Osint Methodology
elementalsouls/Claude-OSINT
Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.
Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and…
$ npx skills add trilwu/secskills --skill producing-threat-intelligence -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills producing-threat-intelligence --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-defense/skills/producing-threat-intelligence .claude/skills/producing-threat-intelligence && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "producing-threat-intelligence" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/producing-threat-intelligence into .claude/skills/producing-threat-intelligence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "producing-threat-intelligence", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/producing-threat-intelligenceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill producing-threat-intelligence -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills producing-threat-intelligence --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-defense/skills/producing-threat-intelligence .agents/skills/producing-threat-intelligence && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "producing-threat-intelligence" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/producing-threat-intelligence into .agents/skills/producing-threat-intelligence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "producing-threat-intelligence", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill producing-threat-intelligence -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills producing-threat-intelligence --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-defense/skills/producing-threat-intelligence .cursor/skills/producing-threat-intelligence && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "producing-threat-intelligence" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/producing-threat-intelligence into .cursor/skills/producing-threat-intelligence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "producing-threat-intelligence", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-defense/skills/producing-threat-intelligence--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill producing-threat-intelligence -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills producing-threat-intelligence --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-defense/skills/producing-threat-intelligence .gemini/skills/producing-threat-intelligence && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "producing-threat-intelligence" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/producing-threat-intelligence into .gemini/skills/producing-threat-intelligence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "producing-threat-intelligence", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills producing-threat-intelligenceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill producing-threat-intelligence -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-defense/skills/producing-threat-intelligence .github/skills/producing-threat-intelligence && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "producing-threat-intelligence" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/producing-threat-intelligence into .github/skills/producing-threat-intelligence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "producing-threat-intelligence", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill producing-threat-intelligence -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills producing-threat-intelligence --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-defense/skills/producing-threat-intelligence .opencode/skills/producing-threat-intelligence && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "producing-threat-intelligence" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/producing-threat-intelligence into .opencode/skills/producing-threat-intelligence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "producing-threat-intelligence", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
producing-threat-intelligenceProduce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and…
Producing Threat Intelligence is an agent skill from trilwu/secskills. Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and analytic confidence, and packaging finished intel products tied to a consumer's decision. Covers the intelligence lifecycle, the Diamond Model and Pyramid of Pain, STIX/MISP/OpenCTI storage, TLP sharing, and passive enrichment via passive DNS, crt.sh, Shodan, Censys, GreyNoise, and VirusTotal. Use when pivoting from a…
Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering OSINT and Threat modeling. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curljqFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
crt.shdefuddle.mdFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Producing Threat Intelligence loads about 4.4k tokens when it runs. Until then it costs about 204 tokens; SKILL.md has 2,138 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 2,138 words, ~4,357 tokens.
.claude/skills/producing-threat-intelligence/SKILL.md (or your agent's skills folder).Intelligence is not a pile of indicators — it is analysis that reduces a decision-maker's uncertainty. An IOC with no context, no confidence, and no recommended action is data, not intelligence. Attribution is a claim you must be able to defend from evidence, not a guess dressed in a threat-actor name. The test of a finished product is simple: did someone decide something differently because of it?
hunting-threatsanalyzing-malwaremapping-attack-techniquesresponding-to-incidentsengineering-detectionsEvery product moves through the same loop. Naming the stages is not bureaucracy — it is where you catch the two failures that make CTI worthless.
1. Direction — whose decision, which question (a PIR)
2. Collection — gather against the requirement, not everything reachable
3. Processing — normalize, deduplicate, translate, enrich
4. Analysis — assess, weigh hypotheses, assign confidence
5. Dissemination — deliver in a form the consumer can act on
6. Feedback — did it help; refine the next requirementThe two failures that account for most wasted CTI effort are at the ends of the loop, not the middle:
Write the PIR before collecting. Examples: "Which ransomware crews target our sector and what is their initial-access tradecraft?" "Is the actor in last week's incident likely to return?" "Does this vendor report describe a threat to us?" Each names a consumer and a decision.
Pivoting expands one observable into an infrastructure picture. The discipline is to stay passive first — every pivot below reads third-party data or historical records, none of it touches the adversary's live infrastructure.
| Start from | Pivot via | Finds |
|---|---|---|
| Domain / IP | Passive DNS (PDNS) | Historical resolutions, sibling domains on an IP, IPs a domain used |
| Domain | WHOIS / registration history | Registrant email, registrar, creation date, name-server reuse |
| Domain / IP | Certificate transparency (crt.sh) | Other hostnames on the same cert, SAN reuse, issuance timeline |
| IP / service | TLS fingerprints — JARM (server), JA3/JA3S (client/server handshake) | Hosts running the same C2 or framework default TLS stack |
| Web service | Favicon hash (Shodan http.favicon.hash, Censys) | Other servers serving the identical panel or login page |
| IP / host | Shodan / Censys banners | Open ports, product versions, response bodies, self-signed cert CNs |
A worked pivot chain: a phishing domain resolves (PDNS) to an IP; crt.sh shows the cert's SANs cover four more lookalike domains; the IP's JARM matches a known Cobalt Strike default; Shodan's favicon hash for the panel returns nine more IPs serving the same interface. One indicator became a cluster of ten, none of which required contacting the adversary.
# Certificate transparency — all certs/SANs seen for a domain
curl -s "https://crt.sh/?q=%25.example.com&output=json" | jq -r '.[].name_value' | sort -u
# Shodan: everything serving an identical favicon
shodan search "http.favicon.hash:-247388890"
# Censys: hosts presenting a given JARM fingerprint.
# Censys Platform (CenQL) prefixes every parsed field with its dataset:
censys search "host.services.jarm.fingerprint: <jarm_hash>"
# Legacy Search used the unprefixed form below. It is deprecated as of
# September 2026, so treat any older query you find as needing conversion:
# services.jarm.fingerprint: <jarm_hash>Do not tip off the adversary. Do not curl the live C2, resolve its domain from a network attributable to you, submit the still-active sample to a public multi-scanner, or scan the infrastructure directly — each of those tells the operator you are watching and invites rotation or a burn of your visibility. Prefer passive datasets. If active interaction is genuinely required, route it through infrastructure that is not attributable to you and make it a deliberate, logged decision.
Every intrusion event has four connected features: adversary, capability (malware, tooling, exploits), infrastructure (C2, staging, redirectors), and victim. Any feature leads to another — a capability points to the adversary who wields it; infrastructure points to other victims. Pivoting is literally traversing the edges of the diamond. Record findings against these four vertices so a partial picture composes with the next one.
Not all indicators cost the adversary the same to change. The higher you track, the more it hurts them and the longer your intelligence survives.
TTPs ← hardest to change — track these
Tools
Network/Host artifacts
Domain names
IP addresses
Hash values ← trivial to change — useful now, dead tomorrowHashes and IPs are cheap for the adversary to rotate, so intelligence built on them decays in days. Tooling and TTPs force real redevelopment. Prioritize collection and tracking toward the top of the pyramid; treat the bottom as perishable and time-stamp it accordingly.
Attribution is the most abused word in CTI. Keep two operations strictly separate:
Use temporary, non-committal labels for clusters you have not confirmed:
UNC-style uncategorized designators, or your own internal CLUSTER-####. Only
promote a cluster to a named actor when the evidence supports it, and state
what evidence. "Same TTPs" is weak grounds: shared tooling, shared exploit
kits, and public tradecraft mean two operators can look identical.
Analytic confidence is a separate axis from the claim. State it explicitly:
Confidence is not the same as how strongly you feel it. It is a function of the evidence and the number of surviving alternative explanations.
Analysis of Competing Hypotheses (ACH): when attribution or intent is contested, enumerate the plausible hypotheses first, then list the evidence, and score each item by how well it is consistent with each hypothesis. The goal is to find evidence that disconfirms — the hypothesis left standing after you try to break it is stronger than the one you set out to prove.
Cognitive-bias traps to name and resist:
Free-text notes do not compose, correlate, or feed automation. Store intelligence in a structured model from the start.
indicator, malware, threat-actor, campaign, intrusion-set,
infrastructure, identity, and attack-pattern; relationships (SROs)
like uses, targets, indicates, attributed-to connect them. A STIX
indicator carries a pattern, valid-from/until, and confidence — context
the bare IOC lacks.Enrichment converts a bare observable into something with context and confidence. Match the source to the question.
| Source | Answers |
|---|---|
| VirusTotal | Detections, relationships (contacted domains, dropped files, siblings), first/last seen, community context |
| Passive DNS (Farsight/DNSDB, SecurityTrails, Circl) | Resolution history, co-hosted domains, infrastructure reuse over time |
| Shodan / Censys | Exposed services, banners, certs, JARM, favicon hashes — the internet-facing view without touching the target directly |
| GreyNoise | Whether an IP is mass-scanning the whole internet (background noise) versus activity aimed at you |
| URLScan | What a URL actually serves — page content, redirects, resources, screenshot — without you browsing it |
GreyNoise earns its place by subtraction. Most flagged IPs are internet background radiation — opportunistic scanners hitting everyone. GreyNoise tells you whether an indicator is that noise or something targeted, so you stop burning analyst hours enriching a Shodan crawler and focus on what is aimed at your organization.
The report is the product; everything upstream is inventory. Structure it for a decision-maker, not for an analyst admiring the work.
Write to the audience: an executive needs the risk and the decision; a SOC lead needs the detections and the pivots. The same underlying intelligence becomes two different products.
Threat intelligence is not a terminal deliverable — it is the fuel for the rest of the defensive program, and it consumes their output in return.
engineering-detections. Hand over behaviors and tiered indicators, not a
raw feed.hunting-threats run against your telemetry.mapping-attack-techniques so your products speak the same taxonomy as
detection and hunting, and coverage gaps become visible.Intelligence that does not flow into detection, hunting, or a decision is a research hobby, not a capability.
Fetch public advisories, specifications, and vendor reports as Markdown:
curl -sL "https://defuddle.md/<url>" # scheme in the path is optionalThis strips page boilerplate — roughly 78% fewer tokens on a prose page — and returns the full text rather than a summary, so you can grep it and trust a negative result.
Three things it is not for. Fetch JSON and API responses raw, because readability extraction mangles structured data. Fetch authenticated or JavaScript-rendered pages directly, because it retrieves them anonymously. And never route adversary infrastructure (phishing links, C2, malware hosting), client-owned hosts, or engagement URLs through it — the request leaves your machine to a third party, and for live adversary infrastructure it also tips off the operator.
Some sites block the extractor and return an error blob rather than the page —
{"error":"Failed to fetch: 418 I'm a teapot"} from freedesktop.org, for
instance. That is the fetch being refused, not the source saying the thing
does not exist. Re-fetch the URL directly before drawing any conclusion from
it.
hunting-threats — running intel-derived hypotheses against your own
telemetryanalyzing-malware — sample-derived config, capability, and IOCs that feed
intelengineering-detections — converting tracked TTPs into deployed rulesmapping-attack-techniques — resolving and standardizing ATT&CK referencesresponding-to-incidents — the consumer and source during an active eventreporting-security-findings — structure and language for the finished
written product© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-defense/skills/producing-threat-intelligence of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Producing Threat Intelligence next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Producing Threat Intelligence this skilltrilwu/secskills | 157 | — | ~4.4k | Automated safety check: Pass | MIT | |
| Osint Methodologyelementalsouls/Claude-OSINT | 2.8k | — | ~8.7k | Automated safety check: Notes | MIT | |
| Analysing Attacktsale/awesome-dfir-skills | 323 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Implementing Attack Surface Managementmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Recon Osinthypnguyen1209/offensive-claude | 388 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Wiki ReconEncod3d-Sec/TORCH | 329 | — | ~1.3k | Automated safety check: Pass | MIT |
elementalsouls/Claude-OSINT
Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.
tsale/awesome-dfir-skills
Analyse Mitre ATT&CK tactics, techniques and sub-techniques.
mukul975/Anthropic-Cybersecurity-Skills
Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting…
hypnguyen1209/offensive-claude
A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…
Encod3d-Sec/TORCH
External recon and OSINT pipeline - subdomain enum, live host discovery, URL crawl, JS analysis, nuclei scan.
penpot/penpot
Hardens code against vulnerabilities. An agent skill from penpot/penpot.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Categories
Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and…. Producing Threat Intelligence is an agent skill from trilwu/secskills. Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and analytic confidence, and packaging finished intel products tied to a consumer's decision.
Producing Threat Intelligence fits situations like: pivoting from a domain; certificate to related infrastructure; tracking a threat actor; enriching raw indicators.
Run `npx skills add trilwu/secskills --skill producing-threat-intelligence -a claude-code`. Or copy the skill folder (secskills-defense/skills/producing-threat-intelligence in trilwu/secskills) into .claude/skills/producing-threat-intelligence in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill producing-threat-intelligence -a codex`. Or copy the skill folder (secskills-defense/skills/producing-threat-intelligence in trilwu/secskills) into .agents/skills/producing-threat-intelligence in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill producing-threat-intelligence -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/producing-threat-intelligence, .gemini/skills/producing-threat-intelligence, .github/skills/producing-threat-intelligence and .opencode/skills/producing-threat-intelligence in your project.
Going by SKILL.md and its folder, Producing Threat Intelligence needs the command-line tools its instructions call (curl and jq).
SKILL.md names 2 domains. In commands or code: crt.sh and defuddle.md; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Producing Threat Intelligence is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.4k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Producing Threat Intelligence: Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars), Analysing Attack (tsale/awesome-dfir-skills, 323 stars), Implementing Attack Surface Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Recon Osint (hypnguyen1209/offensive-claude, 388 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.