osint-methodology

Extract structured metadata from SKILL.md files and verify optional directories.

3.3k|507|Updated May 5, 2026
One-click install
npx skills add https://github.com/elementalsouls/Claude-BugHunter --skill osint-methodology-elementalsouls
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: osint-methodology
Source: https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/osint-methodology
Command: npx skills add https://github.com/elementalsouls/Claude-BugHunter --skill osint-methodology-elementalsouls

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The OSINT methodology skill provides a structured, repeatable framework for external reconnaissance and authorized bug-bounty OSINT, enabling operators to map an organization's external surface with rigor, reproducibility, and compliance.

Core Features & Use Cases

  • 5-stage recon pipeline (Seed Discovery, Asset Expansion, Enrichment, Exposure Analysis, Reporting) to standardize engagements.
  • Identity fabric mapping, asset-graph discipline, and triage rules to improve scoping, prioritization, and client deliverables.
  • Reusable templates for client reports, executive summaries, and reproduction packages to enable repeatable, auditable engagements.

Quick Start

Describe your target's external surface to initiate the OSINT methodology workflow.

Frequently Asked Questions about osint-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a structured OSINT workflow for authorized recon?

A structured OSINT workflow standardizes external reconnaissance into a 5-stage pipeline: Seed Discovery, Asset Expansion, Enrichment, Exposure Analysis, and Reporting, ensuring rigor, reproducibility, and compliance.

How do I map an organization's external attack surface for a pentest?

You map an organization's external attack surface by applying identity fabric mapping and asset-graph discipline during the recon pipeline, triaging exposures to improve scoping and prioritize client deliverables.

Can I use this OSINT methodology for bug bounty reconnaissance?

Yes, this OSINT methodology is explicitly designed for authorized bug-bounty OSINT, providing a repeatable framework to map external surfaces and generate auditable reproduction packages.

What is the best way to standardize threat intelligence gathering during red-team engagements?

The best way to standardize threat intelligence gathering is using a 5-stage recon pipeline with reusable templates for client reports and executive summaries, enabling repeatable and auditable engagements.

How do I generate reproducible reports from external reconnaissance data?

You generate reproducible reports by using the workflow's reusable templates for client reports, executive summaries, and reproduction packages, ensuring all enrichment and exposure analysis remains auditable.