threat-intelligence-enrichment

Perkaya intelijen ancaman dari CVE, IOC, nama malware, aktor ancaman, advisori vendor, insiden keamanan, laporan eksploitasi, pengungkapan kerentanan,…

npx skills add https://github.com/tavily-ai/use-case-skills --skill threat-intelligence-enrichment

Threat Intelligence Enrichment

Workflow

Use search and extract to enrich security entities with authoritative and recent evidence; use map or crawl for known vendor portals or advisory collections. Keep this skill focused on query construction, source priority, verification, and security synthesis; execution mechanics should come from companion endpoint skills.

Treat the guidance below as base guidance; adapt it to the user's request when appropriate.

  • Identify the input type: CVE, IOC, malware/tool, threat actor, vendor/product, advisory URL, incident, or campaign.
  • Break the task into short subqueries under 400 characters: identifier, affected product, exploit status, vendor advisory, patches, mitigations, exploitation in the wild, and recent reporting.
  • Search first, using exact-match style queries for CVEs, hashes, domains, IPs, advisory IDs, and malware names.
  • Filter sources before extraction. Prioritize NVD/CVE records, vendor advisories, CISA/agency alerts, security research blogs, reputable incident reports, and official patch notes.
  • Extract selected pages that can support exploit status, impact, affected versions, mitigations, timeline, or confidence.
  • Use site navigation for vendor advisory portals or documentation sites when the relevant page is hard to find.
  • Collect scoped advisory, changelog, release note, or documentation sections only when the user needs broad coverage.

Research Budget

  • Start with a small focused search set covering the identifier, vendor advisory, exploit status, and mitigation or patch evidence.
  • Extract only the strongest authoritative sources before drafting.
  • Add more searches only for named gaps, such as missing affected versions, missing patch notes, or unclear exploitation status.
  • Do not use map unless a known vendor portal or documentation site has a specific advisory or release note to locate.
  • Do not use crawl unless the user asks for coverage across many related advisories or docs pages.

Capability Guidance

  • Use search for CVEs, IOCs, advisories, exploit status, affected versions, mitigations, and recent incident reporting.
  • Use extract on selected vendor advisories, CVE records, agency alerts, patch notes, and security research pages.
  • Use map when a vendor portal or documentation site is known but the specific advisory is hard to locate.
  • Use crawl for advisory/doc sets only when the user asks for coverage across many related pages.
  • Use research only for threat landscape reports or multi-campaign summaries.

Query And Source Guidance

  • Use exact identifiers in queries: CVE IDs, advisory IDs, product/version names, hashes, domains, IPs, malware names, and actor aliases.
  • Prioritize vendor advisories, NVD/CVE records, CISA or national agency alerts, CERT/CC, official patch notes, and reputable security research.
  • Treat social posts, exploit-db style references, and secondary news as supporting evidence unless confirmed by authoritative sources.
  • Separate "exploited in the wild", "public PoC", "theoretical exploitability", and "patched" as different statuses.
  • Report failed or inaccessible sources when they affect vendor advisories, CVE records, affected-version evidence, or mitigation guidance.

Output Template

Use this markdown structure and label uncertainty:

# Threat Intelligence Brief: <entity>

## Summary
- Current status:
- Confidence:
- Most important source:

## Entity Details
- Type:
- Aliases/identifiers:
- Related products or systems:

## Impact And Exposure
- Affected products/versions:
- Exploit status:
- Evidence quality:

## Mitigation And Detection
- Patches or mitigations:
- Detection or hunting notes:
- Recommended checks:

## Timeline
- <date>: <event> ([source](URL))

## Sources And Gaps
- Sources:
- Gaps or unresolved claims:

Do not overstate attribution, exploitation, or compromise evidence. Label speculation and unverified claims.

Lebih banyak skill dari tavily-ai

research
tavily-ai
We need to translate the given English text into Bahasa Indonesia. The instruction says to preserve product names, protocol names, URLs, numbers, and technical terms. The name "research" is to be preserved if it appears in the source text, but we are not to include the name unless it appears. The source text does not contain the word "research" as a standalone name? Actually it starts with "Comprehensive research on any topic..." so "research" is part of the text. But the instruction says "Do not include the name unless it appears in the source text." So we keep it as is. Also preserve "Tavily MCP server", "OAuth", etc. Translate the rest naturally. Let me translate: "Comprehensive research on any topic with automatic source gathering, analysis, and citations." -> "Riset komprehensif tentang topik apa pun dengan pengumpulan sumber, analisis, dan kutipan otomatis." "Conducts multi-source web research with explicit citations, ideal for comparisons, current events, market analysis, and detailed reports
official
search
tavily-ai
Pencarian web dengan hasil yang dioptimalkan untuk LLM, penilaian relevansi, dan penyaringan fleksibel. Mendukung empat mode kedalaman pencarian (ultra-cepat, cepat, dasar, lanjutan) dengan pengaturan latensi dan tradeoff relevansi yang dapat dikonfigurasi. Termasuk penyaringan domain, batasan rentang waktu, rentang tanggal, penguatan negara, dan ekstraksi konten mentah. Mengembalikan hasil dengan judul, URL, cuplikan konten, dan skor relevansi; hasil gambar opsional dan favicon. Otentikasi OAuth otomatis melalui server Tavily MCP atau konfigurasi kunci API;...
official
tavily-best-practices
tavily-ai
API pencarian web untuk LLM dengan akses data real-time, ekstraksi konten, perayapan situs, dan riset bertenaga AI. Lima metode inti: search() untuk hasil web, extract() untuk konten URL, crawl() untuk ekstraksi seluruh situs, map() untuk penemuan URL, dan research() untuk sintesis AI ujung-ke-ujung. Mendukung SDK Python dan JavaScript dengan klien asinkron untuk kueri paralel dan kedalaman pencarian yang dapat dikonfigurasi (ultra-cepat/cepat/dasar/lanjutan). Metode crawl menerima instruksi semantik untuk memfokuskan ekstraksi pada...
official
tavily-cli
tavily-ai
Pencarian web, ekstraksi konten, perayapan situs, dan riset mendalam melalui Tavily CLI. Lima mode perintah yang mencakup pencarian, ekstraksi, penemuan URL, perayapan massal, dan riset multi-sumber dengan kutipan. Semua perintah mendukung output JSON dan penyimpanan file untuk alur kerja terstruktur dan agen. Pola eskalasi memandu Anda dari pencarian sederhana melalui ekstraksi, pemetaan, perayapan, hingga riset komprehensif berdasarkan kebutuhan Anda. Memerlukan instalasi tavily-cli dan autentikasi kunci API melalui tvly login.
official
tavily-crawl
tavily-ai
Perayap situs web multi-halaman dengan penyaringan semantik dan ekspor markdown. Jelajahi seluruh bagian situs dengan kontrol kedalaman dan luas; filter berdasarkan regex jalur, domain, atau instruksi bahasa alami untuk memfokuskan hasil. Simpan setiap halaman sebagai file markdown lokal melalui --output-dir, atau kembalikan JSON terstruktur untuk pemrosesan agen. Gunakan instruksi semantik dengan ekstraksi potongan untuk mencegah pembengkakan konteks saat memberikan hasil ke LLM; gunakan ekstraksi halaman penuh untuk unduhan dokumentasi offline. Mendukung...
official
tavily-dynamic-search
tavily-ai
Cari web, filter hasil, dan ekstrak konten sehingga data pencarian mentah tidak pernah masuk ke jendela konteks Anda. Hanya keluaran print() yang telah dikurasi yang akan kembali.
official
tavily-extract
tavily-ai
Mengekstrak markdown atau teks bersih dari hingga 20 URL, dengan dukungan rendering JavaScript dan pemotongan berbasis kueri. Menangani halaman yang dirender JavaScript dengan kedalaman ekstraksi yang dapat dikonfigurasi (dasar untuk halaman sederhana, lanjutan untuk SPA dinamis dan tabel). Mendukung ekstraksi berbasis kueri untuk mengembalikan hanya potongan konten yang relevan, bukan halaman penuh. Mengembalikan markdown yang dioptimalkan untuk LLM secara default, dengan opsi format teks biasa dan output JSON terstruktur. Memproses hingga 20 URL dalam satu panggilan;...
official
tavily-map
tavily-ai
Penemuan URL cepat di situs web tanpa mengekstrak konten, ideal untuk menemukan halaman tertentu di situs besar. Mengembalikan daftar terstruktur dari semua URL di suatu domain dengan kedalaman dan lebar yang dapat dikonfigurasi, pemfilteran jalur regex, dan instruksi bahasa alami untuk pemfilteran semantik. Mendukung kontrol kedalaman (1–5 level), batas lebar per halaman, penyertaan/pengecualian tautan eksternal, dan pemfilteran domain melalui pola regex. Dirancang sebagai langkah 1 dalam alur kerja: petakan untuk menemukan halaman yang tepat, lalu gunakan ekstrak atau...
official