tag

ioc

16 indexed skills · max 10 per page

skills (16)

analyzing-threat-actor-ttps-with-mitre-attack

mukul975/Anthropic-Cybersecurity-Skills · analyzing-threat-actor-ttps-with-mitre-attack

0

MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. This skill covers systematically mapping threat actor beh

tracking-threat-actor-infrastructure

mukul975/Anthropic-Cybersecurity-Skills · tracking-threat-actor-infrastructure

0

Threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control (C2) servers, phishing domains, exploit kit hosts, bulletproof hosting, a

building-ioc-defanging-and-sharing-pipeline

mukul975/Anthropic-Cybersecurity-Skills · building-ioc-defanging-and-sharing-pipeline

0

Build an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing and distribute them in STIX format through TAXII feeds and threat intelligence platforms.

building-threat-intelligence-enrichment-in-splunk

mukul975/Anthropic-Cybersecurity-Skills · building-threat-intelligence-enrichment-in-splunk

0

Build automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular inputs, and the Threat Intelligence Framework.

collecting-threat-intelligence-with-misp

mukul975/Anthropic-Cybersecurity-Skills · collecting-threat-intelligence-with-misp

0

MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing, storing, and correlating Indicators of Compromise (IOCs) of targeted attacks, threat

performing-ioc-enrichment-automation

mukul975/Anthropic-Cybersecurity-Skills · performing-ioc-enrichment-automation

0

Automates Indicator of Compromise (IOC) enrichment by orchestrating lookups across VirusTotal, AbuseIPDB, Shodan, MISP, and other intelligence sources to provide contextual scoring and disposition recommendations. Use when SOC analysts need rapid multi-source enrichment of IPs, domains, URLs, and file hashes during alert triage or incident investigation.

prevpage 2 / 2next