Passive OSINT
SkillAI & modelsPassive OSINT to expand attack surface without touching the target: dorks, code/secret leaks, Shodan/Censys, cloud assets, employees. Load at recon start, on "OSINT", "google/github dorks", "shodan", or gathering intel on an org. Signals: org name, root domain, "find leaks/exposed".
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Passive OSINT skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/recon/recon-osint/SKILL.md and read by ahel’s review.
When it applies
Early recon, and anytime you want surface/intel without sending traffic to the target — safest, often highest-signal (leaked keys, forgotten hosts, exposed services).
Why it works
Organizations leak everywhere but their own site: search-engine indexes, public code, internet scan databases, cloud metadata, and employee footprints. Aggregating these finds assets and secrets the target doesn't know are exposed.
Method
- Search dorks: Google (
site: inurl: filetype: intitle:for panels, configs, docs) and GitHub dorks (org:target "api_key","target.com" password) for code/secret leaks. - Code leaks:
trufflehog github --org=<org>, gist/pastebin search — validate live keys (in scope). - Internet scan DBs: Shodan/Censys/FOFA by org/cert/favicon-hash to find exposed services, forgotten hosts, and origin IPs behind CDNs.
- Cloud & DNS assets: CT logs, reverse-DNS, ASN ranges, bucket name guessing (→
cloud-s3-exposure). - People/tech: employees (LinkedIn) for username formats/phishing scope (if allowed), and job posts/stack sites for the tech stack.
Gotchas
- Confirm everything you find is in program scope before active testing — OSINT surfaces out-of-scope acquisitions too.
- Report leaked secrets by location, validate minimally, never exfiltrate.
- Origin-IP discovery via Shodan/cert often bypasses the WAF later (→
payloads-waf-bypass).
Verify success
New in-scope assets, exposed services, or validated leaked secrets — feeding active recon and hunting.
References
Google Hacking DB; GitHub dorks lists; Shodan/Censys docs; trufflehog.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
recon-osint-noorqureshi- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · davila7
The pick for LinkedInlinkedin-content-planner
Skill · sergebulaev
The pick for LinkedInlinkedin-post
Skill · hamzafarooq
The pick for LinkedInlinkedin-writer
Skill · naveedharri
The pick for LinkedInfirecrawl-build-scrape
Skill · firecrawl
The pick for Scrapescrape
Skill · davila7
The pick for Scrape