Topic · Security
Best OSINT skills for Claude Code, Codex and other agents.
- skills
- 117
- official
- 2
OSINT skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Guides building Flowsint enrichers and types: where definitions live, how the base class and vault work, and when a new type is warranted. | reconurge/ | 9.3k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 2 | Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys. | j3ssie/ | 1.8k | — | ~2.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 3 | Provides open source intelligence techniques for CTF challenges. | ljagiello/ | 3.4k | 2 repos | ~2.3k | Automated safety check: Notes | MIT | 23 days ago |
| 4 | Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins. | BigBodyCobain/ | 11k | — | ~8.9k | Automated safety check: Warn | AGPL-3.0 | today |
| 5 | Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from… | shoyann/ | 140 | — | ~4.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 16 days ago |
| 6 | Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test. | elementalsouls/ | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 7 | 7.Osint Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill. | smixs/ | 140 | — | ~5.5k | Automated safety check: Pass | MIT | 7 mo ago |
| 8 | Reference knowledge for open-source intelligence collection: the collection cycle, source reliability tiers, search query patterns and entity extraction. | RightNow-AI/ | 18k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 9 | Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. | elementalsouls/ | 2.8k | — | ~8.7k | Automated safety check: Notes | MIT | 1 mo ago |
| 10 | Deep web-research methodology for the interceptor browser surface — investigate a topic the way researchers, intelligence analysts, investigative journalists, private investigators, and OSINT… | Hacker-Valley-Media/ | 514 | — | ~3.8k | Automated safety check: Pass | Unknown | 4 days ago |
| 11 | Professional malware analysis workflow for PE executables and suspicious files. | tsale/ | 324 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 4 mo ago |
| 12 | 12.Msteams Interact with Microsoft Teams — send and read messages, search conversations, look up people, check calendar, get meeting transcripts, and manage chats. | sigcli/ | 293 | — | ~2.7k | Automated safety check: Pass | MIT | 9 days ago |
| 13 | Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology. | PentesterFlow/ | 1.4k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Enriches IOCs, campaigns, impersonation and scams from public sources, including bounded X search through Xquik, and checks each lead against independent evidence. | zhaoxuya520/ | 40k | 1 repo | ~1k | Automated safety check: Pass | MIT | 15 days ago |
| 15 | Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis. | tsale/ | 324 | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 4 mo ago |
| 16 | Public-records OSINT investigation framework — SEC EDGAR filings, USAspending contracts, Senate lobbying, OFAC sanctions, ICIJ offshore leaks, NYC property records (ACRIS), OpenCorporates… | johnson7788/ | 327 | — | ~3k | Automated safety check: Pass | MIT | 1 mo ago |
| 17 | Analyse Mitre ATT&CK tactics, techniques and sub-techniques. | tsale/ | 324 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | 4 mo ago |
| 18 | 18.Enrich Ioc Enrich an IOC (IP, domain, hash, URL) with threat intelligence. | dandye/ | 127 | — | ~702 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 19 | Follow the money via public records and sanctions data. An agent skill from Luciole-Studio/Misaka-Agent. | Luciole-Studio/ | 125 | 1 repo | ~2.9k | Automated safety check: Pass | MIT | today |
| 20 | Build structured threat actor profiles using the 5W1H framework and the Diamond Model. | tsale/ | 324 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 4 mo ago |
| 21 | 21.Email Search Get verified emails and phones for contacts found by people-search. | extruct-ai/ | 109 | — | ~1.3k | Automated safety check: Pass | No licence | 9 days ago |
| 22 | 22.Sherlock OSINT username search across 400+ social networks. An agent skill from Tommy-yw/RunbookHermes. | Tommy-yw/ | 546 | 3 repos | ~1.5k | Automated safety check: Pass | MIT | 4 mo ago |
| 23 | Run competitive research like an intelligence agency: eight collection disciplines (OSINT to MASINT), signal-to-inference chains, and fusion. | deanpeters/ | 7.2k | — | ~6.6k | Automated safety check: Pass | Unknown | 1 mo ago |
| 24 | 24.Domain Intel Passive domain reconnaissance using Python stdlib. An agent skill from Tommy-yw/RunbookHermes. | Tommy-yw/ | 546 | 1 repo | ~1.1k | Automated safety check: Pass | MIT | 4 mo ago |
| 25 | Build an automated IOC enrichment pipeline on OpenCTI (STIX 2.1 native threat intel platform) using its internal enrichment connectors to pull context from VirusTotal, Shodan, AbuseIPDB, and… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 26 | Build a systematic threat-hunt workflow that turns threat intelligence and ATT&CK gap analysis into testable hypotheses, then executes and validates them via EDR/SIEM queries (CrowdStrike, Defender… | mukul975/ | 34k | — | ~893 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 27 | Build automated IOC enrichment pipelines in Splunk Enterprise Security by ingesting threat feeds into KV Store collections and correlating them against security events via lookup tables, modular… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 28 | Design and deploy a Threat Intelligence Platform (TIP) by integrating open-source CTI tools (MISP, OpenCTI, TheHive, Cortex) into a unified system with feed ingestion pipelines, enrichment… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 29 | Deploy MISP, configure threat feeds (MISP community, freetext, TAXII, CSV), and use the PyMISP API to programmatically fetch, add, and search events and IOCs, building automated collection pipelines… | mukul975/ | 34k | — | ~1.6k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 30 | Extracts embedded configuration from Agent Tesla RAT samples, including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints, via .NET decompilation and memory analysis. | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 31 | Implements a STIX 2.1/TAXII 2.1 threat-intelligence feed consumer and producer in Python, covering TAXII server discovery, collection polling, parsing STIX bundles with the stix2 library, and… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | Configure NextDNS as an encrypted (DoH/DoT) zero trust DNS resolver that blocks malicious, phishing, and cryptojacking domains via real-time threat intelligence, detects DNS rebinding and CNAME… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 33 | Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 34 | Tracks IOCs through discovery, enrichment/validation (VirusTotal, Shodan, passive DNS), deployment to SIEM/IDS watchlists, hit-rate and false-positive monitoring, confidence-score decay, and… | mukul975/ | 34k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 35 | Discovers and maps adversary-controlled infrastructure (C2 servers, phishing domains, exploit-kit hosts, bulletproof hosting) by pivoting across passive DNS, certificate transparency logs… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 36 | Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access. | trilwu/ | 156 | — | ~3.1k | Automated safety check: Notes | MIT | 1 mo ago |
| 37 | 37.People Data Research LinkedIn professional profiles and public business-contact data, including email/phone lookup, people search, and YouTube channel business-email discovery. | sickn33/ | 47k | 1 repo | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 38 | Authorized OSINT and cyber threat intelligence: enriching IOCs, campaigns, impersonation, scams, and threat-actor profiles from public sources with defined boundaries. | sickn33/ | 47k | 1 repo | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 39 | Safely monitor ransomware group Tor-hosted data leak sites (DLS) to collect and extract structured victim posting data, track group activity trends over time, and produce sector- and… | mukul975/ | 34k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 40 | Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs, identifying wallet clusters and tracking fund… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 41 | Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. | mukul975/ | 34k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 42 | Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 43 | Build an automated adversary infrastructure tracking system in Python (dnspython, python-whois, shodan, networkx) that pivots across passive DNS, certificate transparency logs, WHOIS records, and IP… | mukul975/ | 34k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 44 | Parse cyber threat intelligence reports (Mandiant, CrowdStrike, Talos, Microsoft) with stix2, mitreattack-python, and spaCy to extract adversary behaviors, map them to MITRE ATT&CK technique IDs… | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 45 | Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 46 | Build threat actor profiles by collecting OSINT from vendor reports, paste sites, dark web forums, social media, and code repos, correlating indicators, mapping adversary infrastructure with tools… | mukul975/ | 34k | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 47 | Deploy MISP via Docker and configure feeds from sources like abuse.ch, AlienVault OTX, and CIRCL to aggregate, correlate, and distribute threat intelligence, including automated feed synchronization… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 48 | Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
Questions, answered from the data.
What is the best OSINT skill?
Flowsint Enricher Builder from reconurge/flowsint ranks first of the 117 OSINT skills listed here, with the highest score: its repository has 9.3k GitHub stars, its SKILL.md loads about 2.6k tokens and it passes the automated safety check with no findings. Next come Metabigor OSINT Recon and Ctf Osint.
Which OSINT skills are official?
2 of the 117 OSINT skills are official, published by the vendor's own GitHub organization: Secops Detection Engineering and Detection Engineering Coverage Evaluation.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
Category
More topics in Security
- Security review611
- Web application vulnerabilities460
- Vulnerability scanning303
- Static analysis and SAST281
- Security operations248
- Supply chain security242
- Threat modeling207
- Penetration testing183
- Cryptography155
- Prompt injection and agent security154
- Red teaming and adversary simulation147
- Reverse engineering and malware132
- Secure coding105
- Cloud security90
- Digital forensics86
- Smart contract auditing80
- Fuzzing75
- Bug bounty74
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails34