osint-methodology

Automate a 5-stage OSINT recon pipeline for authorized red teaming.

5|Updated May 27, 2026
One-click install
npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill osint-methodology-cybersecwoman
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: osint-methodology
Source: https://github.com/cybersecwoman/Kiro-BugHunter/tree/main/skills/osint-methodology
Command: npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill osint-methodology-cybersecwoman

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill addresses the challenge of conducting thorough reconnaissance and red teaming operations, providing a structured OSINT methodology for authorized targets.

Core Features & Use Cases

  • Comprehensive Recon Pipeline: Covers the 5-stage recon pipeline (seed discovery, asset expansion, enrichment, exposure analysis, reporting).
  • Asset Graph Discipline: Manages and maps 29 asset types, with relationships defined by a 12-point edge taxonomy.
  • Confidence Levels & Workflows: Utilizes TENTATIVE, FIRM, and CONFIRMED confidence levels with defined upgrade workflows.
  • Output Format Conventions: Structures findings for asset management tools with a specified schema.
  • Source Hygiene & Citations: Emphasizes secure and reliable source citations and artifact handling.
  • OpSec & Detection-Aware Probing: Provides guidance on operational security and minimizing detection during recon operations.
  • External Red-Team Recon Pipeline: A 5-stage pipeline for any authorized external assessment, with time budgeting and engagement profiles.
  • Risk Scoring & Reporting: Offers risk scoring per finding, asset graph export, client-facing reports, and reproduction packages.

Quick Start

Run the osint-methodology skill to start a recon engagement on a target.

Frequently Asked Questions about osint-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a comprehensive OSINT methodology for authorized red teaming reconnaissance?

A comprehensive OSINT methodology for red teaming automates a 5-stage pipeline covering seed discovery, asset expansion, enrichment, exposure analysis, and reporting to map target attack surfaces. It manages asset graphs and applies confidence level workflows to structure findings for client-facing reports.

How do I conduct an external red-team recon pipeline with asset graph discipline?

You conduct external red-team recon by executing a 5-stage pipeline that maps 29 asset types using a 12-point edge taxonomy. This methodology manages relationships across seed discovery, asset expansion, and exposure analysis, outputting structured asset graphs and risk-scored findings.

How does confidence level workflow function during security assessment reconnaissance?

Confidence level workflows function by categorizing reconnaissance findings into TENTATIVE, FIRM, and CONFIRMED states with defined upgrade paths. This ensures asset expansion and exposure analysis data is validated before being exported to asset management tools or included in client-facing reports.

Can I use this OSINT methodology for detection-aware probing and operational security?

Yes, this OSINT methodology provides explicit guidance on operational security and detection-aware probing to minimize discovery during authorized recon. It includes source hygiene, secure artifact handling, and time budgeting profiles to maintain OpSec throughout the external assessment.

What output formats are generated for asset management tools from an OSINT recon pipeline?

The OSINT recon pipeline generates structured findings with a specified schema, asset graph exports, risk scores per finding, and reproduction packages. These outputs are formatted for direct ingestion into asset management tools and for generating client-facing reports.