Structured OSINT methodology framework: target definition, source selection, collection workflows, data correlation, timeline reconstruction, and reporting. Covers sock-puppet OpSec, cryptocurrency and L2 tracing, image/video geolocation, chronolocation (shadow/astronomical/satellite), threat-actor investigation with attribution discipline, RU/CN-specific pivots, people and social-media investigation, infrastructure OSINT, Telegram/WeChat, case management, and synthetic-media verification. Use to guide systematic OSINT campaigns, teach OSINT methodology, or run the full collection-to-report workflow against any target. Ported from SnailSploit/Claude-Red (Apache-2.0).