cti-domain-research

Conduct structured web searches across curated security domains for CTI research.

63|6|Updated Mar 8, 2026
One-click install
npx skills add https://github.com/Security-Phoenix-demo/security-skills-claude-code --skill cti-domain-research
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cti-domain-research
Source: https://github.com/Security-Phoenix-demo/security-skills-claude-code/tree/main/skills/cti-search-skill
Command: npx skills add https://github.com/Security-Phoenix-demo/security-skills-claude-code --skill cti-domain-research

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires search-api-key, claude-code, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill solves the problem of efficiently researching cyber threat intelligence across multiple security domains, saving time and ensuring comprehensive coverage.

Core Features & Use Cases

  • Structured CTI Search: Conduct structured searches across 300+ curated security domains.
  • Domain Tiering: Prioritize searches based on domain authority for authoritative, vendor, news, and specialized sources.
  • Output Customization: Choose from concise briefs, detailed reports, or raw JSON output.
  • NotebookLM Integration: Optionally push research findings directly into NotebookLM for further analysis.

Quick Start

Use the cti-search command to search for information on a CVE: /cti-search CVE-2024-21762.

Frequently Asked Questions about cti-domain-research

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I gather cyber threat intelligence from curated security domains?

You can gather cyber threat intelligence by running structured web searches across 300+ curated security domains, which prioritizes authority-based domain tiers to find CVE, threat actor, and malware information. It outputs results as CTI briefs, detailed reports, or raw JSON.

What is the best way to search for CVE details across authoritative security sources?

Searching for CVE details across authoritative sources is best done using a structured search command that queries 300+ curated security domains, prioritizing authority-based domain tiers to deliver relevant threat intelligence directly as briefs or raw JSON data.

Do I need a search API key to research threat actors and malware?

Yes, researching threat actors and malware requires a search API key and Claude Code with WebSearch and Bash tools. These dependencies enable the structured searches across curated security domains needed for comprehensive threat intelligence.

Can I export cyber threat intelligence reports to NotebookLM?

Yes, you can optionally integrate with NotebookLM to push cyber threat intelligence research findings directly into the platform for further analysis and research management after generating your reports or briefs.

How does domain tiering work for security research?

Domain tiering for security research works by prioritizing searches based on domain authority, separating authoritative, vendor, news, and specialized sources to ensure the most credible threat intelligence is surfaced first during your structured searches.

Related Skills