osint-methodology

Execute a 5-stage reconnaissance pipeline for external attack surface mapping.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/pdparchitect/rook --skill osint-methodology-pdparchitect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: osint-methodology
Source: https://github.com/pdparchitect/rook/tree/main/skills/osint-methodology
Command: npx skills add https://github.com/pdparchitect/rook --skill osint-methodology-pdparchitect

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill solves the lack of consistency and rigor in external reconnaissance by providing a standardized, 5-stage methodology for mapping attack surfaces and identifying vulnerabilities.

Core Features & Use Cases

  • 5-Stage Recon Pipeline: Orchestrates seed discovery, asset expansion, enrichment, exposure analysis, and reporting.
  • Asset Graph Discipline: Categorizes findings into 29 typed asset types with defined relationships to ensure data integrity.
  • Severity & Confidence Rubrics: Provides clear frameworks for grading findings and verifying evidence to prevent over-claiming.
  • Use Case: Use this skill to conduct a professional-grade external attack surface assessment, ensuring all findings are documented with proper evidence, UTC timestamps, and risk translation.

Quick Start

Use the osint-methodology skill to perform a full reconnaissance pipeline against the target domain example.com while adhering to the defined authorization and confidence protocols.

Frequently Asked Questions about osint-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform structured external reconnaissance for a red-team engagement?

Structured external reconnaissance follows a 5-stage pipeline: seed discovery, asset expansion, enrichment, exposure analysis, and reporting to map the attack surface. This ensures consistent asset discovery and vulnerability identification with documented evidence.

What is attack surface management and how does it model asset relationships?

Attack surface management identifies and categorizes external exposures into 29 typed asset types with defined relationships. This asset graph discipline ensures data integrity when mapping target vulnerabilities during security audits.

How do I verify confidence levels and prevent over-claiming during bug bounty reconnaissance?

Confidence levels are verified using specific rubrics that require evidence-based reporting for all findings. This prevents over-claiming by ensuring vulnerabilities are graded and backed by proper evidence before submission.

Does this reconnaissance methodology support evidence-based reporting with UTC timestamps?

Yes, the methodology enforces evidence-based reporting by requiring proper documentation, UTC timestamps, and risk translation for all findings. This satisfies professional security audit requirements and detection-aware probing discipline.

Can I use this framework for authorized security audits requiring detection-aware probing?

Yes, this framework is designed for authorized external reconnaissance and attack surface management operations. It explicitly satisfies requirements for detection-aware probing discipline and evidence-based reporting in security audits.

What is the best way to categorize found assets during external attack surface mapping?

The best way to categorize found assets is using an asset graph discipline that maps findings into 29 typed asset types with defined relationships. This ensures data integrity during exposure analysis and reporting.