apify-osint-threat-intel

作成者: apify

ユーザーが「CVEを探して」「私のドメインが侵害されているか確認して」「脅威情報」「OSINT」「セキュリティニュース」「攻撃対象領域…」などと尋ねたときにこのスキルを使用します。

npx skills add https://github.com/apify/awesome-skills --skill apify-osint-threat-intel

OSINT Threat Intelligence

Real-time security intelligence powered by live threat data via Apify actors. Never answer security questions from training knowledge alone. CVEs, breaches, and threat actor activity change daily — always gather live data first, then analyze.


Prerequisites

CLI rules (always follow)

Always pass --user-agent apify-awesome-skills/apify-osint-threat-intel on every apify CLI call — it's critical for telemetry, never omit it.

apify actors call "ACTOR_ID" -i 'INPUT_JSON' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null
apify datasets get-items DATASET_ID --format json --user-agent apify-awesome-skills/apify-osint-threat-intel > /tmp/results.json 2>/dev/null
jq '.[] | "\(.field1) | \(.field2)"' /tmp/results.json
apify actors info "ACTOR_ID" --input --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null   # check schema

Actor Routing Table

Data NeedActor IDNotes
CVE lookupapify/google-search-scraperQuery: site:nvd.nist.gov [product] [version]
NVD full recordapify/website-content-crawlerURL: nvd.nist.gov/vuln/detail/CVE-XXXX-XXXXX
CISA known exploitedapify/rag-web-browserURL: cisa.gov/known-exploited-vulnerabilities-catalog
GitHub advisoriesapify/rag-web-browserURL: github.com/advisories?query=[product]
Exploit-DB searchapify/google-search-scraperQuery: site:exploit-db.com [product] [version]
Security newsdata_xplorer/google-news-scraper-fastKeywords: "[target]" vulnerability OR exploit OR breach
Reddit threat discussionharshmaur/reddit-scrapersearchTerms + withinCommunity — one subreddit per run (netsec, then a second run for cybersecurity); a value like netsec OR cybersecurity silently drops the filter and searches all of Reddit. Always set postedAfter (YYYY-MM-DD) for recency — searchTime is not enforced and the Actor pads the cap with years-old posts. Pay-per-event: $0.02 per run + $0.002 per post; maxPostsCount is per search term.
Threat intel Twitter/Xapidojo/tweet-scraperKeywords: #threatintel [target], search mode
Breach mention searchapify/google-search-scraperQuery: "[domain]" site:pastebin.com OR intext:breach
Vendor security advisoryapify/website-content-crawlerDirect vendor security page URL
Shodan exposure hintsapify/google-search-scraperQuery: site:shodan.io "[domain OR org name]"
Threat actor researchapify/rag-web-browserMITRE ATT&CK: attack.mitre.org/groups/

Prefer apify/google-search-scraper and apify/rag-web-browser over website-content-crawler for speed.
Use website-content-crawler only when you need the full page body (e.g. NVD detail, vendor advisory).
Do NOT use website-content-crawler on: reddit.com, twitter.com, pastebin.com, linkedin.com.


Core Workflow

Step 0 — Clarify scope before running anything

Ask the user:

  • Target type: domain, IP, software/version, CVE ID, threat actor name, or keyword?
  • Goal: one-time lookup vs. ongoing monitoring brief?
  • Autonomy: full autopilot, or checkpoint before each actor call?

Step 1 — Identify module

User saysModuleSteps
"Find CVEs for [product]"CVE Intelligence2a
"Is [domain] breached / exposed"Domain Threat Profile2b
"Research [threat actor / malware]"Threat Actor Profile2c
"Security news about [topic]"Security News Brief2d
"Attack surface of [company]"Attack Surface Discovery2b + 2d
"Full threat report on [target]"Multi-Module2a + 2b + 2c + 2d

Step 2a — CVE Intelligence

Gather live CVE data for a product or version:

# 1. Search NVD via Google
apify actors call "apify/google-search-scraper" -i '{
  "queries": "site:nvd.nist.gov CVE [PRODUCT] [VERSION]",
  "maxPagesPerQuery": 1
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 2. Pull full NVD record for each CVE ID found
apify actors call "apify/website-content-crawler" -i '{
  "startUrls": [{"url": "https://nvd.nist.gov/vuln/detail/CVE-XXXX-XXXXX"}],
  "proxyConfiguration": {"useApifyProxy": true},
  "maxCrawlPages": 1
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 3. Check if CVE is in CISA's Known Exploited Vulnerabilities list
apify actors call "apify/rag-web-browser" -i '{
  "query": "[CVE-ID] site:cisa.gov/known-exploited-vulnerabilities-catalog",
  "maxResults": 3
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 4. Check Exploit-DB for public PoC
apify actors call "apify/google-search-scraper" -i '{
  "queries": "site:exploit-db.com [PRODUCT] [VERSION]",
  "maxPagesPerQuery": 1
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

Synthesize: severity (CVSS), exploitability (CISA KEV = active exploitation), public PoC exists (yes/no), patch available (yes/no).

Step 2b — Domain Threat Profile

# 1. Search for breach mentions
apify actors call "apify/google-search-scraper" -i '{
  "queries": "\"[DOMAIN]\" breach OR leak OR hacked OR \"data exposed\"",
  "maxPagesPerQuery": 1
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 2. Check paste sites for credential leaks
apify actors call "apify/google-search-scraper" -i '{
  "queries": "\"[DOMAIN]\" site:pastebin.com OR site:ghostbin.com OR site:rentry.co",
  "maxPagesPerQuery": 1
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 3. Check Shodan exposure hints via Google
apify actors call "apify/google-search-scraper" -i '{
  "queries": "site:shodan.io \"[DOMAIN OR ORG]\"",
  "maxPagesPerQuery": 1
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 4. Scan r/netsec for mentions — one subreddit per run; repeat with "withinCommunity": "cybersecurity"
#    postedAfter = today minus 365 days (YYYY-MM-DD). 3 terms × 5 posts = 15 posts ≈ $0.05.
#    Use `postUrl` as the Source and `createdAt` for the date stamp.
apify actors call "harshmaur/reddit-scraper" -i '{
  "searchTerms": ["[DOMAIN] breach", "[DOMAIN] hack", "[DOMAIN] vulnerability"],
  "withinCommunity": "netsec",
  "postedAfter": "[YYYY-MM-DD]",
  "maxPostsCount": 5,
  "crawlCommentsPerPost": false
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

Step 2c — Threat Actor Profile

# 1. MITRE ATT&CK lookup
apify actors call "apify/rag-web-browser" -i '{
  "query": "[THREAT ACTOR NAME] site:attack.mitre.org",
  "maxResults": 3
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 2. Recent activity via news
apify actors call "data_xplorer/google-news-scraper-fast" -i '{
  "keywords": ["[THREAT ACTOR NAME] attack OR campaign OR malware"],
  "timeframe": "30d",
  "maxArticles": 15
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 3. Community threat intel on Twitter/X
apify actors call "apidojo/tweet-scraper" -i '{
  "searchTerms": ["#threatintel [THREAT ACTOR]", "[THREAT ACTOR] TTPs"],
  "maxItems": 20,
  "sort": "Latest"
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 4. Reddit discussion — postedAfter = today minus 365 days; `createdAt` of the newest post = "Last seen"
apify actors call "harshmaur/reddit-scraper" -i '{
  "searchTerms": ["[THREAT ACTOR NAME]"],
  "withinCommunity": "netsec",
  "postedAfter": "[YYYY-MM-DD]",
  "maxPostsCount": 10,
  "crawlCommentsPerPost": false
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

Step 2d — Security News Brief

# 1. Google News for topic
apify actors call "data_xplorer/google-news-scraper-fast" -i '{
  "keywords": ["[TOPIC] vulnerability OR CVE OR breach OR exploit"],
  "timeframe": "7d",
  "maxArticles": 20
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 2. Reddit r/netsec latest — sort goes into the URL (/new/); `searchSort` does not apply to startUrls
apify actors call "harshmaur/reddit-scraper" -i '{
  "startUrls": [{"url": "https://www.reddit.com/r/netsec/new/"}],
  "maxPostsCount": 15,
  "crawlCommentsPerPost": false
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

Step 3 — Triage and assess

For every finding, apply this classification:

SeverityCriteria
CriticalCVSS ≥ 9.0 OR on CISA KEV list OR public PoC + unpatched
HighCVSS 7.0–8.9 OR active exploitation reported in news
MediumCVSS 4.0–6.9 OR breach mention without active exploit
LowCVSS < 4.0 OR historical, patched, no active exploitation
InformationalExposure hints without confirmed vulnerability

Step 4 — Deliver structured report

Output format:

## Threat Intelligence Report — [TARGET]
Date: [today]

### Executive Summary
[2–3 sentence risk verdict]

### Critical Findings
- [CVE/Finding] — Severity: [X] — Status: [Patched/Unpatched/Active exploit]
  Source: [URL]

### Breach/Exposure Indicators
- [Finding] — Source: [URL]

### Threat Actor Activity (if applicable)
- [Actor] — TTPs: [list] — Last seen: [date]

### Recommended Actions
1. [Immediate action]
2. [Short-term action]
3. [Monitoring recommendation]

### Data Sources
[Bullet list of all URLs cited]

Data Quality Rules

  • Every claim needs a source URL — no ungrounded assertions
  • Empty results are intelligence — report them explicitly ("no paste mentions found")
  • Date-stamp all findings — CVE severity, patch status, and breach reports are time-sensitive
  • Confidence tiers:
    • [Confirmed] — primary source (NVD, CISA, vendor advisory)
    • [Reported] — news + community corroboration
    • [Unverified] — single secondary source, flag clearly
  • Parallelize independent actor calls (CVE search + news + Reddit can run simultaneously; the two Reddit runs — netsec, cybersecurity — too)
  • Budget: warn user if >10 actor calls needed; get approval before proceeding

Troubleshooting

ProblemFix
google-search-scraper returns 0 resultsSimplify query, remove site: filter, try broader terms
website-content-crawler times out on NVDUse rag-web-browser as fallback with direct CVE URL
harshmaur/reddit-scraper returns 0 items, or posts from unrelated subredditsRead the RUN-SUMMARY record in the run's key-value store: inputWarnings says when withinCommunity was dropped (more than one name) or a date was unparseable, emptyReason explains 0 items. Shorten the term (Reddit search is literal). Fallback: fatihtahta/reddit-scraper-search-fast with {"subredditName": "netsec", "subredditKeywords": ["[TERM]"], "subredditTimeframe": "month", "maxPosts": 10} ($0.00149 per post, no start fee; fields title, url, subreddit, created_utc, score, num_comments)
tweet-scraper returns sparse resultsBroaden to #cybersecurity [term] or drop hashtag requirement
CISA KEV page too large to crawlUse rag-web-browser with specific CVE ID as query

Example prompts

  • "Check if example.com has any known vulnerabilities or appears in recent breach data."
  • "What's the latest threat intel on CVE-2026-1234 — is it actively exploited?"
  • "Profile the APT28 group — recent campaigns, TTPs, and infrastructure."

Boundary: This skill researches organizations, infrastructure and named threat groups. It won't build cross-platform profiles of private individuals.

apifyのその他のスキル

apify-influencer-brand-collabs
apify
Instagramのブランドとクリエイターのパートナーシップを、Apify Actorsを連鎖させて発見します。ユーザーが「あるブランドとコラボしているのは誰か」「あるクリエイターが有償でどのブランドと…」と尋ねた場合に使用します。
apify-actor-development
apify
サーバーレスクラウドプログラムを作成、デバッグ、デプロイし、Webスクレイピング、自動化、データ処理を実現します。JavaScript、TypeScript、Pythonテンプレートに対応し、HTTPおよびブラウザベースのクローリング用に統合されたCrawlee、Playwright、Cheerioライブラリをサポートします。apify runによる分離ストレージを使用したローカルテスト、入出力のスキーマ検証、apify pushによるApifyプラットフォームへのデプロイを含みます。Apify CLI認証と、AI用の.actor/actor.jsonにおける必須のgeneratedByメタデータが必要です...
apify-actorization
apify
既存のプロジェクトをサーバーレスのApifyアクターに変換し、言語固有のSDK統合を提供します。JavaScript/TypeScript(Actor.init() / Actor.exit())、Python(非同期コンテキストマネージャー)、およびCLIラッパーを介した任意の言語をサポート。構造化されたワークフローを提供:apify initでスキャフォールド、SDKラッピングの適用、入出力スキーマの設定、apify runでローカルテスト、その後apify pushでデプロイ。入出力スキーマの検証、Dockerコンテナ化、およびオプションのペイ・パー・イベントを含む。
apify-content-analytics
apify
Apify Actorsを介したInstagram、Facebook、YouTube、TikTok向けのマルチプラットフォームコンテンツ分析。4つのプラットフォームすべてにおいて、投稿、リール、ストーリー、コメント、ハッシュタグ、フォロワー、広告をカバーする17以上の専門Actorsをサポート。mcpc CLIを使用してActorスキーマを動的に取得し、必要な入力と利用可能な出力フィールドを決定。結果は3つの形式(クイックチャット表示、CSVエクスポート、カスタマイズ可能な結果件数のJSONエクスポート)で出力。.envファイル内のApifyトークンとNode.js 20.6+が必要...
apify-ecommerce
apify
50以上のeコマースマーケットプレイスから製品データ、価格、レビュー、出品者情報を抽出します。3つのワークフローモード:製品と価格(価格追跡、競合分析)、カスタマーレビュー(感情分析、品質問題)、出品者インテリジェンス(Googleショッピング経由のベンダー発見)。Amazon(20以上の地域)、Walmart、eBay、IKEA、Costco、欧州の小売業者に対応。製品URL、カテゴリURL、またはキーワード検索で入力。オプションのAI分析により、価格に関するインサイトを生成します。
apify-generate-output-schema
apify
Apify Actorのソースコードを解析して、出力スキーマ(dataset_schema.json、output_schema.json、key_value_store_schema.json)を生成します。以下の場合に使用します…
apify-influencer-discovery
apify
Instagram、Facebook、YouTube、TikTok全体でApify Actorsを使用してインフルエンサーを発見・評価します。発見リクエストを15以上の専門アクターにルーティングし、プロフィールスクレイピング、ハッシュタグ検索、エンゲージメント分析、全主要プラットフォームでのニッチ発見をカバーします。実行前にmcpcを介してアクタースキーマを動的に取得し、必要な入力と利用可能な出力フィールドを決定します。インラインチャット表示、CSV、JSONファイル出力の3つのエクスポートモードをサポートし、結果数をカスタマイズ可能です...
apify-ultimate-scraper
apify
55以上のプラットフォーム(Instagram、TikTok、YouTube、Facebook、Google Mapsなど)に対応し、最適なActorを選択する自動ウェブスクレイパー。8つの主要プラットフォームにわたる55以上の事前設定済みActorをカバーし、ユースケース別の選択ガイダンス(リード生成、インフルエンサー発見、ブランドモニタリング、競合分析、トレンド調査)を提供。3つの出力形式(クイックチャット表示、CSVエクスポート、カスタマイズ可能な結果制限付きJSONエクスポート)をサポート。複雑な処理のためのマルチActorワークフローパターンを含む...