zettelforge
Persistent threat intelligence memory with entity extraction and graph search
All Skills in This Repository (1)
Pure Emerald Level IndicatorsFrequently Asked Questions
FAQPage SchemaHow to install ZettelForge?โผ
Run `npx skills add rolandpg/zettelforge --all -g -y` in your terminal to install everything globally. You can also install the Python package directly with `pip install zettelforge`.
What does ZettelForge do for security teams?โผ
It gives your team persistent memory for cyber threat intelligence, automatically extracting CVEs, threat actors, IOCs, and ATT&CK techniques from notes and reports. Past investigations stay searchable even after analysts leave.
Does ZettelForge resolve threat actor aliases?โผ
Yes. Names like APT28, Fancy Bear, STRONTIUM, and Sofacy automatically resolve to the same actor node during both storage and recall.
Does ZettelForge need API keys or cloud access?โผ
No. Embeddings, storage, and optional local LLM inference all run in-process, so no data leaves the host and it can work on air-gapped machines.
Can ZettelForge work with Claude Code?โผ
Yes. It ships an MCP server that lets Claude Code query your stored threat intelligence in natural language during investigations.
Related Repositories in Data & Analytics
View All in Data & AnalyticsโPaddleOCR
Extract text, tables, and formulas from PDFs and images
Scrapling
Scrape any website and bypass anti-bot protection with AI
last30days-skill
Research any topic across Reddit, X, YouTube, and the web