★ ★ ★LIVE51 SPECIALIZED SKILLS ACROSS 8 ATTACK DOMAINS · BUGGY AI·VIEW SKILLS →★ ★ ★
BUGGY
buggy.hunt("https://target.com")→ [sqli] signal detectedclaude.triage(finding="blind-sqli")→ [7-gate] passed (7/7)recon.subdomains("target.com")→ [142] active assetsauth.audit_jwt(token="ey...")→ [none-alg] bypass foundbuggy.generate_report(cvss=9.8)→ [hackerone] markdown readyapi.probe_graphql("api.target.com/v1")→ [introspection] enabledm365.enum_users("target.com")→ [pw-spray] safe modemobile.decompile_apk("app.apk")→ [hardcoded-key] leakedbuggy.hunt("https://target.com")→ [sqli] signal detectedclaude.triage(finding="blind-sqli")→ [7-gate] passed (7/7)recon.subdomains("target.com")→ [142] active assetsauth.audit_jwt(token="ey...")→ [none-alg] bypass foundbuggy.generate_report(cvss=9.8)→ [hackerone] markdown readyapi.probe_graphql("api.target.com/v1")→ [introspection] enabledm365.enum_users("target.com")→ [pw-spray] safe modemobile.decompile_apk("app.apk")→ [hardcoded-key] leakedbuggy.hunt("https://target.com")→ [sqli] signal detectedclaude.triage(finding="blind-sqli")→ [7-gate] passed (7/7)recon.subdomains("target.com")→ [142] active assetsauth.audit_jwt(token="ey...")→ [none-alg] bypass foundbuggy.generate_report(cvss=9.8)→ [hackerone] markdown readyapi.probe_graphql("api.target.com/v1")→ [introspection] enabledm365.enum_users("target.com")→ [pw-spray] safe modemobile.decompile_apk("app.apk")→ [hardcoded-key] leaked
SKILLS/RECON
> 3 SKILLS ACTIVE

Recon & OSINT SECURITY DOMAIN

5-stage recon pipeline, asset-graph methodology, subdomain enumeration, identity-fabric mapping, and crypto tracing.

3 SKILLS IN DOMAIN
🔍 CATEGORY
← All 8 Domains
/osint-methodology
Recon & OSINT
OSINT Methodology5-stage recon pipeline with 29 asset types, identity-fabric mapping (Entra/Okta/ADFS), crypto tracing, im...
claude "/osint-methodology https://target.com" → trigger: auto-loaded
/offensive-osint
Recon & OSINT
Offensive OSINTOffensive OSINT techniques for authorized red-team engagements — breach correlation, LinkedIn harvesting,...
claude "/offensive-osint https://target.com" → trigger: auto-loaded
/hunt-subdomain
Recon & OSINT
Subdomain HunterSubdomain enumeration and takeover identification — passive/active discovery, dangling DNS patterns, and ...
claude "/hunt-subdomain https://target.com" → trigger: auto-loaded