threat-intelligence-enrichment
Installation
SKILL.md
Threat Intelligence Enrichment
Workflow
Use search and extract to enrich security entities with authoritative and recent evidence; use map or crawl for known vendor portals or advisory collections. Keep this skill focused on query construction, source priority, verification, and security synthesis; execution mechanics should come from companion endpoint skills.
Treat the guidance below as base guidance; adapt it to the user's request when appropriate.
- Identify the input type: CVE, IOC, malware/tool, threat actor, vendor/product, advisory URL, incident, or campaign.
- Break the task into short subqueries under 400 characters: identifier, affected product, exploit status, vendor advisory, patches, mitigations, exploitation in the wild, and recent reporting.
- Search first, using exact-match style queries for CVEs, hashes, domains, IPs, advisory IDs, and malware names.
- Filter sources before extraction. Prioritize NVD/CVE records, vendor advisories, CISA/agency alerts, security research blogs, reputable incident reports, and official patch notes.
- Extract selected pages that can support exploit status, impact, affected versions, mitigations, timeline, or confidence.
- Use site navigation for vendor advisory portals or documentation sites when the relevant page is hard to find.
- Collect scoped advisory, changelog, release note, or documentation sections only when the user needs broad coverage.