threat-intel-engineer

Integrate, normalize, and correlate cyber threat data from STIX/TAXII feeds.

Updated Feb 22, 2026
One-click install
npx skills add https://github.com/Muath2000/TradeStation --skill threat-intel-engineer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: threat-intel-engineer
Source: https://github.com/Muath2000/TradeStation/tree/main/.claude/skills/threat-intel-engineer
Command: npx skills add https://github.com/Muath2000/TradeStation --skill threat-intel-engineer

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill automates the ingestion, normalization, and correlation of cyber threat intelligence, enabling organizations to proactively defend against evolving threats.

Core Features & Use Cases

  • Automated Feed Ingestion: Integrates with STIX/TAXII feeds and other sources to collect Indicators of Compromise (IOCs) and threat actor TTPs.
  • IOC Lifecycle Management: Manages IOCs from ingestion to expiry, including enrichment and confidence scoring.
  • MITRE ATT&CK Mapping: Maps threats to the MITRE ATT&CK framework for better understanding of adversary tactics and identifying defensive gaps.
  • Threat Landscape Correlation: Correlates threats with organizational assets and vulnerabilities to prioritize risks.
  • Use Case: Automatically ingest threat feeds, map newly discovered IOCs to known threat actors, and visualize their associated MITRE ATT&CK techniques on a coverage heatmap.

Quick Start

Use the threat-intel-engineer skill to ingest the latest STIX/TAXII threat feed from the provided URL.

Frequently Asked Questions about threat-intel-engineer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate STIX/TAXII feed ingestion and IOC lifecycle management?

You can automate STIX/TAXII feed ingestion and IOC lifecycle management by using a threat intelligence platform that collects, normalizes, and enriches indicators of compromise with confidence scoring before expiry.

What is the best way to map threat intelligence data to the MITRE ATT&CK framework?

Mapping threat intelligence to the MITRE ATT&CK framework is achieved by correlating ingested indicators and threat actor TTPs to identify adversary tactics and visualize defensive coverage gaps on a heatmap.

Can I build a threat intelligence platform using Node.js, TypeScript, and PostgreSQL?

Yes, you can build a threat intelligence platform using Node.js, TypeScript, PostgreSQL, Kafka, and Redis to engineer robust ingestion, normalization, and correlation operations for cyber threat data.

How does threat-to-asset correlation prioritize organizational risks?

Threat-to-asset correlation prioritizes risks by automatically mapping ingested threat data and newly discovered IOCs against your organizational assets and vulnerabilities to highlight the most critical exposures.

Do I need Kafka and Redis to correlate cyber threat data at scale?

Using Kafka and Redis supports robust threat intelligence operations by providing the scalable messaging and caching infrastructure needed to process and correlate high-volume cyber threat data streams.