threat-intel-fusion

Installation
SKILL.md

Threat Intel Fusion

Operating Rules

  • Separate observation, assessment, and recommendation. Tag every claim with source, date, and confidence.
  • Prefer structured formats: STIX 2.1 objects, MISP events, ATT&CK technique IDs, CVE IDs, CPE strings.
  • Decay IOC value over time; mark sightings, first/last seen, and TLP.

Fusion Workflow

  1. Collect: pull feeds with idempotent connectors; record raw payloads with hash and timestamp.
  2. Normalize: map to STIX SDOs and SROs (indicator, malware, intrusion-set, attack-pattern, relationship).
  3. Deduplicate: canonical-form domain/url/hash; merge by id + pattern, keep all sightings.
  4. Enrich: passive DNS, WHOIS, ASN, geo, VT, GreyNoise tags, sandbox verdicts, KEV/EPSS scores.
  5. Prioritize: score by exploitability, exposure in our environment, actor relevance, and decay.
  6. Operationalize: emit firewall/EDR/SIEM-ready artifacts plus Sigma rules and hunt queries.

Actor Profiling

Installs
1
GitHub Stars
3
First Seen
Aug 26, 2026
threat-intel-fusion — masriyan/gemini-security-skills