开源情报聚合
原名:collecting-open-source-intelligence
收集和综合关于威胁的开源情报(OSINT)。
- 分类
- 数据分析
- 版本
- v1.0.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 0
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-25
- TRACE 评分
- 3.4 / 5
内容概览
Use this skill when: - Investigating external infrastructure associated with a phishing campaign targeting your organization - Enriching threat actor profiles with publicly observable indicators (WHOIS, ASN data, SSL certificates) - Conducting authorized attack surface discovery to understand your organization's external exposure Do not use this skill for active scanning against targets without explicit written authorization — OSINT collection must remain passive (no packets sent to target systems) unless scope permits active recon. - Maltego CE or commercial license for graph-based link analysis - Shodan API key (https://shodan.io) for internet-wide device/service discovery - OSINT Framework familiarity (https://osintframework.com) for tool selection - SpiderFoot HX or open-source SpiderFoot for automated OSINT correlation Establish the intelligence requirement (IR) before collecting. D…