Metabigor OSINT Recon
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis.
$ npx skills add tsale/awesome-dfir-skills --skill admiralty-system -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install tsale/awesome-dfir-skills admiralty-system --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/analysis/admiralty-system-tr .claude/skills/admiralty-system && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "admiralty-system" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/admiralty-system-tr into .claude/skills/admiralty-system/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admiralty-system", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/admiralty-system-trType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add tsale/awesome-dfir-skills --skill admiralty-system -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install tsale/awesome-dfir-skills admiralty-system --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/analysis/admiralty-system-tr .agents/skills/admiralty-system && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "admiralty-system" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/admiralty-system-tr into .agents/skills/admiralty-system/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admiralty-system", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tsale/awesome-dfir-skills --skill admiralty-system -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install tsale/awesome-dfir-skills admiralty-system --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/analysis/admiralty-system-tr .cursor/skills/admiralty-system && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "admiralty-system" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/admiralty-system-tr into .cursor/skills/admiralty-system/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admiralty-system", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/tsale/awesome-dfir-skills.git --path skills/analysis/admiralty-system-tr--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add tsale/awesome-dfir-skills --skill admiralty-system -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install tsale/awesome-dfir-skills admiralty-system --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/analysis/admiralty-system-tr .gemini/skills/admiralty-system && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "admiralty-system" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/admiralty-system-tr into .gemini/skills/admiralty-system/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admiralty-system", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install tsale/awesome-dfir-skills admiralty-systemInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add tsale/awesome-dfir-skills --skill admiralty-system -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/analysis/admiralty-system-tr .github/skills/admiralty-system && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "admiralty-system" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/admiralty-system-tr into .github/skills/admiralty-system/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admiralty-system", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tsale/awesome-dfir-skills --skill admiralty-system -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install tsale/awesome-dfir-skills admiralty-system --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/analysis/admiralty-system-tr .opencode/skills/admiralty-system && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "admiralty-system" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/admiralty-system-tr into .opencode/skills/admiralty-system/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admiralty-system", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
admiralty-systemApply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis.
Admiralty System is an agent skill from tsale/awesome-dfir-skills. Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis. Use this skill whenever you need to evaluate a CTI report, breach claim, dark web forum post, threat actor advertisement, vendor blog, social media intel claim, leaked database listing, or any source plus information pair where trust matters. Trigger phrases include "assess this source", "rate this report", "is this breach real", "evaluate credibility"…
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files and assets (for example `references/edge-cases.md`).
It sits in Security, covering OSINT. The repository describes itself as: A curated collection of DFIR skills and workflows for InfoSec practitioners. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 6e52942. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Admiralty System loads about 3.4k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 245 tokens; SKILL.md has 1,736 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from tsale/awesome-dfir-skills at commit 6e52942, republished under its Apache-2.0 licence (© tsale). 1,736 words, ~3,357 tokens.
.claude/skills/admiralty-system/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.The Admiralty System (NATO AJP-2.1) is the gold standard for assessing intelligence. The British Royal Navy developed it in the early 20th century. NATO intelligence communities now use it worldwide, and it is gaining ground in cyber threat intelligence.
It rates two things, separately:
The combined output is an alphanumeric code such as A1, B3, F6.
This is the single most common mistake. A source who is reliable on malware analysis is not automatically reliable on geopolitics. A piece of information can be true from a sketchy source, or false from a usually reliable one. Always rate them independently, never in lockstep.
Second common mistake: confusing "two vendors reported it" with two independent sources. If both vendors pull from the same original dataset (the same breach forum post, the same scan, the same leak), that is ONE source. Independent corroboration means independent collection.
| Code | Label | Use when |
|---|---|---|
| A | Completely Reliable | Source has consistently delivered accurate information over a long history on this specific topic. Reserve this rating; it is rare. |
| B | Usually Reliable | Source has a strong track record with only minor lapses on this topic |
| C | Fairly Reliable | Source has produced accurate information before but the track record is shorter or mixed |
| D | Not Usually Reliable | Source has been wrong more often than right, but cannot be fully dismissed |
| E | Unreliable | Source has a clear history of inaccuracy, deception, or manipulation |
| F | Reliability Cannot be Judged | New source, no track record, or insufficient access to assess |
Attributes to weigh:
| Code | Label | Use when |
|---|---|---|
| 1 | Confirmed by Other Sources | Information is corroborated by multiple genuinely independent sources |
| 2 | Probably True | Logical, consistent with known facts, and partly corroborated |
| 3 | Possibly True | Logical and plausible but not independently confirmed |
| 4 | Doubtful | Possible but unconfirmed and partly inconsistent with other facts |
| 5 | Improbable | Contradicts known facts or is internally inconsistent |
| 6 | Truth Cannot be Judged | Insufficient information to assess at all |
Attributes to weigh:
When asked to assess a source or information pair, follow this sequence:
For each post, report, blog, or claim, pull out these fields:
This structured extraction forces you to look at the evidence before you score anything.
Walk through the source attributes. Justify the letter with one or two sentences of reasoning. If the user is tracking the same case across multiple posts, rate each post's source independently. Ratings can change as a track record builds.
Walk through the information attributes. Has anyone independently corroborated this? Is the technical claim plausible? Is the sample data verifiable? Could it be recycled data from an older breach? Justify the number with one or two sentences.
For low-confidence ratings (E5, F6, D4, and similar), suggest specific verification actions:
When you are looking at a developing case with multiple posts over time, recommend two structured analytic techniques:
These externalise your reasoning and let peers challenge it. They are also what a stakeholder needs to follow the analysis.
Before locking in an assessment, list at least two competing explanations:
The Admiralty rating should reflect the most likely hypothesis AFTER you consider the alternatives, not before.
Always produce a structured assessment table. Use this template:
| Field | Value |
|-------|-------|
| Case Name | ... |
| Forum / Platform | ... |
| Post Content | ... |
| Date of Post | ... |
| Author | ... |
| Communication Identifiers | ... |
| Associated With | ... |
| Forum Section | ... |
| Post Link | ... |
| Author First Seen | ... |
| Author Involved in Other Cases | ... |
| Author Forum Reputation | ... |
| Author Observed in Other Forums | ... |
| Source Reliability | X (label) |
| Information Credibility | Y (label) |
| Reasoning (source) | ... |
| Reasoning (information) | ... |
| Alternative Hypotheses | ... |
| Recommended Next Steps | ... |When tracking the same case over time, add a final section:
If the rating is D, E, F, 4, 5, or 6, wrap the assessment in caveats:
This protects the reader from treating a preliminary rating as a confirmed fact, and it protects you when the case evolves.
Input: A new user "SpidermanData" on Exploit[.]in posts a sale for 560M Ticketmaster user records at $500,000. Account has 2 posts and joined yesterday.
Output: Source = F (reliability cannot be judged, no track record). Information = 6 (truth cannot be judged, no sample provided, no corroboration). Next steps: monitor for sample drop, cross-check BreachForums, watch for admin endorsement, check XMPP identifier against known actor inventories.
Input: ShinyHunters (BreachForums administrator, reputation score 1,087, known for Tokopedia, AT&T, Santander breaches) reposts the same Ticketmaster claim with folder size data showing 1.3TB.
Output: Source = B (usually reliable, strong track record on breach claims, admin status). Information = 3 (possibly true, structural metadata consistent with a real breach, but no public sample yet). Next steps: pull the folder structure and compare against known Ticketmaster export schemas.
Input: Vendor X publishes a report titled "Biggest supply chain hack of 2025" based on a BreachForums post from a new actor "rose87168".
Output: The vendor source rating depends on the vendor's own track record (rate it separately). The underlying claim source remains the new actor (F). The vendor putting their badge on the claim does NOT upgrade the original source rating. Information credibility depends on what the vendor independently validated versus what they just repeated. Build a link chart and colour each claim: confirmed (green), partially validated (yellow), pending validation (red). Push back on any claim that sits in yellow or red but is presented as fact.
Input: A top-tier CTI vendor with a long, accurate track record on this threat actor publishes a report on an actively exploited zero-day. Three independent vendors confirm the same exploit chain from their own telemetry.
Output: Source = A (completely reliable, long topic-specific history). Information = 1 (confirmed by multiple independent sources, each with their own collection). Note: even at A1, state the limitations and the assessment date, because the situation can shift.
This skill ships with two extra files. Load them only in the specific situations below, not on every assessment.
Read this file when the situation does not cleanly match the four examples in SKILL.md. Covers six tricky scenarios:
If you are rating any of the above, read the file before producing your assessment.
Use this file when the user is tracking the same case across multiple posts over time. It is a CSV with all assessment fields as columns and one example row populated with the SpidermanData Ticketmaster post.
When the user says they want to track a case, hand them a copy of this file populated with rows for each post observed so far. This mirrors the Freddy Murstad / Sean O'Connor workflow: one row per post, ratings change as the case develops, the timeline of ratings becomes the audit trail.
© tsale, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references, assets) in skills/analysis/admiralty-system-tr of tsale/awesome-dfir-skills.
Open the folder on GitHubat commit 6e52942
Admiralty System next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Admiralty System this skilltsale/awesome-dfir-skills | 323 | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| Metabigor OSINT Reconj3ssie/metabigor | 1.8k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Ctf Osintljagiello/ctf-skills | 3.4k | 1 repos | ~2.3k | Automated safety check: Notes | MIT | |
| ShadowBroker Intelligence ClientBigBodyCobain/Shadowbroker | 11k | — | ~8.9k | Automated safety check: Warn | AGPL-3.0 | |
| Awesome Osint Operatorshoyann/RZK-The-Hunter | 141 | — | ~4.8k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Run Claude Osintelementalsouls/Claude-OSINT | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT |
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
ljagiello/ctf-skills
Provides open source intelligence techniques for CTF challenges.
BigBodyCobain/Shadowbroker
Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins.
shoyann/RZK-The-Hunter
Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…
elementalsouls/Claude-OSINT
Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test.
smixs/osint-skill
Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill.
tsale/awesome-dfir-skills
Professional malware analysis workflow for PE executables and suspicious files.
tsale/awesome-dfir-skills
Analyse Mitre ATT&CK tactics, techniques and sub-techniques.
tsale/awesome-dfir-skills
Help users write, validate, and troubleshoot osquery SQL queries using provided osquery table schemas as the authoritative source.
tsale/awesome-dfir-skills
Build structured threat actor profiles using the 5W1H framework and the Diamond Model.
Categories
Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis. Admiralty System is an agent skill from tsale/awesome-dfir-skills.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis.
Admiralty System fits situations like: you need to evaluate a CTI report; dark web forum post; threat actor advertisement; social media intel claim.
Run `npx skills add tsale/awesome-dfir-skills --skill admiralty-system -a claude-code`. Or copy the skill folder (skills/analysis/admiralty-system-tr in tsale/awesome-dfir-skills) into .claude/skills/admiralty-system in your project. Claude Code loads it when a task matches its description.
Run `npx skills add tsale/awesome-dfir-skills --skill admiralty-system -a codex`. Or copy the skill folder (skills/analysis/admiralty-system-tr in tsale/awesome-dfir-skills) into .agents/skills/admiralty-system in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tsale/awesome-dfir-skills --skill admiralty-system -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/admiralty-system, .gemini/skills/admiralty-system, .github/skills/admiralty-system and .opencode/skills/admiralty-system in your project.
SKILL.md names no scripts, command-line tools or credentials: Admiralty System is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Admiralty System is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Admiralty System: Metabigor OSINT Recon (j3ssie/metabigor, 1.8k stars), Ctf Osint (ljagiello/ctf-skills, 3.4k stars), ShadowBroker Intelligence Client (BigBodyCobain/Shadowbroker, 11k stars) and Awesome Osint Operator (shoyann/RZK-The-Hunter, 141 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
tsale (a GitHub user) maintains it in tsale/awesome-dfir-skills, which has 323 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on May 14, 2026.
Source: tsale/awesome-dfir-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.