tag

threat-intelligence

44 indexed skills · max 10 per page

skills (44)

generating-threat-intelligence-reports

mukul975/Anthropic-Cybersecurity-Skills · generating-threat-intelligence-reports

0

Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts. Use when producing finished intelligence products from raw collection data, creating sector threat briefings, or delivering post-incident intelligence assessments. Activates for requests involving CTI report writing, threat briefings, intelligence products, finished intelligence, or executive security reporting.

building-attack-pattern-library-from-cti-reports

mukul975/Anthropic-Cybersecurity-Skills · building-attack-pattern-library-from-cti-reports

0

Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense.

performing-ip-reputation-analysis-with-shodan

mukul975/Anthropic-Cybersecurity-Skills · performing-ip-reputation-analysis-with-shodan

0

Analyze IP address reputation using the Shodan API to identify open ports, running services, known vulnerabilities, and hosting context for threat intelligence enrichment and incident triage.

analyzing-ransomware-leak-site-intelligence

mukul975/Anthropic-Cybersecurity-Skills · analyzing-ransomware-leak-site-intelligence

0

Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.

implementing-diamond-model-analysis

mukul975/Anthropic-Cybersecurity-Skills · implementing-diamond-model-analysis

0

The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining four core features - Adversary, Capability, Infrastructure, and Victim. This skill covers implementing the Diamond Model programmatically to classify and correlate intrusion events, build activity threads, and generate pivot-ready intelligence.

performing-malware-hash-enrichment-with-virustotal

mukul975/Anthropic-Cybersecurity-Skills · performing-malware-hash-enrichment-with-virustotal

0

Enrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches, and contextual threat intelligence for incident triage and IOC validation.

building-threat-intelligence-feed-integration

mukul975/Anthropic-Cybersecurity-Skills · building-threat-intelligence-feed-integration

0

Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need to operationalize threat intelligence by automating feed ingestion, normalization, scoring, and distribution to detection systems.

performing-cve-prioritization-with-kev-catalog

mukul975/Anthropic-Cybersecurity-Skills · performing-cve-prioritization-with-kev-catalog

0

Leverage the CISA Known Exploited Vulnerabilities catalog alongside EPSS and CVSS to prioritize CVE remediation based on real-world exploitation evidence.

performing-dark-web-monitoring-for-threats

mukul975/Anthropic-Cybersecurity-Skills · performing-dark-web-monitoring-for-threats

0

Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked cre

analyzing-campaign-attribution-evidence

mukul975/Anthropic-Cybersecurity-Skills · analyzing-campaign-attribution-evidence

0

Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or group is responsible for a cyber operation. This skill covers collecting and weighting attr

prevpage 1 / 5next