{"id":"c79bb337-8d6b-46fe-9837-be64a8705b6d","entityType":"agent","slug":"crewai-yoelapu-intelstrike","name":"intelstrike","canonicalUrl":"https://www.xpersona.co/agent/crewai-yoelapu-intelstrike","canonicalPath":"/agent/crewai-yoelapu-intelstrike","generatedAt":"2026-10-09T01:42:55.027Z","source":"GITHUB_OPENCLEW","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-05-18T06:45:23.901Z","emptyReason":null},"description":"AI-powered pipeline that transforms Cyber Threat Intelligence into actionable pentesting test cases using CrewAI and MITRE ATT&CK IntelStrike A multi-agent AI pipeline that operationalizes Cyber Threat Intelligence (CTI) for penetration testing engagements. Built with CrewAI, Claude, and Tavily. --- How It Works Three agents run sequentially, each passing context to the next: Output A Markdown report containing: - **Executive Summary** - threat context for the engagement - **Threat Actor Profiles** - relevant groups and their targeting patterns","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 8 GitHub stars reported by the source. Last updated 5/18/2026.","installCommand":"git clone https://github.com/yoelapu/intelstrike.git","sourceUrl":"https://github.com/yoelapu/intelstrike","homepage":null,"primaryLinks":[{"label":"View Source","url":"https://github.com/yoelapu/intelstrike","kind":"source"}],"safetyScore":66,"overallRank":26.8,"popularityScore":24,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"AI-powered pipeline that transforms Cyber Threat Intelligence into actionable pentesting test cases using CrewAI and MITRE ATT&CK IntelStrike A multi-agent AI p"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-05-18T06:45:23.901Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[{"label":"crewai","status":"self-declared"},{"label":"multi-agent","status":"self-declared"}],"verifiedCount":0,"selfDeclaredCount":3,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"},{"key":"crewai","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"multi-agent","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile capability:crewai|supported|profile capability:multi-agent|supported|profile"}},"adoption":{"evidence":{"source":"GITHUB OPENCLEW","verified":false,"confidence":"medium","updatedAt":"2026-05-18T06:45:23.901Z","emptyReason":null},"stars":8,"forks":0,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":"8 GitHub stars"},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-05-18T06:45:23.900Z","emptyReason":null},"lastUpdatedAt":"2026-05-18T06:45:23.901Z","lastCrawledAt":"2026-05-18T06:45:23.900Z","lastIndexedAt":null,"nextCrawlAt":"2026-05-25T06:45:23.900Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"GITHUB OPENCLEW","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"git clone https://github.com/yoelapu/intelstrike.git","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/crewai-yoelapu-intelstrike/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/crewai-yoelapu-intelstrike/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/crewai-yoelapu-intelstrike/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/crewai-yoelapu-intelstrike/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/crewai-yoelapu-intelstrike/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/crewai-yoelapu-intelstrike/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"GITHUB_OPENCLEW","generatedAt":"2026-10-09T01:42:55.027Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/crewai-yoelapu-intelstrike/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/crewai-yoelapu-intelstrike/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/crewai-yoelapu-intelstrike/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/crewai-yoelapu-intelstrike/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"GITHUB OPENCLEW","verified":false,"confidence":"high","updatedAt":"2026-05-18T06:45:23.901Z","emptyReason":null},"readme":"# IntelStrike\n\nA multi-agent AI pipeline that operationalizes Cyber Threat Intelligence (CTI) for penetration testing engagements. Built with CrewAI, Claude, and Tavily.\n\n---\n\n## How It Works\n\nThree agents run sequentially, each passing context to the next:\n\n```\n[config.py]\n    │\n    ▼\nAgent 1: Threat Profiler\n    Identifies 2-3 threat groups relevant to the client's\n    industry, geography, and tech stack\n    │\n    ▼\nAgent 2: TTP Extractor\n    Extracts and filters TTPs applicable to the known stack,\n    mapped to MITRE ATT&CK, prioritized by exploitation frequency\n    │\n    ▼\nAgent 3: Test Case Builder\n    Translates TTPs into an actionable checklist with steps,\n    tools, payloads, success criteria, and quick wins\n    │\n    ▼\n[intelstrike_report.md]\n```\n\n### Output\n\nA Markdown report containing:\n\n- **Executive Summary** - threat context for the engagement\n- **Threat Actor Profiles** - relevant groups and their targeting patterns\n- **Prioritized TTP Table** - filtered by stack, scored by priority\n- **Actionable Test Cases** - checkbox format with steps, tools, and criteria\n- **Top 5 Quick Wins** - highest impact / lowest effort to tackle first\n- **Threat Narrative** - attack chain story to contextualize findings in reports\n\n---\n\n## Project Structure\n\n```\nintelstrike/\n├── .gitignore         # protects secrets and outputs from version control\n├── README.md\n├── requirements.txt   # dependencies\n├── config.py          # only file you edit per engagement\n├── agents.py          # agent definitions\n├── tasks.py           # task definitions\n└── main.py            # entry point\n```\n\n**config.py**\nCentralized configuration for the pipeline. Contains the engagement profile (industry, geography, tech stack, scope, duration), LLM provider and model selection, output file path, and search settings. This is the only file you need to edit before running a new engagement.\n\n**agents.py**\nDefines the three AI agents used in the pipeline. Each agent has a specific role, goal, and backstory that shapes how it approaches its task. Also contains the `_build_llm()` function that dynamically constructs the LLM object based on the provider configured in `config.py`.\n\n| Agent | Role | Responsibility |\n|---|---|---|\n| `threat_profiler` | Threat Intelligence Analyst | Researches and identifies relevant threat actor groups for the client profile |\n| `ttp_extractor` | Offensive Security TTP Specialist | Extracts and filters TTPs from identified groups, mapped to MITRE ATT&CK |\n| `test_case_builder` | Penetration Testing Lead | Translates TTPs into an actionable pentest checklist |\n\n**tasks.py**\nDefines the three tasks executed by the pipeline, built dynamically using the engagement context from `config.py`. Each task specifies what the agent must do, what output is expected, and which previous task results it has access to via CrewAI's context mechanism.\n\n**main.py**\nEntry point for the pipeline. Imports configuration, initializes the agents and tasks, assembles the CrewAI crew, and runs the pipeline. Also handles the console output that shows the engagement profile before execution starts.\n\n---\n\n## Setup\n\n### Requirements\n\nPython 3.10 or higher is required. CrewAI supports 3.10-3.12.\n\n```bash\npython3 --version  # verify your version\n```\n\n### 1. Create a virtual environment\n\nA virtual environment is recommended on all platforms. It isolates project dependencies and avoids conflicts with system packages.\n\n```bash\npython3 -m venv venv\nsource venv/bin/activate      # Mac / Linux\nvenv\\Scripts\\activate         # Windows\n```\n\nYou should see `(venv)` at the start of your terminal prompt confirming the environment is active.\n\n### 2. Install dependencies\n\n```bash\n./venv/bin/pip3 install -r requirements.txt\n```\n\n### 3. Set environment variables\n\nSet the API key for your chosen LLM provider and Tavily:\n\n```bash\n# Tavily (required for web search)\nexport TAVILY_API_KEY=\"your-key\"      # https://tavily.com (free tier: 1,000 calls/month)\n\n# Choose ONE LLM provider:\nexport ANTHROPIC_API_KEY=\"your-key\"   # https://console.anthropic.com\nexport OPENAI_API_KEY=\"your-key\"      # https://platform.openai.com\nexport GOOGLE_API_KEY=\"your-key\"      # https://aistudio.google.com\nexport GROQ_API_KEY=\"your-key\"        # https://console.groq.com (free tier available)\n# Ollama: no key needed, just run: ollama pull llama3.2\n```\n\n### 4. Configure the engagement\n\nEdit `config.py` with the client's details and your preferred LLM:\n\n```python\n# LLM provider - pick one\nLLM_PROVIDER = \"anthropic\"          # anthropic / openai / google / groq / ollama / azure / bedrock\nLLM_MODEL    = \"claude-sonnet-4-5\"  # model name for the selected provider\n\nENGAGEMENT = {\n    \"client_industry\":  \"Financial Services\",\n    \"client_geography\": \"Latin America\",\n    \"tech_stack\":       [\"WordPress\", \"AWS\", \"MySQL\"],\n    \"scope_type\":       \"web application\",\n    \"scope_focus\":      \"initial access, authentication bypass, data exfiltration\",\n    \"engagement_days\":  10,\n}\n```\n\n**Provider and model examples:**\n\n| Provider | `LLM_PROVIDER` | `LLM_MODEL` |\n|---|---|---|\n| Anthropic | `\"anthropic\"` | `\"claude-sonnet-4-5\"` |\n| OpenAI | `\"openai\"` | `\"gpt-4o\"` |\n| Google Gemini | `\"google\"` | `\"gemini/gemini-1.5-pro\"` |\n| Groq | `\"groq\"` | `\"groq/llama-3.1-70b-versatile\"` |\n| Ollama (local) | `\"ollama\"` | `\"ollama/llama3.2\"` |\n\n### 5. Run the pipeline\n\n```bash\npython main.py\n```\n\nValidate config and API keys without running:\n```bash\npython main.py --dry-run\n```\n\nThe report is saved to `intelstrike_report.md` by default. The output path can be changed in `config.py`.\n\n---\n\n## Configuration Reference\n\nAll settings live in `config.py`:\n\n| Setting | Description | Default |\n|---|---|---|\n| `ENGAGEMENT[\"client_industry\"]` | Client's industry vertical | `\"Financial Services\"` |\n| `ENGAGEMENT[\"client_geography\"]` | Client's operating geography | `\"Latin America\"` |\n| `ENGAGEMENT[\"tech_stack\"]` | Known technologies in scope | `[\"WordPress\", \"AWS\", \"MySQL\"]` |\n| `ENGAGEMENT[\"scope_type\"]` | Type of engagement | `\"web application\"` |\n| `ENGAGEMENT[\"scope_focus\"]` | Key objectives to prioritize within the scope | `\"initial access, authentication bypass, data exfiltration\"` |\n| `ENGAGEMENT[\"engagement_days\"]` | Engagement duration in days | `10` |\n| `OUTPUT_FILE` | Output report filename | `\"intelstrike_report.md\"` |\n| `LLM_PROVIDER` | LLM provider to use | `\"anthropic\"` |\n| `LLM_MODEL` | Model name for the selected provider | `\"claude-sonnet-4-5\"` |\n| `LLM_MAX_ITER` | Max agent iterations | `3` |\n| `VERBOSE` | Console output verbosity | `True` |\n| `SEARCH_MAX_RESULTS` | Tavily results per query | `3` |\n\n---\n\n## Adapting to Different Engagement Types\n\nThe pipeline is not limited to web application testing. It works for any engagement type - the agents adapt their research and TTP selection based on `scope_type`, `scope_focus`, and `tech_stack`.\n\n**Web Application**\n```python\nENGAGEMENT = {\n    \"client_industry\":  \"Financial Services\",\n    \"client_geography\": \"Latin America\",\n    \"tech_stack\":       [\"WordPress\", \"AWS\", \"MySQL\"],\n    \"scope_type\":       \"web application\",\n    \"scope_focus\":      \"initial access, authentication bypass, data exfiltration\",\n    \"engagement_days\":  10,\n}\n```\n\n**Active Directory / Internal Network**\n```python\nENGAGEMENT = {\n    \"client_industry\":  \"Government\",\n    \"client_geography\": \"United States\",\n    \"tech_stack\":       [\"Active Directory\", \"Windows Server 2022\", \"Exchange\"],\n    \"scope_type\":       \"internal network\",\n    \"scope_focus\":      \"lateral movement, privilege escalation, domain compromise\",\n    \"engagement_days\":  14,\n}\n```\n\n**Infrastructure / Network**\n```python\nENGAGEMENT = {\n    \"client_industry\":  \"Energy\",\n    \"client_geography\": \"Europe\",\n    \"tech_stack\":       [\"Cisco IOS\", \"Windows Server\", \"VMware\"],\n    \"scope_type\":       \"infrastructure\",\n    \"scope_focus\":      \"network access, credential harvesting, persistence\",\n    \"engagement_days\":  10,\n}\n```\n\n**Cloud**\n```python\nENGAGEMENT = {\n    \"client_industry\":  \"Technology\",\n    \"client_geography\": \"Asia Pacific\",\n    \"tech_stack\":       [\"AWS\", \"S3\", \"EC2\", \"IAM\", \"Lambda\"],\n    \"scope_type\":       \"cloud\",\n    \"scope_focus\":      \"misconfiguration, IAM privilege escalation, data exfiltration\",\n    \"engagement_days\":  7,\n}\n```\n\n---\n\n## License\n\nMIT - use freely, attribution appreciated.\n","readmeExcerpt":"IntelStrike A multi-agent AI pipeline that operationalizes Cyber Threat Intelligence (CTI) for penetration testing engagements. Built with CrewAI, Claude, and Tavily. --- How It Works Three agents run sequentially, each passing context to the next: Output A Markdown report containing: - **Executive Summary** - threat context for the engagement - **Threat Actor Profiles** - relevant groups and their targeting patterns","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"[config.py]\n    │\n    ▼\nAgent 1: Threat Profiler\n    Identifies 2-3 threat groups relevant to the client's\n    industry, geography, and tech stack\n    │\n    ▼\nAgent 2: TTP Extractor\n    Extracts and filters TTPs applicable to the known stack,\n    mapped to MITRE ATT&CK, prioritized by exploitation frequency\n    │\n    ▼\nAgent 3: Test Case Builder\n    Translates TTPs into an actionable checklist with steps,\n    tools, payloads, success criteria, and quick wins\n    │\n    ▼\n[intelstrike_report.md]"},{"language":"text","snippet":"intelstrike/\n├── .gitignore         # protects secrets and outputs from version control\n├── README.md\n├── requirements.txt   # dependencies\n├── config.py          # only file you edit per engagement\n├── agents.py          # agent definitions\n├── tasks.py           # task definitions\n└── main.py            # entry point"},{"language":"bash","snippet":"python3 --version  # verify your version"},{"language":"bash","snippet":"python3 -m venv venv\nsource venv/bin/activate      # Mac / Linux\nvenv\\Scripts\\activate         # Windows"},{"language":"bash","snippet":"./venv/bin/pip3 install -r requirements.txt"},{"language":"bash","snippet":"# Tavily (required for web search)\nexport TAVILY_API_KEY=\"your-key\"      # https://tavily.com (free tier: 1,000 calls/month)\n\n# Choose ONE LLM provider:\nexport ANTHROPIC_API_KEY=\"your-key\"   # https://console.anthropic.com\nexport OPENAI_API_KEY=\"your-key\"      # https://platform.openai.com\nexport GOOGLE_API_KEY=\"your-key\"      # https://aistudio.google.com\nexport GROQ_API_KEY=\"your-key\"        # https://console.groq.com (free tier available)\n# Ollama: no key needed, just run: ollama pull llama3.2"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["python"],"docsSourceLabel":"GITHUB OPENCLEW","editorialOverview":"AI-powered pipeline that transforms Cyber Threat Intelligence into actionable pentesting test cases using CrewAI and MITRE ATT&CK IntelStrike A multi-agent AI pipeline that operationalizes Cyber Threat Intelligence (CTI) for penetration testing engagements. Built with CrewAI, Claude, and Tavily. --- How It Works Three agents run sequentially, each passing context to the next: Output A Markdown report containing: - **Executive Summary** - threat context for the engagement - **Threat Actor Profiles** - relevant groups and their targeting patterns","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":365,"uniquenessScore":71,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-05-18T06:45:23.901Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-05-18T06:45:23.901Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T01:42:55.027Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/github_openclew","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}