osint-methodology

Orchestrate OSINT and red-team reconnaissance across external targets and asset mapping.

Updated Jul 1, 2026
One-click install
npx skills add https://github.com/bpnrockstar/UnifiedBugHunter --skill osint-methodology-bpnrockstar
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: osint-methodology
Source: https://github.com/bpnrockstar/UnifiedBugHunter/tree/main/skills/osint-methodology
Command: npx skills add https://github.com/bpnrockstar/UnifiedBugHunter --skill osint-methodology-bpnrockstar

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides a comprehensive framework for OSINT (Open Source Intelligence) and red-team operations, enabling users to conduct thorough reconnaissance and security assessments against authorized targets.

Core Features & Use Cases

  • 5-Stage Recon Pipeline: Seed discovery, asset expansion, enrichment, exposure analysis, and reporting.
  • Asset Graph Discipline: Map and manage assets as nodes in a graph, defining relationships and provenance.
  • Identity Fabric Mapping: Identify and analyze identity providers and SSO (Single Sign-On) services.
  • API & Auth-Map Methodology: Enumerate, classify, and rank APIs for potential security vulnerabilities.
  • JavaScript Deep Analysis: Scrape and analyze JavaScript code for secrets, endpoints, and internal hostnames.
  • Mobile Attack Surface: Discover and analyze mobile applications for vulnerabilities.
  • Cloud Attack Surface: Enumerate and analyze cloud services and buckets for misconfigurations.
  • Cryptocurrency Investigation: Track transactions and analyze cryptocurrency flows.
  • Image & Video Analysis: Reverse image search, metadata extraction, and geolocation.
  • Chronolocation & Time Analysis: Analyze timestamps and geolocation data for media files.
  • Threat Actor Investigation: Map threat actor infrastructure and attributes.
  • People & Social Media Investigation: Enumerate usernames, profile pictures, and social graphs.
  • Breach × Identity Correlation: Correlate breaches with identities for potential exposure.
  • Infrastructure OSINT: Discover IP, domain, certificate, and malware artifacts.
  • Automation & Case Management: Tools for coordination and preservation of evidence.
  • Synthetic Media Verification: Verify authenticity of media files.
  • Anti-Patterns & Common Failure Modes: Guidance on common mistakes and best practices.
  • Use Case: Conduct a comprehensive OSINT assessment of a target organization, mapping their external attack surface, identifying potential vulnerabilities, and preparing a report for stakeholders.

Quick Start

Load the osint-methodology skill and use the provided prompts for specific tasks, such as performing a reconnaissance on a target domain or analyzing a particular asset.

Frequently Asked Questions about osint-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is OSINT reconnaissance for external red-team operations?

OSINT reconnaissance for external red-team operations involves gathering open-source intelligence to map an organization's attack surface. It targets external assets, APIs, and infrastructure to identify potential vulnerabilities and security exposures.

How do I map an organization's external attack surface?

To map an external attack surface, conduct a 5-stage recon pipeline: discover seeds, expand assets, enrich data, analyze exposures, and report. Manage all discovered assets as interconnected nodes within an asset graph to track relationships and provenance.

Can I trace cryptocurrency flows during a threat actor investigation?

Yes, you can trace cryptocurrency flows and analyze transactions to map threat actor infrastructure and attribute activities. This methodology integrates crypto investigation with broader infrastructure OSINT to correlate IPs, domains, and malware artifacts.

How do I analyze JavaScript code for security vulnerabilities?

Analyze JavaScript code by scraping and performing deep analysis to extract hidden secrets, internal hostnames, and API endpoints. This process helps enumerate and rank APIs while mapping the identity fabric and SSO services of the target.

What is the best way to geolocate media files for OSINT chronolocation?

The best way to geolocate media files is combining reverse image search, metadata extraction, and timestamp analysis. This chronolocation process analyzes visual clues and embedded data to verify synthetic media and pinpoint geographic locations.

What are common OSINT failure modes and anti-patterns to avoid?

Common OSINT failure modes include neglecting asset provenance, failing to preserve evidence, and ignoring operational security. This methodology provides explicit guidance on avoiding these anti-patterns while ensuring proper case management and evidence preservation during reconnaissance.