apify-osint-threat-intel

작성자: apify

사용자가 "CVE 찾아줘", "내 도메인 침해 여부 확인해줘", "위협 인텔리전스", "OSINT", "보안 뉴스", "공격 표면" 등에 대해 물어볼 때 이 스킬을 사용하세요…

npx skills add https://github.com/apify/awesome-skills --skill apify-osint-threat-intel

OSINT Threat Intelligence

Real-time security intelligence powered by live threat data via Apify actors. Never answer security questions from training knowledge alone. CVEs, breaches, and threat actor activity change daily — always gather live data first, then analyze.


Prerequisites

CLI rules (always follow)

Always pass --user-agent apify-awesome-skills/apify-osint-threat-intel on every apify CLI call — it's critical for telemetry, never omit it.

apify actors call "ACTOR_ID" -i 'INPUT_JSON' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null
apify datasets get-items DATASET_ID --format json --user-agent apify-awesome-skills/apify-osint-threat-intel > /tmp/results.json 2>/dev/null
jq '.[] | "\(.field1) | \(.field2)"' /tmp/results.json
apify actors info "ACTOR_ID" --input --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null   # check schema

Actor Routing Table

Data NeedActor IDNotes
CVE lookupapify/google-search-scraperQuery: site:nvd.nist.gov [product] [version]
NVD full recordapify/website-content-crawlerURL: nvd.nist.gov/vuln/detail/CVE-XXXX-XXXXX
CISA known exploitedapify/rag-web-browserURL: cisa.gov/known-exploited-vulnerabilities-catalog
GitHub advisoriesapify/rag-web-browserURL: github.com/advisories?query=[product]
Exploit-DB searchapify/google-search-scraperQuery: site:exploit-db.com [product] [version]
Security newsdata_xplorer/google-news-scraper-fastKeywords: "[target]" vulnerability OR exploit OR breach
Reddit threat discussionharshmaur/reddit-scrapersearchTerms + withinCommunity — one subreddit per run (netsec, then a second run for cybersecurity); a value like netsec OR cybersecurity silently drops the filter and searches all of Reddit. Always set postedAfter (YYYY-MM-DD) for recency — searchTime is not enforced and the Actor pads the cap with years-old posts. Pay-per-event: $0.02 per run + $0.002 per post; maxPostsCount is per search term.
Threat intel Twitter/Xapidojo/tweet-scraperKeywords: #threatintel [target], search mode
Breach mention searchapify/google-search-scraperQuery: "[domain]" site:pastebin.com OR intext:breach
Vendor security advisoryapify/website-content-crawlerDirect vendor security page URL
Shodan exposure hintsapify/google-search-scraperQuery: site:shodan.io "[domain OR org name]"
Threat actor researchapify/rag-web-browserMITRE ATT&CK: attack.mitre.org/groups/

Prefer apify/google-search-scraper and apify/rag-web-browser over website-content-crawler for speed.
Use website-content-crawler only when you need the full page body (e.g. NVD detail, vendor advisory).
Do NOT use website-content-crawler on: reddit.com, twitter.com, pastebin.com, linkedin.com.


Core Workflow

Step 0 — Clarify scope before running anything

Ask the user:

  • Target type: domain, IP, software/version, CVE ID, threat actor name, or keyword?
  • Goal: one-time lookup vs. ongoing monitoring brief?
  • Autonomy: full autopilot, or checkpoint before each actor call?

Step 1 — Identify module

User saysModuleSteps
"Find CVEs for [product]"CVE Intelligence2a
"Is [domain] breached / exposed"Domain Threat Profile2b
"Research [threat actor / malware]"Threat Actor Profile2c
"Security news about [topic]"Security News Brief2d
"Attack surface of [company]"Attack Surface Discovery2b + 2d
"Full threat report on [target]"Multi-Module2a + 2b + 2c + 2d

Step 2a — CVE Intelligence

Gather live CVE data for a product or version:

# 1. Search NVD via Google
apify actors call "apify/google-search-scraper" -i '{
  "queries": "site:nvd.nist.gov CVE [PRODUCT] [VERSION]",
  "maxPagesPerQuery": 1
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 2. Pull full NVD record for each CVE ID found
apify actors call "apify/website-content-crawler" -i '{
  "startUrls": [{"url": "https://nvd.nist.gov/vuln/detail/CVE-XXXX-XXXXX"}],
  "proxyConfiguration": {"useApifyProxy": true},
  "maxCrawlPages": 1
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 3. Check if CVE is in CISA's Known Exploited Vulnerabilities list
apify actors call "apify/rag-web-browser" -i '{
  "query": "[CVE-ID] site:cisa.gov/known-exploited-vulnerabilities-catalog",
  "maxResults": 3
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 4. Check Exploit-DB for public PoC
apify actors call "apify/google-search-scraper" -i '{
  "queries": "site:exploit-db.com [PRODUCT] [VERSION]",
  "maxPagesPerQuery": 1
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

Synthesize: severity (CVSS), exploitability (CISA KEV = active exploitation), public PoC exists (yes/no), patch available (yes/no).

Step 2b — Domain Threat Profile

# 1. Search for breach mentions
apify actors call "apify/google-search-scraper" -i '{
  "queries": "\"[DOMAIN]\" breach OR leak OR hacked OR \"data exposed\"",
  "maxPagesPerQuery": 1
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 2. Check paste sites for credential leaks
apify actors call "apify/google-search-scraper" -i '{
  "queries": "\"[DOMAIN]\" site:pastebin.com OR site:ghostbin.com OR site:rentry.co",
  "maxPagesPerQuery": 1
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 3. Check Shodan exposure hints via Google
apify actors call "apify/google-search-scraper" -i '{
  "queries": "site:shodan.io \"[DOMAIN OR ORG]\"",
  "maxPagesPerQuery": 1
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 4. Scan r/netsec for mentions — one subreddit per run; repeat with "withinCommunity": "cybersecurity"
#    postedAfter = today minus 365 days (YYYY-MM-DD). 3 terms × 5 posts = 15 posts ≈ $0.05.
#    Use `postUrl` as the Source and `createdAt` for the date stamp.
apify actors call "harshmaur/reddit-scraper" -i '{
  "searchTerms": ["[DOMAIN] breach", "[DOMAIN] hack", "[DOMAIN] vulnerability"],
  "withinCommunity": "netsec",
  "postedAfter": "[YYYY-MM-DD]",
  "maxPostsCount": 5,
  "crawlCommentsPerPost": false
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

Step 2c — Threat Actor Profile

# 1. MITRE ATT&CK lookup
apify actors call "apify/rag-web-browser" -i '{
  "query": "[THREAT ACTOR NAME] site:attack.mitre.org",
  "maxResults": 3
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 2. Recent activity via news
apify actors call "data_xplorer/google-news-scraper-fast" -i '{
  "keywords": ["[THREAT ACTOR NAME] attack OR campaign OR malware"],
  "timeframe": "30d",
  "maxArticles": 15
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 3. Community threat intel on Twitter/X
apify actors call "apidojo/tweet-scraper" -i '{
  "searchTerms": ["#threatintel [THREAT ACTOR]", "[THREAT ACTOR] TTPs"],
  "maxItems": 20,
  "sort": "Latest"
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 4. Reddit discussion — postedAfter = today minus 365 days; `createdAt` of the newest post = "Last seen"
apify actors call "harshmaur/reddit-scraper" -i '{
  "searchTerms": ["[THREAT ACTOR NAME]"],
  "withinCommunity": "netsec",
  "postedAfter": "[YYYY-MM-DD]",
  "maxPostsCount": 10,
  "crawlCommentsPerPost": false
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

Step 2d — Security News Brief

# 1. Google News for topic
apify actors call "data_xplorer/google-news-scraper-fast" -i '{
  "keywords": ["[TOPIC] vulnerability OR CVE OR breach OR exploit"],
  "timeframe": "7d",
  "maxArticles": 20
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

# 2. Reddit r/netsec latest — sort goes into the URL (/new/); `searchSort` does not apply to startUrls
apify actors call "harshmaur/reddit-scraper" -i '{
  "startUrls": [{"url": "https://www.reddit.com/r/netsec/new/"}],
  "maxPostsCount": 15,
  "crawlCommentsPerPost": false
}' --user-agent apify-awesome-skills/apify-osint-threat-intel --json 2>/dev/null

Step 3 — Triage and assess

For every finding, apply this classification:

SeverityCriteria
CriticalCVSS ≥ 9.0 OR on CISA KEV list OR public PoC + unpatched
HighCVSS 7.0–8.9 OR active exploitation reported in news
MediumCVSS 4.0–6.9 OR breach mention without active exploit
LowCVSS < 4.0 OR historical, patched, no active exploitation
InformationalExposure hints without confirmed vulnerability

Step 4 — Deliver structured report

Output format:

## Threat Intelligence Report — [TARGET]
Date: [today]

### Executive Summary
[2–3 sentence risk verdict]

### Critical Findings
- [CVE/Finding] — Severity: [X] — Status: [Patched/Unpatched/Active exploit]
  Source: [URL]

### Breach/Exposure Indicators
- [Finding] — Source: [URL]

### Threat Actor Activity (if applicable)
- [Actor] — TTPs: [list] — Last seen: [date]

### Recommended Actions
1. [Immediate action]
2. [Short-term action]
3. [Monitoring recommendation]

### Data Sources
[Bullet list of all URLs cited]

Data Quality Rules

  • Every claim needs a source URL — no ungrounded assertions
  • Empty results are intelligence — report them explicitly ("no paste mentions found")
  • Date-stamp all findings — CVE severity, patch status, and breach reports are time-sensitive
  • Confidence tiers:
    • [Confirmed] — primary source (NVD, CISA, vendor advisory)
    • [Reported] — news + community corroboration
    • [Unverified] — single secondary source, flag clearly
  • Parallelize independent actor calls (CVE search + news + Reddit can run simultaneously; the two Reddit runs — netsec, cybersecurity — too)
  • Budget: warn user if >10 actor calls needed; get approval before proceeding

Troubleshooting

ProblemFix
google-search-scraper returns 0 resultsSimplify query, remove site: filter, try broader terms
website-content-crawler times out on NVDUse rag-web-browser as fallback with direct CVE URL
harshmaur/reddit-scraper returns 0 items, or posts from unrelated subredditsRead the RUN-SUMMARY record in the run's key-value store: inputWarnings says when withinCommunity was dropped (more than one name) or a date was unparseable, emptyReason explains 0 items. Shorten the term (Reddit search is literal). Fallback: fatihtahta/reddit-scraper-search-fast with {"subredditName": "netsec", "subredditKeywords": ["[TERM]"], "subredditTimeframe": "month", "maxPosts": 10} ($0.00149 per post, no start fee; fields title, url, subreddit, created_utc, score, num_comments)
tweet-scraper returns sparse resultsBroaden to #cybersecurity [term] or drop hashtag requirement
CISA KEV page too large to crawlUse rag-web-browser with specific CVE ID as query

Example prompts

  • "Check if example.com has any known vulnerabilities or appears in recent breach data."
  • "What's the latest threat intel on CVE-2026-1234 — is it actively exploited?"
  • "Profile the APT28 group — recent campaigns, TTPs, and infrastructure."

Boundary: This skill researches organizations, infrastructure and named threat groups. It won't build cross-platform profiles of private individuals.

apify의 다른 스킬

apify-influencer-brand-collabs
apify
인스타그램 브랜드-크리에이터 파트너십을 Apify 액터를 연결하여 발견하세요. 사용자가 브랜드와 협업하는 사람, 크리에이터가 유료로 진행한 브랜드 등을 물을 때 사용하세요.
apify-actor-development
apify
서버리스 클라우드 프로그램을 생성, 디버깅 및 배포하여 웹 스크래핑, 자동화 및 데이터 처리를 수행합니다. JavaScript, TypeScript 및 Python 템플릿을 지원하며, HTTP 및 브라우저 기반 크롤링을 위한 통합 Crawlee, Playwright 및 Cheerio 라이브러리를 포함합니다. 격리된 스토리지와 함께 apify run을 통한 로컬 테스트, 입력/출력에 대한 스키마 검증, apify push를 통한 Apify 플랫폼 배포를 포함합니다. Apify CLI 인증 및 AI를 위한 .actor/actor.json의 필수 generatedBy 메타데이터가 필요합니다...
apify-actorization
apify
기존 프로젝트를 언어별 SDK 통합을 통해 서버리스 Apify Actor로 변환합니다. JavaScript/TypeScript(Actor.init() / Actor.exit() 사용), Python(비동기 컨텍스트 매니저), CLI 래퍼를 통한 모든 언어를 지원합니다. 구조화된 워크플로우를 제공합니다: apify init으로 스캐폴딩, SDK 래핑 적용, 입출력 스키마 구성, apify run으로 로컬 테스트, apify push로 배포. 입출력 스키마 검증, Docker 컨테이너화, 선택적 이벤트당 과금을 포함합니다.
apify-content-analytics
apify
Apify Actors를 통한 Instagram, Facebook, YouTube, TikTok의 멀티 플랫폼 콘텐츠 분석. 네 플랫폼의 게시물, 릴스, 스토리, 댓글, 해시태그, 팔로워, 광고를 포함한 17개 이상의 특화 Actors를 지원합니다. mcpc CLI를 사용하여 Actor 스키마를 동적으로 가져와 필요한 입력과 사용 가능한 출력 필드를 결정합니다. 빠른 채팅 표시, CSV 내보내기, JSON 내보내기(결과 수 사용자 지정 가능)의 세 가지 형식으로 결과를 출력합니다. .env 파일에 Apify 토큰이 필요하며 Node.js 20.6+가 필요합니다...
apify-ecommerce
apify
50개 이상의 전자상거래 마켓플레이스에서 제품 데이터, 가격, 리뷰, 판매자 정보를 추출합니다. 세 가지 워크플로우 모드: 제품 및 가격(가격 추적, 경쟁사 분석), 고객 리뷰(감정 분석, 품질 문제), 판매자 인텔리전스(Google Shopping을 통한 공급업체 발견). Amazon(20개 이상 지역), Walmart, eBay, IKEA, Costco, 유럽 소매업체 지원; 제품 URL, 카테고리 URL 또는 키워드 검색을 통해 입력. 선택적 AI 기반 분석으로 가격에 대한 인사이트를 생성합니다...
apify-generate-output-schema
apify
Apify Actor의 소스 코드를 분석하여 출력 스키마(dataset_schema.json, output_schema.json, key_value_store_schema.json)를 생성합니다. 다음과 같은 경우에 사용하세요…
apify-influencer-discovery
apify
Instagram, Facebook, YouTube, TikTok에서 Apify Actors를 사용하여 인플루언서를 발견하고 평가합니다. 발견 요청을 15개 이상의 전문 Actors로 라우팅하여 프로필 스크래핑, 해시태그 검색, 참여도 분석, 모든 주요 플랫폼의 틈새 발견을 다룹니다. 실행 전에 mcpc를 통해 Actor 스키마를 동적으로 가져와 필요한 입력과 사용 가능한 출력 필드를 결정합니다. 인라인 채팅 표시, CSV 또는 JSON 파일 출력의 세 가지 내보내기 모드를 지원하며 결과 수를 사용자 지정할 수 있습니다...
apify-ultimate-scraper
apify
Instagram, TikTok, YouTube, Facebook, Google Maps 등 55개 이상의 플랫폼에 최적의 Actor를 선택하는 자동화된 웹 스크래퍼. 8개 주요 플랫폼에 걸쳐 55개 이상의 사전 구성된 Actor를 포함하며, 사용 사례별 선택 가이드(리드 생성, 인플루언서 발굴, 브랜드 모니터링, 경쟁사 분석, 트렌드 조사)를 제공합니다. 빠른 채팅 표시, CSV 내보내기, 또는 사용자 정의 가능한 결과 제한이 있는 JSON 내보내기의 세 가지 출력 형식을 지원합니다. 복잡한 작업을 위한 다중 Actor 워크플로 패턴을 포함합니다...