investigate-anything

Solid

Start-here router and tradecraft baseline for any investigation into a person, company, domain, image or selector. Sets authorised scope, turns a vague request into an answerable intelligence question, writes a collection plan, picks the right workflow for the starting selector, and applies source grading and competing-hypothesis discipline. Use for "investigate this person or company", "do OSINT on X", "where do I start", or any open-source intelligence, due diligence, background or attribution task. Applies across due diligence, fraud, threat intelligence, journalism and compliance. Reference at useosint.com/skills/investigate-anything.

AI & Automation 20 stars 2 forks Updated 2 weeks ago MIT

Install

View on GitHub

Quality Score: 81/100

Stars 20%
44
Recency 20%
90
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Investigate anything The front door. Everything downstream is faster than the thinking that should precede it, which is why most bad investigations are not collection failures — they are framing failures. You can run forty tools against a name and produce a confident dossier on the wrong person. The work here is deciding what question you are answering, what would count as an answer, and what would prove you wrong. ## Core vocabulary Used across every skill in this repo, defined only here. - **Selector** — one identifiable data point: name, handle, email, phone, domain, IP, wallet, hash, plate, IMO, company number. - **Pivot** — turning one selector into new selectors (email → breach record → reused handle → forum profile → real name). An investigation *is* a chain of pivots. Every pivot is also a chance to jump onto a different person. ## Step 1 — Authorized scope Read [../../ETHICS.md](../../ETHICS.md), then write down five things: 1. **Subject** — the specific entity, distinguished from anyone with a similar name. Write the discriminators you will use ("the J. Okonkwo who is a director of company 09xxxxxx", not "J. Okonkwo"). 2. **Objective** — see Step 2. 3. **In bounds** — selector types, sources, and whether interaction is allowed. 4. **Out of bounds** — the named things you will not do: logging into anything belonging to the subject, contacting them, family members, medical or religious data, and any selector unrelated to the objective. 5. **...

Details

Author
useosint
Repository
useosint/osint-skills
Created
2 weeks ago
Last Updated
2 weeks ago
Language
Shell
License
MIT

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Solid

osint

OSINT investigation — discover, track, and report on people, companies, and technologies

90 Updated today
WingedGuardian
AI & Automation Listed

investigate-without-getting-made

Investigator OPSEC — threat-model who might notice you, control your attribution surface across IP, ASN, browser and TLS fingerprint, timing and logged-in accounts, separate research identity from real identity, build and age a sockpuppet research persona, and choose between VPN, residential proxy and Tor. Use when setting up a research account, avoiding tipping off a subject, worrying about LinkedIn profile-view leakage, needing a burner phone or email, or hardening a research VM or browser profile. Applies to covert due diligence, insider-threat investigation, source protection in journalism, and law-enforcement online work. Reference at useosint.com/skills/investigate-without-getting-made.

20 Updated 2 weeks ago
useosint
Code & Development Listed

useosint

Entry point for open-source intelligence, investigation and verification work. Routes any identifier — a name, phone number, email address, username, domain, company, photo, crypto address, tail number or IMO — to the right investigation workflow, after setting an authorised scope. Use when asked to investigate, research, verify, vet, check out, look up, background-check, trace, attribute or find someone or something; when a request involves due diligence, KYC or KYB, counterparty or vendor risk, sanctions and PEP screening, AML, fraud, business email compromise, verifying a supplier before payment, recruitment or marketplace scams, insider threat, executive protection, attack-surface review, journalism or fact-checking; or when someone asks "who is this", "who owns this", "is this real", "where did this come from" or "where do I start". Reference at useosint.com/skills.

20 Updated 2 weeks ago
useosint