threat-intelligence-enrichment

Enrich threat intelligence from CVEs, IOCs, malware names, threat actors, vendor advisories, security incidents, exploit reports, vulnerability disclosures,…

npx skills add https://github.com/tavily-ai/use-case-skills --skill threat-intelligence-enrichment

Threat Intelligence Enrichment

Workflow

Use search and extract to enrich security entities with authoritative and recent evidence; use map or crawl for known vendor portals or advisory collections. Keep this skill focused on query construction, source priority, verification, and security synthesis; execution mechanics should come from companion endpoint skills.

Treat the guidance below as base guidance; adapt it to the user's request when appropriate.

  • Identify the input type: CVE, IOC, malware/tool, threat actor, vendor/product, advisory URL, incident, or campaign.
  • Break the task into short subqueries under 400 characters: identifier, affected product, exploit status, vendor advisory, patches, mitigations, exploitation in the wild, and recent reporting.
  • Search first, using exact-match style queries for CVEs, hashes, domains, IPs, advisory IDs, and malware names.
  • Filter sources before extraction. Prioritize NVD/CVE records, vendor advisories, CISA/agency alerts, security research blogs, reputable incident reports, and official patch notes.
  • Extract selected pages that can support exploit status, impact, affected versions, mitigations, timeline, or confidence.
  • Use site navigation for vendor advisory portals or documentation sites when the relevant page is hard to find.
  • Collect scoped advisory, changelog, release note, or documentation sections only when the user needs broad coverage.

Research Budget

  • Start with a small focused search set covering the identifier, vendor advisory, exploit status, and mitigation or patch evidence.
  • Extract only the strongest authoritative sources before drafting.
  • Add more searches only for named gaps, such as missing affected versions, missing patch notes, or unclear exploitation status.
  • Do not use map unless a known vendor portal or documentation site has a specific advisory or release note to locate.
  • Do not use crawl unless the user asks for coverage across many related advisories or docs pages.

Capability Guidance

  • Use search for CVEs, IOCs, advisories, exploit status, affected versions, mitigations, and recent incident reporting.
  • Use extract on selected vendor advisories, CVE records, agency alerts, patch notes, and security research pages.
  • Use map when a vendor portal or documentation site is known but the specific advisory is hard to locate.
  • Use crawl for advisory/doc sets only when the user asks for coverage across many related pages.
  • Use research only for threat landscape reports or multi-campaign summaries.

Query And Source Guidance

  • Use exact identifiers in queries: CVE IDs, advisory IDs, product/version names, hashes, domains, IPs, malware names, and actor aliases.
  • Prioritize vendor advisories, NVD/CVE records, CISA or national agency alerts, CERT/CC, official patch notes, and reputable security research.
  • Treat social posts, exploit-db style references, and secondary news as supporting evidence unless confirmed by authoritative sources.
  • Separate "exploited in the wild", "public PoC", "theoretical exploitability", and "patched" as different statuses.
  • Report failed or inaccessible sources when they affect vendor advisories, CVE records, affected-version evidence, or mitigation guidance.

Output Template

Use this markdown structure and label uncertainty:

# Threat Intelligence Brief: <entity>

## Summary
- Current status:
- Confidence:
- Most important source:

## Entity Details
- Type:
- Aliases/identifiers:
- Related products or systems:

## Impact And Exposure
- Affected products/versions:
- Exploit status:
- Evidence quality:

## Mitigation And Detection
- Patches or mitigations:
- Detection or hunting notes:
- Recommended checks:

## Timeline
- <date>: <event> ([source](URL))

## Sources And Gaps
- Sources:
- Gaps or unresolved claims:

Do not overstate attribution, exploitation, or compromise evidence. Label speculation and unverified claims.

More skills from tavily-ai

research
tavily-ai
Comprehensive research on any topic with automatic source gathering, analysis, and citations. Conducts multi-source web research with explicit citations, ideal for comparisons, current events, market analysis, and detailed reports Offers three model options: mini for targeted single-topic research (~30s), pro for comprehensive multi-angle analysis (~60-120s), and auto for API-driven complexity detection Authenticates via OAuth through Tavily MCP server with automatic browser-based login on...
official
search
tavily-ai
Web search with LLM-optimized results, relevance scoring, and flexible filtering. Supports four search depth modes (ultra-fast, fast, basic, advanced) with configurable latency and relevance tradeoffs Includes domain filtering, time range constraints, date ranges, country boosting, and raw content extraction Returns results with title, URL, content snippet, and relevance score; optional image results and favicons Automatic OAuth authentication via Tavily MCP server or API key configuration;...
official
tavily-best-practices
tavily-ai
Web search API for LLMs with real-time data access, content extraction, site crawling, and AI-powered research. Five core methods: search() for web results, extract() for URL content, crawl() for site-wide extraction, map() for URL discovery, and research() for end-to-end AI synthesis Supports Python and JavaScript SDKs with async clients for parallel queries and configurable search depth (ultra-fast/fast/basic/advanced) Crawl method accepts semantic instructions to focus extraction on...
official
tavily-cli
tavily-ai
Web search, content extraction, site crawling, and deep research via Tavily CLI. Five command modes covering search, extraction, URL discovery, bulk crawling, and multi-source research with citations All commands support JSON output and file saving for structured, agentic workflows Escalation pattern guides you from simple search through extraction, mapping, crawling, to comprehensive research based on your needs Requires tavily-cli installation and API key authentication via tvly login
official
tavily-crawl
tavily-ai
Multi-page website crawler with semantic filtering and markdown export. Crawl entire site sections with depth and breadth control; filter by path regex, domain, or natural language instructions to focus results Save each page as local markdown files via --output-dir , or return structured JSON for agentic processing Use semantic instructions with chunk extraction to prevent context bloat when feeding results to LLMs; use full-page extraction for offline documentation downloads Supports...
official
tavily-dynamic-search
tavily-ai
Search the web, filter results, and extract content so that raw search data never enters your context window . Only your curated print() output comes back.
official
tavily-extract
tavily-ai
Extract clean markdown or text from up to 20 URLs, with JavaScript rendering and query-focused chunking support. Handles JavaScript-rendered pages with configurable extraction depth (basic for simple pages, advanced for dynamic SPAs and tables) Supports query-focused extraction to return only relevant content chunks instead of full pages Returns LLM-optimized markdown by default, with options for plain text format and structured JSON output Processes up to 20 URLs in a single call;...
official
tavily-map
tavily-ai
Fast URL discovery on websites without extracting content, ideal for finding specific pages on large sites. Returns structured lists of all URLs on a domain with configurable depth and breadth, regex path filtering, and natural language instructions for semantic filtering Supports depth control (1–5 levels), breadth limits per page, external link inclusion/exclusion, and domain filtering via regex patterns Designed as step 1 in a workflow: map to find the right page, then use extract or...
official