Install
$ agentstack add skill-liberty91ltd-cti-skills-lookup-crowdstrike ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
lookup-crowdstrike
Queries the CrowdStrike Falcon Intelligence (Intel) API for indicator (IOC) reputation, threat-actor (adversary) profiles, actor search by origin/target, MITRE ATT&CK technique coverage, and finished intelligence reports. Retrieval only — do not interpret, assess, or conclude. The invoking skill or agent reasons about the result.
When to invoke
- User asks to look up an IP / domain / hash / URL and CrowdStrike credentials are configured — return CrowdStrike's malicious-confidence, linked actors, malware families, and report references alongside the other lookups
- User asks for the latest / recent malicious IOCs, a CrowdStrike indicator feed, or "what's CrowdStrike seeing lately" →
indicators --malicious(browse/sweep, newest-first; filter by type/actor/malware/recency) - User asks "what TTPs / techniques does use?" →
ttps(MITRE ATT&CK mapping) - User asks "which threat actors operate from ?" / "who targets ?" →
actors --origin/--target-industry - User asks to profile a named adversary (Charming Kitten, Mustang Panda, Cozy Bear, …) →
actor - User wants the latest finished reporting on an actor or topic →
reports --actor --latestorreports --search "" /threat-actor-profilingor a regional espionage cell wants vendor-authoritative attribution, origins, motivations, and capability- Need to download a specific intel report PDF by ID →
reports --pdf
How to invoke
One CLI: a Python wrapper around the official crowdstrike-falconpy SDK. Self-bootstraps a private venv at tools/clis/.venv-crowdstrike/ on first run; no global install. The SDK exchanges your client id + secret for an OAuth2 bearer token at /oauth2/token automatically.
# IOC reputation — ip / domain / hash / url (auto-detected by CrowdStrike via FQL indicator: match)
python3 tools/clis/crowdstrike.py indicator [--limit N] [--include-deleted]
# Browse / sweep the indicator feed — latest malicious IOCs, by type / actor / recency
python3 tools/clis/crowdstrike.py indicators [--malicious] [--type ip|domain|url|hash|md5|sha1|sha256|email] \
[--actor ""] [--malware ] [--since 7d] [--filter ""] [--limit N]
# Profile a single named threat actor (adversary)
python3 tools/clis/crowdstrike.py actor "" [--limit N] [--fields F1,F2,...]
# Search actors by origin / target / motivation / raw FQL
python3 tools/clis/crowdstrike.py actors [--origin russia] [--target-country united-states] \
[--target-industry financial-services] [--motivation state-sponsored] [--filter ""] [--limit N]
# Finished intel reports — by actor, free-text, latest-first, or PDF download
python3 tools/clis/crowdstrike.py reports [--actor ""] [--search ""] [--filter ""] \
[--latest] [--limit N] [--pdf --out ]
# MITRE ATT&CK techniques mapped to an actor (add --detailed for the full Navigator/CSV/JSON report)
python3 tools/clis/crowdstrike.py ttps "" [--detailed] [--format csv|json|json_navigator]
All subcommands accept --dry-run to preview the request plan without spending an API call, and --base-url to override the cloud region for one call. All exit code 2 if $CROWDSTRIKE_CLIENT_ID or $CROWDSTRIKE_CLIENT_SECRET is unset (when not in dry-run). Report missing credentials; do not fabricate.
Examples
# 0) "What are the latest 10 malicious IOCs from CrowdStrike?"
python3 tools/clis/crowdstrike.py indicators --malicious --limit 10
# e.g. latest malicious domains from the past week tied to an actor:
python3 tools/clis/crowdstrike.py indicators --malicious --type domain --since 7d --actor "Fancy Bear"
# 1) "Look up IP 1.1.1.1" — CrowdStrike's view of the indicator
python3 tools/clis/crowdstrike.py indicator 1.1.1.1
# 2) "What TTPs does Charming Kitten use?"
python3 tools/clis/crowdstrike.py ttps "Charming Kitten" --detailed --format json_navigator
# 3) "Which threat actors operate from Russia?"
python3 tools/clis/crowdstrike.py actors --origin russia --limit 30
# 4) "Give me the latest report on Mustang Panda"
python3 tools/clis/crowdstrike.py reports --actor "Mustang Panda" --latest --limit 5
# 5) Profile an actor, then pull its newest report PDF
python3 tools/clis/crowdstrike.py actor "Cozy Bear"
python3 tools/clis/crowdstrike.py reports --pdf CSA-250123 --out cozy-bear-latest.pdf
Quota awareness
The Intel API is governed by CrowdStrike's per-tenant rate limit (token-bucket; the response carries X-RateLimit-Limit / X-RateLimit-Remaining headers). On exhaustion the API returns HTTP 429 with a Retry-After header — back off and retry. Each subcommand is a single API call, except ttps (resolves the actor slug, then queries MITRE — 2 calls, 3 with --detailed) and reports --pdf (1 call returning binary). Use --dry-run to confirm the call plan before fan-out across many actors.
Response format
The CLI emits JSON to stdout. Skills consuming it should treat it as:
source: crowdstrike
operation: indicator_lookup | indicator_search | actor_profile | actor_search | report_search | report_pdf | actor_ttps
indicator:
type: indicator | indicator_query | actor | actor_query | report_query | report_id
base_url: https://api.crowdstrike.com
query_time:
count: # number of resources returned
# operation-specific payload — the SDK's deserialised resources array
indicators: [ ... ] # for `indicator`
actors: [ ... ] # for `actor`, `actors`
reports: [ ... ] # for `reports`
technique_ids: [ ... ] # for `ttps`; + mitre_report when --detailed
saved_to: # for `reports --pdf`
Common fields inside each resource type:
| Resource | Key fields | |---|---| | indicator | indicator, type, malicious_confidence (high/medium/low/unverified), actors, malware_families, kill_chains, threat_types, reports, labels, published_date, last_updated | | actor | name, slug, short_description, description, known_as, origins[], target_countries[], target_industries[], motivations[], capability, group, actor_type, first_activity_date, last_activity_date | | report | name, title, slug, short_description, created_date, last_modified_date, actors[], target_countries[], target_industries[], tags[], report_type, url, attachments[] | | ttps | technique_ids[] (ATT&CK technique IDs); mitre_report (CSV / JSON / Navigator layer when --detailed) |
Rate limits
Per-tenant token bucket; 429 + Retry-After on exhaustion. indicator/actor/actors/reports = 1 call each; ttps = 2–3 calls. Back off on 429.
Source reliability (Admiralty default)
Default rating for downstream /score-source: A2 (completely reliable, probably true). CrowdStrike Falcon Intelligence is vendor-authoritative finished intelligence produced by a dedicated analyst team; attribution, origins, and TTP mappings are well validated.
Downgrade to B3 if:
- An indicator's
malicious_confidenceisloworunverified - An actor record is sparse (no
origins/capability) or flagged provisional - The judgement rests on a single report with hedged language — read the report body, don't infer from the tag alone
Stay at A2 / consider A1 if:
malicious_confidenceishighAND the indicator is linked to a named actor or malware family- Multiple finished reports corroborate the actor attribution and TTP set
Related skills
/lookup-virustotal— community-aggregated detection; complements CrowdStrike's vendor view on the same IOC/lookup-reversinglabs— vendor-authoritative malware classification + sandbox for a hash/lookup-otx— community pulse context for the same indicator/threat-actor-profiling— chainsactor/ttps/reportsinto a full adversary profile/ip-investigation,/domain-investigation,/hash-investigation,/url-investigation— chain theindicatorlookup/mitre-attack— resolve thetechnique_idsfromttpsagainst the local ATT&CK dataset/score-source— apply the Admiralty rating to the result
See also
- Integration setup:
tools/integrations/crowdstrike.md - Python CLI source:
tools/clis/crowdstrike.py - Companion API reference (non-invokable):
skills/crowdstrike-api/SKILL.md - Official API docs: https://developer.crowdstrike.com/api-reference/collections/intel/
- SDK source: https://github.com/CrowdStrike/falconpy
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Liberty91LTD
- Source: Liberty91LTD/cti-skills
- License: MIT
- Homepage: https://liberty91.com/cti-skills
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.