phishing-social-engineering

Centralize and update phishing and social engineering threat intelligence.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill phishing-social-engineering
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: phishing-social-engineering
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/phishing-social-engineering
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill phishing-social-engineering

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Phishing and social engineering threats are complex and evolving, and security teams need a centralized, self-updating knowledge source that captures attacker techniques, campaigns, and countermeasures to inform analysis and defense.

Core Features & Use Cases

  • Self-updating knowledge base on phishing, social engineering, and related TTPs, including current threat actors, campaigns, and techniques.
  • Executive summaries & reports that distill threat intel for incident response, security operations, and awareness training.
  • Living content with versioning metadata and structured sections for rapid embedding into workflows, risk assessments, and training materials.

Quick Start

Query the latest phishing threat briefing to get an up-to-date executive summary.

Frequently Asked Questions about phishing-social-engineering

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I centralize evolving phishing and social engineering threat intelligence for my security team?

Centralize evolving phishing and social engineering threat intelligence using a self-updating knowledge base that captures attacker techniques, campaigns, and countermeasures to inform analysis and defense. Content stays synchronized via embedded metadata.

What is the best way to get an up-to-date executive summary of current phishing campaigns for incident response?

Get an up-to-date executive summary of current phishing campaigns by querying the living threat intel knowledge base. It distills threat actors, techniques, and countermeasures into structured Markdown reports for incident response operations.

Can I embed phishing threat intel directly into security awareness training materials?

You can embed phishing threat intel directly into security awareness training materials. The knowledge base provides a human-readable Markdown body with structured sections and versioning metadata designed for rapid workflow integration.

Does this threat intelligence knowledge base support frontmatter-based discovery for automated workflows?

The threat intelligence knowledge base supports frontmatter-based discovery for automated workflows. Embedded metadata keeps content synchronized, enabling rapid embedding into threat intel workflows, risk assessments, and training programs.

How do I keep social engineering TTPs and threat actor data synchronized across risk assessments?

Keep social engineering TTPs and threat actor data synchronized across risk assessments by using a living content knowledge base. Embedded versioning metadata ensures threat intelligence remains current for operational use without manual updates.

When do I need a self-updating knowledge base for phishing threat intelligence?

You need a self-updating knowledge base for phishing threat intelligence when security teams require a centralized source that continuously captures evolving attacker techniques, campaigns, and countermeasures to inform detection and defense decisions.