deep-research-offensive

Analyze CVEs, research exploits, and synthesize threat intelligence from live web sources.

15|1|Updated Feb 12, 2026
One-click install
npx skills add https://github.com/AeonDave/malskill --skill deep-research-offensive
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: deep-research-offensive
Source: https://github.com/AeonDave/malskill/tree/main/knowledge/deep-research-offensive
Command: npx skills add https://github.com/AeonDave/malskill --skill deep-research-offensive

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill streamlines the complex and time-consuming process of offensive security research, enabling faster and more thorough analysis of vulnerabilities, exploits, and threat intelligence.

Core Features & Use Cases

  • CVE Analysis: Deep dive into CVE details, including CVSS scores, affected versions, and exploitability.
  • Exploit Research: Discover Proof-of-Concept (PoC) code and active exploitation details across multiple platforms.
  • Threat Intelligence Synthesis: Gather real-time information on threats, malware, and attack campaigns from diverse sources like X/Twitter and Telegram.
  • Use Case: When a new critical CVE is announced, use this Skill to quickly gather its NVD details, find public PoCs on GitHub and Exploit-DB, check CISA's KEV catalog, and monitor X/Twitter for real-world exploitation discussions.

Quick Start

Use the deep-research-offensive skill to research CVE-2023-12345 by finding its NVD details and any available exploit PoCs.

Frequently Asked Questions about deep-research-offensive

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I research a CVE and find public exploit PoCs?

To research a CVE and find public proof-of-concept exploits, you need to gather NVD details and scan platforms like GitHub and Exploit-DB. This Skill automates that CVE analysis by extracting CVSS scores, affected versions, and discovering public PoC code.

What is the best way to gather threat intelligence for red team planning?

Gathering threat intelligence for red team planning requires synthesizing real-time data on malware and attack campaigns. This Skill automates intelligence synthesis by leveraging live web sources like X and Telegram to collect and analyze real-world exploitation discussions.

How does OSINT vulnerability research handle CISA's KEV catalog checks?

OSINT vulnerability research handles CISA's KEV catalog checks by cross-referencing newly announced critical CVEs against actively exploited vulnerabilities. This Skill streamlines checking the KEV catalog alongside gathering NVD details and monitoring social media.

Can I use Playwright and Firecrawl to automate live web source threat intelligence gathering?

Yes, you can use Playwright and Firecrawl to automate live web source threat intelligence gathering. This Skill leverages these MCP tools alongside Tavily to perform comprehensive data gathering and analysis from diverse, real-time platforms.

Does this offensive security research approach require manual browsing of Exploit-DB?

No, this offensive security research approach does not require manual browsing of Exploit-DB. It automates discovering active exploitation details and PoC code across multiple platforms, streamlining the time-consuming process of vulnerability assessment.