Liberty91LTD

61 mods across 1 repository, 17 stars between them.

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when a user asks to investigate, check, or characterize a domain or hostname. Chains VirusTotal, URLScan (search existing scans), Shodan (DNS resolve + host), OTX, ransomware.live (victim-status sweep), and optionally Censys. Returns reputation, resolution, hosting fingerprint, ransomware-claim status, and pivot…

17 28d ago A 90 tokens original MIT

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when the user asks about North Korean state-sponsored cyber operations or specific DPRK actors (Lazarus, APT38, BlueNoroff, Andariel, Kimsuky, etc.), revenue-generation campaigns, IT-worker schemes, or DPRK targeting of cryptocurrency / supply chain. Self-updating knowledge cell.

17 28d ago A 75 tokens original MIT

feedback-loops

27

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Feedback loop implementation for continuous CTI improvement. Consumer feedback, analyst retrospectives, source quality tracking.

17 28d ago A 24 tokens original MIT

greynoise-api

28

Liberty91LTD/cti-skills

Skill Claude CodeCodex

GreyNoise API reference. Internet scanner/noise classification for IPs.

17 28d ago A 19 tokens original MIT

hacktivism

29

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when the user asks about hacktivist activity (Killnet, NoName057(16), IT Army of Ukraine, Anonymous Sudan, RipperSec, CARR, etc.), DDoS-claiming groups, politically-motivated cyber operations, or wartime cyber-ops chatter. Self-updating knowledge cell.

17 28d ago A 72 tokens original MIT

hash-investigation

30

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when a user asks to check, identify, or characterize a file hash (MD5, SHA-1, SHA-256). Chains VirusTotal and OTX, optionally triggers /malware-analysis for deeper behavioral review. Returns detection signals, malware family, behavioral tags, and pivot candidates (communicating IPs, dropped files). Invoked by…

17 28d ago A 87 tokens original MIT

horizon-scanning

31

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when the user asks "what is coming next?", wants strategic forecasting, or is hunting weak signals of emerging threats before they materialise. Covers signal identification, trend analysis, and scenario development.

17 28d ago A 44 tokens original MIT

indicator-pivoting

32

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Indicator pivoting methodology — how to use one known indicator to discover related infrastructure across the IOC graph. Decision tree by indicator type with concrete /lookup- commands per pivot, a worked multi-hop example, pivot-quality scoring, and routing into the rigor pipeline. Use when the user asks "what else…

17 28d ago A 103 tokens original MIT

infostealers

33

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when the user asks about infostealer families (LummaC2, RedLine, Vidar, Stealc, Raccoon, Rhadamanthys, etc.), log marketplaces (Russian Market, Genesis successors, BidenCash, Hudson Rock corpus), or stealer-driven incidents and credential exposure. Self-updating knowledge cell.

17 28d ago A 72 tokens original MIT

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when the user asks about initial access brokers (IABs), the access-listing market, ransomware-feeding-IAB pipelines, specific broker handles, or how access is priced and packaged. Self-updating knowledge cell.

17 28d ago A 51 tokens original MIT

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when the user asks about ISAC participation, TAXII feeds, MISP communities, FIRST, STIX-based sharing, or how to publish intelligence externally. Covers sharing models, standards, communities, and TLP-governed dissemination.

17 28d ago A 52 tokens original MIT

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when writing a finished intelligence product, the user asks for a flash-report / threat-assessment / briefing / FINTEL template, or wants the BLUF + active-voice + clear-sourcing conventions. Covers all product types.

17 28d ago A 51 tokens original MIT

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Workflow for enriching raw IOCs. Routes each IOC type to the appropriate /lookup- skills, optionally correlates against MISP, and synthesises a single enrichment record per indicator. Use when the user has a batch of raw IOCs to process before triage or before pushing into a sharing platform.

17 28d ago A 66 tokens original MIT

ioc-export

38

Liberty91LTD/cti-skills

Skill Claude CodeCodex

IOC export formats and procedures. CSV, STIX 2.1, OpenIOC, MISP. Handles format conversion and packaging.

17 28d ago A 30 tokens original MIT

ip-investigation

39

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when a user asks to investigate, check, enrich, or characterize an IP address (IPv4 or IPv6). Chains VirusTotal, Shodan, AbuseIPDB, GreyNoise, OTX, and optionally Censys in parallel, then consolidates findings and prioritizes follow-up IOCs. Invoked by /cti-orchestrator when the target is an IP.

17 28d ago A 81 tokens original MIT

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when the user asks about Iranian state-sponsored cyber operations or specific IRGC/MOIS-aligned actors (APT35/Charming Kitten, APT34/OilRig, MuddyWater, Imperial Kitten, etc.), wiper campaigns, or front-group hacktivist clusters (Predatory Sparrow, Handala). Self-updating knowledge cell.

17 28d ago A 82 tokens original MIT

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when surfacing the assumptions underlying an analytical judgment, the user asks "what are we assuming?" / "are these assumptions still valid?", or before publishing a high-impact assessment. Standard SAT applied during major assessments.

17 28d ago A 49 tokens original MIT

kql-writing

42

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when the user asks for a KQL query, a Microsoft Sentinel / Defender / Azure Log Analytics detection or hunt, or wants to translate a finding from /hash-investigation / /malware-analysis into KQL. Format spec + writing guide.

17 28d ago A 56 tokens original MIT

likelihood-language

43

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when phrasing a forward-looking statement, the user asks "how likely is X?" / "what's the likelihood?", or the tradecraft pipeline applies a probability yardstick to a finished product. Standardised likelihood language across all products.

17 28d ago A 52 tokens original MIT

lookup-abuseipdb

44

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when you need abuse-report history for an IPv4/IPv6 address — confidence score, total reports, distinct reporters, usage type. IP-only. Commonly invoked by /ip-investigation. Retrieval only.

17 28d ago A 49 tokens original MIT

lookup-censys

45

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when you need deep host + certificate reconnaissance for an IP or need to run a Censys search query. Returns services, TLS certificates, ASN, and location. Free tier is severely limited (250 queries/month) — use sparingly. Retrieval only.

17 28d ago A 57 tokens original MIT

lookup-crowdstrike

46

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when you need CrowdStrike Falcon Intelligence on an indicator (IOC reputation for an IP, domain, hash, or URL — malicious confidence, linked actors, malware families, reports) OR on an adversary (threat-actor profile, origin/target search, MITRE ATT&CK TTPs, finished intel reports). Answers questions like "look up…

17 28d ago A 173 tokens original MIT

lookup-greynoise

47

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when you need to classify an IP as internet scanner noise vs. targeted activity. Returns noise/riot flags, classification (benign/malicious/unknown), actor name if known. IP-only. Commonly invoked by /ip-investigation to filter out mass-scanning noise. Retrieval only.

17 28d ago A 66 tokens original MIT

lookup-liberty91

48

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when you need Liberty91 platform intelligence — what actually happened (deduplicated Threat Events with every source, Admiralty reliability/credibility and verification stage), whether an IOC is already known to your account, the canonical threat library (actors, malware, vulnerabilities, clusters, ATT&CK TTPs)…

17 28d ago A 160 tokens original MIT