A 5-stage external recon methodology for authorized red-team and attack-surface work - asset-graph discipline, severity and confidence rubrics, breach correlation, CDN/WAF bypass, and client deliverables.
---
name: OSINT Methodology
description: Comprehensive OSINT methodology for authorized external red-team operations and attack-surface assessments - the recon pipeline, asset-graph discipline, severity rubric, breach correlation, CDN/WAF bypass, vulnerability prioritization, and client deliverables. Use when planning or executing recon against authorized targets or producing client reports.
---
A disciplined methodology for external reconnaissance and attack-surface mapping on assets you own or have written authorization to assess. Not for active exploitation, post-exploitation, or blue-team work.
## Workflow
1. Confirm authorization: do a soft scope check once if it isn't established; never weaken auth, rate limits, or safety controls, run destructive probes outside an explicit aggressive mode, or paste real PII/credentials into cloud LLMs.
2. Run the recon pipeline: asset discovery and triage, building an asset graph; map the identity fabric (SSO/IdP/tenant fingerprinting, M365), APIs, and mobile/cloud surfaces.
3. Correlate breach data with identities and hunt leaked secrets; tag findings for detectability and use detection-aware probing with back-off.
4. Prioritize vulnerabilities with a severity rubric and confidence-upgrade workflow (EPSS, CISA KEV); discover origins behind CDN/WAF.
5. Produce client deliverables - exec summary, risk translation, and submission-ready findings.
Full skill & source: https://github.com/elementalsouls/Claude-OSINT/tree/main/skills/osint-methodology