Metabigor OSINT Recon
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
Build structured threat actor profiles using the 5W1H framework and the Diamond Model.
$ npx skills add tsale/awesome-dfir-skills --skill threat-actor-profiling -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install tsale/awesome-dfir-skills threat-actor-profiling --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/analysis/threat-actor-profiling .claude/skills/threat-actor-profiling && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "threat-actor-profiling" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/threat-actor-profiling into .claude/skills/threat-actor-profiling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-actor-profiling", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/threat-actor-profilingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add tsale/awesome-dfir-skills --skill threat-actor-profiling -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install tsale/awesome-dfir-skills threat-actor-profiling --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/analysis/threat-actor-profiling .agents/skills/threat-actor-profiling && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "threat-actor-profiling" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/threat-actor-profiling into .agents/skills/threat-actor-profiling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-actor-profiling", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tsale/awesome-dfir-skills --skill threat-actor-profiling -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install tsale/awesome-dfir-skills threat-actor-profiling --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/analysis/threat-actor-profiling .cursor/skills/threat-actor-profiling && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "threat-actor-profiling" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/threat-actor-profiling into .cursor/skills/threat-actor-profiling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-actor-profiling", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/tsale/awesome-dfir-skills.git --path skills/analysis/threat-actor-profiling--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add tsale/awesome-dfir-skills --skill threat-actor-profiling -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install tsale/awesome-dfir-skills threat-actor-profiling --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/analysis/threat-actor-profiling .gemini/skills/threat-actor-profiling && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "threat-actor-profiling" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/threat-actor-profiling into .gemini/skills/threat-actor-profiling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-actor-profiling", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install tsale/awesome-dfir-skills threat-actor-profilingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add tsale/awesome-dfir-skills --skill threat-actor-profiling -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/analysis/threat-actor-profiling .github/skills/threat-actor-profiling && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "threat-actor-profiling" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/threat-actor-profiling into .github/skills/threat-actor-profiling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-actor-profiling", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tsale/awesome-dfir-skills --skill threat-actor-profiling -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install tsale/awesome-dfir-skills threat-actor-profiling --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/analysis/threat-actor-profiling .opencode/skills/threat-actor-profiling && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "threat-actor-profiling" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/threat-actor-profiling into .opencode/skills/threat-actor-profiling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-actor-profiling", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
threat-actor-profilingBuild structured threat actor profiles using the 5W1H framework and the Diamond Model.
Threat Actor Profiling is an agent skill from tsale/awesome-dfir-skills. Build structured threat actor profiles using the 5W1H framework and the Diamond Model. Use this skill whenever the user wants to profile a threat actor, create a TA report, analyze an APT group, build an adversary profile, assess threat actor capability, map TTPs to MITRE ATT&CK for a specific group, or produce any intelligence deliverable about a threat actor. Also trigger when the user mentions threat actor names (e.g. APT29, Lazarus, FIN7), asks about victimology, modus operandi, or wants to structure threat…
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering OSINT. The repository describes itself as: A curated collection of DFIR skills and workflows for InfoSec practitioners. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 6e52942. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Threat Actor Profiling loads about 2.8k tokens when it runs. Until then it costs about 168 tokens; SKILL.md has 1,288 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from tsale/awesome-dfir-skills at commit 6e52942, republished under its Apache-2.0 licence (© tsale). 1,288 words, ~2,833 tokens.
.claude/skills/threat-actor-profiling/SKILL.md (or your agent's skills folder).Generate structured, actionable threat actor profiles following a deliverable-first methodology grounded in the 5W1H framework and the Diamond Model of Intrusion Analysis.
Follow these six steps in order. Each step builds toward a complete profile.
Before collecting any data, clarify:
Use this decision matrix:
| Purpose | Audience | Focus | Risk to Avoid |
|---|---|---|---|
| Internal tracking | CTI, SOC, IR | Structured IOCs and TTPs, minimal narrative | Building a library nobody uses |
| Analytical deliverable | Management, Legal, Comms, IR | Timelines, impact analysis, recommendations | Unfocused data collection |
Gather from two categories:
Internal telemetry (if incident-related):
External intelligence:
Evaluate source quality using the Admiralty Code:
Assign a letter-number pair to each source (e.g., B2 = usually reliable, probably true).
Structure the profile using these sections:
Use a three-level scale:
| Level | Description | Tooling | Resources | Examples |
|---|---|---|---|---|
| High | Nation-state backed, highly skilled | Custom tooling, zero-days, long dwell time | Extensive/unlimited funding | APT28, Lazarus |
| Moderate | Skilled, no direct state sponsorship | Mix of open-source and limited custom tools | Substantial but unclear funding | FIN7, Wizard Spider |
| Low | Basic attacks, script-level | Commodity/public tools only | Minimal | Hacktivists, script kiddies |
Optionally use five levels (High, Medium-High, Moderate, Medium-Low, Low) for more granular assessment.
In STIX 2.1 format where possible:
This step is required for analytical deliverables. Skip for internal tracking profiles.
Forecast (What Next?)
Implications (So What?)
Recommendations (Now What?)
Maintain a transparent audit trail:
Produce the right output for the audience:
| Audience | Focus | Include | Exclude |
|---|---|---|---|
| Executive leadership | So What | Business risk, financial impact, high-level mitigation | Raw IOCs, technical TTPs |
| IR / SOC team | Now What | Detection logic, TTPs, huntable indicators | Strategic narrative |
| Threat Hunting / Red Team | Modus operandi | Technical evidence, kill chain detail | Business impact analysis |
Executive summary: Write it last. Use BLUF (Bottom Line Up Front) format. Place the most critical findings at the top.
Cut-off date: Always state the date the analysis represents. Intelligence is perishable.
The primary output of this skill is an interactive visual diagram rendered inline using the Visualizer (show_widget), NOT a lengthy markdown document.
visualize:read_me tool (module: diagram) before generating, then use visualize:show_widgetThe diagram must include these panels/cards arranged in a readable layout:
If the user explicitly asks for markdown, a document, or a file export, fall back to a structured markdown document using this template:
# Threat Actor Profile: [NAME]
**Cut-off Date**: [DATE]
**Classification**: [TLP level]
**Profile Type**: [Internal Tracking | Analytical Deliverable]
**Prepared for**: [Audience]
## Executive Summary
## 1. Identity and Attribution
## 2. Motive and Objective
## 3. Victimology
## 4. Capability Assessment
## 5. Modus Operandi
## 6. Activity Timeline
## 7. Forecast, Implications, and Recommendations
## 8. Technical Evidence (Appendix)
## 9. Referencesvisualize:read_me with module diagram before generating the visual output© tsale, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/analysis/threat-actor-profiling of tsale/awesome-dfir-skills.
Open the folder on GitHubat commit 6e52942
Threat Actor Profiling next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Threat Actor Profiling this skilltsale/awesome-dfir-skills | 324 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Metabigor OSINT Reconj3ssie/metabigor | 1.9k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Ctf Osintljagiello/ctf-skills | 3.4k | 2 repos | ~2.3k | Automated safety check: Notes | MIT | |
| ShadowBroker Intelligence ClientBigBodyCobain/Shadowbroker | 11k | — | ~8.9k | Automated safety check: Warn | AGPL-3.0 | |
| Awesome Osint Operatorshoyann/RZK-The-Hunter | 140 | — | ~4.8k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Run Claude Osintelementalsouls/Claude-OSINT | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT |
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
ljagiello/ctf-skills
Provides open source intelligence techniques for CTF challenges.
BigBodyCobain/Shadowbroker
Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins.
shoyann/RZK-The-Hunter
Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…
elementalsouls/Claude-OSINT
Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test.
smixs/osint-skill
Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill.
tsale/awesome-dfir-skills
Professional malware analysis workflow for PE executables and suspicious files.
tsale/awesome-dfir-skills
Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis.
tsale/awesome-dfir-skills
Analyse Mitre ATT&CK tactics, techniques and sub-techniques.
tsale/awesome-dfir-skills
Help users write, validate, and troubleshoot osquery SQL queries using provided osquery table schemas as the authoritative source.
Categories
Build structured threat actor profiles using the 5W1H framework and the Diamond Model. Threat Actor Profiling is an agent skill from tsale/awesome-dfir-skills. Build structured threat actor profiles using the 5W1H framework and the Diamond Model.
Threat Actor Profiling fits situations like: the user wants to profile a threat actor; create a TA report; analyze an APT group; build an adversary profile.
Run `npx skills add tsale/awesome-dfir-skills --skill threat-actor-profiling -a claude-code`. Or copy the skill folder (skills/analysis/threat-actor-profiling in tsale/awesome-dfir-skills) into .claude/skills/threat-actor-profiling in your project. Claude Code loads it when a task matches its description.
Run `npx skills add tsale/awesome-dfir-skills --skill threat-actor-profiling -a codex`. Or copy the skill folder (skills/analysis/threat-actor-profiling in tsale/awesome-dfir-skills) into .agents/skills/threat-actor-profiling in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tsale/awesome-dfir-skills --skill threat-actor-profiling -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/threat-actor-profiling, .gemini/skills/threat-actor-profiling, .github/skills/threat-actor-profiling and .opencode/skills/threat-actor-profiling in your project.
SKILL.md names no scripts, command-line tools or credentials: Threat Actor Profiling is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Threat Actor Profiling is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Threat Actor Profiling: Metabigor OSINT Recon (j3ssie/metabigor, 1.9k stars), Ctf Osint (ljagiello/ctf-skills, 3.4k stars), ShadowBroker Intelligence Client (BigBodyCobain/Shadowbroker, 11k stars) and Awesome Osint Operator (shoyann/RZK-The-Hunter, 140 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
tsale (a GitHub user) maintains it in tsale/awesome-dfir-skills, which has 324 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on May 14, 2026.
Source: tsale/awesome-dfir-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.