osint-methodology

Structure external red-team reconnaissance with a 5-stage OSINT pipeline.

Updated Jun 18, 2026
One-click install
npx skills add https://github.com/Kisilev13/Hermes-Agent-Workspace --skill osint-methodology-kisilev13
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: osint-methodology
Source: https://github.com/Kisilev13/Hermes-Agent-Workspace/tree/main/skills/osint-methodology
Command: npx skills add https://github.com/Kisilev13/Hermes-Agent-Workspace --skill osint-methodology-kisilev13

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a structured OSINT methodology for comprehensive external red-team operations and attack-surface assessments, enabling efficient reconnaissance and evidence gathering.

Core Features & Use Cases

  • Comprehensive OSINT Pipeline: 5-stage pipeline for authorized recon, including seed discovery, asset expansion, enrichment, exposure analysis, and reporting.
  • Asset Graph Discipline: 29 typed asset types and 23 typed edges for structured discovery and correlation.
  • Confidence Levels: TENTATIVE, FIRM, and CONFIRMED confidence levels for every assertion.
  • Output Format Conventions: Structured findings for integration with asset management tools.
  • Source Hygiene & Citations: Durable references and detailed artifact recording for traceability.
  • OpSec Tagging: Detectability tagging for operational security.

Quick Start

Run the osint-methodology skill to initiate an external reconnaissance operation against an authorized target.

Frequently Asked Questions about osint-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure OSINT reconnaissance for external red-team operations?

Structure OSINT reconnaissance using a 5-stage pipeline: seed discovery, asset expansion, enrichment, exposure analysis, and reporting. This methodology enforces asset graph discipline and structured findings for authorized attack-surface assessments.

What is the best way to track confidence levels during attack-surface assessments?

Track confidence levels during attack-surface assessments by assigning TENTATIVE, FIRM, or CONFIRMED statuses to every assertion. This ensures structured findings and traceable evidence for external red-team operations.

How do I map asset relationships during red-team OSINT gathering?

Map asset relationships during OSINT gathering using asset graph discipline, which defines 29 typed asset types and 23 typed edges for structured discovery and correlation across the reconnaissance pipeline.

Does this OSINT methodology support operational security and source traceability?

Yes, the OSINT methodology supports operational security by tagging detectability for recon actions and maintains source hygiene through durable references and detailed artifact recording for full traceability.

Can I integrate OSINT findings with external asset management tools?

Yes, you can integrate findings with external asset management tools because the methodology uses output format conventions that generate structured findings and asset graphs suitable for downstream analysis.

Do I need external tools to perform attack-surface reconnaissance with this methodology?

Yes, this methodology requires OSINT expertise and external tools for data gathering and analysis, providing the structured pipeline, asset graph discipline, and reporting conventions rather than executing the scans directly.