Analyzing Threat Intelligence Feeds

Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. Use when ingesting commercial or open-source CTI feeds, evaluating feed quality, normalizing data into STIX 2.1 format, or enriching existing IOCs with campaign attribution. Activates for requests involving ThreatConnect, Recorded Future, Mandiant Advantage, MISP, AlienVault OTX, or automated feed aggregation pipelines.

26zl c77d88f 4 files · 25.9 KB Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/analyzing-threat-intelligence-feeds commit c77d88f5c2

Frequently asked questions

npx skillmds@latest add 26zl/analyzing-threat-intelligence-feeds