Cti Setup
Use when the user wants to configure API keys for the CTI skills pack, asks "how do I set up keys", "configure VirusTotal", "add my Shodan key", or runs /cti-setup. Walks through API key configuration inside Claude Code without needing to run a shell script. Also handles re-running setup, adding individual keys, and verifying that configured keys work.
Dprk Cyber Espionage
Use when the user asks about North Korean state-sponsored cyber operations or specific DPRK actors (Lazarus, APT38, BlueNoroff, Andariel, Kimsuky, etc.), revenue-generation campaigns, IT-worker schemes, or DPRK targeting of cryptocurrency / supply chain. Self-updating knowledge cell.
Feedback Loops
Feedback loop implementation for continuous CTI improvement. Consumer feedback, analyst retrospectives, source quality tracking.
Lookup Abuseipdb
Use when you need abuse-report history for an IPv4/IPv6 address — confidence score, total reports, distinct reporters, usage type. IP-only. Commonly invoked by /ip-investigation. Retrieval only.
Mitre Attack
MITRE ATT&CK local dataset reference. Query techniques, groups, software, and mitigations from the local enterprise-attack.json.
Ioc Export
IOC export formats and procedures. CSV, STIX 2.1, OpenIOC, MISP. Handles format conversion and packaging.
Kql Writing
Use when the user asks for a KQL query, a Microsoft Sentinel / Defender / Azure Log Analytics detection or hunt, or wants to translate a finding from `/hash-investigation` / `/malware-analysis` into KQL. Format spec + writing guide.
Lookup Shodan
Use when you need host reconnaissance for an IP or domain — open ports, services, banners, OS detection, vulnerabilities. For domains, resolves DNS first then queries the IP. Commonly invoked by /ip-investigation and /domain-investigation. Retrieval only.
Lookup Urlscan
Use when you need to submit a URL for live scanning via URLScan.io and retrieve results, or search existing scans for a domain. Returns verdict, final URL after redirects, resolved IP, contacted domains/IPs, and screenshot URL. Commonly invoked by /url-investigation and /domain-investigation.
Greynoise Api
GreyNoise API reference. Internet scanner/noise classification for IPs.
Lookup Greynoise
Use when you need to classify an IP as internet scanner noise vs. targeted activity. Returns noise/riot flags, classification (benign/malicious/unknown), actor name if known. IP-only. Commonly invoked by /ip-investigation to filter out mass-scanning noise. Retrieval only.
Lookup Opencti
Use when you need to query an OpenCTI instance — is this IOC already known, what entities/reports/campaigns exist for an actor — or push new intel into it — creating indicators/observables, labelling, TLP markings, relationships, or importing a STIX 2.1 bundle. Two-way integration. Commonly invoked by /ip-investigation and friends to check whether an indicator is already in your knowledge base, a…
Ach
Analysis of Competing Hypotheses — structured technique for evaluating multiple explanations against evidence. Use when facing ambiguous attribution or multiple plausible scenarios.
Cti Orchestrator
Use as the default entry point for any CTI request that doesn't name a specific skill. Activates when a user asks to investigate an indicator, profile a threat actor, write an assessment, enrich IOCs, or build detection rules. Routes to the right investigation or analysis skill, then auto-applies rigor skills (source rating, TLP, confidence, likelihood) on the output.
Intelligence Sharing
Use when the user asks about ISAC participation, TAXII feeds, MISP communities, FIRST, STIX-based sharing, or how to publish intelligence externally. Covers sharing models, standards, communities, and TLP-governed dissemination.
Carding Financial Fraud
Use when the user asks about carding, BIN attacks, payment-card breach markets, fullz/CVV2 trade, autoshops (BidenCash, Brian's Club, Russianmarket, B1ack's Stash), or financial-fraud TTPs. Self-updating knowledge cell.
Lookup Censys
Use when you need deep host + certificate reconnaissance for an IP or need to run a Censys search query. Returns services, TLS certificates, ASN, and location. Free tier is severely limited (250 queries/month) — use sparingly. Retrieval only.
Darkweb Collection
Dark web intelligence collection methodology — vendor-first access posture, sourced reference lists for 35+ underground forums and 30+ Telegram channels, OPSEC primer, passive-monitoring strategy, and bundled Python CLIs for onion-indexer search, Telegram channel monitoring, and local keyword matching. Use when the user wants to design or run dark-web collection, build a selector list, pick a ven…
Otx Api
AlienVault OTX API reference. Community threat intelligence pulses and indicator lookups.
Confidence Levels
Use when assigning a confidence level to an analytical judgment, the user asks "how confident are we?" / "what is the confidence on X?", or the orchestrator's tradecraft pipeline calls for a confidence level before publishing. Provides the MISP 0-100 scale and qualitative-band mapping.
Lookup Otx
Use when you need to check an IP, domain, file hash, or URL against AlienVault OTX community pulses. Returns pulse count, key pulses, tags, related indicators, and passive DNS. Commonly invoked by investigation skills to pull community context. Retrieval only — does not interpret.
Lookup Ransomwarelive
Use when you need to check whether an organisation/domain has been claimed by a ransomware group, profile a specific ransomware group (TTPs, leak-site infra, IOCs, YARA), or aggregate ransomware victim claims by country/sector/timeframe. Backed by ransomware.live's leak-site scrapes — 27k+ victims across 330+ groups. Commonly invoked by /domain-investigation, /ransomware-ecosystem, /threat-actor-…
Infostealers
Use when the user asks about infostealer families (LummaC2, RedLine, Vidar, Stealc, Raccoon, Rhadamanthys, etc.), log marketplaces (Russian Market, Genesis successors, BidenCash, Hudson Rock corpus), or stealer-driven incidents and credential exposure. Self-updating knowledge cell.
Maturity Assessment
Use when assessing the maturity of a CTI programme, the user asks "how mature is our CTI?" / "what should we improve next?", or wants a benchmark against the five-level model across six dimensions.
Osint Methodology
Structured OSINT collection methodology. Planning, collection techniques, search operators, and documentation. Loaded by the osint-researcher agent.
Key Assumptions Check
Use when surfacing the assumptions underlying an analytical judgment, the user asks "what are we assuming?" / "are these assumptions still valid?", or before publishing a high-impact assessment. Standard SAT applied during major assessments.
Hacktivism
Use when the user asks about hacktivist activity (Killnet, NoName057(16), IT Army of Ukraine, Anonymous Sudan, RipperSec, CARR, etc.), DDoS-claiming groups, politically-motivated cyber operations, or wartime cyber-ops chatter. Self-updating knowledge cell.
Crowdstrike Api
CrowdStrike Falcon Intelligence (Intel API) reference. OAuth2 auth, Falcon Query Language, indicator (IOC) lookups, threat-actor entities, intel reports, MITRE ATT&CK mappings, malware families, vulnerabilities, rule sets.
Lookup Virustotal
Use when you need to check an IP, domain, file hash, or URL against VirusTotal's reputation database. Returns detection ratio, verdict, community score, and key findings. Commonly invoked by investigation skills (/ip-investigation, /domain-investigation, /hash-investigation, /url-investigation) and by analysts enriching IOCs. Other agents/skills can chain this for VirusTotal enrichment.
Iran Cyber Espionage
Use when the user asks about Iranian state-sponsored cyber operations or specific IRGC/MOIS-aligned actors (APT35/Charming Kitten, APT34/OilRig, MuddyWater, Imperial Kitten, etc.), wiper campaigns, or front-group hacktivist clusters (Predatory Sparrow, Handala). Self-updating knowledge cell.
Initial Access Brokers
Use when the user asks about initial access brokers (IABs), the access-listing market, ransomware-feeding-IAB pipelines, specific broker handles, or how access is priced and packaged. Self-updating knowledge cell.
Campaign Tracking
Use when documenting a named campaign across time and victims, the user asks to start or update a campaign record, or another skill identified a multi-incident cluster that warrants formal tracking. Provides the template (timeline, attribution, victimology, attack chain, Diamond Model mapping, IOC clusters) and the lifecycle from active to historical.
Cti Hyperloop
Use when the user asks about the CTI Hyperloop framework, the intelligence lifecycle as a high-tempo loop, or how to map intelligence work across strategic / operational / tactical levels with bidirectional feedback. Liberty91's operational doctrine.
Domain Investigation
Use when a user asks to investigate, check, or characterize a domain or hostname. Chains VirusTotal, URLScan (search existing scans), Shodan (DNS resolve + host), OTX, ransomware.live (victim-status sweep), and optionally Censys. Returns reputation, resolution, hosting fingerprint, ransomware-claim status, and pivot candidates. Invoked by /cti-orchestrator when the target is a domain.
Ip Investigation
Use when a user asks to investigate, check, enrich, or characterize an IP address (IPv4 or IPv6). Chains VirusTotal, Shodan, AbuseIPDB, GreyNoise, OTX, and optionally Censys in parallel, then consolidates findings and prioritizes follow-up IOCs. Invoked by /cti-orchestrator when the target is an IP.
Censys Api
Censys API v2 reference. Host reconnaissance and certificate data.
Lookup Reversinglabs
Use when you need authoritative classification, threat-name, MITRE ATT&CK mapping, dynamic-analysis or sandbox results on a file hash, or when you need network threat intelligence for a URL/domain/IP from ReversingLabs Spectra Analyze (A1000). Returns verdict, risk score, AV detection ratio, threat name, behavioural tags, and pivot candidates (parent containers, extracted files, related samples b…
Lookup Misp
Use when you need to query a MISP instance for existing events/attributes/objects, or push new intel into MISP — adding attributes to an event, creating an event, or uploading a STIX 2 bundle as one or more events. Two-way integration. Commonly invoked by /ip-investigation and friends to check whether an indicator is already known to your CTI sharing community, and by analytical skills that want…
Ioc Enrichment Workflow
Workflow for enriching raw IOCs. Routes each IOC type to the appropriate /lookup-* skills, optionally correlates against MISP, and synthesises a single enrichment record per indicator. Use when the user has a batch of raw IOCs to process before triage or before pushing into a sharing platform.
Phishing Social Engineering
Use when the user asks about phishing campaigns, social-engineering techniques, BEC (business email compromise), pretexting, AiTM (adversary-in-the-middle) kits, or specific phishing-kit families. Self-updating knowledge cell.
Horizon Scanning
Use when the user asks "what is coming next?", wants strategic forecasting, or is hunting weak signals of emerging threats before they materialise. Covers signal identification, trend analysis, and scenario development.
Abuseipdb Api
AbuseIPDB API reference. IP reputation and abuse report lookups.
Likelihood Language
Use when phrasing a forward-looking statement, the user asks "how likely is X?" / "what's the likelihood?", or the tradecraft pipeline applies a probability yardstick to a finished product. Standardised likelihood language across all products.
Intelligence Writing
Use when writing a finished intelligence product, the user asks for a flash-report / threat-assessment / briefing / FINTEL template, or wants the BLUF + active-voice + clear-sourcing conventions. Covers all product types.
Malware Analysis
Use when characterising a malware sample, the user asks "what does this binary do?" / "analyse this hash deeply", or `/hash-investigation` flags a novel sample warranting deeper review. Static + dynamic methodology, behavioural indicators, sandbox interpretation.
Indicator Pivoting
Indicator pivoting methodology — how to use one known indicator to discover related infrastructure across the IOC graph. Decision tree by indicator type with concrete `/lookup-*` commands per pivot, a worked multi-hop example, pivot-quality scoring, and routing into the rigor pipeline. Use when the user asks "what else is connected to this IP / domain / hash / cert / actor?", needs to expand a si…
Pir Management
Use when the user asks to create, review, retire, or refine Priority Intelligence Requirements, or wants to align collection and analysis to the current PIR set. Covers the PIR lifecycle end-to-end.
Lookup Crowdstrike
Use when you need CrowdStrike Falcon Intelligence on an indicator (IOC reputation for an IP, domain, hash, or URL — malicious confidence, linked actors, malware families, reports) OR on an adversary (threat-actor profile, origin/target search, MITRE ATT&CK TTPs, finished intel reports). Answers questions like "look up 1.1.1.1", "what TTPs does Charming Kitten use?", "which threat actors operate f…
China Cyber Espionage
Use when the user asks about Chinese state-sponsored cyber operations or specific PRC-aligned actors (APT41, Volt Typhoon, Mustang Panda, APT10, APT31, Salt Typhoon, etc.), MSS/PLA-attributed campaigns, or PRC sector targeting. Self-updating knowledge cell.
Hash Investigation
Use when a user asks to check, identify, or characterize a file hash (MD5, SHA-1, SHA-256). Chains VirusTotal and OTX, optionally triggers /malware-analysis for deeper behavioral review. Returns detection signals, malware family, behavioral tags, and pivot candidates (communicating IPs, dropped files). Invoked by /cti-orchestrator when the target is a hash.