开源情报聚合

原名:collecting-open-source-intelligence

收集和综合关于威胁的开源情报(OSINT)。

分类
数据分析
版本
v1.0.0
作者
弈韬(@ra1nzzz)
下载
0
收藏
0
发布
2026-08-18
更新
2026-08-25
TRACE 评分
3.4 / 5

内容概览

Use this skill when: - Investigating external infrastructure associated with a phishing campaign targeting your organization - Enriching threat actor profiles with publicly observable indicators (WHOIS, ASN data, SSL certificates) - Conducting authorized attack surface discovery to understand your organization's external exposure Do not use this skill for active scanning against targets without explicit written authorization — OSINT collection must remain passive (no packets sent to target systems) unless scope permits active recon. - Maltego CE or commercial license for graph-based link analysis - Shodan API key (https://shodan.io) for internet-wide device/service discovery - OSINT Framework familiarity (https://osintframework.com) for tool selection - SpiderFoot HX or open-source SpiderFoot for automated OSINT correlation Establish the intelligence requirement (IR) before collecting. D…

查看 SKILL 详情