{"slug":"offensive-osint","title":"offensive-osint","summary":"Operational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks, curl one-liners for: subdomain enum, GraphQL/Swagger/REST discovery, identity fabric (Entra/Okta/ADFS/Google/SAML/M365 deep — Teams/SharePoint/OneDrive), cloud b","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-08-24T05:37:52.863822Z","repo":{"url":"https://github.com/elementalsouls/Claude-BugHunter","stars":4626,"forks":696,"license":"MIT","updatedAt":"2026-09-23T09:21:09Z"},"bodyHtml":"<h1><code>offensive-osint</code> skill</h1>\n<p>The \"what to reach for\" operational arsenal for external red-team OSINT and bug-bounty reconnaissance.</p>\n<table>\n<thead>\n<tr>\n<th>Field</th>\n<th>Value</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Name</td>\n<td><code>offensive-osint</code></td>\n</tr>\n<tr>\n<td>Version</td>\n<td>2.1</td>\n</tr>\n<tr>\n<td>Lines</td>\n<td>~3,800</td>\n</tr>\n<tr>\n<td>Top-level sections</td>\n<td>51</td>\n</tr>\n<tr>\n<td>Subsections</td>\n<td>~135</td>\n</tr>\n<tr>\n<td>Companion skill</td>\n<td><a href=\"../osint-methodology/\"><code>osint-methodology</code></a></td>\n</tr>\n</tbody>\n</table>\n<h2>When this skill triggers</h2>\n<p>Auto-triggers on prompts containing any of ~110 trigger phrases. Common ones:</p>\n<ul>\n<li>All triggers from <code>osint-methodology</code> (most prompts pull both)</li>\n<li><code>swagger discovery</code>, <code>openapi discovery</code>, <code>graphql introspection</code>, <code>graphql field suggestion</code></li>\n<li><code>subdomain enumeration</code>, <code>subdomain takeover</code>, <code>cloud bucket enum</code>, <code>S3 enum</code>, <code>GCS enum</code>, <code>Azure blob enum</code></li>\n<li><code>okta enum</code>, <code>entra enum</code>, <code>azure AD enum</code>, <code>ADFS enum</code>, <code>SAML metadata</code></li>\n<li><code>mobile recon</code>, <code>APK analysis</code>, <code>Microsoft 365 deep</code>, <code>Teams federation</code>, <code>SharePoint enum</code>, <code>OneDrive enum</code></li>\n<li><code>secret scanning</code>, <code>secret leak</code>, <code>leaked credential</code>, <code>JWT triage</code>, <code>AWS key triage</code></li>\n<li><code>github dorking</code>, <code>google dorking</code>, <code>postman workspace</code>, <code>stack exchange OSINT</code></li>\n<li><code>breach lookup</code>, <code>have I been pwned</code>, <code>HudsonRock cavalier</code>, <code>infostealer</code>, <code>dehashed</code>, <code>intelx</code></li>\n<li><code>shodan recon</code>, <code>censys recon</code>, <code>certificate transparency</code>, <code>crt.sh</code>, <code>JARM</code>, <code>favicon mmh3</code></li>\n<li><code>JS endpoint extraction</code>, <code>sourcemap leak</code></li>\n<li><code>copy paste probes</code>, <code>curl one-liner</code></li>\n<li><code>email security analysis</code>, <code>SPF DMARC DKIM</code></li>\n<li><code>origin discovery</code>, <code>CDN bypass</code>, <code>WAF bypass</code></li>\n<li><code>vendor product fingerprints</code>, <code>Citrix Netscaler</code>, <code>F5 BIG-IP</code>, <code>Pulse Secure</code>, <code>FortiGate</code>, <code>PaloAlto GlobalProtect</code>, <code>Cisco AnyConnect</code>, <code>VMware vCenter</code></li>\n<li><code>cloud native fingerprint</code>, <code>Lambda function URL</code>, <code>Cloud Run</code></li>\n<li><code>kubernetes exposure</code>, <code>kubelet</code>, <code>etcd</code></li>\n<li><code>CI CD exposure</code>, <code>Jenkins recon</code>, <code>GitLab self-hosted</code>, <code>GitHub Actions secrets</code></li>\n<li><code>documentation leak</code>, <code>Notion public</code>, <code>Confluence anonymous</code>, <code>Trello board</code></li>\n<li><code>WHOIS RDAP</code>, <code>DNS record catalog</code>, <code>Wayback CDX</code></li>\n<li><code>LinkedIn enumeration</code>, <code>job posting tech stack</code></li>\n<li><code>Slack workspace discovery</code>, <code>Discord server discovery</code></li>\n<li><code>npm token leak</code>, <code>PyPI token leak</code>, <code>Docker Hub leak</code></li>\n<li><code>sat imagery physical recon</code></li>\n<li><code>TLS deep audit</code>, <code>JA3 JA4</code>, <code>reverse DNS sweep</code>, <code>IPv6 enumeration</code></li>\n<li><code>CVE prioritization</code>, <code>EPSS scoring</code>, <code>CISA KEV</code>, <code>vulnerability prioritization</code></li>\n<li><code>tooling install</code></li>\n<li><code>sector specific recon</code>, <code>healthcare DICOM</code>, <code>finance SWIFT</code>, <code>ICS SCADA</code>, <code>Modbus</code>, <code>BACnet</code></li>\n<li><code>post discovery workflow</code></li>\n<li><code>Anthropic API key</code>, <code>OpenAI API key</code></li>\n</ul>\n<p>Full trigger list in the SKILL.md frontmatter.</p>\n<h2>What's in it</h2>\n<p>See the parent <a href=\"../../README.md#whats-in-the-box\">README's \"What's in the box\" table</a> for the full §-by-§ breakdown.</p>\n<p>Highlights:</p>\n<ul>\n<li><strong>§16 — Pre-built wordlists &amp; probe paths</strong> including 28 Swagger paths, 13 GraphQL paths + introspection POST body, 35 high-risk ports, 6 missing security headers, 15 always-on HTTP checks, 5 SAML metadata paths, 8 SSO subdomain prefixes, cloud-bucket arsenal (6 prefixes × 15 suffixes × 47 stems × 3 providers), JS guess-paths, endpoint-extraction regex tiers, internal-host leakage regexes, 27 takeover provider fingerprints, copy-paste curl probes, email security analysis, origin discovery / CDN bypass, vendor product fingerprints, cloud-native fingerprints, container/K8s exposure, CI/CD exposure, doc/wiki leak paths, WHOIS/RDAP, DNS catalog with TXT verification token table, Wayback CDX deep usage.</li>\n<li><strong>§17 — Secret-pattern catalog (48 patterns)</strong> with severity, category, false-positive notes.</li>\n<li><strong>§18 — Dork corpus (80+ templates, 9 categories)</strong>.</li>\n<li><strong>§20 — Endpoint interest score (0–100 rubric)</strong>.</li>\n<li><strong>§21 — Mobile app ownership confidence (0–100 rubric)</strong>.</li>\n<li><strong>§22 — Identity-fabric concrete endpoints</strong> (incl. M365 Deep + GraphQL field-suggestion enum).</li>\n<li><strong>§23 — 9 read-only secret validators</strong> + post-discovery enumeration workflows.</li>\n<li><strong>§39 — 27 attack-path hint templates</strong>.</li>\n<li><strong>§40 — Severity decision matrix (80+ worked examples)</strong>.</li>\n<li><strong>§41–§47 — LinkedIn enum, job posting analysis, Slack/Discord discovery, package registry leaks, sat imagery, tooling install, sector notes</strong>.</li>\n<li><strong>§48 — Runnable secret-scan helper</strong> (stdlib-only Python, available standalone at <a href=\"scripts/secret_scan.py\"><code>scripts/secret_scan.py</code></a>).</li>\n</ul>\n<h2>Loading</h2>\n<pre><code># Local Claude Code install\ncp SKILL.md ~/.claude/skills/offensive-osint/SKILL.md\ncp scripts/secret_scan.py ~/.claude/skills/offensive-osint/scripts/secret_scan.py\n\n# Or attach to a Claude.ai project / Claude API system prompt\n</code></pre>\n<p>The full content lives in this <code>SKILL.md</code> (or in <code>docs/full-skills/offensive-osint.SKILL.full.md</code> if this file is the structured-outline variant).</p>\n<h2>Helper script</h2>\n<p><a href=\"scripts/secret_scan.py\"><code>scripts/secret_scan.py</code></a> — stdlib-only Python scanner mirroring the §17 secret-pattern catalog. Run standalone:</p>\n<pre><code>python3 scripts/secret_scan.py path/to/repo/        # scan a directory tree\npython3 scripts/secret_scan.py file1 file2 file3    # scan specific files\ncat my.log | python3 scripts/secret_scan.py         # pipe stdin\n</code></pre>\n<p>Output: JSONL — one finding per line — <code>jq</code>-friendly.</p>\n<h2>Self-test</h2>\n<p>Run the prompts in <a href=\"../../tests/smoke-test-prompts.md\"><code>../../tests/smoke-test-prompts.md</code></a>. Arsenal-targeted prompts are tagged in the test file.</p>\n<h2>License</h2>\n<p>MIT — see <a href=\"../../LICENSE\">LICENSE</a>.</p>\n","files":[{"path":"README.md","sizeBytes":5313,"isText":true},{"path":"references/breach-and-credentials.md","sizeBytes":7419,"isText":true},{"path":"references/dork-corpus.md","sizeBytes":6295,"isText":true},{"path":"references/helpers-and-automation.md","sizeBytes":11155,"isText":true},{"path":"references/identity-fabric.md","sizeBytes":12042,"isText":true},{"path":"references/people-osint.md","sizeBytes":6098,"isText":true},{"path":"references/probes-and-wordlists.md","sizeBytes":55596,"isText":true},{"path":"references/recon-stack.md","sizeBytes":13587,"isText":true},{"path":"references/recon-techniques.md","sizeBytes":16610,"isText":true},{"path":"references/saas-public-surfaces.md","sizeBytes":4405,"isText":true},{"path":"references/secret-patterns.md","sizeBytes":5700,"isText":true},{"path":"references/secret-validators.md","sizeBytes":11712,"isText":true},{"path":"references/sector-notes.md","sizeBytes":4443,"isText":true},{"path":"references/severity-matrix.md","sizeBytes":9645,"isText":true},{"path":"references/specialized-osint.md","sizeBytes":11517,"isText":true},{"path":"references/tooling-install.md","sizeBytes":4297,"isText":true},{"path":"scripts/assets/archivo-black.woff2","sizeBytes":14332,"isText":false},{"path":"scripts/assets/FONT-LICENSE.txt","sizeBytes":528,"isText":true},{"path":"scripts/dashboard.py","sizeBytes":48752,"isText":true},{"path":"scripts/h1_reference.py","sizeBytes":12938,"isText":true},{"path":"scripts/secret_scan.py","sizeBytes":8111,"isText":true},{"path":"SKILL.md","sizeBytes":34038,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"human-reviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"human-reviewed","screen":{"ran":true,"outcome":"flagged-cleared-by-moderator","suspicious":1,"notes":13,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-08-25T17:14:49.995207Z","sha256":"30A7601A6B7683CAF378D16F891D5512B1784462E977ECB34AF969FB5C137568","sizeBytes":132082},"review":null,"source":{"repositoryUrl":"https://github.com/elementalsouls/Claude-BugHunter","path":"skills/offensive-osint","license":"MIT","commit":"4d7b4cdfddb7ec67fba87821e54c768248a544bd","subtreeSha":"1E5D7591EDF3DFBE8F2F726B69AB3B4CA0EC85C1E7F669C7456CBC4BABD92781","lastSyncedAt":"2026-09-24T06:49:51.293025Z"},"reviewedAt":"2026-08-27T17:05:32.315658Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/offensive-osint"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install elementalsouls-claude-bughunter@llmmart"},{"target":"git","command":"git clone https://github.com/elementalsouls/Claude-BugHunter.git"}]}