Evaluates threat intelligence platforms (TIPs) like MISP, OpenCTI, ThreatConnect, Anomali, EclecticIQ on push integrations, STIX/TAXII, automation, UI, and cost for procurement, migration, or maturity assessment.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cybersecurity-skills-zh:evaluating-threat-intelligence-platformsThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
在以下情况下使用本技能:
在以下情况下使用本技能:
请勿使用本技能独立评估推送质量——推送评估是专注于数据质量而非平台能力的独立工作流。
将需求分为必须(M)和期望(D)两类:
核心 TIP 功能:
集成:
运营:
MISP(开源):
OpenCTI(开源):
ThreatConnect(商业):
Anomali ThreatStream(商业):
EclecticIQ Platform(商业):
向入围供应商申请 30 天 PoC。测试:
使用加权评分矩阵(按组织优先级为每个标准分配权重):
评估标准 权重 供应商 A 供应商 B
STIX 2.1 合规性 20% 95 85
SIEM 集成 25% 90 70
ATT&CK 映射 15% 85 95
成本(反向) 20% 60 90
界面/分析师体验 10% 80 75
供应商支持质量 10% 85 80
总计 100% 82.0 81.5
规划 90 天实施计划:
| 术语 | 定义 |
|---|---|
| TIP | 威胁情报平台——用于收集、处理、分析和分发网络威胁情报的软件 |
| TAXII 服务器 | TIP 的组件,按需向消费系统提供 STIX bundle |
| TC Exchange | ThreatConnect 的商业市场,提供预建推送集成和应用连接器 |
| 多租户 | TIP 为多个组织单位或客户提供隔离数据环境服务的能力 |
| 去重 | 识别并合并 TIP 内重复指标,以减少分析师噪音的过程 |
npx claudepluginhub killvxk/cybersecurity-skills-zhStructures TIP procurement and migration evaluations with criteria for STIX/TAXII, API integrations, RBAC, and TCO. Activates for MISP, ThreatConnect, OpenCTI, Anomali, EclecticIQ discussions.
Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Activates for TIP procurement or migration decisions.
Evaluates Threat Intelligence Platforms (TIPs) like MISP, OpenCTI, ThreatConnect based on STIX/TAXII support, integrations, automation, UI, and cost for procurement or migration.