tag

stix

18 indexed skills · max 10 per page

skills (18)

building-attack-pattern-library-from-cti-reports

mukul975/Anthropic-Cybersecurity-Skills · building-attack-pattern-library-from-cti-reports

0

Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense.

implementing-diamond-model-analysis

mukul975/Anthropic-Cybersecurity-Skills · implementing-diamond-model-analysis

0

The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining four core features - Adversary, Capability, Infrastructure, and Victim. This skill covers implementing the Diamond Model programmatically to classify and correlate intrusion events, build activity threads, and generate pivot-ready intelligence.

building-threat-intelligence-feed-integration

mukul975/Anthropic-Cybersecurity-Skills · building-threat-intelligence-feed-integration

0

Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need to operationalize threat intelligence by automating feed ingestion, normalization, scoring, and distribution to detection systems.

performing-dark-web-monitoring-for-threats

mukul975/Anthropic-Cybersecurity-Skills · performing-dark-web-monitoring-for-threats

0

Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked cre

analyzing-campaign-attribution-evidence

mukul975/Anthropic-Cybersecurity-Skills · analyzing-campaign-attribution-evidence

0

Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or group is responsible for a cyber operation. This skill covers collecting and weighting attr

implementing-stix-taxii-feed-integration

mukul975/Anthropic-Cybersecurity-Skills · implementing-stix-taxii-feed-integration

0

STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) are OASIS open standards for representing and transporting cyber threat intelligence.

analyzing-threat-actor-ttps-with-mitre-navigator

mukul975/Anthropic-Cybersecurity-Skills · analyzing-threat-actor-ttps-with-mitre-navigator

0

Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework using the ATT&CK Navigator and attackcti Python library. The analyst queries STIX/TAXII data for group-technique associations, generates Navigator layer files for visualization, and compares defensive coverage against adversary profiles. Activates for requests involving APT TTP mapping, ATT&CK Navigator layers, threat actor profiling, or MITRE technique coverage analysis.

implementing-taxii-server-with-opentaxii

mukul975/Anthropic-Cybersecurity-Skills · implementing-taxii-server-with-opentaxii

0

Deploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using the TAXII 2.1 protocol for automated indicator exchange between organizations.

performing-indicator-lifecycle-management

mukul975/Anthropic-Cybersecurity-Skills · performing-indicator-lifecycle-management

0

Indicator lifecycle management tracks IOCs from initial discovery through validation, enrichment, deployment, monitoring, and eventual retirement. This skill covers implementing systematic processes f

building-threat-intelligence-platform

mukul975/Anthropic-Cybersecurity-Skills · building-threat-intelligence-platform

0

Building a Threat Intelligence Platform (TIP) involves deploying and integrating multiple CTI tools into a unified system for collecting, analyzing, enriching, and disseminating threat intelligence. T

prevpage 1 / 2next