osint-methodology

Coordinate five-stage OSINT reconnaissance for authorized red-team operations.

Updated Jun 5, 2026
One-click install
npx skills add https://github.com/sseshachala/Claude-BugHunter-archive --skill osint-methodology-sseshachala
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: osint-methodology
Source: https://github.com/sseshachala/Claude-BugHunter-archive/tree/main/skills/osint-methodology
Command: npx skills add https://github.com/sseshachala/Claude-BugHunter-archive --skill osint-methodology-sseshachala

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Coordinates and codifies external OSINT reconnaissance for authorized red-team engagements, turning scattered intel into a structured, reproducible campaign plan.

Core Features & Use Cases

  • 5-stage recon pipeline (seed discovery, asset expansion, enrichment, exposure analysis, reporting) to systematically identify and triage assets.
  • Asset-graph discipline with 29 asset types and triage rules to enable scalable, repeatable red-team engagements.
  • Comprehensive coverage of identity, cloud, app, and network surfaces with client-facing deliverables and risk translation.

Quick Start

Define a scoped external-recon engagement and run the OSINT methodology to generate a structured asset graph and client-ready findings.

Frequently Asked Questions about osint-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure OSINT recon for an external red-team engagement?

Structure OSINT recon using a five-stage pipeline: seed discovery, asset expansion, enrichment, exposure analysis, and reporting. This methodology coordinates scattered intel into a reproducible campaign plan with an asset graph, triage rules, and client-ready deliverables.

What is the best way to identify and triage external attack surfaces during a red-team campaign?

Identify and triage attack surfaces by applying asset-graph discipline across 29 asset types. The methodology systematically covers identity, cloud, app, and network surfaces, translating findings into risk assessments with confidence levels and UTC-timestamped evidence logs.

How does this OSINT methodology ensure operational security and authorization during recon?

The methodology enforces authorization and provides operational security guardrails throughout the end-to-end workflow. It logs all evidence with UTC timestamps and assigns confidence levels to findings to ensure safe, governed, and reproducible external reconnaissance.

Can I use this methodology to map cloud and web exposures for threat intelligence?

Yes, you can map cloud and web exposures for threat intelligence. The pipeline covers comprehensive identity, cloud, app, and network surfaces, performing exposure analysis to identify authorized target assets and generate structured, reproducible findings.

Does external red-team recon require specific tools or dependencies to run this workflow?

No specific dependencies are required to run this external red-team recon workflow. The methodology provides the structured five-stage process, asset-graph discipline, and triage rules needed to coordinate threat intelligence and attack surface discovery across authorized targets.