SkillAgentSearch skills...

cti-expert

CTI Expert — Cyber Threat Intelligence & OSINT analysis skill for Claude Code / Codex. 120+ commands, 57 techniques, 79 typed MCP tools, deterministic case pipeline + ICD-203 reports. No API keys required for core.

Install / Use

npx skills add 7onez/cti-expert

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

83/100

Category

Security

Supported Platforms

Claude Code
OpenAI Codex
<div align="center">

CTI Expert

Cyber Threat Intelligence & OSINT Analysis Toolkit

Transform Claude into a trained intelligence analyst — 74+ commands, 49 techniques, zero API keys required for core functionality.

<br> <p> <a href="#installation">Installation</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href="#demo">View Demo</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href="#quick-start">Quick Start</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href="#command-reference">Commands</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href="#contributing">Contribute</a> </p> <br> <!-- Feature Badges --> <p> <a href="https://github.com/7onez/cti-expert"><img src="https://img.shields.io/badge/version-2.7-0080ff?style=for-the-badge&logo=semver&logoColor=white" alt="Version 2.7"></a>&nbsp; <a href="LICENSE"><img src="https://img.shields.io/badge/license-MIT-00c853?style=for-the-badge&logo=opensourceinitiative&logoColor=white" alt="License: MIT"></a>&nbsp; <a href="#command-reference"><img src="https://img.shields.io/badge/commands-74+-ff6d00?style=for-the-badge&logo=windowsterminal&logoColor=white" alt="74+ Commands"></a>&nbsp; <a href="#technique-catalog"><img src="https://img.shields.io/badge/techniques-49-aa00ff?style=for-the-badge&logo=hackthebox&logoColor=white" alt="49 Techniques"></a>&nbsp; <a href="#installation"><img src="https://img.shields.io/badge/API_keys-none_for_core-00bfa5?style=for-the-badge&logo=shield&logoColor=white" alt="No API Keys for Core"></a> </p> <!-- GitHub Stats --> <p> <a href="https://github.com/7onez/cti-expert/stargazers"><img src="https://img.shields.io/github/stars/7onez/cti-expert?style=flat-square&logo=github&label=Stars" alt="Stars"></a>&nbsp; <a href="https://github.com/7onez/cti-expert/network/members"><img src="https://img.shields.io/github/forks/7onez/cti-expert?style=flat-square&logo=github&label=Forks" alt="Forks"></a>&nbsp; <a href="https://github.com/7onez/cti-expert/releases"><img src="https://img.shields.io/github/downloads/7onez/cti-expert/total?style=flat-square&logo=github&label=Downloads&color=brightgreen" alt="Downloads"></a>&nbsp; <a href="https://github.com/7onez/cti-expert/issues"><img src="https://img.shields.io/github/issues/7onez/cti-expert?style=flat-square&logo=github&label=Issues" alt="Issues"></a>&nbsp; <a href="https://github.com/7onez/cti-expert/pulls"><img src="https://img.shields.io/github/issues-pr/7onez/cti-expert?style=flat-square&logo=github&label=PRs" alt="Pull Requests"></a>&nbsp; <a href="https://github.com/7onez/cti-expert/commits"><img src="https://img.shields.io/github/last-commit/7onez/cti-expert?style=flat-square&logo=github&label=Last%20Commit" alt="Last Commit"></a>&nbsp; <a href="https://github.com/7onez/cti-expert"><img src="https://img.shields.io/github/repo-size/7onez/cti-expert?style=flat-square&logo=github&label=Size" alt="Repo Size"></a>&nbsp; <a href="https://github.com/7onez/cti-expert/graphs/contributors"><img src="https://img.shields.io/github/contributors/7onez/cti-expert?style=flat-square&logo=github&label=Contributors" alt="Contributors"></a> </p> <!-- Language Selector --> <p> 🇬🇧 <a href="README.md"><b>English</b></a>&nbsp;&nbsp;·&nbsp;&nbsp;🇻🇳 <a href="README.vi.md">Tiếng Việt</a>&nbsp;&nbsp;·&nbsp;&nbsp;🇨🇳 <a href="README.zh-CN.md">中文</a> </p> <br>

<sub>Built by <a href="https://www.linkedin.com/in/hieu-minh-ngo-hieupc/"><b>Hieu Ngo</b></a><a href="mailto:hieu.ngo@chongluadao.vn">hieu.ngo@chongluadao.vn</a><a href="https://chongluadao.vn">chongluadao.vn</a></sub>

</div> <br>
<br>

🤝 Sponsors & Supporters

<div align="center">

CTI Expert is built in the open. These organisations back the work — with data, tooling, and hard-won investigative tradecraft.

<p> <a href="https://rexxfield.com"><img src="https://img.shields.io/badge/Rexxfield-Cybercrime_Investigations-B3272D?style=for-the-badge" alt="Rexxfield"></a>&nbsp; <a href="https://www.hudsonrock.com"><img src="https://img.shields.io/badge/Hudson_Rock-Infostealer_Intel-1B2A4A?style=for-the-badge" alt="Hudson Rock"></a>&nbsp; <a href="https://paranoidlab.com"><img src="https://img.shields.io/badge/ParanoidLab-Dark_Web_%26_IAB-0F172A?style=for-the-badge" alt="ParanoidLab"></a> </p> <p> <a href="https://any.run"><img src="https://img.shields.io/badge/ANY.RUN-Sandbox_%26_TI_Lookup-FF6A2B?style=for-the-badge" alt="ANY.RUN"></a>&nbsp; <a href="https://zetalytics.com"><img src="https://img.shields.io/badge/ZETAlytics-Passive_DNS-0B7285?style=for-the-badge" alt="ZETAlytics"></a>&nbsp; <a href="https://intelx.io"><img src="https://img.shields.io/badge/IntelX-Leak_%26_Darknet_Search-2B6E6B?style=for-the-badge" alt="Intelligence X"></a> </p> </div>

| Supporter | What they bring | In the toolkit | |-----------|-----------------|----------------| | Rexxfield | Cybercrime investigation and victim-side casework since 2008 — the real-world tradecraft the case workflow and attribution standards are modelled on | Tradecraft & methodology | | Hudson Rock | Infostealer-infection intelligence — which machines leaked which credentials, and when | /breach-deep · /stealer-log | | ParanoidLab | Dark-web, Initial-Access-Broker and infostealer-log monitoring across forums, markets and private Telegram | Dark-web collection & review | | ANY.RUN | Interactive malware sandbox + TI Lookup — sandbox-observed C2 and real endpoints from packed samples | /binary · /hash-id | | ZETAlytics | Global passive DNS with rare geographic diversity — historical resolution and co-tenancy pivots | /webpivot · /cti-pivot | | IntelX | Intelligence X — paste sites, leaks, darknet and phonebook selector search | /webpivot · /email-deep |

[!IMPORTANT] ANY.RUN is used read-only. anyrun_lookup queries TI Lookup for hashes that have already been detonated. This skill never submits a sample — a public sandbox task is world-readable and irreversible. That boundary is enforced by a regression test (tests/test_no_sample_submission.py), not just by convention.

<sub>Listing here reflects support for the project and does <b>not</b> imply affiliation, endorsement, or any verification of this tool by the organisations named. Integrations marked above are optional and key-gated — <b>every core technique still runs with zero API keys</b>. Always respect each provider's terms of service. The full list of open-source projects and free public-interest services this skill depends on is in <a href="#-acknowledgments--credits">Acknowledgments & Credits</a>.</sub>

<br>
<br>

What is CTI Expert?

A Claude Code skill that transforms Claude into a trained cyber threat intelligence and open-source intelligence analyst. It runs structured intelligence collection using 74+ commands across 49 techniques — no API keys required for core functionality. To take full advantage, add your own free or paid API keys to the skill's .env — each is auto-detected and unlocks higher-tier access (e.g., Wigle, VirusTotal, URLScan.io, Shodan, Censys, SecurityTrails, WhoisXML).

[!TIP] Keyless by default, more powerful with your keys. Every core technique runs with zero API keys. Add any free or paid keys to .env (or run /apikeys set <service> <KEY>) and the skill auto-detects them, unlocking higher-tier pivots: reverse favicon→host, passive DNS, certificate search, sibling-domain discovery. A missing or bad key never breaks a run — it just degrades to a note. Setup guide: handbook/api-keys.md.

[!TIP] One skill, two layers. cti-expert is the broad collector — the wide net (/sweep, /webpivot, /subdomain, /username, /email-deep…). Built into the repo is a deep pipeline (intel_engine/) that turns raw collection into a real case: a persistent knowledge base, versioned cases, cross-case correlation, and calibrated assessment. The flow reads like a sentence — collect broadly → "seen this operator before?" → cluster → filter false positives → assess. No external setup: the backend resolves to SELF; install the deep-layer deps once with uv venv && uv pip install -r requirements.txt. Architecture: connectors/intel-backend.md.

<table> <tr> <td width="50%">

Core Capability

Multi-vector reconnaissance on any target type — person, domain, organization, username, email, IP, WiFi — with automated finding validation, exposure scoring, and structured intelligence delivery.

</td> <td width="50%">

AEAD Workflow

Acquire raw data → Enrich with pivot expansion → Assess findings → Deliver structured reports (interactive HTML + Markdown + JSON/CSV + IOC bundle; Word on request).

</td> </tr> </table> <br>
<br>

Demo

Full Case Investigation

<div align="center"> <img src="assets/demo-full-case.gif" alt="Full Case Demo — /case command running a complete investigation" width="800"> </div> <br>

CTI Report Generation

<div align="center"> <img src="assets/demo-cti-report.gif" alt="CTI Report Demo — Markdown + DOCX report output" width="800"> </div> <br>

Screenshots

<div align="center">

| INTSUM Report | Network Topology | Risk Assessment | |:---:|:---:|:---:| | <img src="assets/intsum.png" alt="INTSUM Report" width="280"> | <img src="assets/network-topology.png" alt="Network Topology Diagram" width="280"> | <img src="assets/risk-assessment.png" alt="Risk Assessment Score" width="280"> |

</div> <br>
<br>

What's New in v2.7

The release where the deep pipeline landed. v2.6 sharpened the collector. v2.7 makes cti-expert a two-layer system — a broad collector plus a built-in, self-contained intelligence pipeline with a persistent knowledge base — reachable from a cold prompt by one command, and guarded by a gate that checks the repo against its own rules on every push.

| Category | What's New | Details | |----------|-----------|---------| | One skill, two layers | The deep pipeline is now built in — no external backend to stand up | intel_engine/ vendors the whole Collect → Correlate → Assess pipeline: a persistent knowledge base, versioned cases, cross-case correlation, calibrated assessment and rendering (WebPivot · IntelAnalysis · IntelGraph · IntelReport · BinaryPivot). /backend resolves to SELF — nothing to configure, nothing to host. Install the deep-layer deps once with uv venv && uv pip install -r requirements.txt. The tree regrouped from 22 top-level directories to 14 behind a single SKILL.md. See STRUCTURE.md | | 8 registered commands | /cti works from a cold prompt, in any project | Commands used to require the skill be loaded first. scripts/register.sh symlinks the skill and commands/*.md into ~/.claude/ and writes the per-machine .mcp.json, so /cti, /cti-recall, /cti-case, /cti-pivot, /cti-cluster, /cti-check, /cti-report and /cti-status are available immediately. There is now one command to remember — /cti <target> — which routes by target type (domain · IP · email · username · phone · wallet · hash · APK) and runs the right chain. Everything else remains a convention command | | --deep is genuinely parallel | Sub-agent fan-out on both collection and assessment | /cti --deep spawns one sub-agent per discovered frontier seed — pruned through recall and false-positive control first, ≤6 concurrent, depth-capped at 2 hops, with --passive propagating to every child — then converges them into one case. New here: when convergence yields 2+ clusters, the Assess phase fans out too, one agent per cluster (ACH, confidence, risk, scoped to that cluster), while the **cross-cluster judgment stays

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars600
CategorySecurity
Updated5d ago
Forks88

Languages

Python

Security Score

88/100

Audited on Sep 16, 2026

1 medium