Topic · Security
Best OSINT skills, page 2
OSINT skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using publicly available data sources, passive reconnaissance tools, and… | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 50 | Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 51 | Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting… | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 52 | Create, validate, and share STIX 2.1 threat intelligence objects (indicators, malware, campaigns, relationships, bundles) using the stix2 Python library, and publish them over TAXII 2.1. | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 53 | Build out a full CTI program around the six-phase threat intelligence lifecycle (direction, collection, processing, analysis, dissemination, feedback), including defining intelligence requirements… | mukul975/ | 34k | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 54 | Use AI/LLM-based reasoning with Sherlock, theHarvester, and SpiderFoot to correlate OSINT findings—usernames, emails, social profiles, domain records, breach databases, and dark-web mentions—into… | mukul975/ | 34k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 55 | Automates Indicator of Compromise (IOC) enrichment by orchestrating lookups across VirusTotal, AbuseIPDB, Shodan, MISP, and other intelligence sources to provide contextual scoring and disposition… | mukul975/ | 34k | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 56 | Processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to appropriate consuming systems. | mukul975/ | 34k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 57 | 57.Recon Osint A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover… | hypnguyen1209/ | 386 | — | ~2.2k | Automated safety check: Pass | MIT | 9 days ago |
| 58 | Guidance for Azure Firewall — managed cloud-native L3-L7 stateful network firewall for centralised egress, east-west, and ingress control. | vinayaklatthe/ | 175 | — | ~1.7k | Automated safety check: Pass | MIT | 3 mo ago |
| 59 | Query a MISP (Malware Information Sharing Platform) instance via PyMISP to compute event statistics, IOC type breakdowns, threat actor galaxy clusters, and tag trends, and generate threat landscape… | mukul975/ | 34k | — | ~597 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 60 | Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance… | mukul975/ | 34k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 61 | Systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 62 | Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 63 | Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet… | mukul975/ | 34k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 64 | Analyze IP address reputation using the Shodan API to identify open ports, running services, known vulnerabilities, and hosting context for threat intelligence enrichment and incident triage. | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 65 | Enrich malware file hashes (MD5, SHA-1, SHA-256) using the VirusTotal API v3 to retrieve multi-engine detection rates, sandbox behavioral analysis, YARA rule matches, related indicators, and… | mukul975/ | 34k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 66 | Automate OSINT collection with the SpiderFoot REST API and CLI (sf.py/spiderfoot-cli) across 200+ modules, selecting scan modes (footprint, investigate, passive) and parsing results for domains… | mukul975/ | 34k | — | ~608 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 67 | Uses PyMISP (the official MISP REST API library) to create events with structured IOCs (IPs, domains, hashes, URLs), enrich them with MITRE ATT&CK tags and galaxy clusters, manage sharing groups and… | mukul975/ | 34k | — | ~776 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 68 | 68.Unbroker Find and remove authorized personal information exposures from data brokers and people-search sites with a consent-gated local workflow. | CoWork-OS/ | 473 | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 69 | Export your entire Prospeo people search to CSV. An agent skill from growthenginenowoslawski/coldoutboundskills. | growthenginenowoslawski/ | 740 | — | ~5k | Automated safety check: Pass | MIT | 2 days ago |
| 70 | 70.Osint Recon Perform OSINT and external reconnaissance for approved targets. | SpecterOps/ | 702 | — | ~813 | Automated safety check: Pass | Apache-2.0 | 14 days ago |
| 71 | Detect transcription factor binding footprints in ATAC-seq using TOBIAS, HINT-ATAC, Wellington, or scprinter. | GPTomics/ | 1.2k | 2 repos | ~4.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 72 | Author, validate, test, and deploy YARA-L 2.0 detection rules and evaluate end-to-end detection coverage gaps in Google SecOps. | google/ | 21k | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 73 | Expert malware analyst specializing in defensive malware research, threat intelligence, and incident response. | aiskillstore/ | 430 | 6 repos | ~1.7k | Automated safety check: Pass | No licence | today |
| 74 | 74.Osint Recon Gather and correlate open source intelligence from public sources for authorized investigations, threat intelligence, and attack surface assessment. | briiirussell/ | 412 | — | ~1.1k | Automated safety check: Notes | MIT | 4 mo ago |
| 75 | Analyze TF motif accessibility variability across samples or single cells using chromVAR. | GPTomics/ | 1.2k | 2 repos | ~5.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 76 | 76.Domain Intel Passive recon of subdomains, SSL certs, WHOIS, and DNS. An agent skill from Luciole-Studio/Misaka-Agent. | Luciole-Studio/ | 125 | 1 repo | ~1.1k | Automated safety check: Pass | MIT | today |
| 77 | Zero friction. An agent skill from HKUDS/CLI-Anything. | HKUDS/ | 52k | — | ~360 | Automated safety check: Pass | Apache-2.0 | 15 days ago |
| 78 | Two-phase Apollo.io prospecting: free People Search to discover ICP-matching leads, then selective enrichment to reveal emails/phones (credits per contact). | gooseworks-ai/ | 1.2k | 1 repo | ~2k | Automated safety check: Notes | MIT | today |
| 79 | 79.Shodan Shodan lookups: internet-connected devices, ports, services. An agent skill from taracodlabs/aiden. | taracodlabs/ | 849 | — | ~954 | Automated safety check: Pass | Apache-2.0 | 24 days ago |
| 80 | 80.Wiki Recon External recon and OSINT pipeline - subdomain enum, live host discovery, URL crawl, JS analysis, nuclei scan. | Encod3d-Sec/ | 329 | — | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 81 | Automates the end-to-end detection engineering workflow in Google SecOps using MCP tools. | google/ | 21k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 82 | Orchestrates the end-to-end bulk ATAC-seq pipeline from FASTQ to differential accessibility and TF footprints, chaining Nextera-aware fastp QC, Bowtie2 alignment, chrM removal, dedup, a single Tn5… | GPTomics/ | 1.2k | 1 repo | ~4.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 83 | 83.Hunt Threat Conduct proactive, hypothesis-driven threat hunting. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 84 | 84.Osint Open-source intelligence gathering - company repository enumeration, secret scanning, git history analysis, employee footprint, and code exposure discovery. | transilienceai/ | 559 | — | ~494 | Automated safety check: Notes | MIT | 2 mo ago |
| 85 | OSINT-based technology stack identification. An agent skill from transilienceai/communitytools. | transilienceai/ | 559 | — | ~826 | Automated safety check: Pass | MIT | 2 mo ago |
| 86 | Social media monitoring, narrative tracking, and OSINT. An agent skill from jamditis/claude-skills-journalism. | jamditis/ | 416 | — | ~7.1k | Automated safety check: Pass | MIT | 3 days ago |
| 87 | Multi-source threat intelligence and vulnerability lookup. An agent skill from ptn1411/skill. | ptn1411/ | 219 | — | ~1.1k | Automated safety check: Pass | No licence | 15 days ago |
| 88 | Monitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 89 | Security engineering router for penetration testing, code auditing, red/blue/purple team operations, threat intelligence, and vulnerability research. | telagod/ | 244 | — | ~581 | Automated safety check: Pass | MIT | 2 mo ago |
| 90 | Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise. | elementalsouls/ | 4.8k | — | ~1.9k | Automated safety check: Notes | MIT | yesterday |
| 91 | A skill your agent uses when asked to analyze, investigate, or report on honeypot server security. | SCStelz/ | 249 | — | ~5.8k | Automated safety check: Pass | MIT | yesterday |
| 92 | Turn a published threat-intelligence article into a tested threat-hunting campaign. | SCStelz/ | 249 | — | ~6.9k | Automated safety check: Pass | MIT | yesterday |
| 93 | Find decision-makers at a specific company using Apollo, Crustdata, Fiber, and PDL people search via Gooseworks MCP. | gooseworks-ai/ | 1.2k | 1 repo | ~2.7k | Automated safety check: Pass | MIT | today |
| 94 | 94.Tam Builder Build and maintain a scored Total Addressable Market (TAM) using Apollo Company Search. | gooseworks-ai/ | 1.2k | 1 repo | ~1.4k | Automated safety check: Notes | MIT | today |
| 95 | Threat Intelligence Report Design System — ReportLab-based PDF generation for A4 reports with Transilience branding, typography, and layout standards. | transilienceai/ | 559 | — | ~6.3k | Automated safety check: Pass | MIT | 2 mo ago |
| 96 | Find LinkedIn profiles of decision makers at target companies using Extruct's companypeoplefinder. | extruct-ai/ | 109 | — | ~1.3k | Automated safety check: Pass | No licence | 9 days ago |
Explore related skills
Category
More topics in Security
- Security review611
- Web application vulnerabilities460
- Vulnerability scanning303
- Static analysis and SAST281
- Security operations248
- Supply chain security242
- Threat modeling207
- Penetration testing183
- Cryptography155
- Prompt injection and agent security154
- Red teaming and adversary simulation147
- Reverse engineering and malware132
- Secure coding105
- Cloud security90
- Digital forensics86
- Smart contract auditing80
- Fuzzing75
- Bug bounty74
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails34