hacktivism

Identify and summarize hacktivist actors, TTPs, and geopolitical alignments.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill hacktivism
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hacktivism
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/hacktivism
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill hacktivism

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Provides a self-updating intelligence knowledge base on hacktivism to accelerate threat research and contextual understanding for security teams and researchers.

Core Features & Use Cases

  • Up-to-date profiles of key hacktivist groups (e.g., KillNet, NoName057(16), Anonymous Sudan, IT Army of Ukraine, Cyber Av3ngers).
  • Timelines of historical events, current activity snapshots, and evolving TTPs (DDoS, ICS targeting, data leaks).
  • Cross-referenced sources and risk-context to support briefing, attribution considerations, and strategic decision making.

Quick Start

Ask it for a current hacktivist profile or a summary of ongoing campaigns.

Frequently Asked Questions about hacktivism

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are the current TTPs of state-aligned hacktivist groups like KillNet and NoName057(16)?

State-aligned hacktivist groups like KillNet and NoName057(16) currently utilize DDoS attacks, data leaks, and ICS targeting. This Skill provides up-to-date profiles of these actors, summarizing their tactics, techniques, and procedures alongside geopolitical alignments.

How do I get an intelligence briefing on ongoing hacktivist campaigns and data leaks?

You can get an intelligence briefing on ongoing hacktivist campaigns by requesting a current campaign summary. The Skill generates concise, source-backed reports featuring attribution details, timelines, and risk assessments suitable for security briefing production.

Does this hacktivism intel cover threat groups targeting ICS infrastructure?

Yes, this hacktivism intel covers threat groups targeting ICS infrastructure. It specifically tracks actors like Cyber Av3ngers and tracks evolving patterns in ICS targeting, providing historical context from 2022 through 2025 for security teams.

Can I use this knowledge base for threat attribution of Anonymous Sudan and IT Army of Ukraine?

Yes, you can use this knowledge base for threat attribution considerations regarding Anonymous Sudan and IT Army of Ukraine. It cross-references sources and risk-context to support attribution analysis and strategic decision making for researchers.

What is the best way to research the geopolitical alignments of hacktivist actors from 2022 to 2025?

The best way to research the geopolitical alignments of hacktivist actors from 2022 to 2025 is using a self-updating knowledge base. This Skill identifies and summarizes actor alignments, providing historical context and ongoing campaign tracking for threat intelligence.

Are there limitations to using a self-updating hacktivism knowledge base for security operations?

A limitation of using this hacktivism knowledge base is that it provides concise summaries rather than raw data feeds. It is designed for accelerating threat research and contextual understanding, meaning security teams must still correlate reports with internal telemetry for operational defense.