威胁情报源分析

原名:analyzing-threat-intelligence-feeds

分析结构化与非结构化威胁情报数据,提取关键信息。

分类
数据分析
版本
v1.0.0
作者
弈韬(@ra1nzzz)
下载
0
收藏
0
发布
2026-08-18
更新
2026-08-19
TRACE 评分
3.2 / 5

内容概览

Use this skill when: - Ingesting new commercial or OSINT threat feeds and assessing their signal-to-noise ratio - Normalizing heterogeneous IOC formats (STIX 2.1, OpenIOC, YARA, Sigma) into a unified schema - Evaluating feed freshness, fidelity, and relevance to the organization's threat profile - Building automated enrichment pipelines that correlate IOCs against SIEM events Do not use this skill for raw packet capture analysis or live incident triage without first establishing a CTI baseline. - Access to a Threat Intelligence Platform (TIP) such as ThreatConnect, MISP, or OpenCTI - API keys for at least one commercial feed (Recorded Future, Mandiant Advantage, or VirusTotal Enterprise) - TAXII 2.1 client library (taxii2-client Python package or equivalent) - Role with read/write permissions to the TIP's indicator database List all available feeds categorized by type (commercial, govern…

查看 SKILL 详情