智源通脉
原名:building-threat-intelligence-feed-integration
构建自动化的威胁情报源集成管道,连接
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 2
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-25
- TRACE 评分
- 3.6 / 5
内容概览
Use this skill when: - SOC teams need automated ingestion of threat intelligence feeds into SIEM platforms - Multiple TI sources require normalization into a common format (STIX 2.1) - Detection systems need real-time IOC matching against network and endpoint telemetry - TI feed quality assessment and deduplication processes need to be established Do not use for manual IOC lookup — use dedicated enrichment tools (VirusTotal, AbuseIPDB) for ad-hoc queries. - MISP instance or Threat Intelligence Platform (TIP) for feed aggregation - STIX/TAXII client library (taxii2-client, stix2 Python packages) - SIEM platform (Splunk ES, Elastic Security, or Sentinel) with TI framework configured - API keys for commercial and open-source feeds (AlienVault OTX, Abuse.ch, CISA AIS) - Python 3.8+ for feed processing automation Map available feeds by type, format, and update frequency: Feed Source Format IO…