elementalsouls/Claude-OSINT

8 Claude skills · 100+ recon capabilities · 80 secret-regex patterns · 80+ dorks · 9 read-only credential validators · 27 attack-path templates · ~10,000 lines of structured tradecraft. Drop-in SKILL.md files that turn Claude into a god-mode external recon operator for authorized red-team and bug-bounty engagements.

What it solves

claude-osint provides a comprehensive library of expert-level reconnaissance and Open Source Intelligence (OSINT) methodologies for authorized red-team and bug-bounty engagements. It transforms Claude into a senior recon analyst by providing structured tradecraft, toolsets, and procedural guidance to identify attack surfaces, discover assets, and quantify risk without requiring the user to manually research every technique.

How it works

The project consists of a series of SKILL.md files designed for the Claude skills system. These files prime the LLM with specific expert knowledge. The library is divided into two main categories:

  • Core Recon Pair: Focuses on strategic thinking (osint-methodology) and tactical execution (offensive-osint), providing the backbone for asset discovery and probe paths.
  • Organization-Grade Depth Skills: Six specialized skills that handle enterprise-scale reasoning, such as mapping legal entities to footprints, analyzing email domain security, quantifying risk using the FAIR model, and performing identity provider reconnaissance.

Users can install these skills into their Claude environment, where they are automatically triggered by relevant phrases during a session.

Who it’s for

This tool is designed for security researchers, red-teamers, and bug-bounty hunters who have written authorization to assess targets. It is specifically built for the reconnaissance phase of an engagement.

Highlights

  • Extensive Tradecraft: Includes over 100 recon capabilities, 80 secret-regex patterns, and 80+ dorks.
  • Broad Coverage: Spans 13 domains including Cloud/Container exposure, Identity & SSO mapping, and Sector-Specific (Healthcare, Finance, ICS/SCADA) reconnaissance.
  • Integrated Helpers: Includes a standalone secret scanner (secret_scan.py) and a HackerOne disclosed-reports reference agent (h1_reference.py).
  • Risk Quantification: Implements FAIR-based risk scoring and board-level reporting templates.
  • Strict Boundaries: Explicitly excludes active exploitation and credential submission to maintain a focus on OSINT-driven reconnaissance.

Related

  • Project
  • Project
  • Project
  • Project
  • Project