cti-expert

Automate cyber threat intelligence investigations using OSINT and forensic analysis.

3|1|Updated Dec 5, 2025
One-click install
npx skills add https://github.com/trungdo9/ClauKit --skill cti-expert-trungdo9
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cti-expert
Source: https://github.com/trungdo9/ClauKit/tree/main/skills/software/cti-expert
Command: npx skills add https://github.com/trungdo9/ClauKit --skill cti-expert-trungdo9

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

The cti-expert Skill solves the problem of conducting thorough cyber threat intelligence investigations, providing a comprehensive toolset for analyzing threat actors, reconstructing attack timelines, and mapping tactics, techniques, and procedures (TTPs).

Core Features & Use Cases

  • Threat Intelligence Investigations: Leverage OSINT and forensic analysis to investigate cyber threats.
  • Actor Profiling & Timeline Reconstruction: Build detailed profiles of threat actors and reconstruct attack timelines.
  • TTP Mapping & Indicator Extraction: Map observed behaviors to known TTPs and extract technical indicators of compromise.
  • Use Case: For instance, use this Skill to investigate a suspected breach by analyzing logs, reconstructing the timeline, and identifying TTPs associated with the attack.

Quick Start

To initiate an investigation, use the cti-expert Skill to analyze the log files from the recent security incident.

Frequently Asked Questions about cti-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I reconstruct an attack timeline from OSINT and forensic logs?

Reconstructing an attack timeline requires analyzing OSINT and forensic logs to profile threat actors and map their behaviors chronologically. This Skill automates that investigative process to build detailed timelines.

What is threat actor profiling in cyber threat intelligence investigations?

Threat actor profiling identifies and documents the motives, capabilities, and tactics of adversaries using OSINT and forensic analysis. This Skill automates profiling to support incident response and threat-informed defense operations.

How do I map observed behaviors to known TTPs during an incident response?

Mapping observed behaviors to TTPs involves correlating forensic analysis findings with known adversary tactics, techniques, and procedures. This Skill maps extracted indicators of compromise to standard TTPs for threat-informed defense.

Can I use forensic analysis to extract indicators of compromise from security incident logs?

Yes, forensic analysis can extract indicators of compromise from security incident logs. This Skill leverages OSINT and forensic data to identify technical indicators and map them to observed attack patterns.

Does this approach require raw log files to investigate a suspected breach?

Investigating a suspected breach requires log files from the security incident. This Skill analyzes those provided logs using OSINT and forensic techniques to reconstruct the timeline and identify associated TTPs.

What is the best way to automate cyber threat intelligence investigations?

Automating cyber threat intelligence investigations involves using OSINT and forensic analysis to profile actors, reconstruct timelines, and map TTPs. This Skill provides an automated toolset designed for incident response operations.

Related Skills