Skip to main content
building-threat-intelligence-feed-integration Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need to operationalize threat intelligence by automating feed ingestion, normalization, scoring, and distribution to detection systems.
Ir a la instalación Skills Marketplace Descubre y explora habilidades de IA creadas por la comunidad.
Instalar con Codex o Claude Copia este prompt, pégalo en Codex, Claude u otro asistente, y deja que revise la página de la skill y la instale por ti.
Copiar promptMostrar detalles del prompt Un comando directo omite el prompt de revisión. Revisa el origen antes de ejecutarlo.
npx skills add https://github.com/mukul975/Anthropic-Cybersecurity-Skills --skill building-threat-intelligence-feed-integrationEl comando permanece en una sola línea. Desplázate horizontalmente para revisarlo antes de copiarlo.
¿Prefieres una copia local? Descarga los archivos que SkillsMP tiene disponibles ahora.
Descargar Zip Descargando... Más de este repositorio abusing-dpapi-for-credential-access Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or Impacket's dpapi.py, including domain-wide decryption via the DPAPI backup key. Use during authorized red-team credential-access engagements after gaining a foothold or when triaging DPAPI blobs pulled from a host.
abusing-shadow-credentials-for-privesc Take over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, or Certipy, then authenticate via PKINIT to recover the target's NT hash without a password reset. Use when BloodHound shows GenericWrite/GenericAll/AddKeyCredentialLink over a target, as a stealthier alternative to ForceChangePassword, during authorized red-team engagements.
acquiring-disk-image-with-dd-and-dcfldd Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification (MD5/SHA) during acquisition. Use when imaging a suspect drive, USB device, or memory card for investigation, preserving volatile disk evidence during incident response, or producing a verified copy for legal or law-enforcement proceedings before any destructive analysis.
Ocupaciones relacionadas SOC
Basado en la clasificación ocupacional SOC
Explorador de archivos
4 archivos name building-threat-intelligence-feed-integration description Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need to operationalize threat intelligence by automating feed ingestion, normalization, scoring, and distribution to detection systems.
domain cybersecurity subdomain soc-operations tags ["soc","threat-intelligence","stix","taxii","misp","feeds","ioc","siem-integration"] version 1.0 author mahipal license Apache-2.0 nist_csf ["DE.CM-01","DE.AE-02","RS.MA-01","DE.AE-06"] mitre_attack ["T1071","T1105","T1588.001"]
Building Threat Intelligence Feed Integration
When to Use
Use this skill when:
SOC teams need automated ingestion of threat intelligence feeds into SIEM platforms
Multiple TI sources require normalization into a common format (STIX 2.1)
Detection systems need real-time IOC matching against network and endpoint telemetry
TI feed quality assessment and deduplication processes need to be established
Do not use for manual IOC lookup — use dedicated enrichment tools (VirusTotal, AbuseIPDB) for ad-hoc queries.
Prerequisites
MISP instance or Threat Intelligence Platform (TIP) for feed aggregation
STIX/TAXII client library (taxii2-client, stix2 Python packages)
SIEM platform (Splunk ES, Elastic Security, or Sentinel) with TI framework configured
API keys for commercial and open-source feeds (AlienVault OTX, Abuse.ch, CISA AIS)
Python 3.8+ for feed processing automation
Workflow
Step 1: Identify and Catalog Intelligence Sources
Map available feeds by type, format, and update frequency:
Feed Source Format IOC Types Update Freq Cost AlienVault OTX STIX/JSON IP, Domain, Hash, URL Real-time Free Abuse.ch URLhaus CSV/JSON URL, Domain Every 5 min Free Abuse.ch MalwareBazaar JSON API File Hash Real-time Free CISA AIS STIX/TAXII 2.1 All types Daily Free (US Gov) CrowdStrike Intel STIX/JSON All types + Actor TTP Real-time Commercial Mandiant Advantage STIX 2.1 All types + Reports Real-time Commercial
Step 2: Ingest STIX/TAXII Feeds
Connect to a TAXII 2.1 server and download indicators:
from taxii2client.v21 import Server, Collection
from stix2 import parse
server = Server(
,
user= ,
password=
)
api_root server.api_roots:
( )
collection api_root.collections:
( )
collection = Collection(
,
user= ,
password=
)
datetime datetime, timedelta
added_after = (datetime.utcnow() - timedelta(days= )).strftime( )
response = collection.get_objects(added_after=added_after, =[ ])
obj response.get( , []):
indicator = parse(obj)
( )
( )
( )
( )
( )
"https://taxii.cisa.gov/taxii2/"
"your_username"
"your_password"
for
in
print
f"API Root: {api_root.title} "
for
in
print
f" Collection: {collection.title} (ID: {collection.id } )"
"https://taxii.cisa.gov/taxii2/collections/COLLECTION_ID/"
"your_username"
"your_password"
from
import
1
"%Y-%m-%dT%H:%M:%S.000Z"
type
"indicator"
for
in
"objects"
print
f"Type: {indicator.type } "
print
f"Pattern: {indicator.pattern} "
print
f"Valid Until: {indicator.valid_until} "
print
f"Confidence: {indicator.confidence} "
print
"---"
Step 3: Ingest Open-Source Feeds import requests
import csv
from io import StringIO
response = requests.get("https://urlhaus.abuse.ch/downloads/csv_recent/" )
reader = csv.reader(StringIO(response.text), delimiter=',' )
indicators = []
for row in reader:
if row[0 ].startswith("#" ):
continue
indicators.append({
"id" : row[0 ],
"dateadded" : row[1 ],
"url" : row[2 ],
"url_status" : row[3 ],
"threat" : row[5 ],
"tags" : row[6 ]
})
print (f"Ingested {len (indicators)} URLs from URLhaus" )
active = [i for i in indicators if i["url_status" ] == "online" ]
print (f"Active threats: {len (active)} " )
AlienVault OTX Pulse Feed:
from OTXv2 import OTXv2, IndicatorTypes
otx = OTXv2("YOUR_OTX_API_KEY" )
pulses = otx.getall(modified_since="2024-03-14T00:00:00" )
for pulse in pulses:
print (f"Pulse: {pulse['name' ]} " )
print (f"Tags: {pulse['tags' ]} " )
for indicator in pulse["indicators" ]:
print (f" IOC: {indicator['indicator' ]} ({indicator['type' ]} )" )
Abuse.ch Feodo Tracker (C2 IPs):
response = requests.get("https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.json" )
c2_data = response.json()
for entry in c2_data:
print (f"IP: {entry['ip_address' ]} :{entry['port' ]} " )
print (f"Malware: {entry['malware' ]} " )
print (f"First Seen: {entry['first_seen' ]} " )
print (f"Last Online: {entry['last_online' ]} " )
Step 4: Normalize and Deduplicate Convert all feeds to STIX 2.1 format for standardization:
from stix2 import Indicator, Bundle
import hashlib
def create_stix_indicator (ioc_value, ioc_type, source, confidence=50 ):
"""Convert raw IOC to STIX 2.1 indicator"""
pattern_map = {
"ipv4" : f"[ipv4-addr:value = '{ioc_value} ']" ,
"domain" : f"[domain-name:value = '{ioc_value} ']" ,
"url" : f"[url:value = '{ioc_value} ']" ,
"sha256" : f"[file:hashes.'SHA-256' = '{ioc_value} ']" ,
"md5" : f"[file:hashes.MD5 = '{ioc_value} ']" ,
}
return Indicator(
name=f"{ioc_type} : {ioc_value} " ,
pattern=pattern_map[ioc_type],
pattern_type="stix" ,
valid_from="2024-03-15T00:00:00Z" ,
confidence=confidence,
labels=[source],
custom_properties={"x_source_feed" : source}
)
seen_iocs = set ()
unique_indicators = []
for ioc in all_collected_iocs:
ioc_hash = hashlib.sha256(f"{ioc['type' ]} :{ioc['value' ]} " .encode()).hexdigest()
if ioc_hash not in seen_iocs:
seen_iocs.add(ioc_hash)
unique_indicators.append(
create_stix_indicator(ioc["value" ], ioc["type" ], ioc["source" ])
)
bundle = Bundle(objects=unique_indicators)
print (f"Unique indicators: {len (unique_indicators)} " )
Step 5: Push to SIEM Threat Intelligence Framework Push to Splunk ES Threat Intelligence:
import requests
splunk_url = "https://splunk.company.com:8089"
headers = {"Authorization" : f"Bearer {splunk_token} " }
for indicator in unique_indicators:
ioc_value = indicator.pattern.split("'" )[1 ]
data = {
"ip" : ioc_value,
"description" : indicator.name,
"weight" : indicator.confidence // 10 ,
"threat_key" : indicator.id ,
"source_feed" : indicator.get("x_source_feed" , "unknown" )
}
requests.post(
f"{splunk_url} /services/data/threat_intel/item/ip_intel" ,
headers=headers, data=data,
verify=not os.environ.get("SKIP_TLS_VERIFY" , "" ).lower() == "true" ,
)
Push to MISP for centralized management:
from pymisp import PyMISP, MISPEvent, MISPAttribute
misp = PyMISP("https://misp.company.com" , "YOUR_MISP_API_KEY" )
event = MISPEvent()
event.info = f"TI Feed Import - {datetime.now().strftime('%Y-%m-%d' )} "
event.threat_level_id = 2
event.analysis = 2
for ioc in unique_indicators:
attr = MISPAttribute()
attr.type = "ip-dst" if "ipv4" in ioc.pattern else "domain"
attr.value = ioc.pattern.split("'" )[1 ]
attr.to_ids = True
attr.comment = f"Source: {ioc.get('x_source_feed' , 'mixed' )} "
event.add_attribute(**attr)
result = misp.add_event(event)
print (f"MISP Event created: {result['Event' ]['id' ]} " )
Step 6: Monitor Feed Health and Quality Track feed effectiveness metrics:
index=threat_intel sourcetype="threat_intel_manager"
| stats count AS total_iocs,
dc(threat_key) AS unique_iocs,
dc(source_feed) AS feed_count
by source_feed
| join source_feed [
search index=notable source="Threat Intelligence"
| stats count AS matches by source_feed
]
| eval match_rate = round(matches / unique_iocs * 100, 2)
| sort - match_rate
| table source_feed, unique_iocs, matches, match_rate
Key Concepts Term Definition STIX 2.1 Structured Threat Information Expression — standardized JSON format for sharing threat intelligence objects TAXII Trusted Automated eXchange of Indicator Information — transport protocol for sharing STIX data via REST API TIP Threat Intelligence Platform — centralized system for aggregating, scoring, and distributing threat intelligence IOC Scoring Process of assigning confidence values to indicators based on source reliability and corroboration Feed Deduplication Removing duplicate IOCs across multiple sources while preserving multi-source attribution IOC Expiration Time-to-live policy removing aged indicators (IP: 30 days, Domain: 90 days, Hash: 1 year)
Tools & Systems
MISP : Open-source threat intelligence platform for feed aggregation, correlation, and sharing
AlienVault OTX : Free threat intelligence sharing platform with community pulse feeds
Abuse.ch : Suite of free threat feeds (URLhaus, MalwareBazaar, Feodo Tracker, ThreatFox)
OpenCTI : Open-source cyber threat intelligence platform supporting STIX 2.1 native storage
TAXII2 Client : Python library for connecting to STIX/TAXII 2.1 servers for automated indicator retrieval
Common Scenarios
New Feed Onboarding : Evaluate feed quality, map fields to STIX, configure automated ingestion pipeline
Multi-SIEM Distribution : Push normalized IOCs from MISP to Splunk, Elastic, and Sentinel simultaneously
False Positive Reduction : Score IOCs by source count and age, expire stale indicators automatically
Feed Quality Audit : Compare detection match rates across feeds to identify highest-value sources
Incident IOC Sharing : Package investigation IOCs as STIX bundle and share with ISACs via TAXII
Output Format THREAT INTEL FEED STATUS — Daily Report
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Date: 2024-03-15
Total IOCs: 45,892 active indicators
Feed Health:
Feed IOCs Matches Match Rate Status
Abuse.ch URLhaus 12,340 47 0.38% HEALTHY
AlienVault OTX 18,567 23 0.12% HEALTHY
Abuse.ch Feodo 1,203 12 1.00% HEALTHY
CISA AIS 8,945 8 0.09% HEALTHY
CrowdStrike Intel 4,837 31 0.64% HEALTHY
Actions Today:
New IOCs ingested: 1,247
IOCs expired: 892
Duplicates removed: 156
SIEM matches: 121 notable events generated
False positives: 3 (CDN IPs removed from feed)