osint-methodology

Provides a structured 5-stage reconnaissance framework for authorized red-team campaigns.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill osint-methodology-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: osint-methodology
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/redteam/osint-methodology
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill osint-methodology-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill solves the lack of structured, reproducible, and detection-aware reconnaissance workflows in offensive security engagements, preventing scope creep and missed attack surface areas.

Core Features & Use Cases

  • 5-Stage Recon Pipeline: Provides a rigorous framework for seed discovery, asset expansion, enrichment, exposure analysis, and reporting.
  • Asset-Graph Discipline: Enables tracking of 29 distinct asset types with typed relationships to ensure comprehensive coverage.
  • Use Case: When tasked with an external red-team assessment, use this skill to map an organization's entire identity fabric, identify exposed cloud buckets, and prioritize vulnerabilities based on real-world exploitability.

Quick Start

Use the osint-methodology skill to initiate a structured reconnaissance campaign against the target domain example.com.

Frequently Asked Questions about osint-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure external red-team reconnaissance to avoid scope creep?

Mapping an organization's attack surface starts with seed discovery and asset expansion to identify cloud assets and exposed infrastructure. It requires tracking distinct asset types with typed relationships to ensure comprehensive coverage of the identity fabric without missing critical exposures.

How does detection-aware probing work during attack surface management?

Detection-aware probing ensures reconnaissance activities remain stealthy while mapping the attack surface. It involves strict confidence-level tracking and asset-graph discipline to maintain high-quality, defensible security assessments without triggering the target's security alerts during red-team engagements.

What is the best way to track asset relationships during bug bounty reconnaissance?

This reconnaissance methodology supports authorized external red-team assessments, bug bounty hunting, and attack surface management. It is designed for security professionals who need to map an organization's entire identity fabric, identify exposed cloud buckets, and prioritize vulnerabilities based on real-world exploitability.

What should be included in professional reporting for red-team reconnaissance?

Professional red-team reporting should encompass the full reconnaissance lifecycle from initial seed discovery to exposure analysis. It implements strict confidence-level tracking and asset-graph discipline to produce defensible security assessments that prioritize vulnerabilities based on real-world exploitability.