自动化威胁指标富化

原名:automating-ioc-enrichment

自动从多源数据中丰富原始入侵指标,提升威胁情报的完整性和准确性。

分类
开发提效
版本
v1.0.0
作者
弈韬(@ra1nzzz)
下载
1
收藏
0
发布
2026-08-18
更新
2026-08-21
TRACE 评分
3.6 / 5

内容概览

Use this skill when: - Building a SOAR playbook that automatically enriches SIEM alerts with threat intelligence context before routing to analysts - Creating a Python pipeline for bulk IOC enrichment from phishing email submissions - Reducing analyst mean time to triage (MTTT) by pre-populating alert context with VT, Shodan, and MISP data Do not use this skill for fully automated blocking decisions without human review — enrichment automation should inform decisions, not execute blocks autonomously for high-impact actions. - SOAR platform (Cortex XSOAR, Splunk SOAR, Tines, or n8n) or Python 3.9+ environment - API keys: VirusTotal, AbuseIPDB, Shodan, and at minimum one TIP (MISP or OpenCTI) - SIEM integration endpoint for alert consumption - Rate limit budgets documented per API (VT: 4/min free, 500/min enterprise) Define the enrichment flow for each IOC type: In Cortex XSOAR, create an …

查看 SKILL 详情