Operational arsenal for external red-team and bug-bounty reconnaissance. Includes concrete wordlists for various paths (Swagger, GraphQL, SAML), high-risk ports, missing headers, HTTP checks, cloud bucket permutations, JS guess-paths, and vendor/cloud-native/container/K8s fingerprints.
The exact command may vary by repository. Check the README on GitHub.
For the skill author
Drop this on your repo README
Shows your skill is listed on Skillteca, generates a backlink and trackable traffic.
[](https://www.skillteca.com.br/skills/offensive-osint?utm_source=badge&utm_medium=readme&utm_campaign=badge)