cti-case
01Command
Part of cti-expert
Run the full deterministic pipeline on one or more seeds: collect, ingest, prior-overlap, risk, cluster, ICD-203 assessment. Usage: /cti-case [seed...].
CTI Expert — Cyber Threat Intelligence & OSINT analysis skill for Claude Code. 67+ commands, 35 techniques, no API keys required.
Command
Part of cti-expert
Run the full deterministic pipeline on one or more seeds: collect, ingest, prior-overlap, risk, cluster, ICD-203 assessment. Usage: /cti-case [seed...].
Command
Part of cti-expert
False-positive control — is this indicator a real operator link or shared noise? Run BEFORE clustering on anything. Usage: /cti-check.
Command
Part of cti-expert
Expand and correlate an existing case — peers, shared indicators, TLS overlap, reverse-WHOIS. Usage: /cti-cluster.
Command
Part of cti-expert
Collect pivot artifacts from ONE target — favicon, trackers, wallets, emails, CORS, mail/SPF/DMARC, WHOIS, co-tenancy. Usage: /cti-pivot [--passive].
Command
Part of cti-expert
Have I seen this before? Check a seed against every prior case BEFORE collecting. Always run this first. Usage: /cti-recall.
Command
Part of cti-expert
Render case deliverables — relationship graph (PNG/SVG/Mermaid) and a polished PDF/DOCX assessment. Usage: /cti-report [--graph|--pdf].
Command
Part of cti-expert
Health check — backend tier, case store, MCP tools, API credit balances. Run this when something behaves oddly. Usage: /cti-status.
Command
Part of cti-expert
THE ENTRY POINT for cti-expert. Investigate any target — domain, IP, email, username, phone, wallet, hash or APK. Routes to the right chain automatically. Usage: /cti [--deep|--quick|--passive].
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: