techstack-identification

v2026.09.24

OSINT-based technology stack identification. Routes to 6 domain sub-skills (frontend, backend, infra, security, osint, correlation) to discover a target's stack from publicly available signals.

GitHub
Install command
npx skhub add transilienceai/techstack-identification
Markdown
SKILL.md

Tech Stack Identification

Passive OSINT reconnaissance to identify a target's technology stack. No credentials, no active scanning — only publicly available signals.

Quick Start

1. Provide company name (+ optional domain hint)
2. Run infra first (asset inventory) → frontend / backend / security / osint in parallel
3. Pass all signals into correlation → final report (JSON + Markdown)

Domain Sub-Skills

Sub-skillIdentifiesRead
frontendJS frameworks, meta-frameworks, CSS libraries, build tools, CMS via DOM/HTML/JSfrontend/SKILL.md
backendWeb servers, runtimes, languages, frameworks, DB, APIs, CMSbackend/SKILL.md
infraCloud, CDN/WAF, DNS, TLS/CT, DevOps, asset discovery (domains/subdomains/IPs)infra/SKILL.md
securitySecurity headers, CSP, email auth, security.txt, third-party SaaSsecurity/SKILL.md
osintPublic repos (GitHub/GitLab), job postings/ATS, Wayback Machineosint/SKILL.md
correlationCross-validation, confidence scoring, conflict resolutioncorrelation/SKILL.md

Routing by Objective

ObjectiveMount
Full stack discoveryinfra → (frontend, backend, security, osint) → correlation
CDN/WAF identification onlyinfra
API surface mappingbackend
Supply-chain / SaaS exposuresecurity + osint
CVE matching by versionbackend + frontend (then correlation)
Migration / historical contextosint (web archive) + correlation
CMS fingerprintfrontend (HTML generators) + backend (CMS paths/cookies)
Asset inventory onlyinfra (domain discovery, subdomain enum, IP attribution, CT)

Confidence Levels

  • High: 3+ independent sources OR explicit identifier (header/meta/global) + supporting evidence + version known
  • Medium: Single strong source OR multiple indirect signals (URL patterns, cookies, DOM attrs, job postings)
  • Low: Speculative — single weak signal, conflicting data, or archive-only evidence

Computed in correlation/. Target distribution: 50-70% High, 20-35% Medium, <15% Low.

Final Report Schema

{ "report_id": "uuid", "company": "string", "primary_domain": "string",
  "discovered_assets": {"domains", "subdomains", "ip_addresses", "certificates", "api_portals"},
  "technologies": {
    "frontend": [{"name", "version?", "confidence", "evidence": []}],
    "backend": [...], "infrastructure": [...], "security": [...],
    "devops": [...], "third_party": [...] },
  "confidence_summary": {"high_confidence", "medium_confidence", "low_confidence", "overall_score"} }

Rate Limits

crt.sh 10/min · GitHub (unauth) 60/h · HTTP 30/min/domain · DNS 30/min · Wayback CDX 15/min · WHOIS 5/min.

Ethics

Passive only. No active scanning, credentialed access, zone transfers, or brute force. Public sources only. Log every external request for audit.

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

skills/techstack-identification

Default branch

main

Latest commit

95fdc12

Tree SHA

854bd03