Agent skill

Admiralty System

by tsale in tsale/awesome-dfir-skills

Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis.

Apache-2.0Auto-check passedSecurity

Install Admiralty System

skills CLI
$ npx skills add tsale/awesome-dfir-skills --skill admiralty-system -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tsale/awesome-dfir-skills admiralty-system --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/analysis/admiralty-system-tr .claude/skills/admiralty-system && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
admiralty-system
GitHub stars
323
Token cost
~3.4k tokens
SKILL.md length
1,736 words
Files
3 (incl. references, assets)
Skills in repo
5
Repo updated
First seen
Licence
Apache-2.0

At a glance

Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis.

  • Works in 6 steps: Extract structured metadata → Rate the source (A to F) → Rate the information (1 to 6) → …
  • You need to evaluate a CTI report
  • SKILL.md covers Core rule: assess source and…, Source Reliability Scale (A to…, Information Credibility Scale… and Workflow, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Admiralty System is an agent skill from tsale/awesome-dfir-skills. Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis. Use this skill whenever you need to evaluate a CTI report, breach claim, dark web forum post, threat actor advertisement, vendor blog, social media intel claim, leaked database listing, or any source plus information pair where trust matters. Trigger phrases include "assess this source", "rate this report", "is this breach real", "evaluate credibility"…

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files and assets (for example `references/edge-cases.md`).

It sits in Security, covering OSINT. The repository describes itself as: A curated collection of DFIR skills and workflows for InfoSec practitioners. The licence is Apache-2.0.

When your agent uses it

  • You need to evaluate a CTI report
  • Dark web forum post
  • Threat actor advertisement
  • Social media intel claim

Example prompts

  • “assess this source”
  • “rate this report”
  • “is this breach real”
  • “/admiralty-system”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Extract structured metadata
  2. Rate the source (A to F)
  3. Rate the information (1 to 6)
  4. Recommend next steps
  5. Suggest SATs when relevant
  6. Always flag alternative hypotheses

What it can do on your machine

Read from SKILL.md and the folder at commit 6e52942. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Admiralty System loads about 3.4k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 245 tokens; SKILL.md has 1,736 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~245
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tsale/awesome-dfir-skills at commit 6e52942, republished under its Apache-2.0 licence (© tsale). 1,736 words, ~3,357 tokens.

Download SKILL.mdSave it as .claude/skills/admiralty-system/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
admiralty-system
description
Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis. Use this skill whenever you need to evaluate a CTI report, breach claim, dark web forum post, threat actor advertisement, vendor blog, social media intel claim, leaked database listing, or any source plus information pair where trust matters. Trigger phrases include "assess this source", "rate this report", "is this breach real", "evaluate credibility", "source assessment", "should I trust this claim", "admiralty rating", "A1 to F6", and any review of CTI or OSINT material where you need to decide how much weight to give it. Use proactively when the user shares a breach post, threat actor claim, or vendor report and asks for analysis, even if they do not explicitly mention the Admiralty System. Also use when teaching, building courseware, or producing a training example around source evaluation.

Admiralty System for CTI

The Admiralty System (NATO AJP-2.1) is the gold standard for assessing intelligence. The British Royal Navy developed it in the early 20th century. NATO intelligence communities now use it worldwide, and it is gaining ground in cyber threat intelligence.

It rates two things, separately:

  • Source Reliability (A to F): how trustworthy the origin is
  • Information Credibility (1 to 6): how trustworthy the data is, independent of the source

The combined output is an alphanumeric code such as A1, B3, F6.

Core rule: assess source and information SEPARATELY

This is the single most common mistake. A source who is reliable on malware analysis is not automatically reliable on geopolitics. A piece of information can be true from a sketchy source, or false from a usually reliable one. Always rate them independently, never in lockstep.

Second common mistake: confusing "two vendors reported it" with two independent sources. If both vendors pull from the same original dataset (the same breach forum post, the same scan, the same leak), that is ONE source. Independent corroboration means independent collection.

Source Reliability Scale (A to F)

CodeLabelUse when
ACompletely ReliableSource has consistently delivered accurate information over a long history on this specific topic. Reserve this rating; it is rare.
BUsually ReliableSource has a strong track record with only minor lapses on this topic
CFairly ReliableSource has produced accurate information before but the track record is shorter or mixed
DNot Usually ReliableSource has been wrong more often than right, but cannot be fully dismissed
EUnreliableSource has a clear history of inaccuracy, deception, or manipulation
FReliability Cannot be JudgedNew source, no track record, or insufficient access to assess

Attributes to weigh:

  • History of accuracy on this specific topic (not other topics)
  • Proximity to the event (firsthand, secondhand, hearsay)
  • Technical skill in the domain
  • Motivation (financial gain, reputation, ideology, deception)
  • Identity corroboration (links to known infrastructure or aliases)
  • Forum reputation score, post count, join date
  • Administrator or moderator status on the forum
  • Documented links to other known threat actors or breaches

Information Credibility Scale (1 to 6)

CodeLabelUse when
1Confirmed by Other SourcesInformation is corroborated by multiple genuinely independent sources
2Probably TrueLogical, consistent with known facts, and partly corroborated
3Possibly TrueLogical and plausible but not independently confirmed
4DoubtfulPossible but unconfirmed and partly inconsistent with other facts
5ImprobableContradicts known facts or is internally inconsistent
6Truth Cannot be JudgedInsufficient information to assess at all

Attributes to weigh:

  • Internal logical consistency
  • Fit with prior known facts
  • Independent corroboration (genuinely independent, not echoed)
  • Technical plausibility (does the claimed attack chain actually work)
  • Presence of sample data, hashes, or other concrete proof
  • Time elapsed since the event
  • Whether the data could be recycled from earlier breaches

Workflow

When asked to assess a source or information pair, follow this sequence:

1. Extract structured metadata

For each post, report, blog, or claim, pull out these fields:

  • Case name
  • Forum or platform
  • Post content (what is being claimed)
  • Date of post
  • Author handle
  • Communication identifiers (XMPP, Telegram, email, Tox)
  • Associated handles or known aliases
  • Forum section
  • Post link (defanged)
  • Author first seen date
  • Author involvement in other cases
  • Author forum reputation
  • Author observed in other forums

This structured extraction forces you to look at the evidence before you score anything.

2. Rate the source (A to F)

Walk through the source attributes. Justify the letter with one or two sentences of reasoning. If the user is tracking the same case across multiple posts, rate each post's source independently. Ratings can change as a track record builds.

3. Rate the information (1 to 6)

Walk through the information attributes. Has anyone independently corroborated this? Is the technical claim plausible? Is the sample data verifiable? Could it be recycled data from an older breach? Justify the number with one or two sentences.

4. Recommend next steps

For low-confidence ratings (E5, F6, D4, and similar), suggest specific verification actions:

  • Cross-check on other forums or marketplaces
  • Pull a sample of the data and validate against known schemas
  • Check the original infrastructure (login endpoints, archived snapshots, Wayback, FOFA)
  • Compare timestamps with public incident announcements
  • Hash-check leaked samples against known prior leaks to detect recycled data
  • Look for admin endorsement or community vouching
5. Suggest SATs when relevant

When you are looking at a developing case with multiple posts over time, recommend two structured analytic techniques:

  • Timeline: showing how source and information ratings evolve over each post
  • Link chart: showing relationships between aliases, infrastructure, and forums, with each edge colour-coded as confirmed, partially validated, or pending validation

These externalise your reasoning and let peers challenge it. They are also what a stakeholder needs to follow the analysis.

6. Always flag alternative hypotheses

Before locking in an assessment, list at least two competing explanations:

  • The actor really did breach the company
  • The actor is recycling old or unrelated data
  • The actor is aggregating multiple smaller leaks and rebranding them as one
  • The data is from a third-party processor, not the named company
  • The post is a reputation play with no real data behind it
  • The post is misinformation or disinformation

The Admiralty rating should reflect the most likely hypothesis AFTER you consider the alternatives, not before.

Output Format

Always produce a structured assessment table. Use this template:

| Field | Value |
|-------|-------|
| Case Name | ... |
| Forum / Platform | ... |
| Post Content | ... |
| Date of Post | ... |
| Author | ... |
| Communication Identifiers | ... |
| Associated With | ... |
| Forum Section | ... |
| Post Link | ... |
| Author First Seen | ... |
| Author Involved in Other Cases | ... |
| Author Forum Reputation | ... |
| Author Observed in Other Forums | ... |
| Source Reliability | X (label) |
| Information Credibility | Y (label) |
| Reasoning (source) | ... |
| Reasoning (information) | ... |
| Alternative Hypotheses | ... |
| Recommended Next Steps | ... |

When tracking the same case over time, add a final section:

  • Timeline of ratings: post 1 (date, rating), post 2 (date, rating), and so on
  • Observed trend: for example, rating climbing from F6 to B2 as corroboration arrives

Hard constraints

  • NEVER conflate the source rating with the information rating. They are independent axes.
  • NEVER count two reports using the same underlying data as independent corroboration.
  • NEVER give an A rating casually. A is reserved for sources with a long, well-documented, topic-specific track record.
  • When unsure, prefer F or 6 over guessing. "Cannot be judged" is a valid and honest rating.
  • ALWAYS justify the rating with a short written reason. A bare letter-number score is not enough.
  • ALWAYS preserve the system as defined (NATO AJP-2.1). Do not invent custom variants. Otherwise teams cannot compare assessments and the system collapses into noise.
Show full SKILL.md (701 more words)Show less

When to flag uncertainty in the output

If the rating is D, E, F, 4, 5, or 6, wrap the assessment in caveats:

  • "We assess this to be [rating] based on available information, with the following limitations..."
  • "This rating may change as the case develops"
  • "Pending [verification step], this assessment should be treated as preliminary"

This protects the reader from treating a preliminary rating as a confirmed fact, and it protects you when the case evolves.

Examples

Example 1: New dark web forum post

Input: A new user "SpidermanData" on Exploit[.]in posts a sale for 560M Ticketmaster user records at $500,000. Account has 2 posts and joined yesterday.

Output: Source = F (reliability cannot be judged, no track record). Information = 6 (truth cannot be judged, no sample provided, no corroboration). Next steps: monitor for sample drop, cross-check BreachForums, watch for admin endorsement, check XMPP identifier against known actor inventories.

Example 2: Established threat actor reposts the claim

Input: ShinyHunters (BreachForums administrator, reputation score 1,087, known for Tokopedia, AT&T, Santander breaches) reposts the same Ticketmaster claim with folder size data showing 1.3TB.

Output: Source = B (usually reliable, strong track record on breach claims, admin status). Information = 3 (possibly true, structural metadata consistent with a real breach, but no public sample yet). Next steps: pull the folder structure and compare against known Ticketmaster export schemas.

Example 3: Vendor report citing a single dark web source

Input: Vendor X publishes a report titled "Biggest supply chain hack of 2025" based on a BreachForums post from a new actor "rose87168".

Output: The vendor source rating depends on the vendor's own track record (rate it separately). The underlying claim source remains the new actor (F). The vendor putting their badge on the claim does NOT upgrade the original source rating. Information credibility depends on what the vendor independently validated versus what they just repeated. Build a link chart and colour each claim: confirmed (green), partially validated (yellow), pending validation (red). Push back on any claim that sits in yellow or red but is presented as fact.

Example 4: Trusted vendor with multi-source corroboration

Input: A top-tier CTI vendor with a long, accurate track record on this threat actor publishes a report on an actively exploited zero-day. Three independent vendors confirm the same exploit chain from their own telemetry.

Output: Source = A (completely reliable, long topic-specific history). Information = 1 (confirmed by multiple independent sources, each with their own collection). Note: even at A1, state the limitations and the assessment date, because the situation can shift.

Notes on terminology

  • "Information" in this context means the data and claims being conveyed, not the platform or channel.
  • "Source" means the originator of the claim, which can be a person, a forum account, a system, or a sensor.
  • A system or sensor is still a source, and logs can still be tampered with. Cross-check internal and external logs for consistency before trusting either.
  • Treat each post by the same actor as a separate observation. A B-rated actor can drop an F-rated post if the specific claim is implausible.

Bundled Resources

This skill ships with two extra files. Load them only in the specific situations below, not on every assessment.

references/edge-cases.md

Read this file when the situation does not cleanly match the four examples in SKILL.md. Covers six tricky scenarios:

  • Two vendors with contradictory attributions on the same campaign
  • Sensor or honeypot data (system as source)
  • Aggregated feed data where origin cannot be traced
  • Law enforcement attribution with sealed evidence
  • Insider leaks where motivation is hostile but information is accurate
  • Recycled-data detection in breach claims (Australian and US examples)

If you are rating any of the above, read the file before producing your assessment.

assets/case-tracking-template.csv

Use this file when the user is tracking the same case across multiple posts over time. It is a CSV with all assessment fields as columns and one example row populated with the SpidermanData Ticketmaster post.

When the user says they want to track a case, hand them a copy of this file populated with rows for each post observed so far. This mirrors the Freddy Murstad / Sean O'Connor workflow: one row per post, ratings change as the case develops, the timeline of ratings becomes the audit trail.

© tsale, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references, assets) in skills/analysis/admiralty-system-tr of tsale/awesome-dfir-skills.

  • SKILL.md
  • assets/case-tracking-template.csv
  • references/edge-cases.md

Open the folder on GitHubat commit 6e52942

Compare with similar skills

Admiralty System next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Admiralty System compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Admiralty System this skilltsale/awesome-dfir-skills323—~3.4kAutomated safety check: PassApache-2.0
Metabigor OSINT Reconj3ssie/metabigor1.8k—~2.4kAutomated safety check: PassMIT
Ctf Osintljagiello/ctf-skills3.4k1 repos~2.3kAutomated safety check: NotesMIT
ShadowBroker Intelligence ClientBigBodyCobain/Shadowbroker11k—~8.9kAutomated safety check: WarnAGPL-3.0
Awesome Osint Operatorshoyann/RZK-The-Hunter141—~4.8kAutomated safety check: PassCC-BY-SA-4.0
Run Claude Osintelementalsouls/Claude-OSINT2.8k—~1.2kAutomated safety check: PassMIT

Similar skills

  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.8k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Ctf Osint

    ljagiello/ctf-skills

    Provides open source intelligence techniques for CTF challenges.

    3.4k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • ShadowBroker Intelligence Client

    BigBodyCobain/Shadowbroker

    Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins.

    11k GitHub stars~8.9k tokensUpdated yesterday
    SecurityAuto-check: warnings
  • Awesome Osint Operator

    shoyann/RZK-The-Hunter

    Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…

    141 GitHub stars~4.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Run Claude Osint

    elementalsouls/Claude-OSINT

    Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test.

    2.8k GitHub stars~1.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Osint

    smixs/osint-skill

    Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill.

    141 GitHub stars~5.5k tokensUpdated 7 mo ago
    SecurityAuto-check passed

More from tsale/awesome-dfir-skills

  • Malware Analysis

    tsale/awesome-dfir-skills

    Professional malware analysis workflow for PE executables and suspicious files.

    323 GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Analysing Attack

    tsale/awesome-dfir-skills

    Analyse Mitre ATT&CK tactics, techniques and sub-techniques.

    323 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed
  • Osquery Query Helper

    tsale/awesome-dfir-skills

    Help users write, validate, and troubleshoot osquery SQL queries using provided osquery table schemas as the authoritative source.

    323 GitHub stars~1.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Threat Actor Profiling

    tsale/awesome-dfir-skills

    Build structured threat actor profiles using the 5W1H framework and the Diamond Model.

    323 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Admiralty System

What does Admiralty System do?

Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis. Admiralty System is an agent skill from tsale/awesome-dfir-skills.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis.

When should I use Admiralty System?

Admiralty System fits situations like: you need to evaluate a CTI report; dark web forum post; threat actor advertisement; social media intel claim.

How do I install Admiralty System in Claude Code?

Run `npx skills add tsale/awesome-dfir-skills --skill admiralty-system -a claude-code`. Or copy the skill folder (skills/analysis/admiralty-system-tr in tsale/awesome-dfir-skills) into .claude/skills/admiralty-system in your project. Claude Code loads it when a task matches its description.

How do I install Admiralty System in Codex?

Run `npx skills add tsale/awesome-dfir-skills --skill admiralty-system -a codex`. Or copy the skill folder (skills/analysis/admiralty-system-tr in tsale/awesome-dfir-skills) into .agents/skills/admiralty-system in your project. Codex loads it when a task matches its description.

Can I use Admiralty System in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tsale/awesome-dfir-skills --skill admiralty-system -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/admiralty-system, .gemini/skills/admiralty-system, .github/skills/admiralty-system and .opencode/skills/admiralty-system in your project.

What does Admiralty System need to run?

SKILL.md names no scripts, command-line tools or credentials: Admiralty System is instructions for the agent only.

Does Admiralty System access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Admiralty System safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Admiralty System use?

Admiralty System is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Admiralty System use?

About 3.4k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Admiralty System?

Skills that share tags, products or a category with Admiralty System: Metabigor OSINT Recon (j3ssie/metabigor, 1.8k stars), Ctf Osint (ljagiello/ctf-skills, 3.4k stars), ShadowBroker Intelligence Client (BigBodyCobain/Shadowbroker, 11k stars) and Awesome Osint Operator (shoyann/RZK-The-Hunter, 141 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Admiralty System?

tsale (a GitHub user) maintains it in tsale/awesome-dfir-skills, which has 323 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on May 14, 2026.

Source: tsale/awesome-dfir-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.