snailsploit/claude-red

offensive-osint

Comprehensive OSINT methodology skill for offensive security, red team intelligence gathering, and bug bounty reconnaissance.

View source
Original skill document

Rendered from the source repository. Headings, examples, code, tables, links, and referenced images are preserved.

Offensive OSINT Methodology

Workflow

  1. Define target scope (domain, org, person, crypto address, or geo subject)
  2. Select applicable categories below based on scope
  3. Work top-down within each category; pivot on discovered artifacts
  4. Archive every key artifact: URL + timestamp + screenshot (PNG) + hash (SHA-256)
  5. Log findings in JSONL with a run_id and tool versions for reproducibility
  6. Suggest next steps based on what each tool returns

General OSINT

Search Engines

ToolNotes
Carrot2Clusters results by topic
etoolsMetasearch engine
KagiPrivacy-first, non-personalized results
Brave SearchIndependent index; Goggles for custom ranking
PDF SearchSearch PDF files and view table of contents
Google Fact Check ExplorerCross-site fact-check search

Username & Email Investigation

ToolPurpose
SherlockUsername search across social networks
MaigretCollect profiles by username from many sites
What's My NameUsername search across platforms
HoleheCheck if email is registered on platforms
EpieosEmail address pivots and metadata
OSINT IndustriesEmail/username/phone lookups
Hunter.ioFind email addresses for a domain
EmailRepEmail reputation and associated data
EmailableVerify email existence
MugetsuX/Twitter username history
RocketReach / ApolloEmail enrichment and pattern guessing
PhoneInfogaPhone number intelligence framework

Browser extensions: GetProspect, SignalHire


People Search


Phone Number OSINT


Social Media

PlatformTool
InstagramPicuki — view profiles without account
X/Twittersnscrape — preferred CLI scraper; use Twint only as fallback
FacebookGraph Search, sowsearch.info, lookup-id.com, whopostedwhat.com
Facebook (research)Meta Content Library — CrowdTangle successor (researcher-gated)
YouTube/TwitchSocial Blade — analytics
TikTokTokboard — trend and profile analytics
RedditReveddit — removed content; RedTrack.social — user history
BlueskyFiresky — real-time firehose; SkyView — follower graphs
MastodonFediSearch — cross-instance search; Fedifinder — find Twitter users on Mastodon
FacesSearch4Faces

Public Records & Company Information

RU/CN Registries

Russia: Rusprofile, Kontur.Focus (freemium), zakupki.gov.ru (procurement), EGRUL/EGRIP (official, captcha-gated)

China: GSXT (National Enterprise Credit), Qichacha/Tianyancha (freemium), MIIT ICP/Beian (ICP filings)

Sanctions & Compliance


Breach & Leak Data


Infrastructure & Attack-Surface OSINT

ASN/BGP & Internet Measurement

Certificates & CT Monitoring

  • crt.sh — Search Certificate Transparency logs
  • Censys Certificates — CT and x509 attribute pivots
  • CertStream — Real-time CT feed via WebSocket
  • Rapid7 Open Data — Sonar DNS/HTTP/SSL datasets
  • Cert Spotter [Freemium] — CT monitoring and alerts
  • Favicon hash (mmh3): cluster infrastructure; pair with Shodan/Censys favicon search

Threat Intel & IOCs

Malware Analysis & Sandboxes


Cryptocurrency OSINT

Blockchain Explorers

ChainExplorer
BitcoinBlockchain.com, Blockchair
EthereumEtherscan
BNB ChainBSCScan
Polygon PoSPolygonScan
SolanaSolscan
Multi-chainOKLink [Freemium], Cielo

L2 Explorers: Arbiscan, Optimistic Etherscan, BaseScan, zkSync Era, L2Beat (risk/TVL comparison)

Transaction Tracking & Analytics

NFT & Exchange Intelligence

Bridge Monitoring


Media Intelligence

Reverse Image & Facial Search

Image Forensics

Video Analysis

Browser Extensions for Media


Geospatial Intelligence

Satellite Imagery & Mapping

Geolocation Tools

Street View: Google Street View, Apple Maps, Yandex Maps, Baidu Maps

Flight OSINT

Maritime OSINT


AI-Assisted OSINT

Warning: Never paste PII, sensitive IOCs, or unique pivots into cloud LLMs. They log inputs and may use them for training. Use local models (Ollama, LM Studio) for sensitive analysis.
ToolStrength
ChatGPT (paid)Log parsing, dataset analysis, Code Interpreter for CSVs/JSON, GPT-4 Vision for image OCR
Claude (paid)200K token context for large document dumps and report synthesis
Gemini 1.5 Pro2M token context; Deep Research mode with citations
Perplexity Pro (paid)Real-time web search + reasoning; multi-query synthesis

Local/privacy-preserving: Ollama (Llama 3, Mistral), LM Studio, GPT4All

Commercial AI OSINT Platforms

Deepfake & Synthetic Media Detection


Archiving & Evidence Preservation

  • archive.today — One-page content archiver with screenshot
  • URLScan.io — On-demand webpage scan with resource map
  • ArchiveBox — Self-hosted archiving (HTML, PDF, screenshots, media)
  • Hunchly — Evidence capture for investigators (paid)
  • Wayback SavePageNow API v3 — On-demand archiving with job IDs
  • SingleFileZ — Browser extension for offline HTML archives
  • Kasm Workspaces — Containerized OSINT workspace/browser isolation

Evidence handling:

  • Capture: URL + timestamp + PNG screenshot + WARC/SingleFileZ archive
  • Hash all downloaded files (SHA-256) and record in case notes
  • Separate work profiles/containers per case; store evidence read-only
  • Use JSONL (NDJSON) logs with run_id and tool versions for reproducibility

Automation & Workflows

  • n8n — Self-hosted workflow automation (e.g., RSS → scrape → alert pipelines)
  • Huginn — Agent-based monitoring, scraping, alerting
  • Playwright — Headless browser automation with stealth plugins
  • Browsertrix Crawler — Archival crawling with WARC export
  • Prefect / Apache Airflow — Workflow orchestration for data pipelines

Regional Search Engines


Telegram & Messaging Intelligence

  • TGStat — Channel analytics and search
  • Telemetr — Channel growth, overlaps, forwards
  • Combot — Group analytics (partially paid)
  • TelegramDB Search Bot — Basic Telegram OSINT
  • Discord ID — Basic Discord account information
  • Sogou Weixin search — WeChat Official Accounts content search
  • View public Telegram channels: https://t.me/s/<channel>
from this repository

More skills

All skills
snailsploit
Community

offensive-netexec

Use this skill whenever the user asks about NetExec (nxc) — a network exploitation and post-exploitation tool for Active Directory environments. Triggers include: any mention of 'nxc', 'netexec', 'crackmapexec' successor questions, AD enumeration, SMB/LDAP/WinRM/MSSQL/SSH/RDP/VNC/WMI/FTP/NFS protocol attacks, password spraying, credential dumping (SAM, NTDS, LSASS, DPAPI), Kerberoasting, ASREPRoasting, lateral movement, BloodHound collection, module usage, or any pentest workflow involving Windows domain environments. This skill covers ALL protocols, ALL modules, and ALL core features of NetExec. Always provide full command examples with correct flags and options.

installs
1
GitHub stars
6.4K
Updated
Sep 19
snailsploit
Community

offensive-anti-forensics

Anti-forensics and evidence destruction techniques for red team operators conducting authorized engagements. Covers log clearing on Windows (wevtutil, Clear-EventLog, ETW provider patching) and Linux (journal truncation, utmp/wtmp binary editing, syslog manipulation), timestamp manipulation via Timestomp and SetMACE to defeat timeline analysis, filesystem-level anti-forensics including NTFS Alternate Data Streams for payload hiding and secure deletion with sdelete/shred, memory artifact removal to counter live forensics, disk artifact manipulation targeting MFT entries and USN journal records, network forensics evasion through encrypted C2 channels and DNS-over-HTTPS tunneling, and anti-VM/sandbox detection to avoid dynamic analysis environments. Tools: Timestomp, wevtutil, sdelete, shred, MimiPenguin, Invoke-Phant0m. Aligns to MITRE ATT&CK T1070 (Indicator Removal), T1027 (Obfuscated Files or Information), T1497 (Virtualization/Sandbox Evasion). Each technique includes the forensic artifact it targets, the destruction or manipulation method, and the defender perspective so operators understand detection gaps they must account for.

installs
1
GitHub stars
4.1K
Updated
Aug 30
snailsploit
Community

offensive-container-escape

Container escape and breakout techniques targeting Docker, containerd, and Podman runtimes. Covers privileged container breakout via host filesystem mount and nsenter, Docker socket abuse through /var/run/docker.sock, Linux capability exploitation including CAPSYSADMIN, CAPSYSPTRACE, and CAPNETADMIN, cgroup v1 notifyonrelease escape, runc CVEs such as CVE-2019-5736 and CVE-2024-21626 Leaky Vessels, kernel exploits from within containers, and Dockerfile misconfigurations like --privileged and host namespace sharing. Includes enumeration with capsh, amicontained, deepce, CDK, and nsenter. Maps to MITRE ATT&CK T1611 Escape to Host. Use this skill when the engagement scope includes container breakout, Docker escape, container privilege escalation, host access from container, or when you land inside a containerized environment and need to reach the underlying host.

installs
1
GitHub stars
4.1K
Updated
Aug 30
snailsploit
Community

offensive-graphql

Offensive methodology for attacking GraphQL APIs during penetration tests and bug bounty engagements. Covers the full attack lifecycle: endpoint discovery, introspection abuse and blind schema reconstruction when introspection is disabled, authentication and authorization bypass through Relay node IDs and nested object traversal, injection via variables and directives, query batching for brute force and OTP bypass, denial of service through depth bombs and alias amplification, WebSocket subscription hijacking, information disclosure through verbose errors and field suggestion oracles, and file upload abuse via the multipart GraphQL specification. Includes tool-specific guidance for InQL, graphql-cop, CrackQL, BatchQL, Altair, GraphQL Voyager, and clairvoyance. Trigger on: GraphQL, graphql, introspection query, batching attack, query depth, GraphQL injection, GraphQL IDOR, field suggestion, GraphQL auth bypass, GraphQL DoS, GraphQL security, graphql-cop, InQL, CrackQL, BatchQL, Relay node, alias amplification, subscription abuse, multipart upload GraphQL, schema enumeration, schema, type.

installs
1
GitHub stars
4.1K
Updated
Aug 30