offensive-tools/osint/maltego/SKILL.md
Visual intelligence and link analysis platform for mapping relationships between people, organizations, domains, IPs, and infrastructure. Use when building entity relationship graphs during recon or threat intelligence gathering.
npx skillsauth add aeondave/malskill maltegoInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Visual OSINT and link analysis — entity graph mapping for people, domains, IPs, orgs.
| Entity | Transforms | |--------|-----------| | Domain | DNS, WHOIS, subdomains, MX, NS | | IP Address | Geo, reverse DNS, netblock, Shodan | | Person | Social accounts, email, phone | | Organization | People, domains, certificates | | Email | Breaches, social accounts (Holehe) | | Website | Tech fingerprint, links |
| Transform | Purpose |
|-----------|---------|
| To DNS Name | Subdomain enum |
| To IP Address | Resolve domain |
| To Website | Enumerate web presence |
| To Email Address | Find emails |
| To Social Accounts | Map social media |
| Shodan Search | Enumerate open ports |
Domain recon:
DNS Name – To DNS Name [MX/NS/A]Domain – To WebsiteIP – To ShodanPerson OSINT:
Person – To EmailEmail – To Social Accounts| File | When to load |
|------|--------------|
| references/ | Custom transform and API integration notes |
development
White-box auditing methodology for AI-generated ('vibe-coded') applications. Focuses on modern stack misconfigurations (Supabase, Next.js, Vercel).
development
Hybrid AI/Deterministic SAST methodology for discovering zero-day vulnerabilities in source code. Orchestrates structural search with AI-driven data flow and sink validation.
development
Auth assessment: hardware/embedded methodology; UART/JTAG/SWD/SPI/I2C, firmware extraction, boot/debug paths, embedded OS evidence.
devops
Container methodology: Identifying containerization limits, Docker/K8s misconfigurations, and executing escapes to the host node.