techstack-identification

v2026.09.24

OSINT-based technology stack identification. Routes to 6 domain sub-skills (frontend, backend, infra, security, osint, correlation) to discover a target's stack from publicly available signals.

GitHub
安装命令
npx skhub add transilienceai/techstack-identification
Markdown
SKILL.md

Tech Stack Identification

Passive OSINT reconnaissance to identify a target's technology stack. No credentials, no active scanning — only publicly available signals.

Quick Start

1. Provide company name (+ optional domain hint)
2. Run infra first (asset inventory) → frontend / backend / security / osint in parallel
3. Pass all signals into correlation → final report (JSON + Markdown)

Domain Sub-Skills

Sub-skillIdentifiesRead
frontendJS frameworks, meta-frameworks, CSS libraries, build tools, CMS via DOM/HTML/JSfrontend/SKILL.md
backendWeb servers, runtimes, languages, frameworks, DB, APIs, CMSbackend/SKILL.md
infraCloud, CDN/WAF, DNS, TLS/CT, DevOps, asset discovery (domains/subdomains/IPs)infra/SKILL.md
securitySecurity headers, CSP, email auth, security.txt, third-party SaaSsecurity/SKILL.md
osintPublic repos (GitHub/GitLab), job postings/ATS, Wayback Machineosint/SKILL.md
correlationCross-validation, confidence scoring, conflict resolutioncorrelation/SKILL.md

Routing by Objective

ObjectiveMount
Full stack discoveryinfra → (frontend, backend, security, osint) → correlation
CDN/WAF identification onlyinfra
API surface mappingbackend
Supply-chain / SaaS exposuresecurity + osint
CVE matching by versionbackend + frontend (then correlation)
Migration / historical contextosint (web archive) + correlation
CMS fingerprintfrontend (HTML generators) + backend (CMS paths/cookies)
Asset inventory onlyinfra (domain discovery, subdomain enum, IP attribution, CT)

Confidence Levels

  • High: 3+ independent sources OR explicit identifier (header/meta/global) + supporting evidence + version known
  • Medium: Single strong source OR multiple indirect signals (URL patterns, cookies, DOM attrs, job postings)
  • Low: Speculative — single weak signal, conflicting data, or archive-only evidence

Computed in correlation/. Target distribution: 50-70% High, 20-35% Medium, <15% Low.

Final Report Schema

{ "report_id": "uuid", "company": "string", "primary_domain": "string",
  "discovered_assets": {"domains", "subdomains", "ip_addresses", "certificates", "api_portals"},
  "technologies": {
    "frontend": [{"name", "version?", "confidence", "evidence": []}],
    "backend": [...], "infrastructure": [...], "security": [...],
    "devops": [...], "third_party": [...] },
  "confidence_summary": {"high_confidence", "medium_confidence", "low_confidence", "overall_score"} }

Rate Limits

crt.sh 10/min · GitHub (unauth) 60/h · HTTP 30/min/domain · DNS 30/min · Wayback CDX 15/min · WHOIS 5/min.

Ethics

Passive only. No active scanning, credentialed access, zone transfers, or brute force. Public sources only. Log every external request for audit.

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

Sep 24, 2026

分类

未分类

许可证

MIT

源路径

skills/techstack-identification

默认分支

main

最新提交

95fdc12

Tree SHA

854bd03