threat-intelligence-enrichment

Installation
SKILL.md

Threat Intelligence Enrichment

Workflow

Use search and extract to enrich security entities with authoritative and recent evidence; use map or crawl for known vendor portals or advisory collections. Keep this skill focused on query construction, source priority, verification, and security synthesis; execution mechanics should come from companion endpoint skills.

Treat the guidance below as base guidance; adapt it to the user's request when appropriate.

  • Identify the input type: CVE, IOC, malware/tool, threat actor, vendor/product, advisory URL, incident, or campaign.
  • Break the task into short subqueries under 400 characters: identifier, affected product, exploit status, vendor advisory, patches, mitigations, exploitation in the wild, and recent reporting.
  • Search first, using exact-match style queries for CVEs, hashes, domains, IPs, advisory IDs, and malware names.
  • Filter sources before extraction. Prioritize NVD/CVE records, vendor advisories, CISA/agency alerts, security research blogs, reputable incident reports, and official patch notes.
  • Extract selected pages that can support exploit status, impact, affected versions, mitigations, timeline, or confidence.
  • Use site navigation for vendor advisory portals or documentation sites when the relevant page is hard to find.
  • Collect scoped advisory, changelog, release note, or documentation sections only when the user needs broad coverage.

Research Budget

Installs
3
First Seen
11 days ago
threat-intelligence-enrichment — tavily-ai/use-case-skills