tracking-threat-actor-infrastructure

mukul975/tracking-threat-actor-infrastructure · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Monitor and map adversary-controlled assets including C2 servers, phishing domains, and exploit kit hosts using passive DNS, certificate transparency logs, Shodan/Censys scanning, WHOIS analysis, and network fingerprinting.

SKILL.md

Files

This skill is a package of 8 files. Install with the command above, or download the folder.

Related

  1. collecting-open-source-intelligence · mukul975 bundle
    Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using passive reconnaissance tools and public data sources.
    24.6k
    repo stars
  2. building-adversary-infrastructure-tracking-system · mukul975 bundle
    Build an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS data, and IP enrichment to map and monitor threat actor command-and-control networks.
    24.6k
    repo stars
  3. implementing-attack-surface-management · mukul975 bundle
    Builds an external attack surface management (EASM) program using Shodan, Censys, and ProjectDiscovery tools for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring.
    24.6k
    repo stars
  4. performing-ioc-enrichment-automation · mukul975 bundle
    Automates multi-source enrichment of IPs, domains, URLs, and file hashes using VirusTotal, AbuseIPDB, Shodan, GreyNoise, URLScan.io, and MISP to provide contextual risk scoring and disposition recommendations for SOC analysts.
    24.6k
    repo stars
  5. performing-ip-reputation-analysis-with-shodan · mukul975 bundle
    Enrich IP addresses with Shodan API data to identify open ports, running services, known vulnerabilities, and hosting context for threat intelligence and incident triage.
    24.6k
    repo stars
  6. performing-open-source-intelligence-gathering · mukul975 bundle
    Collects publicly available information about a target organization to identify attack surfaces, social engineering targets, technology stacks, and credential exposures for authorized security testing.
    24.6k
    repo stars

Frequently asked questions

How do I install the tracking-threat-actor-infrastructure skill?

Run npx skillmds add mukul975/tracking-threat-actor-infrastructure in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the tracking-threat-actor-infrastructure skill do?

Monitor and map adversary-controlled assets including C2 servers, phishing domains, and exploit kit hosts using passive DNS, certificate transparency logs, Shodan/Censys scanning, WHOIS analysis, and network fingerprinting. It is listed under Security on SkillMD.

Is tracking-threat-actor-infrastructure safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with tracking-threat-actor-infrastructure?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is tracking-threat-actor-infrastructure free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published tracking-threat-actor-infrastructure?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.