← all plugins

Threat Intelligence Analysis

curated by SkillMD · plugin · 9 skills

For threat analysts correlating IOCs, building campaign graphs, and producing intelligence reports.

Install the whole plugin (CLI)
npx skillmds add mukul975/correlating-threat-campaigns npx skillmds add mukul975/profiling-threat-actor-groups npx skillmds add mukul975/implementing-diamond-model-analysis npx skillmds add mukul975/analyzing-cobalt-strike-beacon-configuration npx skillmds add zhaoxuya520/threat-hunting npx skillmds add zhaoxuya520/malware-analysis npx skillmds add drnabeelkhan/security-threat-intelligence npx skillmds add drnabeelkhan/threat-analyst npx skillmds add phoroth/007
⬇ Download

Skills in this plugin

  1. correlating-threat-campaigns · mukul975 bundle
    Correlates disparate security incidents, IOCs, and adversary behaviors across time and organizations to identify unified threat campaigns and attribute them to common threat actors.
    24.6k
    repo stars
  2. profiling-threat-actor-groups · mukul975 bundle
    Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints, and attribution indicators from multiple intelligence sources.
    24.6k
    repo stars
  3. implementing-diamond-model-analysis · mukul975 bundle
    Provides a structured framework for analyzing cyber intrusions by examining four core features: Adversary, Capability, Infrastructure, and Victim. Covers implementing the Diamond Model programmatically to classify and correlate intrusion events, build activity threads, and generate pivot-ready intelligence.
    24.6k
    repo stars
  4. analyzing-cobalt-strike-beacon-configuration · mukul975 bundle
    Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.
    24.6k
    repo stars
  5. threat-hunting · zhaoxuya520 bundle
    Guides blue-team threat hunting and detection engineering with hypothesis-driven workflows, Sigma/YARA rule creation, SIEM query design, and validation using Atomic Red Team in authorized environments.
    12.8k
    repo stars
  6. malware-analysis · zhaoxuya520 bundle
    Analyze suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YARA or Sigma rules, sandboxing, and anti-analysis behavior detection.
    12.8k
    repo stars
  7. security-threat-intelligence · drnabeelkhan bundle
    Routes security, compliance, and threat-intelligence tasks to specialized sub-skills for threat modeling, penetration testing, incident response, and vulnerability scanning.
    2
    repo stars
  8. threat-analyst · drnabeelkhan
    Monitors authorized threat intelligence feeds and maps adversary TTPs to MITRE ATT&CK, NIST CSF, and ISO 27001 frameworks to produce actionable intelligence reports with IOCs and defensive recommendations.
    2
    repo stars
  9. 007 · phoroth bundle
    Runs a structured 6-phase security audit covering attack-surface mapping, STRIDE/PASTA threat modeling, technical checklists, red/blue team exercises, and a final verdict, plus incident-response and monitoring playbooks.
    3
    repo stars