Skip to content
Back to skills

Osint Reconnaissance Techniques

ASecurity

Use when performing OSINT and reconnaissance.

  • 2 stars
  • 0 votes
  • 0 copies
  • 4 views
  • Added September 10, 2026
securitypythongophptestinggit

Security analysis

A100/100

Scanned September 10, 2026

npx -y skills add LoopyLuci/Skills --skill osint-reconnaissance-techniques --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Osint Reconnaissance Techniques?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Osint Reconnaissance Techniques
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/loopyluci-osint-reconnaissance-techniques/badge)](https://www.skillsdirectory.com/skills/loopyluci-osint-reconnaissance-techniques)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: osint-reconnaissance-techniques
description: "Use when performing OSINT and reconnaissance."
version: 1.0.0
author: Hermes Agent
license: MIT
metadata:
  hermes:
    tags: [OSINT, reconnaissance, passive-recon, subdomain-enum, Google-dorking, Shodan]
    related_skills: [bug-bounty-methodology, network-scanning-enumeration, penetration-testing-methodology, social-engineering-phishing]
---

# OSINT and Reconnaissance Techniques

Performing open-source intelligence gathering — from passive reconnaissance through subdomain enumeration, technology fingerprinting, Google dorking, and Shodan/Censys querying.

## When to Use

- Passive recon before penetration testing
- Gathering target information from public sources
- Subdomain and technology discovery
- Employee and email enumeration
- OSINT for social engineering preparation

## OSINT Techniques

```python
OSINT_TOOLS = {
    'subdomain_enum': 'subfinder, amass, assetfinder, Sublist3r, crt.sh (Certificate Transparency)',
    'tech_detection': 'wappalyzer, builtwith, whatweb, webanalyze — framework/css/js/server detection',
    'google_dorking': 'site:, intitle:, inurl:, filetype:, cache: — find exposed information',
    'email_enum': 'hunter.io, phonebook.cz, theHarvester — discover email patterns',
    'shodan': 'Search devices, open ports, banners, vulnerabilities with filters',
    'github_leaks': 'gitrob, truffleHog — search repos for secrets, tokens, credentials',
    'wayback_machine': 'archive.org — find historical endpoints, parameters, hidden paths',
}

# Google dork examples
GOOGLE_DORKS = {
    'login_pages': 'inurl:admin intitle:login',
    'exposed_files': 'site:target.com filetype:pdf OR filetype:xlsx',
    'directory_listing': 'intitle:"index of" site:target.com',
    'error_messages': 'inurl:"error=php"|"warning=php" site:target.com',
    'config_files': 'filetype:env OR filetype:config site:target.com',
}

def crt_sh_subdomains(domain: str) -> List[str]:
    """Query crt.sh Certificate Transparency logs for subdomains."""
    import requests
    resp = requests.get(f'https://crt.sh/?q=%25.{domain}&output=json')
    if resp.status_code == 200:
        return list(set(e['name_value'] for e in resp.json()))
    return []
```

## Verification Checklist

- [ ] Passive recon completed before active scanning
- [ ] Subdomain enumeration (certificate transparency, DNS bruteforce)
- [ ] Technology stack identified (Wappalyzer, BuiltWith)
- [ ] Google dorking for exposed information
- [ ] Email/employee enumeration (if in scope)
- [ ] Shodan/Censys search for exposed services
- [ ] GitHub/GitLab for leaked credentials and internal tools
- [ ] Wayback Machine for historical endpoints
- [ ] Information organized and documented for next phase
- [ ] Legal review: only public information, no social engineering without explicit scope

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…