analyzing-threat-intelligence-feeds

Featured

Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. Use when ingesting commercial or open-source CTI feeds, evaluating feed quality, normalizing data into STIX 2.1 format, or enriching existing IOCs with campaign attribution. Activates for requests involving ThreatConnect, Recorded Future, Mandiant Advantage, MISP, AlienVault OTX, or automated feed aggregation pipelines.

AI & Automation 12,642 stars 1468 forks Updated today Apache-2.0

Install

View on GitHub

Quality Score: 99/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Analyzing Threat Intelligence Feeds ## When to Use Use this skill when: - Ingesting new commercial or OSINT threat feeds and assessing their signal-to-noise ratio - Normalizing heterogeneous IOC formats (STIX 2.1, OpenIOC, YARA, Sigma) into a unified schema - Evaluating feed freshness, fidelity, and relevance to the organization's threat profile - Building automated enrichment pipelines that correlate IOCs against SIEM events **Do not use** this skill for raw packet capture analysis or live incident triage without first establishing a CTI baseline. ## Prerequisites - Access to a Threat Intelligence Platform (TIP) such as ThreatConnect, MISP, or OpenCTI - API keys for at least one commercial feed (Recorded Future, Mandiant Advantage, or VirusTotal Enterprise) - TAXII 2.1 client library (taxii2-client Python package or equivalent) - Role with read/write permissions to the TIP's indicator database ## Workflow ### Step 1: Enumerate and Prioritize Feed Sources List all available feeds categorized by type (commercial, government, ISAC, OSINT): - Commercial: Recorded Future, Mandiant Advantage, CrowdStrike Falcon Intelligence - Government: CISA AIS (Automated Indicator Sharing), FBI InfraGard, MS-ISAC - OSINT: AlienVault OTX, Abuse.ch, PhishTank, Emerging Threats Score each feed on: update frequency, historical accuracy rate, coverage of your sector, and attribution depth. Use a weighted scoring matrix with criteria from NIST SP 800-150 (Guide to Cyber Threat Information ...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
today
Language
Python
License
Apache-2.0

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Featured

building-threat-intelligence-feed-integration

Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need to operationalize threat intelligence by automating feed ingestion, normalization, scoring, and distribution to detection systems.

12,642 Updated today
mukul975
AI & Automation Featured

evaluating-threat-intelligence-platforms

Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP procurement, migrating between TIP solutions, or assessing whether the current TIP meets program maturity requirements. Activates for requests involving ThreatConnect, MISP, OpenCTI, Anomali, EclecticIQ, or TIP procurement decisions.

12,642 Updated today
mukul975
AI & Automation Listed

evaluating-threat-intelligence-platforms

Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP procurement, migrating between TIP solutions, or assessing whether the current TIP meets program maturity requirements. Activates for requests involving ThreatConnect, MISP, OpenCTI, Anomali, EclecticIQ, or TIP procurement decisions.

1 Updated today
seikaikyo
API & Backend Listed

evaluating-threat-intelligence-platforms

Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP procurement, migrating between TIP solutions, or assessing whether the current TIP meets program maturity requirements. Activates for requests involving ThreatConnect, MISP, OpenCTI, Anomali, EclecticIQ, or TIP procurement decisions.

8 Updated today
gabrielmoreira
Data & Documents Solid

threat-hunting--ioc-analysis

IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation

47 Updated today
Masriyan