osint-methodology

Coordinate external OSINT reconnaissance with a five-stage pipeline and asset-graph taxonomy.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/chatbotkit/rook --skill osint-methodology-chatbotkit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: osint-methodology
Source: https://github.com/chatbotkit/rook/tree/main/skills/osint-methodology
Command: npx skills add https://github.com/chatbotkit/rook --skill osint-methodology-chatbotkit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

External security assessments require a repeatable, auditable methodology to plan, execute, and document OSINT reconnaissance against in-scope targets. This skill provides a structured approach to identify assets, exposure, and attack paths while maintaining compliance with authorization.

Core Features & Use Cases

  • Five-stage recon pipeline (seed discovery, asset expansion, enrichment, exposure analysis, reporting) for repeatable campaigns.
  • Asset-graph discipline with 29 asset types enabling precise triage and network mapping.
  • Identity fabric mapping, breach correlation guidance, and client-facing deliverable templates for risk translation.

Quick Start

Describe an end-to-end OSINT campaign against an authorized target using the five-stage recon pipeline and asset-graph taxonomy.

Frequently Asked Questions about osint-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a structured OSINT reconnaissance pipeline for mapping an attack surface?

A structured OSINT reconnaissance pipeline maps an organization's attack surface through five stages: seed discovery, asset expansion, enrichment, exposure analysis, and reporting, ensuring repeatable and auditable security assessments.

How do I map an organization's external attack surface for a red-team engagement?

You map an external attack surface by executing a five-stage reconnaissance workflow that identifies assets, expands the network graph, enriches identity data, analyzes exposure, and generates client-ready risk reports.

Can I use this OSINT methodology for authorized bug bounty programs?

Yes, the OSINT methodology is explicitly designed for authorized bug bounty programs and risk assessments, providing detection-aware probing guidance and confidence-upgrade workflows to maintain compliance.

What is the best way to organize discovered assets during external security reconnaissance?

The best way to organize discovered assets is using an asset-graph taxonomy covering 29 specific asset types, enabling precise triage, identity fabric mapping, and accurate attack path documentation.

How does time budgeting work in an OSINT campaign?

Time budgeting in an OSINT campaign allocates specific durations across the five-stage reconnaissance pipeline, ensuring efficient coverage of web apps, cloud assets, and identity platforms without exceeding engagement limits.

When should I not use detection-aware probing during reconnaissance?

Detection-aware probing should be carefully limited or paused when active monitoring risks blocking your IP or violating the authorization scope of a red-team engagement or risk assessment.