What problem does it solve?
This skill provides a structured, operational arsenal for authorized external red-team and bug-bounty reconnaissance, eliminating the need to manually curate probes, wordlists, and regex patterns during engagements.
Core Features & Use Cases
- Reconnaissance Arsenal: Access a comprehensive library of concrete probes, wordlists, and regexes for subdomain enumeration, cloud bucket discovery, and identity fabric mapping.
- Secret Triage: Utilize a 48-pattern secret-scanning catalog to identify leaked credentials across various platforms like AWS, GitHub, and OpenAI.
- Use Case: When performing an authorized external audit, use this skill to systematically map an organization's attack surface, identify exposed cloud buckets, and validate potential secret leaks using the provided helper scripts.
Quick Start
Use the offensive-osint skill to perform an external reconnaissance scan on target.com and identify exposed subdomains and cloud buckets.