Last commit on August 5, 2026·Created on April 6, 2026
7onez/cti-expert
“Turns a language model into a trained analyst for structured CTI and OSINT investigations.”
Combined rank
#306
across all skills
In Security
#17
category rank
Stars
440
+25.7% in last 7d
Forks
64
+18.5% in last 7d
Watchers
6
+20.0% in last 7d
Traction scoreGitHub stars can be faked, so popularity alone can be misleading. Traction Score looks for broader signs of real attention, adoption, and active maintenance.
This toolkit provides a framework for running cyber threat intelligence and open-source intelligence cases. It helps security researchers and forensic investigators move from raw data collection to analyst-grade intelligence products through a structured lifecycle of acquisition, enrichment, assessment, and delivery.
The skill specializes in web-infrastructure pivoting using favicon hashes and TLS certificates, infostealer-log triage, and regional reconnaissance including PRC corporate registries and ICP filings. It automates the recursive pivot loop, treating discovered identifiers as new seeds to expand investigation graphs until the frontier is exhausted.
WHO IT'S FOR
Threat Intelligence Analysts
running structured CTI and OSINT investigations
Digital Forensics and Incident Response (DFIR) teams
triaging infostealer logs and breach data
Security Researchers
performing web-infrastructure pivoting and reconnaissance