What problem does it solve?
This Skill automates the ingestion, normalization, and correlation of cyber threat intelligence, enabling organizations to proactively defend against evolving threats.
Core Features & Use Cases
- Automated Feed Ingestion: Integrates with STIX/TAXII feeds and other sources to collect Indicators of Compromise (IOCs) and threat actor TTPs.
- IOC Lifecycle Management: Manages IOCs from ingestion to expiry, including enrichment and confidence scoring.
- MITRE ATT&CK Mapping: Maps threats to the MITRE ATT&CK framework for better understanding of adversary tactics and identifying defensive gaps.
- Threat Landscape Correlation: Correlates threats with organizational assets and vulnerabilities to prioritize risks.
- Use Case: Automatically ingest threat feeds, map newly discovered IOCs to known threat actors, and visualize their associated MITRE ATT&CK techniques on a coverage heatmap.
Quick Start
Use the threat-intel-engineer skill to ingest the latest STIX/TAXII threat feed from the provided URL.