智源通脉

原名:building-threat-intelligence-feed-integration

构建自动化的威胁情报源集成管道,连接

分类
开发提效
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
2
收藏
0
发布
2026-08-18
更新
2026-08-25
TRACE 评分
3.6 / 5

内容概览

Use this skill when: - SOC teams need automated ingestion of threat intelligence feeds into SIEM platforms - Multiple TI sources require normalization into a common format (STIX 2.1) - Detection systems need real-time IOC matching against network and endpoint telemetry - TI feed quality assessment and deduplication processes need to be established Do not use for manual IOC lookup — use dedicated enrichment tools (VirusTotal, AbuseIPDB) for ad-hoc queries. - MISP instance or Threat Intelligence Platform (TIP) for feed aggregation - STIX/TAXII client library (taxii2-client, stix2 Python packages) - SIEM platform (Splunk ES, Elastic Security, or Sentinel) with TI framework configured - API keys for commercial and open-source feeds (AlienVault OTX, Abuse.ch, CISA AIS) - Python 3.8+ for feed processing automation Map available feeds by type, format, and update frequency: Feed Source Format IO…

查看 SKILL 详情