{"slug":"osint-methodology","title":"osint-methodology","summary":"Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers the 5-stage recon pipeline (seed discovery, asset expansion, enrichment, exposure analysis, reporting), asset-graph discipline with 29 asset types, severity rubric (","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-08-24T05:37:53.151724Z","repo":{"url":"https://github.com/elementalsouls/Claude-BugHunter","stars":4626,"forks":696,"license":"MIT","updatedAt":"2026-09-23T09:21:09Z"},"bodyHtml":"<h1><code>osint-methodology</code> skill</h1>\n<p>The \"how to think\" reference for external red-team OSINT and bug-bounty reconnaissance.</p>\n<table>\n<thead>\n<tr>\n<th>Field</th>\n<th>Value</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Name</td>\n<td><code>osint-methodology</code></td>\n</tr>\n<tr>\n<td>Version</td>\n<td>2.1</td>\n</tr>\n<tr>\n<td>Lines</td>\n<td>~1,700</td>\n</tr>\n<tr>\n<td>Top-level sections</td>\n<td>33</td>\n</tr>\n<tr>\n<td>Subsections</td>\n<td>~125</td>\n</tr>\n<tr>\n<td>Companion skill</td>\n<td><a href=\"../offensive-osint/\"><code>offensive-osint</code></a></td>\n</tr>\n</tbody>\n</table>\n<h2>When this skill triggers</h2>\n<p>Auto-triggers on prompts containing any of ~55 trigger phrases. Common ones:</p>\n<ul>\n<li><code>external recon</code>, <code>external red team</code>, <code>bug bounty recon</code>, <code>attack surface management</code>, <code>ASM</code>, <code>perimeter recon</code></li>\n<li><code>OSINT methodology</code>, <code>recon methodology</code>, <code>target reconnaissance</code>, <code>asset discovery</code>, <code>attack path</code></li>\n<li><code>identity fabric</code>, <code>SSO discovery</code>, <code>IdP fingerprinting</code>, <code>M365 enumeration</code></li>\n<li><code>phishing infrastructure</code>, <code>pretext development</code>, <code>bug bounty submission</code>, <code>responsible disclosure</code></li>\n<li><code>client report</code>, <code>exec summary</code>, <code>risk translation</code></li>\n<li><code>confidence upgrade</code>, <code>time budget</code>, <code>engagement profile</code>, <code>asset triage</code></li>\n<li><code>detection-aware probing</code>, <code>back-off strategy</code>, <code>persona rotation</code></li>\n<li><code>WAF bypass</code>, <code>CDN bypass</code>, <code>origin discovery</code></li>\n<li><code>vulnerability prioritization</code>, <code>CVE prioritization</code>, <code>EPSS</code>, <code>CISA KEV</code></li>\n<li><code>threat actor investigation</code>, <code>attribution</code></li>\n</ul>\n<p>Full trigger list in the SKILL.md frontmatter.</p>\n<h2>What's in it</h2>\n<p>See the parent <a href=\"../../README.md#whats-in-the-box\">README's \"What's in the box\" table</a> for the full §-by-§ breakdown.</p>\n<p>Highlights:</p>\n<ul>\n<li><strong>§7 — 5-stage recon pipeline</strong> + priority order + time budgeting (1h / 4h / 1d / 1w profiles)</li>\n<li><strong>§8 — Asset graph discipline</strong> with 29 typed asset types + 23 typed edges + per-asset-type triage</li>\n<li><strong>§9 — Findings rubric</strong> anchored on examples (CRITICAL → INFO + escalation rules)</li>\n<li><strong>§11 — Identity fabric mapping</strong> (Entra, Okta, ADFS, Google, SAML, AWS, M365 deep)</li>\n<li><strong>§22 — Breach × identity correlation</strong> (HudsonRock + HIBP + DeHashed + IntelX → SSO_EXPOSURE finding)</li>\n<li><strong>§27 — WAF/CDN bypass + origin discovery</strong> (8 techniques)</li>\n<li><strong>§28 — Vulnerability prioritization</strong> (CVE × EPSS × KEV × Metasploit rubric)</li>\n<li><strong>§29 — Phishing infrastructure &amp; pretext development</strong></li>\n<li><strong>§30 — Bug bounty submission templates</strong> (HackerOne, Bugcrowd, Intigriti, etc.)</li>\n<li><strong>§31 — Client deliverable templates</strong> (exec summary + risk translation matrix + reporting cadence)</li>\n</ul>\n<h2>Loading</h2>\n<pre><code># Local Claude Code install\ncp SKILL.md ~/.claude/skills/osint-methodology/SKILL.md\n\n# Or attach to a Claude.ai project / Claude API system prompt\n# (paste contents of SKILL.md as project knowledge)\n</code></pre>\n<p>The full content lives in this <code>SKILL.md</code> (or in <code>docs/full-skills/osint-methodology.SKILL.full.md</code> if this file is the structured-outline variant — see repo root for sync instructions).</p>\n<h2>Self-test</h2>\n<p>Run the prompts in <a href=\"../../tests/smoke-test-prompts.md\"><code>../../tests/smoke-test-prompts.md</code></a> to verify skill behavior after install. Methodology-targeted prompts are tagged in the test file.</p>\n<h2>License</h2>\n<p>MIT — see <a href=\"../../LICENSE\">LICENSE</a>.</p>\n","files":[{"path":"README.md","sizeBytes":2968,"isText":true},{"path":"SKILL.md","sizeBytes":95155,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"notes-only","suspicious":0,"notes":7,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-08-25T17:14:50.53426Z","sha256":"C8A5C4E60E17FFBF9864113235014F003D2F8D4B70572F0BC246226789D44A5E","sizeBytes":41184},"review":null,"source":{"repositoryUrl":"https://github.com/elementalsouls/Claude-BugHunter","path":"skills/osint-methodology","license":"MIT","commit":"4d7b4cdfddb7ec67fba87821e54c768248a544bd","subtreeSha":"15877FE24C936D14DE797DAECE1680F3BD16CF003BBCD21832D1FBF5447602B7","lastSyncedAt":"2026-09-24T06:49:51.293025Z"},"reviewedAt":"2026-08-25T17:20:08.586134Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/osint-methodology"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install elementalsouls-claude-bughunter@llmmart"},{"target":"git","command":"git clone https://github.com/elementalsouls/Claude-BugHunter.git"}]}