CTI Expert — Cyber Threat Intelligence & OSINT analysis skill for Claude Code / Codex. 120+ commands, 57 techniques, 79 typed MCP tools, deterministic case pipeline + ICD-203 reports. No API keys required for core.
$ npx -y skills add 7onez/cti-expert --agent claude-code
Repo: 7onez/cti-expert
What's inside
Transform Claude into a trained intelligence analyst — 120+ commands, 57 techniques, zero API keys required for core functionality.
Built by Hieu Ngo • hieu.ngo@chongluadao.vn • chongluadao.vn Core contributor • Zeroska • khuong.nguyen@chongluadao.vn
CTI Expert is built in the open. These organisations back the work — with data, tooling, and hard-won investigative tradecraft.
| Supporter | What they bring | In the toolkit |
|---|---|---|
| Rexxfield | Cybercrime investigation and victim-side casework since 2008 — the real-world tradecraft the case workflow and attribution standards are modelled on | Tradecraft & methodology |
| ChongLuaDao ⭐ | First-party — the project's home org. Premium VN threat intel: ~20M-URL denylist verdicts, deep AI URL analysis, IoC + data-leak/breach exposure, brand lookalikes and CVE/KEV feeds — your client talks only to CLD, which fetches the target server-side (never your egress) | /cld · /scam-check · /threat-check · /breach-deep |
| Hudson Rock | Infostealer-infection intelligence — which machines leaked which credentials, and when | /breach-deep · /stealer-log |
| ParanoidLab | Dark-web, Initial-Access-Broker and infostealer-log monitoring across forums, markets and private Telegram | Dark-web collection & review |
| ANY.RUN | Interactive malware sandbox + TI Lookup — sandbox-observed C2 and real endpoints from packed samples | /binary · /hash-id |
| ZETAlytics | Global passive DNS with rare geographic diversity — historical resolution and co-tenancy pivots | /webpivot · /cti-pivot |
| IntelX | Intelligence X — paste sites, leaks, darknet and phonebook selector search | /webpivot · /email-deep |
| Shodan | Internet-connected host & service intelligence — open ports, banners, tags and known CVEs, passive-first via InternetDB | /webpivot · /appliance-scan · /cert-pivot |
| Censys | Internet-wide host & certificate scanning — the server-side view; every host on an exact leaf certificate (works on the free plan) | /censys · /cert-pivot |
| URLScan.io | Passive website scanning — what a page served and who it talked to, captured without touching the target | /webpivot · /impersonate |
| SerpApi | Search-engine + Google Ads Transparency results API — who paid to send traffic, plus multi-engine dork results | /serp · /search-pivot |
| GrayHatWarfare | Open cloud-bucket & exposed-file search (S3/Azure/GCS/Spaces) — graded exposure, not a same-operator pivot | /secrets · /docleak |
| Social Links | OSINT investigation platform — 1000+ methods across social media, blockchain and the dark web (SL Professional / Crimewall, Maltego transforms) | OSINT methodology & data |
| Validin | DNS + certificates + favicon + response-body hashes in one graph — passive DNS, subdomain enumeration, reverse-IP and host-response hash pivots on a free community key | Native in /webpivot (domain lookup, reputation, cert & favicon hosts) · MO-neighbour source · /cti-pivot |
| Netlas | Independent internet-asset index — DNS, scan responses, WHOIS and certificate collections behind one key; domains a:<origin-ip> reverses a non-CDN origin to every apex with dates | /webpivot MO-neighbour source · intel.py netlas · entitlement probe |
[!IMPORTANT] ANY.RUN lookups are read-only; detonation is gated.
anyrun_lookupqueries TI Lookup for hashes that have already been detonated.anyrun_submitcan detonate a file or URL, but only behind a per-submission analyst confirmation (a briefing-then-confirm=truetwo-step), private-by-default privacy withpublicrefused, a fail-closed plan check (the account's own/userprivate quota — zero is denied outright — else a prior private task, else an explicit analyst attestation to a paid plan), a post-submit privacy read-back that withdraws and flags a task that still landed public, and a harness deny unlessHARNESS_ALLOW_SUBMIT=1. A public sandbox task is world-readable and irreversible; the gate is enforced by a regression test (tests/test_no_sample_submission.py), not just by convention.
Listing here reflects support for the project and does not imply affiliation, endorsement, or any verification of this tool by the organisations named. Integrations marked above are optional and key-gated — every core technique still runs with zero API keys. Always respect each provider's terms of service. The full list of open-source projects and free public-interest services this skill depends on is in Acknowledgments & Credits.
A Claude Code skill that transforms Claude into a trained cyber threat intelligence and open-source intelligence analyst. It runs structured intelligence collection using 120+ commands across 57 techniques — no API keys required for core functionality. To take full advantage, add your own free or paid API keys to the skill's .env — each is auto-detected and unlocks higher-tier access (e.g., Wigle, VirusTotal, URLScan.io, Shodan, Censys, SecurityTrails, WhoisXML).
[!TIP] Keyless by default, more powerful with your keys. Every core technique runs with zero API keys. Add any free or paid keys to
.env(or run/apikeys set <service> <KEY>) and the skill auto-detects them, unlocking higher-tier pivots: reverse favicon→host, passive DNS, certificate search, sibling-domain discovery. A missing or bad key never breaks a run — it just degrades to a note. Setup guide: handbook/api-keys.md.
[!TIP] One skill, two layers. cti-expert is the broad collector — the wide net (
/sweep,/webpivot,/subdomain,/username,/email-deep…). Built into the repo is a deep pipeline (intel_engine/) that turns raw collection into a real case: a persistent knowledge base, versioned cases, cross-case correlation, and calibrated assessment. The flow reads like a sentence — collect broadly → "seen this operator before?" → cluster → filter false positives → assess. No external setup: the backend resolves toSELF, and as of v2.9 the bundled installer (scripts/install.{sh,ps1}) provisions the deep layer automatically (or by hand:uv venv && uv pip install -r requirements.txt). Architecture: connectors/intel-backend.md.
Core Capability
Multi-vector reconnaissance on any target type — person, domain, organization, username, email, IP, WiFi — with automated finding validation, exposure scoring, and structured intelligence delivery.
AEAD Workflow
Acquire raw data → Enrich with pivot expansion → Assess findings → Deliver structured reports — the base bundle (Markdown + JSON + CSV + IOC bundle) always saves, then you pick a presentation report: PDF, DOCX, HTML, or all.
| INTSUM Report | Network Topology | Risk Assessment |
|---|---|---|
FAQ
cti-expert is a Claude Code plugin with 1 hand-picked skill for security work, indexed on Flowy. Install it with the command on its page. It includes cti-expert. Its skills do not fire on their own yet. Request auto-invocation to have Flowy route them as you prompt. Free and open source.
Is this plugin yours?
Claim it with GitHubSubmit a pluginPromote it