4 skills found
Find leaked or mentioned selectors circulating in pastes, leak forums, Telegram channels and dump markets, and judge whether a claimed leak is genuine or a recycled combolist. Covers paste aggregators, site: searches over paste hosts, channel indexes and leak-search services. Use when checking whether a name, email, domain or credential is circulating, verifying a breach claim made against your organisation, or setting up ongoing leak monitoring. Applies to incident response and breach triage, t
Start-here router and tradecraft baseline for any investigation into a person, company, domain, image or selector. Sets authorised scope, turns a vague request into an answerable intelligence question, writes a collection plan, picks the right workflow for the starting selector, and applies source grading and competing-hypothesis discipline. Use for "investigate this person or company", "do OSINT on X", "where do I start", or any open-source intelligence, due diligence, background or attribution
End-to-end passive reconnaissance for a domain, website or IP — builds an asset inventory covering registration, DNS, subdomains, infrastructure, tech stack, history and ownership without sending a single packet to the target. Use when asked to research or profile a domain or website, map what an organisation runs, or investigate a suspicious site without alerting its operator. Applies to vendor and third-party risk assessment, attack-surface review, M&A technical diligence, phishing and fraud-s
Automates the end-to-end detection engineering workflow in Google SecOps using MCP tools. Use when fetching threat intelligence from blogs, generating Threat Detection Opportunities (TDOs), simulating attacker behavior with synthetic UDM events, evaluating rule coverage, generating new YARA-L 2.0 rules to close coverage gaps, and with user approval, deploy them to SecOps. Don't use when asked to perform threat hunting actions, and SOC investigative actions.