cti-skills
01Plugin Claude Code
Plugin marketplace listing 1 plugin: cti-skills.
Plugin Claude Code
Plugin marketplace listing 1 plugin: cti-skills.
Agent Claude Code
Core intelligence analyst. Applies structured analytic techniques, performs threat actor profiling, campaign tracking, and produces analytical judgments. The analytical brain of the platform.
Agent Claude Code
Writes detection rules in SIGMA, YARA, and KQL based on intelligence findings. Translates threat intelligence into actionable detections.
Agent Claude Code
Processes, enriches, deduplicates, and exports IOCs. Creates STIX 2.1 bundles. Manages IOC lifecycle from raw indicators to exportable packages.
Agent Claude Code
Conducts open-source intelligence research using web search and web fetch. The ONLY agent with WebSearch and WebFetch access.
Agent Claude Code
Peer reviews intelligence products for accuracy, analytical rigor, proper sourcing, TLP compliance, and tradecraft quality. The quality gate before dissemination.
Agent Claude Code
Writes finished intelligence products including threat assessments, flash reports, intelligence summaries, and briefings. Applies proper TLP, confidence, and likelihood language.
Hook Claude Code
Runs after a tool call finishes for Write, Edit and MultiEdit tool calls, executing lookup-skill-propagation.py via python3. From Liberty91LTD/cti-skills.
Settings file Claude Code
Agent settings declaring 1 hook event (PostToolUse) and 6 allowed tools.
Instructions file CodexOpenCode
Instructions for Liberty91LTD/cti-skills, covering agents.md — orientation for ai agents, what this pack is, shape, finding and invoking skills and the orchestrator pattern.
Instructions file
Instructions for Liberty91LTD/cti-skills, covering cti-skills — claude code orientation, what's here, how to use the pack, tradecraft vocabularies and before committing.
Skill Claude CodeCodex
AbuseIPDB API reference. IP reputation and abuse report lookups.
Skill Claude CodeCodex
Analysis of Competing Hypotheses — structured technique for evaluating multiple explanations against evidence. Use when facing ambiguous attribution or multiple plausible scenarios.
Skill Claude CodeCodex
Use when documenting a named campaign across time and victims, the user asks to start or update a campaign record, or another skill identified a multi-incident cluster that warrants formal tracking. Provides the template (timeline, attribution, victimology, attack chain, Diamond Model mapping, IOC clusters) and the…
Skill Claude CodeCodex
Use when the user asks about carding, BIN attacks, payment-card breach markets, fullz/CVV2 trade, autoshops (BidenCash, Brian's Club, Russianmarket, B1ack's Stash), or financial-fraud TTPs. Self-updating knowledge cell.
Skill Claude CodeCodex
Censys API v2 reference. Host reconnaissance and certificate data.
Skill Claude CodeCodex
Use when the user asks about Chinese state-sponsored cyber operations or specific PRC-aligned actors (APT41, Volt Typhoon, Mustang Panda, APT10, APT31, Salt Typhoon, etc.), MSS/PLA-attributed campaigns, or PRC sector targeting. Self-updating knowledge cell.
Skill Claude CodeCodex
Use when assigning a confidence level to an analytical judgment, the user asks "how confident are we?" / "what is the confidence on X?", or the orchestrator's tradecraft pipeline calls for a confidence level before publishing. Provides the MISP 0-100 scale and qualitative-band mapping.
Skill Claude CodeCodex
Use when you need to answer "which attacker techniques do our controls actually stop, and how well?", "what controls should I have for this threat?", or "what telemetry should I collect to detect it?" — joining a customer's or your own security control baseline to ATT&CK techniques using a public, versioned evidence…
Skill Claude CodeCodex
CrowdStrike Falcon Intelligence (Intel API) reference. OAuth2 auth, Falcon Query Language, indicator (IOC) lookups, threat-actor entities, intel reports, MITRE ATT&CK mappings, malware families, vulnerabilities, rule sets.
Skill Claude CodeCodex
Use when the user asks about the CTI Hyperloop framework, the intelligence lifecycle as a high-tempo loop, or how to map intelligence work across strategic / operational / tactical levels with bidirectional feedback. Liberty91's operational doctrine.
Skill Claude CodeCodex
Use as the default entry point for any CTI request that doesn't name a specific skill. Activates when a user asks to investigate an indicator, profile a threat actor, write an assessment, enrich IOCs, or build detection rules. Routes to the right investigation or analysis skill, then auto-applies rigor skills (source…
Skill Claude CodeCodex
Use when the user wants to configure API keys for the CTI skills pack, asks "how do I set up keys", "configure VirusTotal", "add my Shodan key", or runs /cti-setup. Walks through API key configuration inside Claude Code without needing to run a shell script. Also handles re-running setup, adding individual keys, and…
Skill Claude CodeCodex
Dark web intelligence collection methodology — vendor-first access posture, sourced reference lists for 35+ underground forums and 30+ Telegram channels, OPSEC primer, passive-monitoring strategy, and bundled Python CLIs for onion-indexer search, Telegram channel monitoring, and local keyword matching. Use when the…