Threat Intelligence Analysis
curated by SkillMD · plugin · 9 skills
For threat analysts correlating IOCs, building campaign graphs, and producing intelligence reports.
Install the whole plugin (CLI)
npx skillmds add mukul975/correlating-threat-campaigns
npx skillmds add mukul975/profiling-threat-actor-groups
npx skillmds add mukul975/implementing-diamond-model-analysis
npx skillmds add mukul975/analyzing-cobalt-strike-beacon-configuration
npx skillmds add zhaoxuya520/threat-hunting
npx skillmds add zhaoxuya520/malware-analysis
npx skillmds add drnabeelkhan/security-threat-intelligence
npx skillmds add drnabeelkhan/threat-analyst
npx skillmds add phoroth/007Skills in this plugin
- ▌ correlating-threat-campaigns · mukul975 bundleCorrelates disparate security incidents, IOCs, and adversary behaviors across time and organizations to identify unified threat campaigns and attribute them to common threat actors.
- ▌ profiling-threat-actor-groups · mukul975 bundleDevelops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints, and attribution indicators from multiple intelligence sources.
- ▌ implementing-diamond-model-analysis · mukul975 bundleProvides a structured framework for analyzing cyber intrusions by examining four core features: Adversary, Capability, Infrastructure, and Victim. Covers implementing the Diamond Model programmatically to classify and correlate intrusion events, build activity threads, and generate pivot-ready intelligence.
- ▌ analyzing-cobalt-strike-beacon-configuration · mukul975 bundleExtract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.
- ▌ threat-hunting · zhaoxuya520 bundleGuides blue-team threat hunting and detection engineering with hypothesis-driven workflows, Sigma/YARA rule creation, SIEM query design, and validation using Atomic Red Team in authorized environments.
- ▌ malware-analysis · zhaoxuya520 bundleAnalyze suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YARA or Sigma rules, sandboxing, and anti-analysis behavior detection.
- ▌ security-threat-intelligence · drnabeelkhan bundleRoutes security, compliance, and threat-intelligence tasks to specialized sub-skills for threat modeling, penetration testing, incident response, and vulnerability scanning.
- ▌ threat-analyst · drnabeelkhanMonitors authorized threat intelligence feeds and maps adversary TTPs to MITRE ATT&CK, NIST CSF, and ISO 27001 frameworks to produce actionable intelligence reports with IOCs and defensive recommendations.
- ▌ 007 · phoroth bundleRuns a structured 6-phase security audit covering attack-surface mapping, STRIDE/PASTA threat modeling, technical checklists, red/blue team exercises, and a final verdict, plus incident-response and monitoring playbooks.