offensive-osint

Discovers subdomains, APIs, and sensitive information for authorized red-teaming using Subfinder, Amass, and Wayback Machine.

5|Updated May 27, 2026
One-click install
npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill offensive-osint-cybersecwoman
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offensive-osint
Source: https://github.com/cybersecwoman/Kiro-BugHunter/tree/main/skills/offensive-osint
Command: npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill offensive-osint-cybersecwoman

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a robust set of operational tools for authorized reconnaissance and red-team OSINT activities, allowing you to uncover valuable intelligence from various sources and automate the discovery of critical assets.

Core Features & Use Cases

  • Comprehensive Reconnaissance: Offers a wide range of tools for discovering subdomains, APIs, endpoints, and sensitive information from various sources.
  • Automated Discovery: Automates the discovery of cloud assets, SaaS platforms, and other critical data stores.
  • Use Case: Ideal for red-teaming exercises, bug bounties, or internal security audits to map out the attack surface and identify potential vulnerabilities.

Quick Start

Trigger the offensive-osint skill to initiate reconnaissance on a target.

Frequently Asked Questions about offensive-osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is offensive OSINT and how does it help with red-teaming?

Offensive OSINT involves gathering external intelligence to map an attack surface and uncover sensitive information. It helps red-teaming by automating the discovery of subdomains, APIs, and cloud assets to identify potential vulnerabilities.

How do I discover subdomains and APIs for bug bounty reconnaissance?

You can discover subdomains and APIs for bug bounty reconnaissance by utilizing automated tools that query various data sources. This Skill leverages tools like Subfinder, Amass, and the Wayback Machine to enumerate endpoints and map assets.

Can I use this OSINT toolkit to find sensitive information in cloud assets?

Yes, this OSINT toolkit automates the discovery of cloud assets, SaaS platforms, and critical data stores. It queries multiple data sources to uncover exposed endpoints and sensitive information during authorized external reconnaissance.

What is the best way to automate attack surface mapping for security audits?

The best way to automate attack surface mapping is using a comprehensive toolkit that integrates multiple data sources. This Skill automates external reconnaissance to enumerate subdomains and APIs, providing a complete asset inventory for security audits.

Do I need specific authorization before performing external reconnaissance?

Yes, you must have explicit authorization before performing external reconnaissance and red-team OSINT activities. This Skill is strictly designed for authorized security audits, bug bounties, and red-teaming exercises to ensure legal compliance.

Does this Subfinder and Amass integration support Wayback Machine queries?

Yes, this Skill integrates Subfinder and Amass for asset discovery while also utilizing the Wayback Machine. It combines these data sources to comprehensively identify historical endpoints, subdomains, and sensitive information.

Related Skills