threat-intel

Analyzes IPs, domains, and hashes to produce threat scores and verdicts.

1|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/Dhruvipatel0514/cyberguard-agent --skill threat-intel-dhruvipatel0514
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: threat-intel
Source: https://github.com/Dhruvipatel0514/cyberguard-agent/tree/main/skills/threat-intel
Command: npx skills add https://github.com/Dhruvipatel0514/cyberguard-agent --skill threat-intel-dhruvipatel0514

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Quickly assess the credibility and risk of IOCs (IPs, domains, and hashes) to enable informed response decisions.

Core Features & Use Cases

  • IOC evaluation and risk scoring for IPs, domains, and hashes
  • Threat context enrichment with brief analysis and recommended actions
  • Use Case: triage a suspicious IOC to decide whether to block, monitor, or investigate

Quick Start

Analyze a sample IOC by running threat-intel on a suspicious IP address to obtain a threat score and verdict.

Frequently Asked Questions about threat-intel

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I analyze an IP address to get a threat score and verdict?

To analyze an IP address, submit the IOC to receive a threat score and verdict. The output follows a strict format providing the IOC, type, threat score, and recommended actions for incident triage.

Can I analyze a batch of IOCs including domains and hashes at the same time?

Yes, you can analyze batches of IOCs including domains and hashes simultaneously. The Skill processes multiple indicators to provide a strict output format with threat scores, verdicts, and MITRE ATT&CK mappings for each.

What is the output format for threat intelligence assessment results?

The threat intelligence assessment output uses a strict format containing IOC, TYPE, THREAT SCORE, and VERDICT. It also includes brief analysis, MITRE ATT&CK mappings, and actionable recommendations for response decisions.

Does threat intelligence analysis provide MITRE ATT&CK mappings for indicators of compromise?

Yes, threat intelligence analysis provides MITRE ATT&CK mappings for indicators of compromise. It assesses IPs, domains, and hashes to enrich threat context and guide whether to block, monitor, or investigate the IOC.

How do I triage a suspicious IOC to decide whether to block or monitor it?

To triage a suspicious IOC, run an analysis to obtain a threat score and verdict. The output includes actionable recommendations that help you decide whether to block, monitor, or investigate the indicator during incident response.

Can I use this threat intelligence analysis for ongoing risk assessment and threat hunting?

Yes, you can use this threat intelligence analysis for ongoing risk assessment and threat hunting. It evaluates single indicators or batches of IPs, domains, and hashes to provide continuous risk scoring and context enrichment.