A comprehensive OSINT and cyber threat intelligence skill for Claude that transforms it into an intelligence analyst using 74+ commands and 40 techniques. It performs multi-vector reconnaissance on targets including domains, IPs, organizations, and people, with support for specialized workflows like China-focused attribution, cryptocurrency tracking, and structured report generation—all without requiring API keys for core functionality.
CTI Expert — Cyber Threat Intelligence & OSINT analysis skill for Claude Code. 67+ commands, 35 techniques, no API keys required.
At a glance
README
CTI Expert
Cyber Threat Intelligence & OSINT Analysis Toolkit
Transform Claude into a trained intelligence analyst — 74+ commands, 49 techniques, zero API keys required for core functionality.
Built by Hieu Ngo • [email protected] • chongluadao.vn
🤝 Sponsors & Supporters
CTI Expert is built in the open. These organisations back the work — with data, tooling, and hard-won investigative tradecraft.
| Supporter | What they bring | In the toolkit |
|---|---|---|
| Rexxfield | Cybercrime investigation and victim-side casework since 2008 — the real-world tradecraft the case workflow and attribution standards are modelled on | Tradecraft & methodology |
| Hudson Rock | Infostealer-infection intelligence — which machines leaked which credentials, and when | /breach-deep · /stealer-log |
| ParanoidLab | Dark-web, Initial-Access-Broker and infostealer-log monitoring across forums, markets and private Telegram | Dark-web collection & review |
| ANY.RUN | Interactive malware sandbox + TI Lookup — sandbox-observed C2 and real endpoints from packed samples | /binary · /hash-id |
| ZETAlytics | Global passive DNS with rare geographic diversity — historical resolution and co-tenancy pivots | /webpivot · /cti-pivot |
| IntelX | Intelligence X — paste sites, leaks, darknet and phonebook selector search | /webpivot · /email-deep |
[!IMPORTANT] ANY.RUN is used read-only.
anyrun_lookupqueries TI Lookup for hashes that have already been detonated. This skill never submits a sample — a public sandbox task is world-readable and irreversible. That boundary is enforced by a regression test (tests/test_no_sample_submission.py), not just by convention.
Listing here reflects support for the project and does not imply affiliation, endorsement, or any verification of this tool by the organisations named. Integrations marked above are optional and key-gated — every core technique still runs with zero API keys. Always respect each provider's terms of service. The full list of open-source projects and free public-interest services this skill depends on is in Acknowledgments & Credits.
What is CTI Expert?
A Claude Code skill that transforms Claude into a trained cyber threat intelligence and open-source intelligence analyst. It runs structured intelligence collection using 74+ commands across 49 techniques — no API keys required for core functionality. To take full advantage, add your own free or paid API keys to the skill's .env — each is auto-detected and unlocks higher-tier access (e.g., Wigle, VirusTotal, URLScan.io, Shodan, Censys, SecurityTrails, WhoisXML).
[!TIP] Keyless by default, more powerful with your keys. Every core technique runs with zero API keys. Add any free or paid keys to
.env(or run/apikeys set <service> <KEY>) and the skill auto-detects them, unlocking higher-tier pivots: reverse favicon→host, passive DNS, certificate search, sibling-domain discovery. A missing or bad key never breaks a run — it just degrades to a note. Setup guide: handbook/api-keys.md.
[!TIP] One skill, two layers. cti-expert is the broad collector — the wide net (
/sweep,/webpivot,/subdomain,/username,/email-deep…). Built into the repo is a deep pipeline (intel_engine/) that turns raw collection into a real case: a persistent knowledge base, versioned cases, cross-case correlation, and calibrated assessment. The flow reads like a sentence — collect broadly → "seen this operator before?" → cluster → filter false positives → assess. No external setup: the backend resolves toSELF; install the deep-layer deps once withuv venv && uv pip install -r requirements.txt. Architecture: connectors/intel-backend.md.
Core Capability
Multi-vector reconnaissance on any target type — person, domain, organization, username, email, IP, WiFi — with automated finding validation, exposure scoring, and structured intelligence delivery.
AEAD Workflow
Acquire raw data → Enrich with pivot expansion → Assess findings → Deliver structured reports (interactive HTML + Markdown + JSON/CSV + IOC bundle; Word on request).
Demo
Full Case Investigation
CTI Report Generation
Screenshots
| INTSUM Report | Network Topology | Risk Assessment |
|---|---|---|
What's New in v2.8
The release where the engine caught up and the safety rails moved to where the harness can see them. v2.7 landed the deep pipeline. v2.8 brings the vendored engine ~30 commits forward — 24 → 46 MCP tools, a new engagement skill, and a case loop that runs to convergence — and then fixes the layer underneath it: two safety properties were being enforced at a moment Claude Code never reaches. Both now fire where the work actually happens.
| Category | What's New | Details |
|---|---|---|
| Engine sync — 24 → 46 MCP tools | A three-way merge, not a copy — and that distinction is the whole story | The vendored intel_engine/ was ~30 commits behind. Rather than trust a remembered list of local patches, every vendored file was classified by blob identity against all upstream history: 114 pure copies, 15 deliberately patched, 6 cti-expert-only. A plain rsync would have silently reverted three real behaviours — wp_common's extra .env depth (cti-expert nests one level deeper, so upstream's version resolves every API key to empty, and a keyless run then reports "no siblings" as a fact about the operator), pivot_extract's reverse-WHOIS-on default, and the collect_core single-sourcing — plus destroyed email_permute and turned three RULE 4 shims back into copies. 48 → 69 CLI ops, all resolving |
| Engage — the authentication surface | Find the login; then, only on explicit confirmation, get inside | Detection is passive and free: locate the login form, the password field and the registration page, and classify by FIELDS rather than by label — a confirm-password means register, an invite code is a pivot, not an OTP. Beyond that, engage_account creates a synthetic-persona account and reads the members area the public page hides (panel, deposit/withdraw flow, affiliate tree, support handles). It refuses a non-synthetic persona, refuses direct egress, and stops at a CAPTCHA. Account creation is outbound, attributable and irreversible — gated exactly like a sandbox submission |
| The case loop | Judge the cluster, not the case — and run to convergence, not to an arbitrary depth | /clusters partitions a case into same-operator components before anything is judged, showing each binding indicator's KB-wide prevalence — so an indicator that binds 3 domains here but sits on 400 KB-wide reads as noise, not an owner link. /frontier reports the unresolved gaps: free next seeds already discovered, plus the deferred metered leads held for approval. /loop runs collect → assess until the case converges; /reopen re-opens a converged case on new seeds; /scope derives the intake — no-touch class, victim ownership, egress gate — up front instead of assuming it mid-run |
| Six new collection layers | Each one closes a specific way the old answer was wrong | /liveness — a 200 parking/default/suspended/soft-404 page is not live and a 404/403/bot-wall is not dead; only NXDOMAIN reports dead, and every still-controlled name sets reuse_watch. /pssl — passive SSL runs the historical cert → IP direction that recovers an origin from behind a CDN, with the base-rate rail that keeps a shared CDN certificate (915 addresses in live measurement) out of the clustering. /paths — the URL path as an indicator (path_kit:) for an operator who rotates hosts and selects the template by directory; a generic path emits nothing. /serp — Ads Transparency identifies who paid (a verified, billed advertiser), with a cloaking probe that has a falsification control. /docmeta — PDF /Info + XMP, EXIF incl. GPS, PNG chunks. /victims — infer the access vector from the victim set |
| RULE 1 now fires at write time | The leak gate was enforced at a moment an agent harness rarely reaches | leakcheck.sh ran only as a git pre-commit hook. Claude Code writes files continuously and commits rarely, so a leaked indicator could sit in the working tree all session — and git commit --no-verify skips the gate outright. hooks/leakguard.py moves the check to PreToolUse on Write/Edit, where that flag does not exist. It does not reimplement the patterns — it shells out to leakcheck.sh, because a second copy would drift and a drifted guard reports clean. Scope is narrow on purpose: it denies only inside a cti-expert checkout on a path git does not ignore, so writing case data into intel_engine/cases/ — the correct thing to do — is never blocked |
| The outbound gates moved above the vendored code | A gate only a bad merge stands between is not a gate | submit() refuses without confirm=True; the Engage tools refuse a non-synthetic persona. Those gates are real — and they live in intel_engine/, which is vendored. Re-syncing it is a three-way merge over ~150 files where a deliberate local behaviour is reverted silently; three such reversions were caught by hand in this very release. hooks/actionguard.py sits above the tools, in cti-expert's own tree, and fires on the tool name. It returns ask with a risk briefing, never a hard block — a rail you must disable to work is a rail that gets disabled. Dual-mode tools gate on the flag, not the tool: ordinary collection is silent, only --submit prompts |
| The stale-MCP failure has a name now | A session was driving a four-week-old tool surface with no error anywhere | Claude Code resolves an MCP server's tool list when it connects and keeps it for the session. A session was found holding 17 tools while the engine on disk served 46 — and nothing said so; the model simply never saw the new tools and worked around their absence. hooks/sessionguard.py reports the resolved backend tier at SessionStart and warns when the @tool count has changed since last session, which is precisely when a cached registration went stale |
| Installable as a Claude Code plugin | Skill + commands + MCP + hooks as one unit | register.sh symlinks the skill, the commands and the MCP server — but it cannot install hooks, and that is where the two rails above live. .claude-plugin/plugin.json bundles all four: /plugin marketplace add <clone> then /plugin install cti-expert. Hook paths use exec form with ${CLAUDE_PLUGIN_ROOT}, so nothing is hardcoded to one machine and no path is shell-parsed. Both PreToolUse hooks fail open — a hook bug must never brick your repo; audit.sh and the git pre-commit hook remain the backstop |
| The OPSEC gate was met, not relaxed | Upstream grew a submission path, so the test had to be satisfied honestly | ANY.RUN's API is mostly a submission API, and the upstream engine added a gated path to it — which failed tests/test_no_sample_submission.py, by design. The fix was not to weaken the assertion: the REQUIRES_ANALYST_CONFIRMATION marker was placed on submit() itself, the four submission-lifecycle endpoints were listed explicitly (an unreviewed new key still fails), and the test now demands the marker and the refusal it claims — so the marker cannot decay into a magic string. Verified by planting each failure: remove the marker → fail; remove the refusal → fail; restore → pass |
| The re-sync procedure was the one that breaks the repo | Documented advice that fails silently is worse than none | STRUCTURE.md told the next person to "copy into intel_engine/, then re-apply the 5 shims". That is wrong, and its failure has no error message: the collectors keep running, they just stop finding things. It now documents the procedure that holds — classify by blob identity, three-way merge off the minimum-distance base, check for the duplicate @tool blocks a stale base produces — plus the zsh word-splitting trap that turns an unquoted rsync exclude list into no exclusions at all. The vendored engine's own 17 gates now ship and run alongside cti-expert's 6, and audit.sh gained a check that every path hooks.json registers still resolves, because a renamed script disables its hook silently |
What's New in v2.7
The release where the deep pipeline landed. v2.6 sharpened the collector. v2.7 makes cti-expert a two-layer system — a broad collector plus a built-in, self-contained intelligence pipeline with a persistent knowledge base — reachable from a cold prompt by one command, and guarded by a gate that checks the repo against its own rules on every push.
| Category | What's New | Details |
|---|---|---|
| One skill, two layers | The deep pipeline is now built in — no external backend to stand up | intel_engine/ vendors the whole Collect → Correlate → Assess pipeline: a persistent knowledge base, versioned cases, cross-case correlation, calibrated assessment and rendering (WebPivot · IntelAnalysis · IntelGraph · IntelReport · BinaryPivot). /backend resolves to SELF — nothing to configure, nothing to host. Install the deep-layer deps once with uv venv && uv pip install -r requirements.txt. The tree regrouped from 22 top-level directories to 14 behind a single SKILL.md. See STRUCTURE.md |
| 8 registered commands | /cti works from a cold prompt, in any project |
Commands used to require the skill be loaded first. scripts/register.sh symlinks the skill and commands/*.md into ~/.claude/ and writes the per-machine .mcp.json, so /cti, /cti-recall, /cti-case, /cti-pivot, /cti-cluster, /cti-check, /cti-report and /cti-status are available immediately. There is now one command to remember — /cti <target> — which routes by target type (domain · IP · email · username · phone · wallet · hash · APK) and runs the right chain. Everything else remains a convention command |
--deep is genuinely parallel |
Sub-agent fan-out on both collection and assessment | /cti --deep spawns one sub-agent per discovered frontier seed — pruned through recall and false-positive control first, ≤6 concurrent, depth-capped at 2 hops, with --passive propagating to every child — then converges them into one case. New here: when convergence yields 2+ clusters, the Assess phase fans out too, one agent per cluster (ACH, confidence, risk, scoped to that cluster), while the cross-cluster judgment stays central in the orchestrator. Breadth in parallel; synthesis in one place |
| IntelX + ANY.RUN | Leak/darknet selector search and sandbox-observed C2 — with the evidence graded, not merged | intelx_search reaches pastes, stealer logs, darknet and historical WHOIS. Critically, hits are graded: a breach-corpus or stealer-log sighting is exposure evidence and explicitly not clusterable — two addresses in one combolist share a victim pool, not an operator. Soft selectors are refused locally so a vague name never burns a query unit. anyrun_lookup answers what samples carrying an indicator actually did — the real endpoints a packed binary contacts — and is read-only: this skill never submits a sample, enforced by tests/test_no_sample_submission.py |
| Evidence archiving was silently off | The wrapper was dropping 22 flags, including --archive-missing |
The vendored engine had been left half-migrated — the modular wp_* layer was in place but the live collector was still the pre-split 2,274-line monolith, so the harness's --help probe filtered out flags the collector no longer advertised. Evidence archiving was therefore not running at all. collect_core now drops zero flags and the supported surface went 19 → 42. Dropped flags remain visible in the tool result by design: a silent drop is precisely the failure mode this class of bug hides in |
| Keyless answers stay honest | Capability accounting — an absent key is never reported as a finding | wp_capabilities names the evidence class each missing key costs, so a keyless run that finds no siblings reports "not queried" — never "no siblings exist." Shipping alongside it: Censys (keyless CenQL builder, free-plan lookups, monthly credit guard), asset discovery (JS bundles, source maps, SPA routes, well-known files), impersonation hunting, JARM TLS-stack fingerprinting, and a multi-engine search_pivot. Every denylist, provider registry and permutation table moved out of code into analyst-tunable references/*.json |
| Nothing dead-ends | Six identifier types were classified but had no pivot | The spider-map recognised document, image, youtube_channel, coordinates, vin and ipv6 — then silently stopped on them. Now wired: documents → exiftool + oletools authorship → person/email/org; images → EXIF GPS → coordinates, with reverse-image and face search graded LOW and held pending corroboration, never an auto-merge; YouTube channels → about-panel links; coordinates and VIN enrich only, deliberately producing no new seed, so they cannot invent a false attribution; IPv6 → reverse/passive DNS + ASN, mirroring IPv4. Kept fixed by an invariant test: every classifiable type must have at least one pivot |
| The repo checks itself | audit.sh + CI + a pre-commit leak scan |
scripts/audit.sh is the gate: every DISPATCH op resolves to a real script, all five shared collectors are one canonical file + one re-export shim, the @tool count matches the contributor rules, modules byte-compile, tests pass. It runs in GitHub Actions on every push and PR, scanning only the PR's added lines so curated example values are never re-flagged. scripts/install-hooks.sh wires the identifier leak scan as a pre-commit hook. Five zero-dependency suites ship with it — collection core, indicator classification, the false-positive ledger, no-sample-submission, and email-candidate containment |
| Every collection turn leads with a table | Scannable yield, before the prose | Collection surfaced results only in prose plus the durable file exports; nothing guaranteed a per-domain summary in the conversation itself. A new output rule puts a markdown table first on every collection turn — Resolves · Top pivots · Risk · Cluster · Seen-before — so you see the yield at a glance instead of reading for it |
| Portable & framework-free | No assistant-framework coupling left in the skill | The mandatory voice-notification block is gone and the customization directory moved from a framework-specific path to a neutral ~/.config/cti-expert/ (repo/cwd .env still wins). Also in this release: a Sponsors & Supporters section — Rexxfield · Hudson Rock · ParanoidLab · ANY.RUN · ZETAlytics · IntelX — and the workflow diagrams rebuilt as SVG, including a new end-to-end tool-and-skill sequence diagram |
What's New in v2.6
| Category | What's New | Details |
|---|---|---|
/case runs unattended |
Pivot loop defaults to autonomy=auto; the new recon commands auto-fire |
The spider-map now expands to closure without approval prompts — the confidence gate, not a human prompt, is what keeps expansion tight (exact-match links auto-pursue, weak links held, dedup + depth caps unchanged). Depth summaries still print, so the run stays auditable. And the v2.6 recon commands are in the pipeline with no flags: /icp on every domain/URL/org target, /cn-corp on any company name or USCC found, /iban on any payment detail, /hash-id on every hash (before /hash) — and all three discovery-driven ones feed their yields back into the loop as new seeds. /redact stays opt-in (--redact): a redacted report is a weaker artifact, so producing one should be a deliberate call. Narrow with --checkpoint, --no-cn, --reach balanced|focused, --depth N |
| China / Sinophone recon | /icp + /cn-corp — the attribution layer Western registries can't reach |
ICP filing (工信部备案) maps a domain to its registered PRC entity, and the licence serial reverse-pivots to every sibling site under the same filing — a same-operator link as strong as a shared GA ID. Then the registry chain: GSXT (ground truth) → TianYanCha/QCC/Aiqicha → 信用中国 blacklist → UBO, with USCC validation and revoked-status flags. Adds Quake (360) and ZoomEye as independent cyberspace indexes, a Baidu tier for /dork-sweep (tiers 1–4 index almost no CN content), and CJK variant generation — pinyin, Simplified↔Traditional and company-name stems — as a new /pivot-suggest axis. See techniques/china-recon.md |
| Fiat payment rails | /iban — bank accounts become selectors, like wallets already were |
Most victims never touch crypto — they make a bank transfer. iban_analyze.py runs ISO 7064 mod-97 validation (proving a "bank account" on a payment page is fabricated without contacting anyone), decomposes the BBAN into bank/branch/account, and flags jurisdiction mismatch — the classic beneficiary-abroad mule pattern. Validated accounts export as financial/iban IOCs; invalid ones are recorded as behavioural findings. Covers VN/SEA non-IBAN rails too: VietQR/NAPAS BIN, card BIN, e-wallets, BIC. See techniques/fiat-payment-osint.md |
| Shareable reports | /redact — reversible PII redaction |
redact.py replaces PII with stable numbered placeholders ([EMAIL_1] means one address across the whole case) and writes a reversible JSON map, so a report can leave the organisation and still be reconstituted for evidence. Handles .md/.json/.csv; round-trip is byte-exact. Infrastructure is not redacted by default — in a CTI report the actor's domains are the analysis, not incidental PII |
| Analytic rigor | Probability-anchored likelihood + 5W1H + ACH | Judgments now carry likelihood terms with probability bands (almost no chance → almost certain) reported alongside evidence confidence, because "MODERATE" alone means a 30-point-different thing to writer and reader. /coverage gains a 5W1H pass — a technique matrix measures effort, so a case could score 96% while answering no Why or How. /threat-model now requires an ACH matrix for attribution: rival hypotheses scored by inconsistency, runner-up named, and the evidence that would change the ranking stated. See handbook/analytic-standards.md |
| Hash typing | /hash-id — before any hash lookup |
32 hex is MD5 or NTLM — one is a file hash, the other is credential material, and querying the wrong service returns a confident "unknown sample" that reads as exculpatory. Routes file hashes to MalwareBazaar/VT and credential hashes to /breach-deep, never a public cracking service |
What's New in v2.5
| Category | What's New | Details |
|---|---|---|
| Recursive pivoting | /case is a spider-map — expands the whole network |
/case now runs a recursive BFS pivot engine (pivot_orchestrator.py + engine/pivot-orchestration.md): every discovered identifier (email/domain/IP/username/wallet/…) becomes a new seed and the relationship graph expands hop-by-hop until the frontier is exhausted. Confidence-gated (exact-match links auto-pursue, weak/PII links held), cycle-safe (dedup + depth caps), with per-depth checkpoints. Defaults: active · exhaustive · checkpoint-per-depth |
| Archive IOC harvest | /webpivot --harvest — every selector the site ever exposed |
wayback_harvest.py runs the full extractor over a domain's entire Wayback history, merging emails, phones, crypto wallets, tracking/verification IDs, SaaS-operator IDs and socials with first-seen/last-seen — recovering selectors a network later scrubbed. Emits case-schema indicators[] straight into the IOC bundle; auto-runs in /case for domain/URL targets. /webpivot now also extracts phone numbers (tel: + formatted) as ranked pivot leads |
| Archive access | Fetch archived pages Claude Code's WebFetch can't reach | WebFetch is blocked from web.archive.org (robots.txt at the fetch layer). wayback_fetch.py routes around it — CDX lookup → nearest-snapshot resolve → raw id_ fetch, with retry/backoff (--near, --list, --url-only, --json) |
| Web pivoting | /webpivot — map the infra behind a page |
Favicon mmh3, GA/GTM/AdSense IDs, wallets & SaaS-operator tokens from a page's DOM → ranked pivots; same-operator correlation via /rank-relations (weighted scoring + noise denylist), /cert-pivot, /pivot-suggest, /crypto-balance, /email-hygiene, /sensitive-paths. Auto-runs in /case for domain/URL targets |
| Keyless by default | 100% free — no key, no signup | crt.sh (certificate transparency) + passive DNS + anonymous urlscan always run; full pivoting at zero cost, nothing to configure |
| Premium auto-detect | Drop in a key → it upgrades itself | /webpivot auto-detects any premium key you've set (Shodan, Censys, FOFA, DNSLytics, SecurityTrails, urlscan-PRO, WhoisXML) and unlocks its higher tier — no flag, no re-run; a missing/bad key degrades to a note, never breaks the run. Manage keys with /apikeys |
| Attack surface | /appliance-scan — edge/VPN appliance → KEV mapping |
Passive-first fingerprint of internet-facing Citrix/F5/Cisco/Ivanti/Forti/Palo Alto/Exchange appliances (Shodan InternetDB/Censys) → matched CISA KEV/CVE list; feeds /vuln-check + /threat-model |
| Identity fabric | /saas-map — SaaS tenancy + IdP surface |
DNS-TXT tenancy tokens (Google/Atlassian/Zscaler/Salesforce/Workday…), non-Microsoft IdP fingerprint (Okta/Auth0/OneLogin/Ping/Keycloak/ADFS), unauthenticated API/GraphQL/OpenAPI-spec discovery |
| Credentials | Read-only liveness validation | A discovered key is confirmed live via identity-only endpoints (AWS STS, GitHub scopes, Slack auth.test, …/v1/models) — never a mutating call — upgrading it to CRITICAL with account/scope evidence |
| Integrity | Evidence-gated analysis | every asserted claim cites a resolvable finding; untrusted collected data is tagged, never executed |
| Recon | Native asn command |
Keyless IP/ASN/domain lookups (ipwho.is + RDAP) on Windows; full nitefood/asn auto-installed on Linux/macOS/WSL |
| System tools | whois + dig + asn auto-install on Windows |
winget Microsoft.Sysinternals.Whois + ISC.Bind; previously manual steps |
| Reliability | Windows PowerShell 5.1 hardening | Fixes native-stderr script aborts, the OSArchitecture probe crash, and maigret via uv tool --force; installs clean on WinPS 5.1 |
| Packaging | Auto-PATH for CLI tools | ~/.local/bin (uv tools + asn) added to PATH automatically — current session and persistent |
What's New in v2.4
| Category | What's New | Details |
|---|---|---|
| Platform | Cross-platform OS detection (Windows/macOS/Linux) | OS-aware auto-install; self-healing DOCX (UTF-8 + auto-located pandoc) |
| Packaging | uv-first toolchain | uv venv / uv pip / uv tool; PEP 723 uv run zero-setup scripts; pip/pipx/venv fallback |
| Portability | Cross-agent support | Runs in Claude Code and OpenAI Codex via AGENTS.md + a ready-to-copy /cti-expert Codex prompt |
| CTI | Infostealer-log analyzer (/stealer-log) |
Family ID, victim-vs-operator profiling, cross-log actor correlation, IOC + raw-artifact extraction |
| Recon | Admin / sensitive-endpoint detection | Subdomain-prefix + path + CJK classifier (admin, adm, kef, ador, panel…) |
| Collection | agent-browser integration | Primary interactive browser (vercel-labs): CDP, accessibility-tree snapshots, screenshots; complementary to Scrapling, no API key for core |
| Reliability | Fresh-VPS install hardening + CI | root/sudo + prereq bootstrap; smoke test + GitHub Actions on a minimal root Ubuntu container |
What's New in v2.3
| Category | What's New | Details |
|---|---|---|
| WHOIS | Universal WHOIS for all TLDs | whoisdomain + CLI + Whoxy API; .vn, .th, .sg, .kr, 27+ ccTLD servers |
| WHOIS | Reverse & historical WHOIS (free) | Whoxy reverse API, historical lookup, ViewDNS |
| Web Collection | Scrapling adaptive scraping | 3-tier: static → anti-bot → JS rendering; headless auto-open |
| Web Collection | Headless browser auto-open default | JS-heavy sites auto-detected and rendered via DynamicFetcher |
| Orchestration | AgentFlow parallel enrichment | DAG-based parallel pivot expansion for 3+ subjects |
| Performance | HTML parsing ~2ms | Scrapling parser replaces slow HTTP scraping |
| Platform | Python 3.10+ minimum | Required by Scrapling and AgentFlow |
What's New in v2.2
| Category | What's New | Details |
|---|---|---|
| Image Forensics | Face search, reverse image, manipulation detection, AI geolocation | FaceCheck.id, TinEye, FotoForensics, Forensically, picarta.ai, GeoSpy, Pic2Map |
| Blockchain | Crypto wallet tracing, transaction graphs, scam detection | Blockchair, Etherscan, WalletExplorer, OXT.me, Chainabuse, Breadcrumbs |
| Transport | Aircraft tracking (unfiltered), vessel AIS, vehicle VIN lookup | ADS-B Exchange, Flightradar24, Marine Traffic, VesselFinder, NICB VINCheck |
| Darknet | Tor search, ransomware monitoring, onion service discovery | Ahmia.fi, onionsearch, DarknetLive, ransomwatch |
| Social Media | Reddit, Instagram, TikTok, Telegram investigation | Osintgram, instaloader, toutatis, RedditMetis, TGStat, TelegramDB, Bellingcat TikTok Timestamp |
| People Search | US people search engines, free reverse lookups | TruePeopleSearch, FastPeopleSearch, IDCrawl, That's Them |
| Mega-Dorks | 11 cross-platform Google dork templates covering 73 unique domains | Social, Telegram ecosystem, dev platforms, forums, paste sites, darknet, breach DBs, business, image, messaging, jobs |
| IoT | Webcam directories, IoT device search | Insecam, Thingful |
| Category | New Commands | What It Does |
|---|---|---|
| Intelligence | /render threat-path, /render attack-surface |
Attack path flow + infrastructure exposure visualization |
| Intelligence | /snapshots, /diff |
Wayback Machine snapshots and version diffing |
| Intelligence | /drift, /report ioc |
Temporal risk tracking + IOC export (STIX 2.1) |
| UX | /onboard, /clarify, /quality |
First-time tutorial, finding explanation, quality scoring |
| UX | /blind-spots, /source-check |
Gap analysis + batch URL verification |
| UX | /workspace diff |
Compare two saved investigation sessions |
| Data Model | Source Reliability A-F | Complements trust scores with source-level grading |
| Data Model | 4 new entity types | Device, Image, Crypto Address, Custom |
| Data Model | HIGH conflict severity | 4-level severity: CRITICAL/HIGH/NOTABLE/MINOR |
Installation
Recommended: Use Claude Code CLI — it gives you the full terminal workflow, persistent sessions, and direct skill invocation. Download here or run
npm install -g @anthropic-ai/claude-code.
Why Claude Code CLI?
The entire CTI Expert workflow is optimized for Claude Code CLI. The CLI gives you:
- Persistent sessions — investigations survive terminal restarts via
/workspace save - Full tool access — file writes, Python scripts, DOCX generation, all run natively
- Skill invocation — type
/cti-expertdirectly in the terminal, no browser required - Background agents — parallel enrichment via AgentFlow works best with the CLI
🖥️ Where to run it — the CLI is best for this skill
[!IMPORTANT] CTI Expert is execution-heavy: it runs
uv/Python, installs OSINT tools, writes.md/.html/.json/.csvreports + IOC bundles, reaches many external sites, and saves case workspaces. What matters is a real local shell + persistent files + open network — a CLI or local desktop agent gives you that; an ep
1 skill in this repo
Copy into ~/.claude/skillsCyber threat intelligence and OSINT analysis toolkit. Runs structured investigations and delivers analyst-grade intelligence products with sourced, trust-scored findings. Use for OSINT and CTI cases, digital-footprint and exposure review, d...
git clone --depth 1 https://github.com/7onez/cti-expert
cp -r cti-expert/ ~/.claude/skills/cti-expert
Comments (0)
Sign in to join the discussion.
No comments yet
Be the first to share your take.