一键导入
osint-domain
Investigate a domain — DNS/subdomain enumeration, infrastructure analysis, threat assessment, web presence mapping, and reporting.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Investigate a domain — DNS/subdomain enumeration, infrastructure analysis, threat assessment, web presence mapping, and reporting.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Run a full 11-phase forensic investigation across all MCP servers — disk, memory, Windows artifacts, malware, network, OSINT, threat intel, timeline, and reporting.
Run a 6-phase forensic investigation — evidence intake, artifact collection, network analysis, threat intel, timeline reconstruction, and reporting.
Run a 7-phase incident response — triage, containment assessment, evidence collection, attack chain reconstruction, threat intel, impact assessment, and reporting.
Analyze a malware sample — static analysis with Ghidra/Radare2/Capa, YARA scanning, string extraction, and VirusTotal/MalwareBazaar lookup.
Analyze a memory dump — process analysis, network connections, persistence mechanisms, malware detection with Volatility3, and reporting.
Analyze network traffic — PCAP triage, protocol analysis, anomaly detection, IoC extraction, stream reconstruction, and reporting.
| name | osint-domain |
| description | Investigate a domain — DNS/subdomain enumeration, infrastructure analysis, threat assessment, web presence mapping, and reporting. |
Conduct an OSINT investigation on the specified domain.
Usage: /osint-domain <target>
Where <target> is a domain name — e.g. suspicious-site.com, example.org.
If no target is provided, ask the user for the domain.
get_template(name="osint-domain", target="$ARGUMENTS")