osint-methodology

Map an organization's external attack surface through a five-stage OSINT pipeline.

Updated Jun 23, 2024
One-click install
npx skills add https://github.com/n4igme/randscript --skill osint-methodology-n4igme
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: osint-methodology
Source: https://github.com/n4igme/randscript/tree/main/llm/skills/claude-hunter/skills/osint-methodology
Command: npx skills add https://github.com/n4igme/randscript --skill osint-methodology-n4igme

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

OSINT methodology provides a structured, repeatable framework for external red-team reconnaissance, reducing scope creep, improving data quality, and accelerating client-ready reporting.

Core Features & Use Cases

  • Stage-based 5-step OSINT pipeline (Seed Discovery, Asset Expansion, Enrichment, Exposure Analysis, Reporting) with an asset-graph approach and risk scoring.
  • Identity, cloud, and tech-stack mapping tailored for authorized engagements, enabling reproducible findings and client deliverables.
  • Use Case: plan an external recon for a red-team exercise, build an asset graph, and produce executive-safe deliverables.

Quick Start

To begin, integrate the OSINT methodology into your engagement plan and run the seed discovery stage against the target while maintaining authorization and safe-operational procedures.

Frequently Asked Questions about osint-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure red-team OSINT reconnaissance to avoid scope creep?

Structure red-team OSINT reconnaissance using a five-stage pipeline: Seed Discovery, Asset Expansion, Enrichment, Exposure Analysis, and Reporting. This enforces authorization checks and data provenance to prevent scope creep and ensure compliant engagements.

What is the best way to map an organization's external attack surface for authorized engagements?

The best way to map an external attack surface is applying an asset-graph approach across subdomains, identities, cloud services, and APIs. This method enriches discovered assets and applies risk scoring to produce reproducible findings for authorized testing.

How do I produce client-ready OSINT reports from external recon data?

Produce client-ready OSINT reports by executing the Reporting stage of the recon pipeline, which translates the mapped asset graph and exposure analysis into executive-safe deliverables with applied risk scoring and auditable data provenance.

Can I use a structured OSINT methodology for cloud services and APIs?

Yes, this structured OSINT methodology explicitly supports mapping cloud services and APIs during the Asset Expansion and Enrichment stages, allowing you to identify exposures and build a comprehensive asset graph for these specific external targets.

Does this OSINT methodology enforce authorization checks during reconnaissance?

Yes, the methodology enforces strict authorization checks and safe-operational procedures throughout the entire pipeline. It ensures data provenance and auditable engagements, maintaining compliance during seed discovery and asset expansion.

What are the limitations of using a stage-based OSINT pipeline for red-team exercises?

A stage-based OSINT pipeline is limited to external attack surface reconnaissance for authorized red-team exercises. It does not perform active exploitation and relies entirely on maintaining strict authorization boundaries and safe-operational procedures.