elementalsouls/Claude-OSINT

8 Claude skills · 100+ recon capabilities · 80 secret-regex patterns · 80+ dorks · 9 read-only credential validators · 27 attack-path templates · ~10,000 lines of structured tradecraft. Drop-in SKILL.md files that turn Claude into a god-mode external recon operator for authorized red-team and bug-bounty engagements.

2.5kStars on the repository
9Mods indexed here, across every type
4d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

run-claude-osint

01

elementalsouls/Claude-OSINT

Skill Claude CodeCodex

Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test. Use when asked to run, build, test, validate, or smoke-test claude-osint or its OSINT skills/scripts.

not rated 2.5k +124 4d ago A 78 tokens original MIT

cloud-saas-exposure

02

elementalsouls/Claude-OSINT

Skill Claude CodeCodex

Organization-grade cloud and supply-chain attack-surface discovery: S3/GCS/Azure Blob bucket discovery via observed-name mining (CNAME/cert-SAN/Wayback) and bounded two-class permutation (6 prefixes x 15 suffixes on trusted tokens, bounded target-bound expansion on subdomain stems), existence (HEAD/GET) vs…

not rated 2.5k +124 4d ago C 372 tokens original MIT

elementalsouls/Claude-OSINT

Skill Claude CodeCodex

Turns one-shot external recon into a continuous monitoring program. Covers the scheduled re-scan-and-diff loop (baseline snapshot -> interval sleep -> re-scan -> asset/finding delta -> threshold-gated webhook alert), the scan-to-scan diff engine (new/removed/changed assets by a tracked-attribute table, new/resolved…

not rated 2.5k +124 4d ago A 408 tokens original MIT

elementalsouls/Claude-OSINT

Skill Claude CodeCodex

Rigorous, defensible email-spoofability verdict and SPF supply-chain risk analysis computed from published DNS alone. Deepens the record-level SPF/DMARC/DKIM/BIMI/MTA-STS/DNSSEC fetch recipes in the offensive-osint arsenal (§16.14) with the reasoning that section doesn't do: a priority-ordered composite verdict for…

not rated 2.5k +124 4d ago A 362 tokens original MIT

elementalsouls/Claude-OSINT

Skill Claude CodeCodex

FAIR-aligned exposure quantification: turns a pile of recon findings into a defensible 0-100 + A-F org risk score (Likelihood x Impact, three ownership-aware factors: exposure/threat/impact), an ownership + proof demotion cap so unproven or weakly-owned findings can't inflate the number, a $-denominated FAIR…

not rated 2.5k +124 4d ago A 235 tokens original MIT

elementalsouls/Claude-OSINT

Skill Claude CodeCodex

Organization-grade identity-fabric mapping: tenant/federation fingerprinting and the pre-auth user-ENUMERATION oracle methodology — enumeration and fingerprint only, never credential submission. Covers domain-to-tenant resolution (Microsoft getuserrealm.srf Managed/Federated namespace check, Entra OIDC metadata…

not rated 2.5k +124 4d ago A 418 tokens original MIT

org-attack-surface

07

elementalsouls/Claude-OSINT

Skill Claude CodeCodex

Org-grade attack-surface mapping: given a company's legal identity, discover its ENTIRE owned internet footprint — corporate family -> owned domains -> owned netblocks/ASN -> live assets — with attribution discipline, not just DNS breadth. The org-first attribution pyramid (legal entity -> LEI/registration ->…

not rated 2.5k +124 4d ago A 586 tokens original MIT

osint-autopilot

08

elementalsouls/Claude-OSINT

Skill Claude CodeCodex

End-to-end external OSINT engagement autopilot. Run the FULL osint-methodology pipeline to completion in ONE go for an authorized domain — engagement folder, Stages 1-5 (seed, expansion, enrichment, exposure, convergence), multi-agent per-host content+JS fan-out, headline verification, auto-generated findings, and a…

not rated 2.5k +124 4d ago A 129 tokens original MIT

osint-methodology

09

elementalsouls/Claude-OSINT

Skill Claude CodeCodex

Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers the 6-stage recon pipeline (seed → asset expansion → enrichment → exposure analysis → convergence → operator-armed active validation) with connector-resilience and stage-vs-gating discipline, asset-graph…

not rated 2.5k +124 4d ago A 150 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: