AI Agent Hub
Back to skills
OSINT Tracker icon

OSINT Tracker

Professional Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please follow https://skillhub.cn/install/skillhub.md and install @user_00c9b356/osint.

About this skill

Problem

Open-source investigations often suffer from fragmented clues, unreliable sources, false positives, and reports that are hard to audit. This skill turns ad hoc OSINT into a traceable workflow, requiring evidence links, confidence labels, and counter-evidence checks instead of presenting model inference as fact.

How It Works

It supports two modes:
- Single analysis: follows ACQUIRE, ENRICH, ASSESS, and DELIVER, starting with target, scope, core question, and trust anchors, then gathering multi-source evidence, deduplicating, cross-validating, and analyzing identity, timeline, and relationship signals.
- Monitoring plan: extracts fingerprints such as usernames, emails, domains/IPs, and social IDs, then recommends sources, alert rules, and priority levels for continuous tracking.

Key constraints include covering multiple source types, marking unverified claims, lowering confidence for single-source facts, surfacing contradictions, and adding compliance notes for privacy-sensitive requests.

Boundaries

It fits public-information investigations for people, accounts, domains, IP addresses, events, or organizations where auditable reporting matters. It is not for unauthorized access, intrusive intrusion, or replacing legal and security expertise. When tools are unavailable or clues are insufficient, the workflow should flag data gaps and request anchors.

Use Cases

  • After receiving a suspicious email, determine whether it links to target accounts and output auditable sources with confidence levels.
  • For a domain exposure review, list DNS, certificate, snapshot changes, and flagged data gaps.
  • Generate a continuous tracking plan with username, email, and domain fingerprints, sources, and alert rules.
  • When conflicting social media clues appear in event review, run counter-evidence checks using sources, timestamps, and trust anchors.

Best For

  • Fraud analysts who need to link account, email, and transaction clues into an auditable evidence chain.
  • SOC engineers who review domain or IP exposure and need monitoring sources, change items, and risk labels.
  • Intelligence researchers tracking target accounts, domains, and public statements for events or competitors.
  • Product security engineers who need privacy-compliant investigation plans with permission checks, caveats, and data gaps.