zettelforge

Community

Agentic CTI memory for threat intel recall.

Authorrolandpg
Version1.0.0
Installs0

System Documentation

What problem does it solve?

ZettelForge addresses the challenge of maintaining continuity in threat investigations by providing a persistent, queryable memory system that captures, stores, and recalls threat intelligence, actor aliases, IOCs, and ATT&CK mappings across investigations.

Core Features & Use Cases

  • Hybrid TypeDB (STIX 2.1 ontology) integrated with LanceDB vector search for fast retrieval and relational reasoning.
  • Zero external AI dependencies enabling on-host operation for secure investigations.
  • Entity extraction, memory graph traversal, and multi-hop recall for incident response and threat intel analysis.
  • Synthesis, cross-entity recall, and threat timeline construction for concise reporting.

Quick Start

To begin, ingest threat intel and surface relevant IOCs and actors.

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: zettelforge
Download link: https://github.com/rolandpg/zettelforge/archive/main.zip#zettelforge

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.