Liberty91LTD/cti-skills

Cyber Threat Intelligence Skills for each stage of the CTI Lifecycle.

This repository also configures its own agents. See what cti-skills tells them →

18Stars on the repository
85Mods indexed here, across every type
1mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

mitre-attack

49

Liberty91LTD/cti-skills

Skill Claude Code needs its repo

MITRE ATT&CK local dataset reference. Query techniques, groups, software, and mitigations from the local enterprise-attack.json.

not rated 18 +1 1mo ago A 32 tokens original MIT

osint-methodology

50

Liberty91LTD/cti-skills

Skill Claude Code

Structured OSINT collection methodology. Planning, collection techniques, search operators, and documentation. Loaded by the osint-researcher agent.

not rated 18 +1 1mo ago A 32 tokens original MIT

otx-api

51

Liberty91LTD/cti-skills

Skill Claude Code

AlienVault OTX API reference. Community threat intelligence pulses and indicator lookups.

not rated 18 +1 1mo ago A 20 tokens original MIT

Liberty91LTD/cti-skills

Skill Claude Code

Use when the user asks about phishing campaigns, social-engineering techniques, BEC (business email compromise), pretexting, AiTM (adversary-in-the-middle) kits, or specific phishing-kit families. Self-updating knowledge cell.

not rated 18 +1 1mo ago A 55 tokens original MIT

pir-management

53

Liberty91LTD/cti-skills

Skill Claude Code

Use when the user asks to create, review, retire, or refine Priority Intelligence Requirements, or wants to align collection and analysis to the current PIR set. Covers the PIR lifecycle end-to-end.

not rated 18 +1 1mo ago A 42 tokens original MIT

quality-control

54

Liberty91LTD/cti-skills

Skill Claude Code

Peer review checklist and quality standards for intelligence products. Loaded by the quality-reviewer agent.

not rated 18 +1 1mo ago A 21 tokens original MIT

Liberty91LTD/cti-skills

Skill Claude Code

Use when the user asks about the ransomware ecosystem, RaaS dynamics, affiliate markets, attribution between groups, leak-site behaviour, or recent group activity (LockBit lineage, ALPHV/BlackCat, RansomHub, Akira, Play, Qilin, Cl0p, Medusa, etc.). Self-updating knowledge cell.

not rated 18 +1 1mo ago A 76 tokens original MIT

red-team-analysis

56

Liberty91LTD/cti-skills

Skill Claude Code

Use when challenging a prevailing analytical judgment, the user asks "what is the opposing case?" / "argue the other side", or wants a devil's-advocate review of an assessment. Deliberately argues the opposite position to expose weaknesses.

not rated 18 +1 1mo ago A 54 tokens original MIT

reversinglabs-api

57

Liberty91LTD/cti-skills

Skill Claude Code

ReversingLabs Spectra Analyze (A1000) API reference. File hash classification, detailed reports, dynamic analysis, network indicator reputation, advanced search, YARA, container relationships.

not rated 18 +1 1mo ago A 44 tokens original MIT

Liberty91LTD/cti-skills

Skill Claude Code

Use when the user asks about Russian state-sponsored cyber operations or specific actors (APT28/Fancy Bear, Sandworm, Cozy Bear/APT29, Turla, GRU-affiliated hacktivist fronts like CARR/NoName057), wartime ICS/OT campaigns, or pro-RU information operations. Self-updating knowledge cell.

not rated 18 +1 1mo ago A 80 tokens original MIT

shodan-api

59

Liberty91LTD/cti-skills

Skill Claude Code

Shodan API reference. Host reconnaissance, port scanning, and vulnerability data.

not rated 18 +1 1mo ago A 19 tokens original MIT

sigma-writing

60

Liberty91LTD/cti-skills

Skill Claude Code

Use when the user asks for a SIGMA detection rule, "write a SIGMA rule for X", or /hash-investigation / /malware-analysis surfaces behaviour worth a vendor-agnostic detection. Format spec + writing guide.

not rated 18 +1 1mo ago A 52 tokens original MIT

sops

61

Liberty91LTD/cti-skills

Skill Claude Code

Use when the user asks about CTI standard operating procedures (daily triage, IOC processing, flash-report cadence, threat-actor profile updates, briefing schedule), or wants to look up a specific SOP.

not rated 18 +1 1mo ago A 44 tokens original MIT

source-assessment

62

Liberty91LTD/cti-skills

Skill Claude Code

Use when rating a source with the NATO Admiralty Scale, the user asks "is this reliable?" / "rate this source", or the tradecraft pipeline calls for source assessment before publishing. Reliability A-F, credibility 1-6.

not rated 18 +1 1mo ago A 52 tokens original MIT

Liberty91LTD/cti-skills

Skill Claude Code

Use when the user asks "who are our customers?" / "how do we tailor for X stakeholder?" / "who should this report go to?", or wants to map / re-map stakeholder needs. Ensures intelligence reaches the right people in the right format.

not rated 18 +1 1mo ago A 56 tokens original MIT

stix-bundle

64

Liberty91LTD/cti-skills

Skill Claude Code

STIX 2.1 bundle creation reference. Object types, relationships, and JSON templates for structured threat intelligence sharing.

not rated 18 +1 1mo ago A 29 tokens original MIT

Liberty91LTD/cti-skills

Skill Claude Code

Use when the user asks "which SAT should I use for X?", wants the index of Structured Analytic Techniques, or is choosing between ACH, key-assumptions-check, red-team-analysis, indicators of change, etc.

not rated 18 +1 1mo ago A 51 tokens original MIT

Liberty91LTD/cti-skills

Skill Claude Code

Use when the user asks about supply-chain attacks, third-party / vendor compromise (SolarWinds, Kaseya, 3CX, MOVEit, XZ-utils-style), software-bill-of-materials risks, or library / dependency-injection attacks. Self-updating knowledge cell.

not rated 18 +1 1mo ago A 64 tokens original MIT

Liberty91LTD/cti-skills

Skill Claude Code

Use when the user asks to build or update a threat-actor profile, "tell me about actor X" / "profile actor Y", or another skill needs the canonical profile template (attribution, TTPs, campaigns, infrastructure patterns, intelligence gaps).

not rated 18 +1 1mo ago A 60 tokens original MIT

threat-assessment

68

Liberty91LTD/cti-skills

Skill Claude Code

Structured threat assessment methodology. Intent + Capability + Opportunity = Threat Level. Use when formally evaluating a threat.

not rated 18 +1 1mo ago A 26 tokens original MIT

tlp-guide

69

Liberty91LTD/cti-skills

Skill Claude Code

Use when the user asks "what TLP should this be?", applying TLP markings to a finished product, or the tradecraft pipeline calls for TLP determination before sharing. Covers TLP v2.0 (CLEAR / GREEN / AMBER / AMBER+STRICT / RED).

not rated 18 +1 1mo ago A 61 tokens original MIT

url-investigation

70

Liberty91LTD/cti-skills

Skill Claude CodeCodex

Use when a user asks to scan, investigate, or characterize a URL. Submits to URLScan (unlisted by default), cross-references with VirusTotal and OTX, extracts the parent domain and resolved IP for follow-up investigation. Returns verdict, redirect chain, contacted infrastructure, and screenshot. Invoked by…

not rated 18 +1 1mo ago A 80 tokens original MIT

urlscan-api

71

Liberty91LTD/cti-skills

Skill Claude Code

URLScan.io API reference. URL submission, scanning, and result retrieval.

not rated 18 +1 1mo ago A 19 tokens original MIT

virustotal-api

72

Liberty91LTD/cti-skills

Skill Claude Code

VirusTotal API v3 reference. File, IP, domain, and URL analysis endpoints.

not rated 18 +1 1mo ago A 23 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: