Mmcp.market

offensive-osint-methodology skill

by SnailSploit·SnailSploit/Claude-Red·7.0k stars·MIT

No description in the SKILL.md.

A94/100content scan

Is the offensive-osint-methodology skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

  • lowSKILL.md:1

    The name should be 1 to 64 lowercase letters, digits or hyphens.

    (missing)
  • lowSKILL.md:1

    No description, so an agent cannot tell when to use the skill.

    (missing)

Install the offensive-osint-methodology skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git /tmp/Claude-Red
mkdir -p ~/.claude/skills
cp -r /tmp/Claude-Red/Skills/recon/offensive-osint-methodology ~/.claude/skills/offensive-osint-methodology
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

SKILL: OSINT Methodology

Metadata

  • Skill Name: osint-methodology
  • Folder: offensive-osint-methodology
  • Source: https://github.com/SnailSploit/offensive-checklist/blob/main/osint-method.md

Description

Structured OSINT methodology framework: target definition, source selection, collection workflows, data correlation, timeline reconstruction, and reporting. Use to guide systematic OSINT campaigns or teach OSINT methodology.

Trigger Phrases

Use this skill when the conversation involves any of: OSINT methodology, open source intelligence, target profiling, data correlation, OSINT workflow, intelligence collection, OSINT campaign, recon methodology

Instructions for Claude

When this skill is active:

  1. Load and apply the full methodology below as your operational checklist
  2. Follow steps in order unless the user specifies otherwise
  3. For each technique, consider applicability to the current target/context
  4. Track which checklist items have been completed
  5. Suggest next steps based on findings

Full Methodology

OSINT Methodology

OpSec

Create a Sock Puppet

  • Fake account that cannot be linked to you
  • Build a posting history (post stuff, etc.)
  • Resources
  • Effective Sock Puppets
  • Ultimate Guide to Sock Puppets
  • Fake Name Generator
  • This Person does not Exist
  • Use separate browser profiles or isolation tools (e.g., Firefox Multi‑Account Containers) for any sock‑puppet activity.
  • Acquire disposable VoIP/SMS numbers (e.g., Burner, Silent Link) to satisfy platform verification without exposing real phone numbers.
  • Audit every browser extension before installation; supply‑chain attacks on popular add‑ons have targeted investigators since 2024.
  • Use dedicated browser profiles/containers per case and persona; avoid logging into personal accounts.
  • Prefer hardware‑backed passkeys for critical accounts; store recovery codes offline.

Cryptocurrency Investigation

Transaction Analysis

  • Track transaction flows between wallets
  • Identify clusters of related addresses
  • Monitor large transfers and whale activity
  • Use block explorers to trace fund movements
  • Tools:
  • Cielo: Multi-chain wallet tracking (EVM, Bitcoin, Solana, Tron)
  • TRM: Create relationship graphs for addresses/transactions
  • Arkham: Multichain explorer with entity labels, graph creation, and alerts
  • MetaSleuth: Transaction visualization for retail users
  • Range: CCTP bridge explorer
  • Socketscan: EVM bridge explorer
  • Pulsy: Bridge explorer aggregator

Layer 2 / Rollup Analysis

  • zkSync Era / Polygon zkEVM: Zero-knowledge proofs hide transaction details on L2; only deposit/withdrawal bridge events visible on L1. Use zkSync Era Block Explorer and PolygonScan zkEVM.
  • Arbitrum / Optimism: Transactions batched and compressed; L2 state reconstructed from L1 calldata. Use Arbiscan and Optimistic Etherscan. Check L2Beat for risk framework and technology stack.
  • StarkNet: Cairo VM with STARK proofs; different address derivation. Use Voyager or StarkScan.
  • Base / Blast / Scroll: OP Stack or ZK-rollups; similar challenges to above.
  • Privacy protocols on L2:
  • Aztec Network: Programmable privacy with noir circuits; limited block explorer visibility.
  • Railgun: Privacy system for DeFi on Ethereum/Polygon/BSC; shielded pools obscure sender/receiver/amount.
  • Privacy Pools: Proposed Tornado Cash successor with association sets; not yet deployed at scale.
  • Challenges:
  • Bridge mixers (Hop Protocol, Across, Stargate) create synthetic liquidity pools that break direct tracing; funds enter/exit via pool swaps.
  • Cross-rollup transfers further obfuscate trails; requires tracking via bridge contracts and relayer infrastructure.
  • Many L2s lack mature analytics tools; explorers show transactions but relationship graphs are sparse.

Cautions (bridges and heuristics)

  • Bridges/mixers/wrappers introduce mint/burn semantics; avoid assuming 1:1 flows without on‑chain proofs.
  • MEV/sandwich and aggregator paths can create false "direct" trails; validate with multiple datasets.
  • Cross‑label sanity: vendor labels can disagree; treat labels as hypotheses, not ground truth.
  • L2 finality: Optimistic rollups have 7-day challenge periods; zkRollups finalize faster but proofs can be batched/delayed.

Wallet Profiling

  • Analyze wallet age and activity patterns
  • Check for connections to known entities
  • Monitor balance changes over time
  • Identify associated exchange accounts

Exchange Investigation

  • Track deposits/withdrawals
  • Monitor trading patterns
  • Identify linked accounts
  • Check for regulatory compliance

NFT Investigation

  • Track ownership history
  • Monitor sales and transfers
  • Analyze metadata and hidden content
  • Identify connected wallets and marketplaces

Image Analysis

  • Contextual Analysis
  • Use multiple reverse image search engines to find matches or similar images:
  • Google Images / Google Lens (note: Google Lens now requires authentication for some features; use incognito/sock-puppet account)
  • Yandex Images
  • Bing Image Match
  • TinEye
  • Copyseeker AI‑based reverse‑image search engine
  • Perplexity Pro with image upload: AI-powered contextual analysis and web search
  • Use browser extensions for quick searches:
  • RevEye Reverse Image Search
  • Search by Image (multi-engine support)
  • Change search terms and time to narrow down the possible results

Image Forensics

  • Analyze images for signs of manipulation or to uncover hidden details.
  • Tools
  • Forensically
  • FotoForensics
  • Bellingcat Photo Checker
  • Sensity AI Deepfake Monitor
  • Exposing.ai facial‑dataset search
  • C2PA verification: Adobe Content Credentials Verify and c2patool
  • Techniques
  • Error Level Analysis (ELA)
  • Metadata examination
  • Clone detection

Mountain Geolocation

  • Use tools to identify mountain peaks and match them with the image.
  • Tools
  • PeakVisor
  • Peakfinder
  • PeakLens AR mountain identifier
  • Methodology
  • Align the silhouette of mountains in the image with the 3D models in the tools.
  • Adjust parameters like viewing angle and elevation.

Fire Identification

  • Identify fires, deforestation, or environmental changes.
  • Tools
  • NASA FIRMS
  • Sentinel Hub Playground
  • Global Forest Watch
  • Copernicus EFFIS EU wildfire monitoring portal

Track and Find Planes

  • Use Apollo Hunter to find exact satellite image time
  • Then use FlightRadar to track that plane that you found
  • Verify the size and plane features
  • ADS-B Exchange – unfiltered global flight data

Video Analysis

  • Find context regarding the video
  • Signs, banners, and billboards.
  • Architectural styles and building materials.
  • Road markings and traffic signs.
  • License plates
  • Clothing styles and local customs.
  • Search for video snippets on platforms like YouTube, Twitter, or TikTok.
  • Metadata Extraction
  • YouTube Data Viewer
  • ExifTool: Extract metadata from downloaded video files.
  • Platform-Specific Techniques
  • TikTok and Instagram

Chronolocation and Time Analysis

Shadow Analysis

  • Use shadows to estimate the time of day and date when the image or video was captured.
  • Methodology
  • Determine the length and direction of shadows in the image.
  • Identify objects casting the shadows (e.g., poles, buildings).
  • Calculate Sun Position
  • Use the object's height and shadow length to calculate the solar elevation angle.
  • Determine the azimuth (sun's compass direction).
  • Tools
  • SunCalc
  • ShadeMap – interactive 3‑D shadow simulator
  • Bellingcat Shadow‑Finder micro‑tool
  • Input location coordinates.

Astronomical Calculations

  • For night images, use celestial bodies to determine time and location.
  • Tools
  • Stellarium: Planetarium software
  • SkyMap: Mobile app for stargazing.
  • MoonCalc
  • Methodology
  • Identify visible stars, constellations, or the moon phase.
  • Use software to simulate the sky at different times and locations.
  • Match the celestial arrangement in the image to a specific date and time.

Satellite Imagery Time

  • Use historical satellite imagery to determine changes over time.
  • Tools
  • Google Earth Pro:
  • Use the historical imagery slider to view images from different dates.
  • Sentinel Hub EO Browser
  • Access Sentinel and Landsat data.
  • Create TimeLapse animations.
  • Methodology
  • Enter the location coordinates.
  • Select appropriate satellite datasets (Sentinel-2, Landsat 8).
  • Analyze changes in the environment to narrow down dates.
  • Record coordinates in WKT and hash cached tilesets for reproducibility where feasible.

Threat Actor Investigation

Actor‑Centric Workflow

  • Scoping
  • Define the actor hypothesis (e.g., APT28, APT29, Turla, Sandworm; APT10, APT41, Mustang Panda, Volt Typhoon).
  • Collect seed reports from CERTs and vendors; extract indicators and TTPs.
  • Indicator harvesting
  • Parse IOCs (domains, IPs, hashes, JA3/JA4, user‑agents) from advisories and reports; normalize and de‑duplicate.
  • Validate IOCs with passive DNS, CT logs, sandbox submissions, and open telemetry where possible.
  • Infrastructure mapping
  • Build pivots from CT logs (SANs, issuer, serials), shared hosting, name‑server reuse, registrar accounts, and HTML/page fingerprints.
  • Enrich with ASN/WHOIS history, RPKI/ROA status, geolocation, and hosting provider relationships.
  • Artifact profiling
  • Extract PE/ELF metadata (PDB paths, compile timestamps, Rich headers, resources language, code‑signing certs).
  • Cluster with fuzzy hashes (SSDEEP/TLSH) and identify packers/loaders; search YARA and sandboxes for near‑matches.

Attribution Discipline

  • Separate capability from intent and sponsorship; avoid mirror‑imaging.
  • Use a rule‑of‑three: require at least three independent weak signals, or one strong + one weak, before asserting linkage.
  • Prefer durable pivots (registrar accounts, code‑signing cert reuse, build path idioms) over ephemeral ones (resolving IPs).
  • Clearly mark uncertainty levels and confidence (e.g., low/medium/high) and distinguish correlation from control.

Russia‑Specific Pivots

  • Corporate/people
  • EGRUL/EGRIP extracts (official registry; captcha‑gated) and Rusprofile/Kontur.Focus summaries for entities and directors.
  • Government procurement: zakupki.gov.ru (tenders, contractors), regional portals, and grant listings.
  • Job boards (e.g., hh.ru) for role requirements, tech stacks, and office locations.
  • Infrastructure
  • RU WHOIS: whois.tcinet.ru; check registrar accounts, nserver patterns, and RU‑center usage.
  • Telegram is widely used; analyze channels, admins, cross‑posts, and bot ecosystems.
  • Media/platforms
  • VKontakte, Odnoklassniki, Rutube, and regional news portals; search in Russian and transliterations.

China‑Specific Pivots

  • Corporate/people
  • National Enterprise Credit Info System (gsxt.gov.cn) for registered entities; cross‑check with Tianyancha/Qichacha (paid/freemium).
  • ICP filings (beian.miit.gov.cn) to link domains to legal entities via Unified Social Credit Codes (USCC).
  • Infrastructure
  • CNNIC WHOIS and hosting footprints; common domestic clouds (Aliyun, Tencent Cloud, Huawei Cloud) and registrar patterns.
  • Media/platforms
  • Weibo, WeChat Official Accounts (via weixin.sogou.com), Zhihu, Bilibili, Douyin, Xiaohongshu; search in Chinese and Pinyin.

Infrastructure & Internet Measurement

  • Map IPs to ASNs (HE BGP Toolkit, RIPEstat, BGPView); observe peering and hosting ecosystems.
  • Check CT logs (crt.sh) for certificate reuse and issuance cadence; pivot on subjects/issuers/serials.
  • Use URLScan and similar crawlers to capture HTML finge

More skills from SnailSploit/Claude-Red

  • Aoffensive-active-directoryActive Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerView, ADExplorer), credential abuse (Kerberoasting, ASREProasting, NTLM relay, LLMNR/NBT-NS poisoning), privilege escalation (ACL abuse, GPO abuse, unconstrained/constrained delegation), lateral movement (Pass-the-Hash, Pass-the-Ticket, Overpass-the-Hash, WMI/WinRM/PsExec), persistence (Golden/Silver/Diamond Tickets, DCSync, DCShadow, AdminSDHolder, Skeleton Key), forest trust attacks, ADCS abuse (ESC1-ESC15), and modern MDI/Defender for Identity evasion. Use when assessing on-prem AD, hybrid AD/Entra ID environments, or ADCS deployments.
  • Aoffensive-advanced-redteamComprehensive red team operations methodology covering full engagement lifecycle from planning through reporting. Addresses engagement scoping and rules of engagement negotiation, multi-tier C2 infrastructure design with redirectors and domain fronting, malleable traffic profiles and beacon tradecraft, OPSEC discipline including attribution avoidance and indicator management, EDR and AMSI evasion techniques using direct syscalls and unhooking, data collection with chain-of-custody controls, and structured reporting with purple team debrief workflows. Covers assumed-breach, external-to-internal, insider threat, and hybrid physical-cyber engagement scenarios with MITRE ATT&CK mapping throughout. Targets operators planning or executing adversary simulation engagements against mature defenders.
  • Coffensive-ai-security
  • Aoffensive-anti-forensicsAnti-forensics and evidence destruction techniques for red team operators conducting authorized engagements. Covers log clearing on Windows (wevtutil, Clear-EventLog, ETW provider patching) and Linux (journal truncation, utmp/wtmp binary editing, syslog manipulation), timestamp manipulation via Timestomp and SetMACE to defeat timeline analysis, filesystem-level anti-forensics including NTFS Alternate Data Streams for payload hiding and secure deletion with sdelete/shred, memory artifact removal to counter live forensics, disk artifact manipulation targeting MFT entries and USN journal records, network forensics evasion through encrypted C2 channels and DNS-over-HTTPS tunneling, and anti-VM/sandbox detection to avoid dynamic analysis environments. Tools: Timestomp, wevtutil, sdelete, shred, MimiPenguin, Invoke-Phant0m. Aligns to MITRE ATT&CK T1070 (Indicator Removal), T1027 (Obfuscated Files or Information), T1497 (Virtualization/Sandbox Evasion). Each technique includes the forensic artifact it targets, the destruction or manipulation method, and the defender perspective so operators understand detection gaps they must account for.
  • Aoffensive-api-abuseAdvanced API exploitation methodology focused on business logic abuse and sophisticated attack patterns that bypass traditional security controls. Covers business logic bypass through API call chaining and workflow manipulation. Addresses GraphQL-specific attacks including batching for credential brute-force, query depth exploitation, and introspection abuse. Includes pagination exploitation for data exfiltration, webhook hijacking for SSRF and data interception, and resource exhaustion through algorithmic complexity attacks. Covers race conditions in API transactions using parallel request techniques. Provides comprehensive JWT manipulation including algorithm confusion, kid injection, jku/x5u abuse, and claim tampering. Details API key leakage detection across source repositories, client-side code, and error messages. Covers undocumented endpoint discovery through predictable naming, debug routes, and source map analysis. Tooling includes Arjun, ParamSpider, jwt_tool, and GraphQL Voyager. Designed for authorized penetration testers targeting business logic layers that automated scanners miss.
  • Aoffensive-api-securityComprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. Addresses the full OWASP API Security Top 10 2023 including BOLA/IDOR, broken authentication, excessive data exposure, rate limiting bypass, BFLA, mass assignment, SSRF, and security misconfiguration. Includes REST-specific attacks such as HTTP verb tampering, content-type switching, and parameter pollution. Covers gRPC exploitation through protobuf interception, reflection API enumeration, and metadata injection. Addresses WebSocket vulnerabilities including origin bypass, message injection, and cross-site WebSocket hijacking. Provides tooling guidance for Burp Suite, Postman, grpcurl, websocat, and mitmproxy. Each technique includes detection signatures and defensive indicators so you understand what artifacts your testing leaves behind. Designed for authorized penetration testing engagements against API-driven architectures.
  • Aoffensive-bluetooth-bleBluetooth Low Energy (BLE) attack methodology — GATT enumeration, characteristic read/write without auth, pairing downgrade (Just Works forced), LE Secure Connections bypass, MITM via active relay, sniffing with Sniffle (TI CC1352) / Ubertooth / Frontline, encryption key extraction (LE Legacy Pairing crackable, LE Secure Connections strong), proximity authentication abuse (cars, locks), and companion-app trust analysis. Use for IoT BLE devices, smart locks, fitness trackers, medical devices, BLE beacons, or any device pairing over BLE.
  • Aoffensive-bluetooth-classicBluetooth Classic (BR/EDR) attack methodology — device discovery, service enumeration via SDP, LMP/L2CAP layer attacks, legacy PIN cracking (BlueBorne / KNOB), Bluetooth file-transfer abuse (BlueSnarfing legacy), unauthenticated profile abuse (HSP, HFP, OPP), and modern relevance against older industrial / automotive / accessory targets. Use when in-scope devices use Bluetooth Classic (Bluetooth ≤ 4.0 BR/EDR) — common in legacy car kits, industrial sensors, older medical devices, and audio accessories.
  • Aoffensive-bug-identification
  • Aoffensive-business-logicBusiness logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process abuse, price/quantity/discount manipulation, currency confusion, coupon stacking, refund/chargeback abuse, race conditions on logic boundaries, parameter tampering for hidden flows, role/tenant boundary violations, time-of-check vs use, anti-automation defeat, fraud-detection evasion, and subscription/quota abuse. Use when scoping an application after surface-level OWASP Top 10 has been covered, or when the asset is a transactional/marketplace/fintech/e-commerce/SaaS app where logic flaws produce direct financial impact.
  • Aoffensive-c2-frameworksCommand and Control framework deployment, configuration, and operational tradecraft for red team engagements. Covers Cobalt Strike (malleable C2 profiles, Beacon types HTTP/HTTPS/DNS/SMB, Beacon Object Files for in-memory execution, sleep and jitter tuning, named pipe pivoting), Sliver (implant generation across mTLS/WireGuard/DNS transport, operator multiplayer mode, armory extensions), Mythic (agent ecosystem with Apollo/Poseidon/Medusa, C2 profile configuration, translation containers), Havoc (Demon agent with sleep obfuscation via Ekko/Zilean, indirect syscalls, dotnet inline execution), Metasploit (msfvenom payload generation, multi/handler staging, Meterpreter post-exploitation modules), redirector architecture using Apache mod_rewrite and Nginx, domain fronting through CDN providers, DNS-based C2 for restrictive network egress, and TLS certificate management for infrastructure OPSEC. Tools: Cobalt Strike, Sliver, Mythic, Havoc, Metasploit Framework. Aligns to MITRE ATT&CK T1071 (Application Layer Protocol), T1573 (Encrypted Channel), T1090 (Proxy/Connection Proxy).
  • Doffensive-cicd-pipelineComprehensive CI/CD pipeline exploitation methodology covering GitHub Actions injection vectors (expression injection via PR titles and issue bodies, workflow_run event abuse, GITHUB_TOKEN over-scoping, composite action supply chain compromise), Jenkins attack paths (Groovy sandbox escapes, script console remote code execution, Java remoting deserialization, credential store dumping, shared library injection), GitLab CI exploitation (YAML anchor injection, runner registration token abuse, CI variable extraction, protected branch bypass via merge request pipelines), and Azure DevOps pipeline agent compromise with service connection theft. Includes artifact poisoning techniques across all platforms, tooling guidance for gato and jenkins-attack-framework, and maps to MITRE ATT&CK T1195.002 (Supply Chain Compromise: Compromise Software Supply Chain). Covers enumeration of pipeline configurations, privilege escalation from contributor to code execution, lateral movement through pipeline trust boundaries, and persistence via modified workflow definitions. Each technique section provides working exploitation code, detection indicators, and defensive countermeasures.

All agent skills → · MCP servers