cti-expert
CTI Expert — Cyber Threat Intelligence & OSINT analysis skill for Claude Code / Codex. 120+ commands, 57 techniques, 79 typed MCP tools, deterministic case pipeline + ICD-203 reports. No API keys required for core.
Install / Use
npx skills add 7onez/cti-expertInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Skill content
View source on GitHubCTI Expert
Cyber Threat Intelligence & OSINT Analysis Toolkit
Transform Claude into a trained intelligence analyst — 74+ commands, 49 techniques, zero API keys required for core functionality.
<br> <p> <a href="#installation">Installation</a> | <a href="#demo">View Demo</a> | <a href="#quick-start">Quick Start</a> | <a href="#command-reference">Commands</a> | <a href="#contributing">Contribute</a> </p> <br> <!-- Feature Badges --> <p> <a href="https://github.com/7onez/cti-expert"><img src="https://img.shields.io/badge/version-2.7-0080ff?style=for-the-badge&logo=semver&logoColor=white" alt="Version 2.7"></a> <a href="LICENSE"><img src="https://img.shields.io/badge/license-MIT-00c853?style=for-the-badge&logo=opensourceinitiative&logoColor=white" alt="License: MIT"></a> <a href="#command-reference"><img src="https://img.shields.io/badge/commands-74+-ff6d00?style=for-the-badge&logo=windowsterminal&logoColor=white" alt="74+ Commands"></a> <a href="#technique-catalog"><img src="https://img.shields.io/badge/techniques-49-aa00ff?style=for-the-badge&logo=hackthebox&logoColor=white" alt="49 Techniques"></a> <a href="#installation"><img src="https://img.shields.io/badge/API_keys-none_for_core-00bfa5?style=for-the-badge&logo=shield&logoColor=white" alt="No API Keys for Core"></a> </p> <!-- GitHub Stats --> <p> <a href="https://github.com/7onez/cti-expert/stargazers"><img src="https://img.shields.io/github/stars/7onez/cti-expert?style=flat-square&logo=github&label=Stars" alt="Stars"></a> <a href="https://github.com/7onez/cti-expert/network/members"><img src="https://img.shields.io/github/forks/7onez/cti-expert?style=flat-square&logo=github&label=Forks" alt="Forks"></a> <a href="https://github.com/7onez/cti-expert/releases"><img src="https://img.shields.io/github/downloads/7onez/cti-expert/total?style=flat-square&logo=github&label=Downloads&color=brightgreen" alt="Downloads"></a> <a href="https://github.com/7onez/cti-expert/issues"><img src="https://img.shields.io/github/issues/7onez/cti-expert?style=flat-square&logo=github&label=Issues" alt="Issues"></a> <a href="https://github.com/7onez/cti-expert/pulls"><img src="https://img.shields.io/github/issues-pr/7onez/cti-expert?style=flat-square&logo=github&label=PRs" alt="Pull Requests"></a> <a href="https://github.com/7onez/cti-expert/commits"><img src="https://img.shields.io/github/last-commit/7onez/cti-expert?style=flat-square&logo=github&label=Last%20Commit" alt="Last Commit"></a> <a href="https://github.com/7onez/cti-expert"><img src="https://img.shields.io/github/repo-size/7onez/cti-expert?style=flat-square&logo=github&label=Size" alt="Repo Size"></a> <a href="https://github.com/7onez/cti-expert/graphs/contributors"><img src="https://img.shields.io/github/contributors/7onez/cti-expert?style=flat-square&logo=github&label=Contributors" alt="Contributors"></a> </p> <!-- Language Selector --> <p> 🇬🇧 <a href="README.md"><b>English</b></a> · 🇻🇳 <a href="README.vi.md">Tiếng Việt</a> · 🇨🇳 <a href="README.zh-CN.md">中文</a> </p> <br><sub>Built by <a href="https://www.linkedin.com/in/hieu-minh-ngo-hieupc/"><b>Hieu Ngo</b></a> • <a href="mailto:hieu.ngo@chongluadao.vn">hieu.ngo@chongluadao.vn</a> • <a href="https://chongluadao.vn">chongluadao.vn</a></sub>
</div> <br><br>
🤝 Sponsors & Supporters
<div align="center">CTI Expert is built in the open. These organisations back the work — with data, tooling, and hard-won investigative tradecraft.
<p> <a href="https://rexxfield.com"><img src="https://img.shields.io/badge/Rexxfield-Cybercrime_Investigations-B3272D?style=for-the-badge" alt="Rexxfield"></a> <a href="https://www.hudsonrock.com"><img src="https://img.shields.io/badge/Hudson_Rock-Infostealer_Intel-1B2A4A?style=for-the-badge" alt="Hudson Rock"></a> <a href="https://paranoidlab.com"><img src="https://img.shields.io/badge/ParanoidLab-Dark_Web_%26_IAB-0F172A?style=for-the-badge" alt="ParanoidLab"></a> </p> <p> <a href="https://any.run"><img src="https://img.shields.io/badge/ANY.RUN-Sandbox_%26_TI_Lookup-FF6A2B?style=for-the-badge" alt="ANY.RUN"></a> <a href="https://zetalytics.com"><img src="https://img.shields.io/badge/ZETAlytics-Passive_DNS-0B7285?style=for-the-badge" alt="ZETAlytics"></a> <a href="https://intelx.io"><img src="https://img.shields.io/badge/IntelX-Leak_%26_Darknet_Search-2B6E6B?style=for-the-badge" alt="Intelligence X"></a> </p> </div>| Supporter | What they bring | In the toolkit |
|-----------|-----------------|----------------|
| Rexxfield | Cybercrime investigation and victim-side casework since 2008 — the real-world tradecraft the case workflow and attribution standards are modelled on | Tradecraft & methodology |
| Hudson Rock | Infostealer-infection intelligence — which machines leaked which credentials, and when | /breach-deep · /stealer-log |
| ParanoidLab | Dark-web, Initial-Access-Broker and infostealer-log monitoring across forums, markets and private Telegram | Dark-web collection & review |
| ANY.RUN | Interactive malware sandbox + TI Lookup — sandbox-observed C2 and real endpoints from packed samples | /binary · /hash-id |
| ZETAlytics | Global passive DNS with rare geographic diversity — historical resolution and co-tenancy pivots | /webpivot · /cti-pivot |
| IntelX | Intelligence X — paste sites, leaks, darknet and phonebook selector search | /webpivot · /email-deep |
[!IMPORTANT] ANY.RUN is used read-only.
anyrun_lookupqueries TI Lookup for hashes that have already been detonated. This skill never submits a sample — a public sandbox task is world-readable and irreversible. That boundary is enforced by a regression test (tests/test_no_sample_submission.py), not just by convention.
<sub>Listing here reflects support for the project and does <b>not</b> imply affiliation, endorsement, or any verification of this tool by the organisations named. Integrations marked above are optional and key-gated — <b>every core technique still runs with zero API keys</b>. Always respect each provider's terms of service. The full list of open-source projects and free public-interest services this skill depends on is in <a href="#-acknowledgments--credits">Acknowledgments & Credits</a>.</sub>
<br><br>
What is CTI Expert?
A Claude Code skill that transforms Claude into a trained cyber threat intelligence and open-source intelligence analyst. It runs structured intelligence collection using 74+ commands across 49 techniques — no API keys required for core functionality. To take full advantage, add your own free or paid API keys to the skill's .env — each is auto-detected and unlocks higher-tier access (e.g., Wigle, VirusTotal, URLScan.io, Shodan, Censys, SecurityTrails, WhoisXML).
[!TIP] Keyless by default, more powerful with your keys. Every core technique runs with zero API keys. Add any free or paid keys to
.env(or run/apikeys set <service> <KEY>) and the skill auto-detects them, unlocking higher-tier pivots: reverse favicon→host, passive DNS, certificate search, sibling-domain discovery. A missing or bad key never breaks a run — it just degrades to a note. Setup guide: handbook/api-keys.md.
<table> <tr> <td width="50%">[!TIP] One skill, two layers. cti-expert is the broad collector — the wide net (
/sweep,/webpivot,/subdomain,/username,/email-deep…). Built into the repo is a deep pipeline (intel_engine/) that turns raw collection into a real case: a persistent knowledge base, versioned cases, cross-case correlation, and calibrated assessment. The flow reads like a sentence — collect broadly → "seen this operator before?" → cluster → filter false positives → assess. No external setup: the backend resolves toSELF; install the deep-layer deps once withuv venv && uv pip install -r requirements.txt. Architecture: connectors/intel-backend.md.
Core Capability
Multi-vector reconnaissance on any target type — person, domain, organization, username, email, IP, WiFi — with automated finding validation, exposure scoring, and structured intelligence delivery.
</td> <td width="50%">AEAD Workflow
Acquire raw data → Enrich with pivot expansion → Assess findings → Deliver structured reports (interactive HTML + Markdown + JSON/CSV + IOC bundle; Word on request).
</td> </tr> </table> <br><br>
Demo
Full Case Investigation
<div align="center"> <img src="assets/demo-full-case.gif" alt="Full Case Demo — /case command running a complete investigation" width="800"> </div> <br>CTI Report Generation
<div align="center"> <img src="assets/demo-cti-report.gif" alt="CTI Report Demo — Markdown + DOCX report output" width="800"> </div> <br>Screenshots
<div align="center">| INTSUM Report | Network Topology | Risk Assessment | |:---:|:---:|:---:| | <img src="assets/intsum.png" alt="INTSUM Report" width="280"> | <img src="assets/network-topology.png" alt="Network Topology Diagram" width="280"> | <img src="assets/risk-assessment.png" alt="Risk Assessment Score" width="280"> |
</div> <br><br>
What's New in v2.7
The release where the deep pipeline landed. v2.6 sharpened the collector. v2.7 makes cti-expert a two-layer system — a broad collector plus a built-in, self-contained intelligence pipeline with a persistent knowledge base — reachable from a cold prompt by one command, and guarded by a gate that checks the repo against its own rules on every push.
| Category | What's New | Details |
|----------|-----------|---------|
| One skill, two layers | The deep pipeline is now built in — no external backend to stand up | intel_engine/ vendors the whole Collect → Correlate → Assess pipeline: a persistent knowledge base, versioned cases, cross-case correlation, calibrated assessment and rendering (WebPivot · IntelAnalysis · IntelGraph · IntelReport · BinaryPivot). /backend resolves to SELF — nothing to configure, nothing to host. Install the deep-layer deps once with uv venv && uv pip install -r requirements.txt. The tree regrouped from 22 top-level directories to 14 behind a single SKILL.md. See STRUCTURE.md |
| 8 registered commands | /cti works from a cold prompt, in any project | Commands used to require the skill be loaded first. scripts/register.sh symlinks the skill and commands/*.md into ~/.claude/ and writes the per-machine .mcp.json, so /cti, /cti-recall, /cti-case, /cti-pivot, /cti-cluster, /cti-check, /cti-report and /cti-status are available immediately. There is now one command to remember — /cti <target> — which routes by target type (domain · IP · email · username · phone · wallet · hash · APK) and runs the right chain. Everything else remains a convention command |
| --deep is genuinely parallel | Sub-agent fan-out on both collection and assessment | /cti --deep spawns one sub-agent per discovered frontier seed — pruned through recall and false-positive control first, ≤6 concurrent, depth-capped at 2 hops, with --passive propagating to every child — then converges them into one case. New here: when convergence yields 2+ clusters, the Assess phase fans out too, one agent per cluster (ACH, confidence, risk, scoped to that cluster), while the **cross-cluster judgment stays
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
84.2kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
73.4kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.0k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
CowAgent
47.1kOpen-source super AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
