGET" -b github-code 2>&1 ``` Available sources: `anubis, baidu, bing, binaryedge, bingapi, bufferoverun, censys, certspotter, crtsh, dnsdumpster, duckduckgo, github-code, google, hackertarget, hunter, intelx, linkedin, linkedin_links, netcraft, omnisint, otx, pentesttools, projectdiscovery, rapiddns, rocketreach, securitytrails, shodan, sslcert, subdomaincenter, threatcrowd, threatminer, urlscan, virustotal, yahoo, zoomeye` ### recon-ng — Automated Reconnaissance Initialize and run a recon-ng workspace: ```bash TARGET="example.com" WORKSPACE="osint-$(date +%Y%m%d)" # Create workspace and run modules recon-ng << RECONEOF workspaces create $WORKSPACE add domains $TARGET # Discover contacts modules load recon/contacts-contacts/mailtester run # Certificate transparency modules load recon/domains-certificates/certspotter run # DNS enumeration modules load recon/domains-hosts/bing_domain_web run modules load recon/domains-hosts/google_site_web run # Whois information modules load recon/domains-contacts/whois_pocs run # Shodan integration modules load recon/hosts-ports/shodan_ip run # Generate report modules load reporting/list set FILENAME /tmp/osint/${WORKSPACE}-contacts.txt set TABLE contacts run modules load reporting/list set FILENAME /tmp/osint/${WORKSPACE}-hosts.txt set TABLE hosts run exit RECONEOF echo "Workspace: $WORKSPACE" echo "Report: /tmp/osint/${WORKSPACE}-*.txt" ``` ### DNS Reconnaissance via aynops Use aynops MCP for comprehensive DNS mapping: ```bash TARGET="example.com" echo "=== AynOps DNS Recon: $TARGET ===" # Whois echo "--- Whois ---" curl -s -X POST "http://localhost:8765/aynops/whois" \ -H "Content-Type: application/json" \ -d "{\"domain\": \"$TARGET\"}" | jq '{ registrar: .registrar, created: .creation_date, expires: .expiration_date, nameservers: .name_servers[:5], org: .registrant_organization }' # DNS Records echo "" echo "--- DNS Records ---" curl -s -X POST "http://localhost:8765/aynops/dns" \ -H "Content-Type: application/json" \ -d "{\"domain\": \"$TARGET\", \"type\": \"all\"}" | jq '{ a: .A[:5], mx: .MX[:3], ns: .NS[:5], txt: .TXT[:3], cname: .CNAME[:5], soa: .SOA }' # SSL Certificate Info echo "" echo "--- SSL Certificate ---" curl -s -X POST "http://localhost:8765/aynops/ssl" \ -H "Content-Type: application/json" \ -d "{\"domain\": \"$TARGET\"}" | jq '{ issuer: .issuer, valid_from: .valid_from, valid_until: .valid_until, sans: .subject_alt_names[:10], fingerprint: .sha256_fingerprint[:16] }' ``` ### SpiderFoot — Automated OSINT Scan Run a comprehensive SpiderFoot scan (passive only by default): ```bash TARGET="example.com" SCAN_NAME="osint-$(date +%Y%m%d)" echo "=== SpiderFoot: Passive Scan ===" spiderfoot -s "$TARGET" -t "$SCAN_NAME" -m all 2>&1 | \ tee "/tmp/osint/spiderfoot-$SCAN_NAME.txt" echo "" echo "=== SpiderFoot: High-Risk Findings ===" grep -E "HIGH|CRITICAL|RISK" "/tmp/osint/spiderfoot-$SCAN_NAME.txt" ``` ### Maltego — Graph Export Export Maltego graph data for programmatic analysis: ```bash TARGET="example.com" GRAPH_DIR="/tmp/osint/maltego-$TARGET-$(date +%Y%m%d)" mkdir -p "$GRAPH_DIR" echo "=== Maltego Export Instructions ===" echo "" echo "1. Launch Maltego: maltego" echo "2. New Graph → select 'Company Stalker' or 'Domain Investigation' machine" echo "3. Input: $TARGET" echo "4. Run machine → wait for transforms to complete" echo "5. Export: File → Export as CSV → $GRAPH_DIR/entities.csv" echo "6. Export: File → Export as CSV (connections) → $GRAPH_DIR/links.csv" echo "" echo "After export, analyze:" # Analysis after manual export if [ -f "$GRAPH_DIR/entities.csv" ]; then echo "" echo "=== Entity Summary ===" echo "Total entities: $(wc -l < "$GRAPH_DIR/entities.csv")" echo "" echo "=== Top Entity Types ===" cut -d',' -f2 "$GRAPH_DIR/entities.csv" | sort | uniq -c | sort -rn | head -10 echo "" echo "=== IP Addresses Discovered ===" grep -E '\b([0-9]{1,3}\.){3}[0-9]{1,3}\b' "$GRAPH_DIR/entities.csv" | sort -u echo "" echo "=== Email Addresses ===" grep -E '[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+' "$GRAPH_DIR/entities.csv" | sort -u echo "" echo "=== Domains ===" grep -E '\.[a-z]{2,}$' "$GRAPH_DIR/entities.csv" | cut -d',' -f1 | sort -u | head -20 fi ``` ### Combined OSINT Report Generate a comprehensive OSINT report from all tools: ```bash TARGET="example.com" REPORT_DIR="$HOME/App/domains/argus/reports/osint" REPORT="$REPORT_DIR/osint-report-$TARGET-$(date +%Y%m%d-%H%M%S).md" TMPDIR="/tmp/osint/$TARGET-$(date +%Y%m%d)" mkdir -p "$REPORT_DIR" "$TMPDIR" echo "# OSINT Report: $TARGET" > "$REPORT" echo "**Date:** $(date)" >> "$REPORT" echo "" >> "$REPORT" # 1. Domain Info (aynops) echo "## 1. Domain Registration" >> "$REPORT" curl -s -X POST "http://localhost:8765/aynops/whois" \ -H "Content-Type: application/json" \ -d "{\"domain\": \"$TARGET\"}" | jq -r ' "| Field | Value |\n|---|---|\n" + "| Registrar | \(.registrar // "N/A") |\n" + "| Created | \(.creation_date // "N/A") |\n" + "| Expires | \(.expiration_date // "N/A") |\n" + "| Nameservers | \(.name_servers[:3] | join(", ") // "N/A") |" ' >> "$REPORT" 2>/dev/null # 2. DNS Records (aynops) echo "" >> "$REPORT" echo "## 2. DNS Records" >> "$REPORT" curl -s -X POST "http://localhost:8765/aynops/dns" \ -H "Content-Type: application/json" \ -d "{\"domain\": \"$TARGET\", \"type\": \"all\"}" | jq -r ' "### A Records\n" + (.A[:10] | map(" - " + .) | join("\n") // " None") + "\n\n### MX Records\n" + (.MX[:5] | map(" - " + .) | join("\n") // " None") + "\n\n### NS Records\n" + (.NS[:5] | map(" - " + .) | join("\n") // " None") + "\n\n### TXT Records\n" + (.TXT[:5] | map(" - " + (. | tostring)[:100]) | join("\n") // " None") ' >> "$REPORT" 2>/dev/null # 3. Subdomain Discovery (theHarvester)
Voir sur GitHub
Ce SKILL.md est tres volumineux, SkillsMP affiche donc ici seulement la premiere section. Voir sur GitHub