offensive-osint

Load modular OSINT reference files for authorized external red-team reconnaissance.

Updated Jun 5, 2026
One-click install
npx skills add https://github.com/sseshachala/Claude-BugHunter-archive --skill offensive-osint-sseshachala
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offensive-osint
Source: https://github.com/sseshachala/Claude-BugHunter-archive/tree/main/skills/offensive-osint
Command: npx skills add https://github.com/sseshachala/Claude-BugHunter-archive --skill offensive-osint-sseshachala

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

External red-team OSINT reconnaissance is hampered by fragmented references and inconsistent access to validated probes, wordlists, and end-to-end workflows; this skill aggregates a modular, load-on-demand reference set to accelerate scoping and discovery while maintaining authorization boundaries.

Core Features & Use Cases

  • Concrete probes, wordlists, regexes, and dorks for subdomain enumeration, identity-fabric mapping, cloud bucket enumeration, TLS/JA3 assessment, and sector-specific recon.
  • 15 modular reference files loaded on demand from references/, enabling targeted loading and faster context assembly.
  • Safe, scoped automation through on-demand scripts and references that Claude can load per task prompts.

Quick Start

Load and execute the relevant references and scripts for an authorized external-red-team OSINT engagement focused on subdomain enumeration, identity fabric discovery, cloud-bucket checks, and secret-pattern triage.

Frequently Asked Questions about offensive-osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform external red-team reconnaissance with OSINT probes?

External red-team reconnaissance is executed by loading modular reference files on demand to deploy concrete probes, wordlists, regexes, and curl one-liners for subdomain enumeration and cloud-bucket discovery.

What is identity-fabric discovery in OSINT engagements?

Identity-fabric discovery maps targeted identities and surfaces using validated regexes and dorks, enabling scoped reconnaissance across authorized external targets during red-team operations.

How do I enumerate cloud buckets and subdomains for authorized security testing?

Cloud bucket and subdomain enumeration uses load-on-demand wordlists and targeted curl probes from modular reference scripts, accelerating scoping and discovery while maintaining strict authorization boundaries.

Can I scope OSINT automation to respect authorization boundaries?

Yes, OSINT automation is scoped by loading only relevant reference files per task prompt, strictly respecting authorization boundaries and operational limits for targeted external engagements.

What is TLS JA3 fingerprinting and when do I need it for red-team recon?

TLS JA3 fingerprinting assesses targeted engagements by analyzing handshake patterns, needed when external red-team reconnaissance requires precise service identification across discovered subdomains.

Why use modular reference files instead of a single OSINT script?

Modular reference files enable targeted loading and faster context assembly, solving fragmented references by aggregating validated probes, dorks, and wordlists for on-demand OSINT reconnaissance.