intelligence-sharing

Coordinate structured threat intelligence sharing using STIX/TAXII and MISP standards.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill intelligence-sharing
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: intelligence-sharing
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/intelligence-sharing
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill intelligence-sharing

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Structured threat intelligence sharing is essential for enabling fast, coordinated defense across organizations while maintaining governance and compliance.

Core Features & Use Cases

  • ISAC participation guidance: joining sector-specific information sharing communities.
  • TLP-governed sharing: guidelines on labeling and distributing intelligence.
  • STIX/TAXII and MISP integration: recommended data formats and exchange workflows.
  • Risk and legal considerations: privacy, data minimization, and compliance.
  • Use cases: sharing IOCs, incident lessons, and threat actor context to improve situational awareness.

Quick Start

Use the intelligence-sharing skill to outline best practices for sharing threat intelligence with trusted partners.

Frequently Asked Questions about intelligence-sharing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I share threat intelligence using STIX and TAXII with trusted partners?

To share threat intelligence via STIX and TAXII, you structure IOCs and threat actor context into standardized formats, then exchange them using established workflows. This approach ensures coordinated defense and improves situational awareness across organizations.

What is TLP-governed sharing and how does it apply to threat intelligence?

TLP-governed sharing uses Traffic Light Protocol controls to classify and distribute threat intelligence securely. It provides guidelines on labeling intelligence so security teams can properly handle data minimization, privacy, and compliance during ISAC participation.

How do I join an ISAC and participate in sector-specific threat intelligence sharing?

Joining an ISAC involves connecting with sector-specific information sharing communities to exchange threat intelligence. This coordinated sharing enables fast defense by distributing IOCs and incident lessons while maintaining governance and compliance.

Does MISP support TLP controls for cross-organization threat intelligence collaboration?

Yes, MISP integration supports TLP controls for cross-organization collaboration. It provides recommended data formats and exchange workflows that allow security teams to tag, classify, and share threat intelligence with proper risk and legal considerations.

What are the best practices for data minimization and compliance when sharing CTI?

Best practices for sharing CTI involve applying data minimization, proper TLP labeling, and structured governance. Addressing privacy and legal considerations ensures compliant intelligence sharing across STIX, TAXII, and MISP platforms without exposing sensitive data.

When should I not use STIX or TAXII for threat intelligence sharing?

You should avoid using STIX or TAXII for threat intelligence sharing when strict privacy constraints or legal considerations prevent cross-organization data exchange. In such cases, unstructured sharing or adhering strictly to data minimization may be required.