defensive-threat-intelligence

Enrich and correlate threat intel data to surface actionable indicators for SOC operations.

1|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/riparino/Claude-Cyber --skill defensive-threat-intelligence
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: defensive-threat-intelligence
Source: https://github.com/riparino/Claude-Cyber/tree/main/Claude-Blue/Skills/defensive-threat-intelligence
Command: npx skills add https://github.com/riparino/Claude-Cyber --skill defensive-threat-intelligence

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps security teams enrich and correlate threat data to enable faster detection and response.

Core Features & Use Cases

  • Enrich IOCs with metadata (actors, campaigns) for better triage.
  • Correlate IOCs with telemetry (Network, File) to surface high-confidence threats.
  • Integrate STIX/TAXII feeds and Defender TI through existing connectors for continual intel intake.

Quick Start

Enrich the provided IOCs and correlate them with telemetry to surface actionable threats.

Frequently Asked Questions about defensive-threat-intelligence

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enrich IOCs with threat intelligence for SOC operations?

You can enrich IOCs with threat intelligence by correlating them with live telemetry and third-party feeds to add metadata like actors and campaigns for better triage. This surfaces actionable indicators for SOC operations.

What is the best way to correlate threat intel with network and file telemetry?

The best way to correlate threat intel with telemetry is to match indicators against live network and file logs to surface high-confidence threats. This process enriches raw data with actionable context for proactive hunting.

Does this threat intelligence enrichment work with STIX and TAXII feeds?

Yes, threat intelligence enrichment works directly with STIX and TAXII feeds, alongside Defender TI and MISP integrations. These connectors enable centralized continual intel intake for your security operations.

How can I integrate Defender TI and MISP for centralized threat intel lifecycle management?

You can integrate Defender TI and MISP through existing connectors to ingest and enrich threat intel data. This centralizes your TI lifecycle management and applies the enriched data to proactive threat hunting and incident response.

Can I use KQL for proactive threat hunting with correlated IOCs?

Yes, you can use KQL for proactive threat hunting with correlated IOCs. The Skill surfaces high-confidence threats by applying enriched indicators across your live telemetry, enabling faster detection and response.

When do I need STIX and TAXII integrations for threat intelligence?

You need STIX and TAXII integrations for threat intelligence when you want to automate continual intake of standardized threat data. This supports centralized enrichment and correlates third-party feeds with your internal telemetry.