offensive-osint

Consolidate OSINT reconnaissance data for authorized red-team engagements.

3.3k|507|Updated May 5, 2026
One-click install
npx skills add https://github.com/elementalsouls/Claude-BugHunter --skill offensive-osint-elementalsouls
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offensive-osint
Source: https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/offensive-osint
Command: npx skills add https://github.com/elementalsouls/Claude-BugHunter --skill offensive-osint-elementalsouls

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Operational OSINT capabilities to systematically map external reconnaissance surfaces for authorized red-team and bug-bounty engagements, reducing manual gathering time and increasing accuracy.

Core Features & Use Cases

  • A modular reference-driven toolkit that provides concrete probes, wordlists, regexes, dorks, and curl one-liners for surface discovery (subdomains, OpenAPI/Swagger, GraphQL, identity fabrics, cloud buckets, origin discovery, vendor fingerprints, CI/CD exposure, secret patterns, Postman workspaces, breach correlations, TLS/JA3 audit, and sector notes).
  • Use case examples include mapping external attack surfaces, scoping reconnaissance, and fast evidence gathering by loading only the needed reference files on demand.

Quick Start

Describe your testing objective in plain English to load the applicable references and activate the relevant skills modules.

Frequently Asked Questions about offensive-osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enumerate subdomains and map API surfaces for an authorized red-team engagement?

Subdomain enumeration and API surface mapping load on-demand reference files providing concrete probes, wordlists, and curl one-liners to systematically discover external reconnaissance targets and identify live OpenAPI or GraphQL endpoints.

What is the best way to harvest Postman workspaces and scout for exposed secret patterns during reconnaissance?

Secret pattern scouting and Postman workspace harvesting apply targeted regexes and dorks from reference files to identify exposed credentials and API collections, reducing manual gathering time for external attack surface mapping.

Can I use this OSINT toolkit for cloud-bucket enumeration and TLS/JA3 auditing on live targets?

Cloud-bucket enumeration and TLS/JA3 auditing operate on live targets by loading specific reference guidance, applying concrete probes to discover exposed storage assets and fingerprint client TLS characteristics.

Does this approach require external dependencies or scripts to perform identity-fabric discovery and breach correlation?

Identity-fabric discovery and breach correlation rely solely on frontmatter parsing and on-demand reference files, requiring no external dependencies to execute reconnaissance tasks.

How do I start vendor fingerprinting and CI/CD exposure discovery using plain English objectives?

Describe your testing objective in plain English to load applicable references and activate relevant modules for vendor fingerprinting and CI/CD exposure discovery, gathering evidence rapidly without manual reference selection.

When should I use a modular reference-driven OSINT approach instead of standalone scanning tools?

A modular reference-driven OSINT approach suits authorized red-team and bug-bounty engagements requiring systematic surface discovery, offering on-demand loading of specific guidance like origin discovery and sector-specific reconnaissance over broad automated scanning.