威胁情报源分析
原名:analyzing-threat-intelligence-feeds
分析结构化与非结构化威胁情报数据,提取关键信息。
- 分类
- 数据分析
- 版本
- v1.0.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 0
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-19
- TRACE 评分
- 3.2 / 5
内容概览
Use this skill when: - Ingesting new commercial or OSINT threat feeds and assessing their signal-to-noise ratio - Normalizing heterogeneous IOC formats (STIX 2.1, OpenIOC, YARA, Sigma) into a unified schema - Evaluating feed freshness, fidelity, and relevance to the organization's threat profile - Building automated enrichment pipelines that correlate IOCs against SIEM events Do not use this skill for raw packet capture analysis or live incident triage without first establishing a CTI baseline. - Access to a Threat Intelligence Platform (TIP) such as ThreatConnect, MISP, or OpenCTI - API keys for at least one commercial feed (Recorded Future, Mandiant Advantage, or VirusTotal Enterprise) - TAXII 2.1 client library (taxii2-client Python package or equivalent) - Role with read/write permissions to the TIP's indicator database List all available feeds categorized by type (commercial, govern…