{"id":"794a8497-7015-4f34-8a38-bd6b99ee5d9d","slug":"clawhub-ling-qian-threat-actor-osint","name":"Threat Actor OSINT Profiling","description":"Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary motivations, capabilities, infrastructure,...","canonicalUrl":"https://www.xpersona.co/agent/clawhub-ling-qian-threat-actor-osint","sourceUrl":"https://clawhub.ai/ling-qian/threat-actor-osint","homepage":"https://clawhub.ai/ling-qian/skills/threat-actor-osint","source":"CLAWHUB","vendor":{"slug":"clawhub","label":"Clawhub","url":"https://clawhub.ai/ling-qian/skills/threat-actor-osint"},"protocols":["OPENCLEW"],"capabilities":[],"trustScore":null,"trustConfidence":"unknown","artifactCount":0,"benchmarkCount":0,"lastRelease":"1.0.0","freshnessAt":"2026-10-11T10:39:52.963Z","freshnessLabel":"Oct 11, 2026","securityReviewed":true,"openapiReady":false,"stats":[{"label":"Trust score","value":"Unknown"},{"label":"Compatibility","value":"OpenClaw"},{"label":"Freshness","value":"Oct 11, 2026"},{"label":"Vendor","value":"Clawhub"},{"label":"Artifacts","value":"0"},{"label":"Benchmarks","value":"0"},{"label":"Last release","value":"1.0.0"}],"factsPreview":[{"factKey":"vendor","category":"vendor","label":"Vendor","value":"Clawhub","href":"https://clawhub.ai/ling-qian/skills/threat-actor-osint","sourceUrl":"https://clawhub.ai/ling-qian/skills/threat-actor-osint","sourceType":"profile","confidence":"medium","observedAt":"2026-10-11T10:39:52.977Z","isPublic":true},{"factKey":"protocols","category":"compatibility","label":"Protocol compatibility","value":"OpenClaw","href":"https://www.xpersona.co/api/v1/agents/clawhub-ling-qian-threat-actor-osint/contract","sourceUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ling-qian-threat-actor-osint/contract","sourceType":"contract","confidence":"medium","observedAt":"2026-10-11T10:39:52.977Z","isPublic":true},{"factKey":"traction","category":"adoption","label":"Adoption signal","value":"1.1K downloads","href":"https://clawhub.ai/ling-qian/threat-actor-osint","sourceUrl":"https://clawhub.ai/ling-qian/threat-actor-osint","sourceType":"profile","confidence":"medium","observedAt":"2026-10-11T10:39:52.977Z","isPublic":true},{"factKey":"latest_release","category":"release","label":"Latest release","value":"1.0.0","href":"https://clawhub.ai/ling-qian/threat-actor-osint","sourceUrl":"https://clawhub.ai/ling-qian/threat-actor-osint","sourceType":"release","confidence":"medium","observedAt":"2026-05-26T10:15:26.947Z","isPublic":true},{"factKey":"handshake_status","category":"security","label":"Handshake status","value":"UNKNOWN","href":"https://www.xpersona.co/api/v1/agents/clawhub-ling-qian-threat-actor-osint/trust","sourceUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ling-qian-threat-actor-osint/trust","sourceType":"trust","confidence":"medium","observedAt":null,"isPublic":true}],"highlights":["1.1K downloads","Trust evidence available"],"agentCard":{"name":"Threat Actor OSINT Profiling","description":"Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary motivations, capabilities, infrastructure,...","source":"CLAWHUB","sourceId":"clawhub:s175jefjcmzh2jnhq3pyabyzr985cjma:threat-actor-osint","homepage":"https://clawhub.ai/ling-qian/skills/threat-actor-osint","repository":"https://clawhub.ai/ling-qian/threat-actor-osint","documentation":"https://www.xpersona.co/agent/clawhub-ling-qian-threat-actor-osint","protocols":["OPENCLEW"],"examples":[{"kind":"example","language":"python","snippet":"import requests\nimport json\nfrom datetime import datetime\n\nclass OSINTCollector:\n    def __init__(self, vt_key=None, otx_key=None, shodan_key=None):\n        self.vt_key = vt_key\n        self.otx_key = otx_key\n        self.shodan_key = shodan_key\n        self.collected_data = {\"sources\": [], \"indicators\": [], \"reports\": []}\n\n    def search_alienvault_otx(self, actor_name):\n        \"\"\"Search AlienVault OTX for threat actor pulses.\"\"\"\n        headers = {\"X-OTX-API-KEY\": self.otx_key}\n        url = f\"https://otx.alienvault.com/api/v1/search/pulses?q={actor_name}&limit=20\"\n        resp = requests.get(url, headers=headers)\n        if resp.status_code == 200:\n            data = resp.json()\n            pulses = data.get(\"results\", [])\n            for pulse in pulses:\n                self.collected_data[\"reports\"].append({\n                    \"source\": \"AlienVault OTX\",\n                    \"title\": pulse.get(\"name\", \"\"),\n                    \"created\": pulse.get(\"created\", \"\"),\n                    \"description\": pulse.get(\"description\", \"\")[:500],\n                    \"tags\": pulse.get(\"tags\", []),\n                    \"indicators_count\": len(pulse.get(\"indicators\", [])),\n                    \"pulse_id\": pulse.get(\"id\", \"\"),\n                })\n                for ioc in pulse.get(\"indicators\", []):\n                    self.collected_data[\"indicators\"].append({\n                        \"type\": ioc.get(\"type\", \"\"),\n                        \"value\": ioc.get(\"indicator\", \"\"),\n                        \"source\": \"OTX\",\n                        \"pulse\": pulse.get(\"name\", \"\"),\n                    })\n            print(f\"[+] OTX: Found {len(pulses)} pulses for '{actor_name}'\")\n        return self.collected_data\n\n    def search_virustotal_collections(self, actor_name):\n        \"\"\"Search VirusTotal for threat actor collections.\"\"\"\n        headers = {\"x-apikey\": self.vt_key}\n        url = \"https://www.virustotal.com/api/v3/intelligence/search\"\n        params = {\"query\": f\"tag:{actor_name.lower()"},{"kind":"example","language":"python","snippet":"from stix2 import ThreatActor, IntrusionSet, Identity, Relationship, Bundle\nfrom datetime import datetime\n\n# Create STIX 2.1 Threat Actor profile\nidentity = Identity(\n    name=\"Cybersecurity Analyst\",\n    identity_class=\"individual\",\n)\n\nthreat_actor = ThreatActor(\n    name=\"APT29\",\n    description=\"APT29 (also known as Cozy Bear, Midnight Blizzard, NOBELIUM, The Dukes) \"\n                \"is a Russian state-sponsored threat group attributed to Russia's Foreign \"\n                \"Intelligence Service (SVR). Active since at least 2008, the group conducts \"\n                \"cyber espionage targeting government, diplomatic, think tank, healthcare, \"\n                \"and energy organizations primarily in NATO countries.\",\n    aliases=[\"Cozy Bear\", \"Midnight Blizzard\", \"NOBELIUM\", \"The Dukes\",\n             \"Dark Halo\", \"UNC2452\", \"YTTRIUM\", \"Blue Kitsune\", \"Iron Ritual\"],\n    roles=[\"agent\"],\n    sophistication=\"strategic\",\n    resource_level=\"government\",\n    primary_motivation=\"organizational-gain\",\n    secondary_motivations=[\"ideology\"],\n    threat_actor_types=[\"nation-state\"],\n    goals=[\"Intelligence collection on foreign governments\",\n           \"Long-term persistent access to high-value targets\",\n           \"Supply chain compromise for broad access\"],\n    created_by_ref=identity.id,\n)\n\nintrusion_set = IntrusionSet(\n    name=\"APT29\",\n    description=\"Intrusion set tracked as APT29, attributed to Russian SVR.\",\n    aliases=[\"Cozy Bear\", \"Midnight Blizzard\"],\n    first_seen=\"2008-01-01T00:00:00Z\",\n    goals=[\"espionage\"],\n    resource_level=\"government\",\n    primary_motivation=\"organizational-gain\",\n)\n\nrelationship = Relationship(\n    relationship_type=\"attributed-to\",\n    source_ref=intrusion_set.id,\n    target_ref=threat_actor.id,\n)\n\nbundle = Bundle(objects=[identity, threat_actor, intrusion_set, relationship])\nwith open(\"apt29_profile.json\", \"w\") as f:\n    f.write(bundle.serialize(pretty=True))\nprint(\"[+] STIX profile saved: apt29_profile.json\")"}]}}