AgentStack
Liberty91LTD avatar

Liberty91LTD

50 listings · 0 installs

Open-source publisher. Listings imported from github.com/Liberty91LTD — credited to the original author with their license.

↗ github.com/Liberty91LTD
50+ results
Self-run
SKILL

Cti Setup

Use when the user wants to configure API keys for the CTI skills pack, asks "how do I set up keys", "configure VirusTotal", "add my Shodan key", or runs /cti-setup. Walks through API key configuration inside Claude Code without needing to run a shell script. Also handles re-running setup, adding individual keys, and verifying that configured keys work.

0
17
Free
Self-run
SKILL

Dprk Cyber Espionage

Use when the user asks about North Korean state-sponsored cyber operations or specific DPRK actors (Lazarus, APT38, BlueNoroff, Andariel, Kimsuky, etc.), revenue-generation campaigns, IT-worker schemes, or DPRK targeting of cryptocurrency / supply chain. Self-updating knowledge cell.

0
14
Free
Self-run
SKILL

Feedback Loops

Feedback loop implementation for continuous CTI improvement. Consumer feedback, analyst retrospectives, source quality tracking.

0
11
Free
Self-run
SKILL

Lookup Abuseipdb

Use when you need abuse-report history for an IPv4/IPv6 address — confidence score, total reports, distinct reporters, usage type. IP-only. Commonly invoked by /ip-investigation. Retrieval only.

0
18
Free
Self-run
SKILL

Mitre Attack

MITRE ATT&CK local dataset reference. Query techniques, groups, software, and mitigations from the local enterprise-attack.json.

0
12
Free
Self-run
SKILL

Ioc Export

IOC export formats and procedures. CSV, STIX 2.1, OpenIOC, MISP. Handles format conversion and packaging.

0
14
Free
Self-run
SKILL

Kql Writing

Use when the user asks for a KQL query, a Microsoft Sentinel / Defender / Azure Log Analytics detection or hunt, or wants to translate a finding from `/hash-investigation` / `/malware-analysis` into KQL. Format spec + writing guide.

0
16
Free
Self-run
SKILL

Lookup Shodan

Use when you need host reconnaissance for an IP or domain — open ports, services, banners, OS detection, vulnerabilities. For domains, resolves DNS first then queries the IP. Commonly invoked by /ip-investigation and /domain-investigation. Retrieval only.

0
16
Free
Self-run
SKILL

Lookup Urlscan

Use when you need to submit a URL for live scanning via URLScan.io and retrieve results, or search existing scans for a domain. Returns verdict, final URL after redirects, resolved IP, contacted domains/IPs, and screenshot URL. Commonly invoked by /url-investigation and /domain-investigation.

0
18
Free
Self-run
SKILL

Greynoise Api

GreyNoise API reference. Internet scanner/noise classification for IPs.

0
17
Free
Self-run
SKILL

Lookup Greynoise

Use when you need to classify an IP as internet scanner noise vs. targeted activity. Returns noise/riot flags, classification (benign/malicious/unknown), actor name if known. IP-only. Commonly invoked by /ip-investigation to filter out mass-scanning noise. Retrieval only.

0
13
Free
Self-run
SKILL

Lookup Opencti

Use when you need to query an OpenCTI instance — is this IOC already known, what entities/reports/campaigns exist for an actor — or push new intel into it — creating indicators/observables, labelling, TLP markings, relationships, or importing a STIX 2.1 bundle. Two-way integration. Commonly invoked by /ip-investigation and friends to check whether an indicator is already in your knowledge base, a…

0
18
Free
Self-run
SKILL

Ach

Analysis of Competing Hypotheses — structured technique for evaluating multiple explanations against evidence. Use when facing ambiguous attribution or multiple plausible scenarios.

0
17
Free
Self-run
SKILL

Cti Orchestrator

Use as the default entry point for any CTI request that doesn't name a specific skill. Activates when a user asks to investigate an indicator, profile a threat actor, write an assessment, enrich IOCs, or build detection rules. Routes to the right investigation or analysis skill, then auto-applies rigor skills (source rating, TLP, confidence, likelihood) on the output.

0
19
Free
Self-run
SKILL

Intelligence Sharing

Use when the user asks about ISAC participation, TAXII feeds, MISP communities, FIRST, STIX-based sharing, or how to publish intelligence externally. Covers sharing models, standards, communities, and TLP-governed dissemination.

0
15
Free
Self-run
SKILL

Carding Financial Fraud

Use when the user asks about carding, BIN attacks, payment-card breach markets, fullz/CVV2 trade, autoshops (BidenCash, Brian's Club, Russianmarket, B1ack's Stash), or financial-fraud TTPs. Self-updating knowledge cell.

0
15
Free
Self-run
SKILL

Lookup Censys

Use when you need deep host + certificate reconnaissance for an IP or need to run a Censys search query. Returns services, TLS certificates, ASN, and location. Free tier is severely limited (250 queries/month) — use sparingly. Retrieval only.

0
19
Free
Self-run
SKILL

Darkweb Collection

Dark web intelligence collection methodology — vendor-first access posture, sourced reference lists for 35+ underground forums and 30+ Telegram channels, OPSEC primer, passive-monitoring strategy, and bundled Python CLIs for onion-indexer search, Telegram channel monitoring, and local keyword matching. Use when the user wants to design or run dark-web collection, build a selector list, pick a ven…

0
15
Free
Self-run
SKILL

Otx Api

AlienVault OTX API reference. Community threat intelligence pulses and indicator lookups.

0
18
Free
Self-run
SKILL

Confidence Levels

Use when assigning a confidence level to an analytical judgment, the user asks "how confident are we?" / "what is the confidence on X?", or the orchestrator's tradecraft pipeline calls for a confidence level before publishing. Provides the MISP 0-100 scale and qualitative-band mapping.

0
13
Free
Self-run
SKILL

Lookup Otx

Use when you need to check an IP, domain, file hash, or URL against AlienVault OTX community pulses. Returns pulse count, key pulses, tags, related indicators, and passive DNS. Commonly invoked by investigation skills to pull community context. Retrieval only — does not interpret.

0
14
Free
Self-run
SKILL

Lookup Ransomwarelive

Use when you need to check whether an organisation/domain has been claimed by a ransomware group, profile a specific ransomware group (TTPs, leak-site infra, IOCs, YARA), or aggregate ransomware victim claims by country/sector/timeframe. Backed by ransomware.live's leak-site scrapes — 27k+ victims across 330+ groups. Commonly invoked by /domain-investigation, /ransomware-ecosystem, /threat-actor-…

0
20
Free
Self-run
SKILL

Infostealers

Use when the user asks about infostealer families (LummaC2, RedLine, Vidar, Stealc, Raccoon, Rhadamanthys, etc.), log marketplaces (Russian Market, Genesis successors, BidenCash, Hudson Rock corpus), or stealer-driven incidents and credential exposure. Self-updating knowledge cell.

0
11
Free
Self-run
SKILL

Maturity Assessment

Use when assessing the maturity of a CTI programme, the user asks "how mature is our CTI?" / "what should we improve next?", or wants a benchmark against the five-level model across six dimensions.

0
14
Free
Self-run
SKILL

Osint Methodology

Structured OSINT collection methodology. Planning, collection techniques, search operators, and documentation. Loaded by the osint-researcher agent.

0
16
Free
Self-run
SKILL

Key Assumptions Check

Use when surfacing the assumptions underlying an analytical judgment, the user asks "what are we assuming?" / "are these assumptions still valid?", or before publishing a high-impact assessment. Standard SAT applied during major assessments.

0
14
Free
Self-run
SKILL

Hacktivism

Use when the user asks about hacktivist activity (Killnet, NoName057(16), IT Army of Ukraine, Anonymous Sudan, RipperSec, CARR, etc.), DDoS-claiming groups, politically-motivated cyber operations, or wartime cyber-ops chatter. Self-updating knowledge cell.

0
15
Free
Self-run
SKILL

Crowdstrike Api

CrowdStrike Falcon Intelligence (Intel API) reference. OAuth2 auth, Falcon Query Language, indicator (IOC) lookups, threat-actor entities, intel reports, MITRE ATT&CK mappings, malware families, vulnerabilities, rule sets.

0
16
Free
Self-run
SKILL

Lookup Virustotal

Use when you need to check an IP, domain, file hash, or URL against VirusTotal's reputation database. Returns detection ratio, verdict, community score, and key findings. Commonly invoked by investigation skills (/ip-investigation, /domain-investigation, /hash-investigation, /url-investigation) and by analysts enriching IOCs. Other agents/skills can chain this for VirusTotal enrichment.

0
17
Free
Self-run
SKILL

Iran Cyber Espionage

Use when the user asks about Iranian state-sponsored cyber operations or specific IRGC/MOIS-aligned actors (APT35/Charming Kitten, APT34/OilRig, MuddyWater, Imperial Kitten, etc.), wiper campaigns, or front-group hacktivist clusters (Predatory Sparrow, Handala). Self-updating knowledge cell.

0
18
Free
Self-run
SKILL

Initial Access Brokers

Use when the user asks about initial access brokers (IABs), the access-listing market, ransomware-feeding-IAB pipelines, specific broker handles, or how access is priced and packaged. Self-updating knowledge cell.

0
14
Free
Self-run
SKILL

Campaign Tracking

Use when documenting a named campaign across time and victims, the user asks to start or update a campaign record, or another skill identified a multi-incident cluster that warrants formal tracking. Provides the template (timeline, attribution, victimology, attack chain, Diamond Model mapping, IOC clusters) and the lifecycle from active to historical.

0
12
Free
Self-run
SKILL

Cti Hyperloop

Use when the user asks about the CTI Hyperloop framework, the intelligence lifecycle as a high-tempo loop, or how to map intelligence work across strategic / operational / tactical levels with bidirectional feedback. Liberty91's operational doctrine.

0
15
Free
Self-run
SKILL

Domain Investigation

Use when a user asks to investigate, check, or characterize a domain or hostname. Chains VirusTotal, URLScan (search existing scans), Shodan (DNS resolve + host), OTX, ransomware.live (victim-status sweep), and optionally Censys. Returns reputation, resolution, hosting fingerprint, ransomware-claim status, and pivot candidates. Invoked by /cti-orchestrator when the target is a domain.

0
16
Free
Self-run
SKILL

Ip Investigation

Use when a user asks to investigate, check, enrich, or characterize an IP address (IPv4 or IPv6). Chains VirusTotal, Shodan, AbuseIPDB, GreyNoise, OTX, and optionally Censys in parallel, then consolidates findings and prioritizes follow-up IOCs. Invoked by /cti-orchestrator when the target is an IP.

0
16
Free
Self-run
SKILL

Censys Api

Censys API v2 reference. Host reconnaissance and certificate data.

0
15
Free
Self-run
SKILL

Lookup Reversinglabs

Use when you need authoritative classification, threat-name, MITRE ATT&CK mapping, dynamic-analysis or sandbox results on a file hash, or when you need network threat intelligence for a URL/domain/IP from ReversingLabs Spectra Analyze (A1000). Returns verdict, risk score, AV detection ratio, threat name, behavioural tags, and pivot candidates (parent containers, extracted files, related samples b…

0
16
Free
Self-run
SKILL

Lookup Misp

Use when you need to query a MISP instance for existing events/attributes/objects, or push new intel into MISP — adding attributes to an event, creating an event, or uploading a STIX 2 bundle as one or more events. Two-way integration. Commonly invoked by /ip-investigation and friends to check whether an indicator is already known to your CTI sharing community, and by analytical skills that want…

0
16
Free
Self-run
SKILL

Ioc Enrichment Workflow

Workflow for enriching raw IOCs. Routes each IOC type to the appropriate /lookup-* skills, optionally correlates against MISP, and synthesises a single enrichment record per indicator. Use when the user has a batch of raw IOCs to process before triage or before pushing into a sharing platform.

0
14
Free
Self-run
SKILL

Phishing Social Engineering

Use when the user asks about phishing campaigns, social-engineering techniques, BEC (business email compromise), pretexting, AiTM (adversary-in-the-middle) kits, or specific phishing-kit families. Self-updating knowledge cell.

0
18
Free
Self-run
SKILL

Horizon Scanning

Use when the user asks "what is coming next?", wants strategic forecasting, or is hunting weak signals of emerging threats before they materialise. Covers signal identification, trend analysis, and scenario development.

0
15
Free
Self-run
SKILL

Abuseipdb Api

AbuseIPDB API reference. IP reputation and abuse report lookups.

0
18
Free
Self-run
SKILL

Likelihood Language

Use when phrasing a forward-looking statement, the user asks "how likely is X?" / "what's the likelihood?", or the tradecraft pipeline applies a probability yardstick to a finished product. Standardised likelihood language across all products.

0
12
Free
Self-run
SKILL

Intelligence Writing

Use when writing a finished intelligence product, the user asks for a flash-report / threat-assessment / briefing / FINTEL template, or wants the BLUF + active-voice + clear-sourcing conventions. Covers all product types.

0
16
Free
Self-run
SKILL

Malware Analysis

Use when characterising a malware sample, the user asks "what does this binary do?" / "analyse this hash deeply", or `/hash-investigation` flags a novel sample warranting deeper review. Static + dynamic methodology, behavioural indicators, sandbox interpretation.

0
18
Free
Self-run
SKILL

Indicator Pivoting

Indicator pivoting methodology — how to use one known indicator to discover related infrastructure across the IOC graph. Decision tree by indicator type with concrete `/lookup-*` commands per pivot, a worked multi-hop example, pivot-quality scoring, and routing into the rigor pipeline. Use when the user asks "what else is connected to this IP / domain / hash / cert / actor?", needs to expand a si…

0
19
Free
Self-run
SKILL

Pir Management

Use when the user asks to create, review, retire, or refine Priority Intelligence Requirements, or wants to align collection and analysis to the current PIR set. Covers the PIR lifecycle end-to-end.

0
16
Free
Self-run
SKILL

Lookup Crowdstrike

Use when you need CrowdStrike Falcon Intelligence on an indicator (IOC reputation for an IP, domain, hash, or URL — malicious confidence, linked actors, malware families, reports) OR on an adversary (threat-actor profile, origin/target search, MITRE ATT&CK TTPs, finished intel reports). Answers questions like "look up 1.1.1.1", "what TTPs does Charming Kitten use?", "which threat actors operate f…

0
18
Free
Self-run
SKILL

China Cyber Espionage

Use when the user asks about Chinese state-sponsored cyber operations or specific PRC-aligned actors (APT41, Volt Typhoon, Mustang Panda, APT10, APT31, Salt Typhoon, etc.), MSS/PLA-attributed campaigns, or PRC sector targeting. Self-updating knowledge cell.

0
16
Free
Self-run
SKILL

Hash Investigation

Use when a user asks to check, identify, or characterize a file hash (MD5, SHA-1, SHA-256). Chains VirusTotal and OTX, optionally triggers /malware-analysis for deeper behavioral review. Returns detection signals, malware family, behavioral tags, and pivot candidates (communicating IPs, dropped files). Invoked by /cti-orchestrator when the target is a hash.

0
19
Free