From threat-intelligence
Enrich and pivot on indicators of compromise — resolve context, infrastructure, and relationships, assess confidence and relevance, and decide block vs. monitor. Use to add analytic value to raw IOCs from an incident, feed, or hunt.
How this skill is triggered — by the user, by Claude, or both
Slash command
/threat-intelligence:ioc-enrichmentThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
IOCs turned into context: what each indicator is, how it relates to others and to
IOCs turned into context: what each indicator is, how it relates to others and to known actors, how confident/relevant it is, and what defensive action it warrants.
An enriched indicator set: indicator · type · context/infrastructure · related
indicators · actor/campaign link · confidence · action · expiry. Confirmed-malicious
TTPs → detection-engineering; clusters → threat-actor-profiling.
Validate before blocking — shared/benign infrastructure on a blocklist causes outages. Pivot on durable overlaps (infrastructure, certs, malware config) rather than treating indicators in isolation. Atomic IOCs decay; set review/expiry so stale blocks don't accumulate.
npx claudepluginhub jassics/awesome-claude-security --plugin threat-intelligenceCreates, edits, and optimizes skills for Claude Code, including drafting, evaluating with test prompts, iterating on performance, and improving skill descriptions for better triggering accuracy.