Threat Intelligence Platform
curated by SkillMD · plugin · 9 skills
Deploy and manage open-source CTI tools for threat intelligence operations.
Install the whole plugin (CLI)
npx skillmds add mukul975/building-threat-intelligence-platform
npx skillmds add mukul975/collecting-threat-intelligence-with-misp
npx skillmds add mukul975/implementing-taxii-server-with-opentaxii
npx skillmds add mukul975/building-threat-feed-aggregation-with-misp
npx skillmds add zhaoxuya520/reverse-skill-router
npx skillmds add zhaoxuya520/digital-forensics
npx skillmds add zhaoxuya520/threat-hunting
npx skillmds add zhaoxuya520/malware-analysis
npx skillmds add drnabeelkhan/security-threat-intelligenceSkills in this plugin
- ▌ building-threat-intelligence-platform · mukul975 bundleDeploy and integrate open-source CTI tools (MISP, OpenCTI, TheHive, Cortex) into a unified threat intelligence platform for collecting, analyzing, enriching, and disseminating threat intelligence.
- ▌ collecting-threat-intelligence-with-misp · mukul975 bundleDeploy MISP, configure threat feeds, use the PyMISP API for programmatic access, and build automated collection pipelines that aggregate IOCs from multiple community and commercial sources.
- ▌ implementing-taxii-server-with-opentaxii · mukul975 bundleDeploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using the TAXII 2.1 protocol for automated indicator exchange between organizations.
- ▌ building-threat-feed-aggregation-with-misp · mukul975 bundleDeploy MISP to aggregate, correlate, and distribute threat intelligence feeds from multiple sources for centralized IOC management and automated SIEM integration.
- ▌ reverse-skill-router · zhaoxuya520 bundleRoutes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.
- ▌ digital-forensics · zhaoxuya520 bundleGuides authorized digital forensics and incident response workflows including memory dump analysis, disk timeline creation, PCAP investigation, and artifact triage with evidence preservation.
- ▌ threat-hunting · zhaoxuya520 bundleGuides blue-team threat hunting and detection engineering with hypothesis-driven workflows, Sigma/YARA rule creation, SIEM query design, and validation using Atomic Red Team in authorized environments.
- ▌ malware-analysis · zhaoxuya520 bundleAnalyze suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YARA or Sigma rules, sandboxing, and anti-analysis behavior detection.
- ▌ security-threat-intelligence · drnabeelkhan bundleRoutes security, compliance, and threat-intelligence tasks to specialized sub-skills for threat modeling, penetration testing, incident response, and vulnerability scanning.