开源情报溯源

原名:building-threat-actor-profile-from-osint

通过收集厂商报告、暗网论坛、社交媒体等开源情报,构建威胁行为者档案,关联指标并映射基础设施,生成包含动机、能力、TTPs的结构化档案,适用于归因分析。

分类
学习研究
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
0
收藏
0
发布
2026-08-18
更新
2026-08-24
TRACE 评分
3.6 / 5

内容概览

Threat actor profiling using OSINT systematically gathers and analyzes publicly available information to build comprehensive profiles of adversary groups. This skill covers collecting intelligence from public sources (security vendor reports, paste sites, dark web forums, social media, code repositories), correlating indicators across platforms, mapping adversary infrastructure using tools like Maltego and SpiderFoot, and producing structured threat actor dossiers that inform defensive strategies and attribution assessments. - When deploying or configuring building threat actor profile from osint capabilities in your environment - When establishing security controls aligned to compliance requirements - When building or improving security architecture for this domain - When conducting security assessments that require this implementation - Python 3.9+ with shodan, requests, beautifulsoup4…

查看 SKILL 详情