threat-intel

Query Mimecast threat intelligence to score email sender, domain, or IP reputation.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/afoxnyc3/chelsea-piers-itops --skill threat-intel-afoxnyc3
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: threat-intel
Source: https://github.com/afoxnyc3/chelsea-piers-itops/tree/main/plugins/mimecast-security/skills/threat-intel
Command: npx skills add https://github.com/afoxnyc3/chelsea-piers-itops --skill threat-intel-afoxnyc3

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Threat-intel helps Chelsea Piers IT Ops quickly assess whether an email sender, domain, or IP is likely malicious or suspicious so triage and response can happen faster and with less guesswork.

Core Features & Use Cases

  • Reputation scoring and threat categorization: Evaluates the risk level for an email sender, domain, or IP using Mimecast threat data.
  • Recent activity visibility: Surfaces recent events or signals tied to the subject of the lookup.
  • Decision support for SOC/helpdesk workflows: Supports phishing sender checks and safe/unsafe determinations during email investigation.

Quick Start

Ask the skill to research threat intelligence for a suspicious sender by providing the email address, domain, or IP you want checked.

Frequently Asked Questions about threat-intel

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I check email sender reputation using Mimecast threat intelligence?

To check email sender reputation, provide a suspicious email address, domain, or IP. The skill queries Mimecast threat intelligence, validates the data, and outputs a structured reputation score with categories and recent activity.

What is threat intelligence scoring for phishing triage?

Threat intelligence scoring for phishing triage evaluates the risk level of a sender, domain, or IP using Mimecast data. It categorizes potential maliciousness and surfaces recent signals to support safe or unsafe determinations.

Can I use Mimecast data for IP reputation checks during security investigations?

Yes, you can use Mimecast data for IP reputation checks. Provide the IP address to the skill, and it retrieves Mimecast threat intelligence to summarize reputation signals and recent activity tied to that IP.

Does domain monitoring with Mimecast require any special setup?

Domain monitoring with Mimecast requires no special setup beyond having Mimecast tooling available. You simply provide the domain you want investigated, and the skill parses the identifier and queries the relevant Mimecast MCP tools.

What's the best way to investigate suspicious messages across IT operations workflows?

The best way to investigate suspicious messages is to provide the sender's email address, domain, or IP. The skill applies Mimecast threat intelligence to validate returned data and output a structured reputation score for triage.

Why does phishing sender verification need recent activity visibility?

Phishing sender verification needs recent activity visibility because recent events or signals tied to the subject provide context for determining if a sender is currently malicious, helping SOC and helpdesk workflows make faster decisions.