threat-intel-aggregator

Aggregate threat intelligence feeds and vulnerability data into daily security briefings.

1|1|Updated Feb 8, 2026
One-click install
npx skills add https://github.com/dapperdivers/roundtable-arsenal --skill threat-intel-aggregator
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: threat-intel-aggregator
Source: https://github.com/dapperdivers/roundtable-arsenal/tree/main/security/threat-intel-aggregator
Command: npx skills add https://github.com/dapperdivers/roundtable-arsenal --skill threat-intel-aggregator

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires curl, jq, xmllint, and includes scripts (resource) components.

What problem does it solve?

This Skill reduces the burden of manually monitoring scattered threat intelligence sources by aggregating vulnerabilities, indicators, and security reports into a unified intelligence workflow.

Core Features & Use Cases

  • Multi-Source Threat Collection: Gather intelligence from sources including CISA KEV, NVD CVEs, OpenCTI, RSS feeds, URLhaus, and ThreatFox.
  • Correlation and Prioritization: Link vulnerabilities, threat actors, indicators of compromise, and infrastructure data while scoring relevance for tracked environments.
  • Use Case: Security teams can use this Skill to create automated daily threat briefings that highlight critical vulnerabilities, malicious infrastructure, and recommended investigation priorities.

Quick Start

Use the threat-intel-aggregator skill to collect the latest security intelligence and generate a daily threat briefing.

Frequently Asked Questions about threat-intel-aggregator

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I aggregate threat intelligence feeds and vulnerability data into a daily briefing?

You can aggregate threat intelligence feeds by collecting vulnerabilities and indicators from sources like CISA KEV, NVD, and OpenCTI, then normalizing and correlating the data to generate an automated daily security briefing.

What is the best way to monitor CVEs and IOCs from multiple security sources?

Monitoring CVEs and IOCs from multiple security sources is best handled by aggregating feeds like URLhaus and ThreatFox, then applying correlation workflows to link vulnerabilities, threat actors, and infrastructure data into a unified intelligence report.

Do I need curl and jq to collect threat intelligence from OpenCTI and RSS feeds?

Yes, collecting threat intelligence from OpenCTI and RSS feeds requires command-line data retrieval tools like curl and jq to fetch and process JSON data for feed normalization and correlation.

How does vulnerability correlation and prioritization work for tracked environments?

Vulnerability correlation and prioritization works by linking threat actors, indicators of compromise, and infrastructure data, then scoring the relevance of vulnerabilities specifically for your tracked security environments.

Can I generate automated daily threat briefings highlighting malicious infrastructure?

Yes, you can generate automated daily threat briefings that highlight critical vulnerabilities, malicious infrastructure, and recommended investigation priorities by correlating collected IOC and CVE data.