🛰️
AutomationShell

Passive Domain Recon

by useosint

Passive Domain Recon is an Automation skill for Claude Code, published by useosint in osint-skills.

12 stars1 forkson useosint/osint-skillsAdded 2026/08/12+200% in starsRepository updated 2026/08/03
agent-skillsai-agentsclaudeclaude-skillscursorcursor-skillscybersecuritydigital-forensicsdue-diligencegeointinformation-gatheringinfosecinvestigationopen-source-intelligenceosintosint-toolspentestingreconnaissancesocmintthreat-intelligence
Install in seconds
Install Passive Domain Recon
Copy Passive Domain Recon into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/useosint/osint-skills/tree/main/skills/recon-a-domain-passively ~/.claude/skills/recon-a-domain-passively

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/useosint/osint-skills.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
skills/recon-a-domain-passively/SKILL.md in useosint/osint-skills
Installs to
~/.claude/skills/recon-a-domain-passively
Collection
One of 25 skills cataloged from this repository
Category
Automation1523 skills

What Passive Domain Recon does

Passive Domain Recon builds an asset inventory for a domain, website, or IP from registration, DNS, subdomains, infrastructure, history, and ownership without contacting the target. Use it to profile an organization, assess exposure, or investigate a suspicious site quietly.

Passive Domain Recon is cataloged under Automation on DirSkills. Passive Domain Recon comes from a repository tagged agent-skills, ai-agents, claude, claude-skills and cursor.

Documentation

README

Recon a domain passively

Turn one domain into a defensible map of an organization's internet-facing estate plus the owner behind it. The techniques live in other skills; what this workflow contributes is the order, the inventory, and the stopping rule. Two failure modes to avoid from the start: enumerating for hours and producing 400 hostnames with no attribution, dates or priority, which is not a map; and drifting active without noticing, because one probe "just to check if it's up" ends the passive claim. Decide the passive boundary before step 2, not during it.

Ordering logic

Each stage feeds the next, and the sequence is cheapest-and-quietest first:

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Passive Domain Recon

  • What else does useosint publish alongside Passive Domain Recon?

    Passive Domain Recon is one of 25 skills that DirSkills catalogs from useosint/osint-skills, the repository it ships in. Its siblings there include Dig Through Data Brokers, Find Anyone and Find Exposed Servers. Each one is a separate skill with its own page in this directory, installs the same way Passive Domain Recon does, and is maintained by useosint in that same repository. The rest of the collection is listed on the useosint/osint-skills page.

  • How does Passive Domain Recon compare to other Automation skills?

    Passive Domain Recon ranks #1515 by stars among the 1523 Automation skills in this catalog. The most-starred ones next to it are Autonomous Loops, Autonomous Agent Harness and Automation Audit Ops. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Passive Domain Recon against them. Open each page to compare what they document and how they install.

More from useosint/osint-skills

Passive Domain Recon is one of 25 skills cataloged on DirSkills from useosint/osint-skills.

See all 25 skills
🕵️
3w ago

Dig Through Data Brokers

Dig Through Data Brokers uses people-search sites and public records to turn a name into candidate addresses, phones, relatives, and background details, then confirm them against primary sources. Use it for skip tracing, reverse address lookups, self-audits, and broker data removal.
Automation
121
🕵️
3w ago

Find Anyone

Find Anyone builds a sourced profile of one specific person from public records, professional profiles, court filings, and other open sources. It is used to identify, verify, or background-check someone while avoiding name-mixups.
AI Engineering
121
🔎
3w ago

Find Exposed Servers

Find Exposed Servers uses Shodan, Censys, and similar scan data to identify internet-facing hosts, ports, services, and devices without touching the target. Use it for exposure checks, origin-IP pivots, and Shodan query syntax.
Automation
121
🔎
3w ago

Find Hidden Subdomains

Find Hidden Subdomains enumerates an organization’s subdomains and sibling domains from Certificate Transparency logs and passive DNS without sending traffic to the target. Use it to map hostnames, find staging or admin systems, and spot newly issued certificates.
Automation
121
🕵️
3w ago

Find Leaks In The Wild

Find Leaks In The Wild helps check whether a name, email, domain, or credential is circulating in pastes, forums, and Telegram, and whether a claimed leak is genuine or a recycled combolist. Use it for breach triage, threat intelligence, and leak monitoring.
Automation
121
🖼️
3w ago

Find The Original Image

Find The Original Image uses multiple reverse image search engines to trace an image to its earliest known publication and read the source page. Use it to identify photos, logos, places, profile pictures, reposts, or video keyframes.
Automation
121