"Knowing the enemy is the first step to defending yourself."
OSINT Analyst & Digital Threat Hunter
Research · Intelligence · Development
Threat Intelligence Analyst with a primary focus on persistent threats, hacktivist coalitions, and organized cybercrime. Specialized in Open Source Intelligence (OSINT), Tactics, Techniques, and Procedures (TTP) analysis aligned with the MITRE ATT&CK framework, and the development of early warning systems for detecting malicious infrastructure.
All operations are conducted strictly through open sources and publicly available data, in full compliance with legal and ethical standards. The approach is oriented toward producing actionable intelligence for the defense of critical infrastructure and national strategic interests.
Operational anonymity is maintained until formal engagement with institutional entities (SOCs, CSIRTs, Governments) is established, subject to NDA or formal contract. Personal identifying information is disclosed exclusively upon verified institutional interest and confidentiality guarantees.
| Area | Description |
|---|---|
| 🔍 Threat Intelligence Monitoring | Continuous monitoring of threat actors, campaigns, and TTP evolution. |
| 🎣 Phishing Campaign Analysis | In-depth analysis of phishing campaigns, infrastructure tracking, and malware correlation. |
| 👤 Threat Actor Profiling | Attribution and behavioral profiling of APT groups, hacktivists, and cybercriminal syndicates. |
| 🌐 OSINT Investigations | Custom OSINT investigations across surface, deep, and dark web sources. |
| 📊 Executive & Technical Reporting | Tailored intelligence reports for both technical teams and executive leadership. |
| 🤖 Python Automation for CTI/OSINT | Development of scrapers, ETL pipelines, and automation workflows for intelligence gathering. |
| ⚡ IOC Collection & Enrichment | Aggregation, enrichment, and correlation of Indicators of Compromise (IoCs). |
| 🛠️ Custom Tool Development | Design and deployment of bespoke security tools for defensive and investigative purposes. |
| 📡 Cybercriminal Ecosystem Monitoring | Continuous surveillance of cybercriminal forums, Telegram channels, and underground markets. |
| 🛡️ Strategic Security Consulting | Advisory services for institutional cybersecurity strategy and risk management. |
Python · OSINT · CTI · Flask · APIs · Automation · MITRE ATT&CK · Git · Linux
Threat Intelligence · Passive OSINT · Pro-Russian Group Analysis · Killnet/NoName Tracking · LATAM Organized Crime · DDoS Infrastructure Mapping · Mass Scraping · Actor Attribution · Scanning Prevention · Botnet Monitoring · Defensive Social Engineering · Intelligence Dashboards · Cyber Crime Analytics
| Domain | Description |
|---|---|
| Pro-Russian Hacktivism | Active tracking of Killnet, NoName057(16), DarkStorm, RootSec, Electus, and BotnetKingdom. Comprehensive DDoS infrastructure and TTP mapping. |
| Organized Crime (LATAM & Europe) | Analysis of drug trafficking, extortion, homicides, and gender-based violence patterns using passive OSINT on digital press (Diabolic suite). |
| Malicious Infrastructure | Domain, IP, SSL certificate, WHOIS, JARM fingerprinting, and IOC correlation for actor attribution (ShinyHunters, LAPSUS$, etc.). |
| Advanced OSINT | Mass data extraction from Telegram, Discord, forums, and digital press. Geolocation, digital footprint analysis, and public data correlation. |
| Threat Prevention | Early warning systems (Andrómeda) and monitoring dashboards for botnets and aggressive scanning (Nebula). |
| Defensive Social Engineering | Phishing attack detection and simulation for training and reporting of severe crimes (pedophilia, terrorism). |
| Role | Description |
|---|---|
| 🔍 Threat Intelligence Analyst | Monitoring, analysis, and reporting on actors and campaigns (APT, hacktivism, organized crime). |
| 🛡️ Purple Team / Threat Hunter | Proactive detection, IoC correlation, adversary emulation, and defense gap identification. |
| 🌐 OSINT Investigator | Digital footprint analysis, infrastructure geolocation, and public record correlation for legal or corporate cases. |
| 🤖 Automation Developer (CTI/OSINT) | Development of scrapers, dashboards, API integrations, and ETL pipelines for intelligence. |
| 📊 Cybercrime Analyst | Analysis of criminal patterns in LATAM, Europe, and Spanish-speaking regions. |
| 🧠 Security Consultant / Advisor | Strategic cyber defense advisory, risk management, and incident response planning. |
MITRE ATT&CK · TTPs · IoCs · Purple Team · Threat Hunting · Threat Intelligence · Passive OSINT · Cyber Crime Analytics · DevOps · CI/CD Pipelines · Diamond Model · Cyber Kill Chain
| Project | Description | Status |
|---|---|---|
| 🌌 Nebula AntiScan | Public demo for aggressive scan detection, Killnet IP tracking, and botnet monitoring. Integrates 73 OSINT sources and 80 intelligence feeds. | ✅ Public |
| 🕵️ LYRA OSINT | Public OSINT query tool for phone numbers, emails, IPs, and usernames across 300+ platforms. | ✅ Public |
| 🦅 TrueCall_Condor | OSINT tool for documenting scam calls, phishing domains, and fraudulent URLs. | ✅ Public |
| 📡 Andrómeda | Private counter-intelligence system for DDoS monitoring, botnet tracking, and 3D threat mapping. +250k alerts processed. | 🔒 Private |
| ⚓ OCEANUS-AI v4.5 | Private maritime monitoring system for geo-route tracking and anti-narco operations. | 🔒 Private |
This section provides direct access to all publicly available intelligence reports, dossiers, and in-depth CTI analyses. These reports form an interconnected intelligence web covering hacktivism, organized crime, hybrid threats, and specific incident investigations.
| # | Report / Dossier | Description | Direct Link |
|---|---|---|---|
| 1 | KillNet | Strategic dossier on the evolution, structure, operations, alliances, and campaigns attributed to the KillNet ecosystem and related groups. | → Repo |
| 2 | NoName057(16) | Public threat intelligence tracker for the cybercriminal/hacktivist group NoName057(16), associated with GreenSnow botnet and Emotet. | → Repo |
| 3 | cti-xv-dpx | Complete CTI dossier on X-VDP-X (diable'fire) and the France Cyber Défense breach. Includes TTP analysis, IOCs, and French legal framework. | → Repo |
| 4 | CIBERWAR | OSINT intelligence dossier on Killnet, NoName057(16), and the new generation of hybrid threats. | → Repo |
| 5 | Dossier 764 & Gov.eth | Comprehensive dossier on the 764 terrorist network (satanic-neonazi sect) and the cybercriminal Gov.eth, analyzing modus operandi, ideology, and social impact. | → Repo |
| 6 | CTI GLOBAL REPORT | Global analysis of cyberspace and the invisible war. A macro-level threat intelligence report. | → Repo |
| 7 | CTI RUSSIAN REPORT | Complete dossier on Russian cyber threats. Analysis of actors, TTPs, and infrastructure. | → Repo |
| 8 | Campaign Phishing AEAT | Analysis of a mass phishing campaign impersonating the Spanish Tax Agency (AEAT), including associated malware. | → Repo |
| 9 | ShinyHunters Infrastructure | CTI analysis of shinyhunte.red - Official infrastructure of the ShinyHunters group (2026). | → Repo |
| 10 | Jabaroot | Analysis of the Jabaroot threat actor: hacktivist with OSINT and information operations (info-ops) capabilities. Active since April 2025. | → Repo |
| 11 | IP BruteForce from China | Report on mass brute-force attacks originating from China. Sources: OSINT, Telegram monitoring, Andromeda tools, and prior CTI reports. | → Repo |
| 12 | Threat Intelligence Report (1 Jul 2026) | Comprehensive threat intelligence report. Classification: PUBLIC - INFORMATIVE. Purpose: public awareness and technical documentation. | → Repo |
| 13 | Dossier goo.su | Complete CTI dossier on the goo.su case. | → Repo |
| 14 | Multi-Malware Campaign | Analysis of a multi-malware campaign: China IP + CardSpy + GandCrab. | → Repo |
| 15 | Phishing Infrastructure .shop | Identification of active malicious infrastructure focused on IP 104.17.231.54 (Cloudflare), hosting a network of .shop phishing domains. | → Repo |
| 16 | Twitter Malware Campaign | Analysis of a malware distribution campaign targeting Android devices using compromised Twitter accounts as the initial attack vector. | → Repo |
| 17 | SpamCall | Documentation of heavy spam calling in León, Spain. Identity spoofing alert. | → Repo |
| 18 | Ciberseguridad para humanos | Educational series designed for civilians. Explained in Spanish with real examples, victim stories, and actionable steps. | → Repo |
| 19 | Dead Man's Switch | Digital will with a contingency mechanism for the release of critical intelligence. | → Repo |
| 20 | Diabolic Italia | Passive and analytical OSINT platform monitoring 70+ Italian digital newspapers for criminal pattern detection. | → Repo |
| 21 | Diabolic Peninsular | OSINT platform analyzing 60+ Spanish mainland newspapers to detect criminal patterns. | → Repo |
| 22 | Diabolic Baleares | OSINT platform analyzing 18 Balearic Islands newspapers for criminal patterns (robberies, scams, drug trafficking). | → Repo |
| 23 | Diabolic Canarias | Passive analytical OSINT monitoring of Canary Islands digital newspapers (CRIME focus). | → Repo |
| 24 | Diabolic Francia | OSINT social aid platform monitoring housing, employment, food, health, and poverty in France. 30+ sources, 96 departments, 3 languages. | → Repo |
| 25 | Keltic Kraken | Ireland Criminal Intelligence Platform - Monitoring crime patterns in Ireland. | → Repo |
| 26 | Diabolic Latam | Proactive-passive OSINT analytics tool for detecting and analyzing criminal patterns in Latin America. | → Repo |
| 27 | Diabolic Alemania | OSINT platform for Germany. | → Repo |
Note: These reports are interconnected. For instance, the Russian hacktivist ecosystem (CIBERWAR, Killnet, NoName) feeds into the CTI RUSSIAN and CTI GLOBAL reports, while regional criminal analyses (Diabolic series, Keltic Kraken) provide ground-level OSINT validation for broader geopolitical threat assessments.
- Anonymity as a Shield: Identity protection is maintained strictly for operational security, not as a weapon.
- Open Source for Education: Public tools (Nebula, Diabolic series) are released to educate and empower the community.
- Private Intelligence for Real Defense: The core intellectual capital (Andrómeda) remains private and is never commercialized.
- Trust is Earned Through Results: Credibility is built on the quality and accuracy of intelligence outputs, not certifications or public posturing.
- Legal & Ethical Compliance: All activities are conducted within legal frameworks, using only open-source and publicly available data.
2026-08-28– Publication of KillNet and NoName057(16) strategic dossiers.2026-07-23– Publication of cti-xv-dpx dossier (France Cyber Défense breach).2026-07-23– Profile update with new project indexes.2026-06-04– Nebula AntiScan v1.3 public release.2026-05-30– Diabolic Peninsular v17 improvements.2026-05-20– Integration of 80 intelligence feeds into Andrómeda.
- Strategic Consulting for institutional and governmental entities.
- Threat Intelligence Analysis on persistent threats, hacktivism, and organized crime.
- Automation Development for CTI and OSINT workflows.
- SOC & CSIRT Support in threat hunting, IOC correlation, and incident response.
For operational security reasons, personal data and direct contacts are provided exclusively during formal interviews or after signing a non-disclosure agreement (NDA) with institutional entities.
| Channel | Handle |
|---|---|
| ⌨️ Telegram | Private |
| 🐦 Twitter/X | @PurpleCondors | |
| ☣️ VirusTotal | @KiraSecurity |
KiraSecuruty@proton.me |
|
Not used (OpSec) |
Note: PGP key available upon request.
If you find this threat intelligence work valuable and wish to support independent research and operational costs (servers, APIs, OSINT infrastructure), contributions are welcome:
- ETH:
0x8eEA6C4B77DaB2C20E632407065c4F5d93093EaA - BTC:
bc1qfvmwav55r3fqk88duux70z37kqw05c4k9t7h0j
The journey began as an independent researcher operating in hostile digital environments. Over time, this experience was transformed into scalable prevention frameworks and actionable intelligence platforms.
Today, the focus remains on monitoring persistent threat groups, developing early detection systems, and publishing actionable intelligence for the defense of critical infrastructure. The background provides a unique understanding of adversary TTPs, cultivated through practical experience rather than formal coursework.
Self-taught, with a strong emphasis on operational security, the creator of Andrómeda (private counter-intelligence system) and Nebula (public demo). Specializations include botnet detection, pro-Russian group tracking, DDoS infrastructure mapping, and persistent threat analysis.
🔍 Open to collaboration – Threat Intelligence, OSINT, Purple Team, Automation.
- Contact:
KiraSecuruty@proton.me(PGP on request). - No personal Telegram or LinkedIn for OpSec reasons.
Producing actionable intelligence through rigorous OSINT and TTP analysis.
Maintained by: Condor2026 – Threat Security · Purple Team · Intelligence · Defense
