osint-methodology

Map an organization's external attack surface through a 5-stage OSINT recon pipeline.

Updated May 31, 2026
One-click install
npx skills add https://github.com/grivera82/pi-bughunter --skill osint-methodology-grivera82
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: osint-methodology
Source: https://github.com/grivera82/pi-bughunter/tree/main/skills/osint-methodology
Command: npx skills add https://github.com/grivera82/pi-bughunter --skill osint-methodology-grivera82

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Reconnaissance for external targets across an organization's attack surface is often chaotic and unrepeatable. This skill provides a structured OSINT methodology to standardize external red-team reconnaissance and produce reproducible outcomes.

Core Features & Use Cases

  • 5-stage recon pipeline (Seed Discovery, Asset Expansion, Enrichment, Exposure Analysis, Reporting) to thoroughly map assets and produce actionable findings.
  • Identity fabric mapping (Entra/Okta/ADFS/Google/SAML/M365), API/auth-map discovery, WAF/CDN inference, and vulnerability prioritization to support comprehensive engagement planning and client deliverables.
  • Use cases include red-team operations, bug-bounty prep, ASM engagements, and threat-hunting workflows focusing on evidence hygiene and clear risk translation.

Quick Start

Load this SKILL.md as your project knowledge prompt and start the OSINT methodology workflow to begin seed discovery.

Frequently Asked Questions about osint-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure external reconnaissance for red-team operations across an organization's attack surface?▼

External reconnaissance is structured using a 5-stage OSINT pipeline covering seed discovery, asset expansion, enrichment, exposure analysis, and reporting to map identity, cloud, apps, and infrastructure assets.

What is the best way to map SSO and API attack surfaces during OSINT threat hunting?▼

Mapping SSO and API attack surfaces involves identity fingerprinting for Entra, Okta, ADFS, Google, SAML, and M365, alongside targeted API, GraphQL, and auth-map discovery to reveal external authentication exposures.

Can I use this OSINT methodology for bug bounty prep and ASM readiness?▼

Yes, this OSINT methodology applies directly to bug bounty prep and ASM readiness by standardizing reconnaissance workflows, performing WAF/CDN inference, and maintaining evidence hygiene for actionable vulnerability prioritization.

How do I generate client-ready deliverables from external attack surface fingerprinting?▼

Client-ready deliverables are generated through the final reporting stage, which utilizes risk translation templates to convert raw exposure analysis and vulnerability prioritization findings into production-quality reports.

Does this reconnaissance approach handle threat actor investigations across cloud and identity fabrics?▼

Yes, threat actor investigations are supported by systematically mapping identity fabrics and infrastructure exposure, allowing analysts to track malicious activity across cloud apps and authentication providers.

Why do I need a structured OSINT methodology for external red-team recon?▼

A structured OSINT methodology is needed because external reconnaissance is often chaotic and unrepeatable, and standardization ensures reproducible outcomes when mapping complex organizational attack surfaces.