osint-methodology

Coordinate external OSINT reconnaissance with a five-stage pipeline and asset-graph taxonomy.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/chatbotkit/rook --skill osint-methodology-chatbotkit
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: osint-methodology
Source: https://github.com/chatbotkit/rook/tree/main/skills/osint-methodology
Command: npx skills add https://github.com/chatbotkit/rook --skill osint-methodology-chatbotkit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

External security assessments require a repeatable, auditable methodology to plan, execute, and document OSINT reconnaissance against in-scope targets. This skill provides a structured approach to identify assets, exposure, and attack paths while maintaining compliance with authorization.

Core Features & Use Cases

  • Five-stage recon pipeline (seed discovery, asset expansion, enrichment, exposure analysis, reporting) for repeatable campaigns.
  • Asset-graph discipline with 29 asset types enabling precise triage and network mapping.
  • Identity fabric mapping, breach correlation guidance, and client-facing deliverable templates for risk translation.

Quick Start

Describe an end-to-end OSINT campaign against an authorized target using the five-stage recon pipeline and asset-graph taxonomy.

Frequently Asked Questions about osint-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a structured OSINT reconnaissance pipeline for mapping an attack surface?▼

A structured OSINT reconnaissance pipeline maps an organization's attack surface through five stages: seed discovery, asset expansion, enrichment, exposure analysis, and reporting, ensuring repeatable and auditable security assessments.

How do I map an organization's external attack surface for a red-team engagement?▼

You map an external attack surface by executing a five-stage reconnaissance workflow that identifies assets, expands the network graph, enriches identity data, analyzes exposure, and generates client-ready risk reports.

Can I use this OSINT methodology for authorized bug bounty programs?▼

Yes, the OSINT methodology is explicitly designed for authorized bug bounty programs and risk assessments, providing detection-aware probing guidance and confidence-upgrade workflows to maintain compliance.

What is the best way to organize discovered assets during external security reconnaissance?▼

The best way to organize discovered assets is using an asset-graph taxonomy covering 29 specific asset types, enabling precise triage, identity fabric mapping, and accurate attack path documentation.

How does time budgeting work in an OSINT campaign?▼

Time budgeting in an OSINT campaign allocates specific durations across the five-stage reconnaissance pipeline, ensuring efficient coverage of web apps, cloud assets, and identity platforms without exceeding engagement limits.

When should I not use detection-aware probing during reconnaissance?▼

Detection-aware probing should be carefully limited or paused when active monitoring risks blocking your IP or violating the authorization scope of a red-team engagement or risk assessment.