OSINT Methodology Framework
Paste the following prompt into your AI chat to install this skill:
Please follow https://skillhub.cn/install/skillhub.md to install @user_3c6cb52e/osint-methodology-lr-lplm.
About this skill
Problem
OSINT investigations often fail not because tools are missing, but because collection work lacks sequence: unclear target boundaries, inconsistent source prioritization, and unlinked evidence that only produces a report full of scattered links. osint-methodology turns open-source intelligence analysis into an operational checklist, helping engineers or analysts fix the question, evidence standard, and output structure before searching begins.
How It Works
The skill organizes OSINT into target definition, source selection, collection workflow, data correlation, timeline reconstruction, and reporting. When activated, it checks whether the task has a clear target, then evaluates whether available sources cover identity, behavior, relationships, and technical traces. For each step, it notes applicability, evidence gaps, and next actions, while tracking completed checklist items to reduce repeated searches and missed milestones.
It is useful for:
- Structured investigations: expanding initial clues into a verifiable timeline
- Evidence organization: grouping screenshots, posts, and domain records into linked context
- Methodology teaching: explaining how OSINT moves from hypothesis to conclusion
Note: this is a methodology framework, not a live intelligence feed; users must still assess legal authorization, platform ToS, privacy boundaries, and target legitimacy.
Use Cases
- When receiving a suspicious account clue, organize the target profile, usable sources, and verification order before searching.
- Before drafting a threat attribution report, use the checklist to spot evidence gaps and link posts, domains, and timelines.
- When onboarding new analysts, decompose OSINT tasks into target definition, source selection, and data correlation.
- When reviewing a prior collection effort, check whether timeline reconstruction was missed and propose next steps.
Best For
- Security engineers doing threat hunting who need to turn scattered clues into a reviewable timeline.
- Training instructors teaching OSINT who need fixed steps for target definition, source selection, and correlation.
- Analysts collecting public competitor or adversary information who need a consistent workflow and evidence-gap output.
- SOC on-call engineers writing incident postmortems who need to link posts, domains, and account records into an event chain.
Related Skills
Local workflow memory with matching and SOP updates.
An OpenClaw live streaming executor that initializes TRTC streaming, starts a real-time dashboard, generates viewer URLs, and continuously reports live events.
Breaks down physical supply chains for super-trends to identify second- and third-layer bottlenecks, runs valuation and reverse checks, and maintains trackable reports.
A token-saving compression mode for Chinese LLMs with lite, full, ultra, and classical tiers, preserving code and technical terms while handling edge cases.