cyberspace-search

Automate cyberspace asset discovery and threat hunting across networks.

1|1|Updated Apr 25, 2026
One-click install
npx skills add https://github.com/chenchunrun/onyx-soc --skill cyberspace-search
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cyberspace-search
Source: https://github.com/chenchunrun/onyx-soc/tree/main/skills/cyberspace-search
Command: npx skills add https://github.com/chenchunrun/onyx-soc --skill cyberspace-search

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Cyberspace asset discovery and threat hunting across networks to identify mapped assets and potential threats, enabling proactive security posture and faster incident response.

Core Features & Use Cases

  • Asset discovery and mapping across IPs, domains, and C segments.
  • Threat hunting templates including dynamic DNS, C2 patterns, and risk scoring.
  • Supported workflows with MCP tools and references for deep-dive analysis.

Quick Start

Provide a target IP or domain to seed the cyberspace asset hunt and trigger automatic mapping and threat linkage.

Frequently Asked Questions about cyberspace-search

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate cyberspace asset discovery across IPs and domains?

Automate cyberspace asset discovery by providing a target IP or domain to trigger automatic mapping, C-segment analysis, and domain/IP correlation across networks. The workflow uses MCP tool integration to map assets and identify linked network segments.

What is cyberspace threat hunting and how does risk scoring work?

Cyberspace threat hunting identifies potential threats by applying dynamic DNS and C2 pattern templates to mapped assets. Risk scoring evaluates these correlated patterns against threat intel to generate structured risk signals for faster incident response.

Can I use this for C-segment analysis and threat intel cross-validation?

Yes, C-segment analysis and threat intel cross-validation are core supported workflows. The process correlates discovered assets across network segments and cross-validates findings against threat intelligence to uncover hidden linkages.

What's the best way to hunt for C2 patterns using domain and IP correlation?

Hunt for C2 patterns by seeding the search with a target domain or IP to initiate asset mapping. The workflow constructs standardized queries to correlate domains and IPs, matching results against threat templates to flag potential command and control infrastructure.

Do I need specific MCP tools to map assets across cyberspace?

Yes, MCP tool integration is enforced for standardized query construction and structured output. You provide the initial target, and the workflow leverages these tools to automate the deep-dive analysis and asset mapping.

Why should I use automated pattern correlation for network threat hunting?

Automated pattern correlation identifies mapped assets and potential threats across networks, enabling proactive security posture. It replaces manual checks with standardized queries and structured output with risk signaling for faster incident response.