threat-intelligence
Installation
SKILL.md
Threat Intelligence & Public-Source OSINT
When to Use
- Enriching indicators or profiling a threat actor from public data.
- Investigating impersonation or scam infrastructure.
适用范围
- 用公开来源补充域名、IP、URL、哈希、邮箱或钱包地址等 IOC。
- 追踪公开披露的恶意活动、钓鱼活动、仿冒账号与诈骗叙事。
- 从公开 X/Twitter 帖子发现线索,并交给样本、网络或厂商来源核验。
- 为
threat-hunting/、malware-analysis/、email-security/或digital-forensics/准备情报包。
本 Skill 不处理品牌营销、舆情增长、自动发帖或无安全目的的社交分析。