Skip to content
Security
Command

/cti-cluster

Expand and correlate an existing case — peers, shared indicators, TLS overlap, reverse-WHOIS. Usage: /cti-cluster <domain|CASE-ID>

From plugin
cti-expert
4448 skills8 commands
Install
$ npx -y skills add 7onez/cti-expert --agent claude-code

How it fires

How this command gets triggered: by you, by Claude, or both.

  • Fires itselfClaude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/cti-cluster

Context preview

What this command does when you run it.

Expand and correlate an existing case — peers, shared indicators, TLS overlap, reverse-WHOIS. Usage: /cti-cluster <domain|CASE-ID>

Command definition

cti-cluster.md
name: cti-cluster
description: "Expand and correlate an existing case — peers, shared indicators, TLS overlap, reverse-WHOIS. Usage: /cti-cluster <domain|CASE-ID>"
argument-hint: "<domain|CASE-ID>"

/cti-cluster — correlate and expand

Load the `cti-expert` skill, then expand: `$ARGUMENTS`

Work **down** the SKILL.md §2.5 priority ladder — highest-strength evidence first:

| Rung | Check | Call | |---|---|---| | 1–2 | registrant email/phone/org, incl. **historic** WHOIS; alias bridges | `intel.py whois` · `reverse-whois` | | 3 | site-verification tokens (proves account control) | in `shared.txt` | | 4 | TLS cert / SAN overlap | `mcp__intel__cert_overlap` | | 5 | nameserver delegation to a **self-hosted** NS | in `shared.txt` | | 7 | favicon / tracker / tenant IDs | `mcp__intel__kb_cluster` | | 8–10 | co-tenancy, managed-provider NS, site kit | weak — corroborate or demote |

**Reverse-WHOIS is the highest-yield pivot here — always `mode=preview` first.** The count is free; a term returning hundreds is shared boilerplate and must not be purchased or clustered on.

Run `/cti-check` on every indicator before it becomes an edge. Report each asserted link with the rung it rests on, so a reader can weigh it.

Ships withcti-expert

CTI Expert — Cyber Threat Intelligence & OSINT analysis skill for Claude Code. 67+ commands, 35 techniques, no API keys required.

Get the whole plugin