threat-intelligence-enrichment

作成者: tavily-ai

CVE、IOC、マルウェア名、脅威アクター、ベンダー勧告、セキュリティインシデント、エクスプロイトレポート、脆弱性開示などから脅威インテリジェンスを強化します。

npx skills add https://github.com/tavily-ai/use-case-skills --skill threat-intelligence-enrichment

Threat Intelligence Enrichment

Workflow

Use search and extract to enrich security entities with authoritative and recent evidence; use map or crawl for known vendor portals or advisory collections. Keep this skill focused on query construction, source priority, verification, and security synthesis; execution mechanics should come from companion endpoint skills.

Treat the guidance below as base guidance; adapt it to the user's request when appropriate.

  • Identify the input type: CVE, IOC, malware/tool, threat actor, vendor/product, advisory URL, incident, or campaign.
  • Break the task into short subqueries under 400 characters: identifier, affected product, exploit status, vendor advisory, patches, mitigations, exploitation in the wild, and recent reporting.
  • Search first, using exact-match style queries for CVEs, hashes, domains, IPs, advisory IDs, and malware names.
  • Filter sources before extraction. Prioritize NVD/CVE records, vendor advisories, CISA/agency alerts, security research blogs, reputable incident reports, and official patch notes.
  • Extract selected pages that can support exploit status, impact, affected versions, mitigations, timeline, or confidence.
  • Use site navigation for vendor advisory portals or documentation sites when the relevant page is hard to find.
  • Collect scoped advisory, changelog, release note, or documentation sections only when the user needs broad coverage.

Research Budget

  • Start with a small focused search set covering the identifier, vendor advisory, exploit status, and mitigation or patch evidence.
  • Extract only the strongest authoritative sources before drafting.
  • Add more searches only for named gaps, such as missing affected versions, missing patch notes, or unclear exploitation status.
  • Do not use map unless a known vendor portal or documentation site has a specific advisory or release note to locate.
  • Do not use crawl unless the user asks for coverage across many related advisories or docs pages.

Capability Guidance

  • Use search for CVEs, IOCs, advisories, exploit status, affected versions, mitigations, and recent incident reporting.
  • Use extract on selected vendor advisories, CVE records, agency alerts, patch notes, and security research pages.
  • Use map when a vendor portal or documentation site is known but the specific advisory is hard to locate.
  • Use crawl for advisory/doc sets only when the user asks for coverage across many related pages.
  • Use research only for threat landscape reports or multi-campaign summaries.

Query And Source Guidance

  • Use exact identifiers in queries: CVE IDs, advisory IDs, product/version names, hashes, domains, IPs, malware names, and actor aliases.
  • Prioritize vendor advisories, NVD/CVE records, CISA or national agency alerts, CERT/CC, official patch notes, and reputable security research.
  • Treat social posts, exploit-db style references, and secondary news as supporting evidence unless confirmed by authoritative sources.
  • Separate "exploited in the wild", "public PoC", "theoretical exploitability", and "patched" as different statuses.
  • Report failed or inaccessible sources when they affect vendor advisories, CVE records, affected-version evidence, or mitigation guidance.

Output Template

Use this markdown structure and label uncertainty:

# Threat Intelligence Brief: <entity>

## Summary
- Current status:
- Confidence:
- Most important source:

## Entity Details
- Type:
- Aliases/identifiers:
- Related products or systems:

## Impact And Exposure
- Affected products/versions:
- Exploit status:
- Evidence quality:

## Mitigation And Detection
- Patches or mitigations:
- Detection or hunting notes:
- Recommended checks:

## Timeline
- <date>: <event> ([source](URL))

## Sources And Gaps
- Sources:
- Gaps or unresolved claims:

Do not overstate attribution, exploitation, or compromise evidence. Label speculation and unverified claims.

tavily-aiのその他のスキル

research
tavily-ai
あらゆるトピックについて、自動的な情報収集、分析、引用を伴う包括的なリサーチを実施。明示的な引用付きで複数ソースのウェブリサーチを行い、比較、時事問題、市場分析、詳細レポートに最適。3つのモデルオプションを提供:ミニ(対象を絞った単一トピックのリサーチ、約30秒)、プロ(包括的な多角的分析、約60~120秒)、オート(APIによる複雑性検出で自動選択)。Tavily MCPサーバーを通じてOAuth認証を行い、自動ブラウザベースのログインを...
official
search
tavily-ai
LLM最適化された結果、関連性スコアリング、柔軟なフィルタリングを備えたWeb検索。4つの検索深度モード(超高速、高速、基本、高度)をサポートし、レイテンシと関連性のトレードオフを設定可能。ドメインフィルタリング、時間範囲制約、日付範囲、国別ブースト、生コンテンツ抽出を含む。タイトル、URL、コンテンツスニペット、関連性スコアを含む結果を返し、オプションで画像結果とファビコンも提供。Tavily MCPサーバーまたはAPIキー設定による自動OAuth認証。
official
tavily-best-practices
tavily-ai
LLM向けWeb検索API。リアルタイムデータアクセス、コンテンツ抽出、サイトクローリング、AI駆動のリサーチを提供。5つのコアメソッド:search()(Web結果取得)、extract()(URLコンテンツ抽出)、crawl()(サイト全体の抽出)、map()(URL発見)、research()(エンドツーエンドのAI合成)。PythonおよびJavaScript SDKに対応し、非同期クライアントによる並列クエリと設定可能な検索深度(ultra-fast/fast/basic/advanced)をサポート。Crawlメソッドはセマンティック指示を受け付け、抽出を特定の内容に集中させる。
official
tavily-cli
tavily-ai
Web検索、コンテンツ抽出、サイトクローリング、およびTavily CLIによる深層リサーチ。検索、抽出、URL発見、一括クローリング、引用付きマルチソースリサーチをカバーする5つのコマンドモード。すべてのコマンドはJSON出力とファイル保存に対応し、構造化されたエージェントワークフローを実現。エスカレーションパターンにより、単純な検索から抽出、マッピング、クローリング、包括的なリサーチまで、ニーズに応じてガイド。tavily-cliのインストールと、tvly loginによるAPIキー認証が必要。
official
tavily-crawl
tavily-ai
マルチページウェブサイトクローラーで、セマンティックフィルタリングとマークダウンエクスポート機能を備えています。深さと幅を制御してサイト全体のセクションをクロールし、パス正規表現、ドメイン、または自然言語の指示でフィルタリングして結果を絞り込みます。各ページを--output-dirでローカルのマークダウンファイルとして保存するか、エージェント処理用に構造化JSONを返します。結果をLLMに渡す際のコンテキスト肥大化を防ぐために、チャンク抽出を伴うセマンティック指示を使用します。オフラインのドキュメントダウンロードには全ページ抽出を使用します。対応...
official
tavily-dynamic-search
tavily-ai
ウェブを検索し、結果をフィルタリングしてコンテンツを抽出することで、生の検索データがコンテキストウィンドウに入ることはありません。厳選されたprint()出力のみが返されます。
official
tavily-extract
tavily-ai
最大20件のURLからクリーンなマークダウンまたはテキストを抽出。JavaScriptレンダリングとクエリに焦点を当てたチャンク分割をサポート。JavaScriptでレンダリングされたページを処理し、抽出深度を設定可能(シンプルなページは基本、動的なSPAやテーブルは高度)。クエリに焦点を当てた抽出をサポートし、全ページではなく関連コンテンツのチャンクのみを返却。デフォルトでLLM最適化されたマークダウンを返し、プレーンテキスト形式や構造化JSON出力のオプションも提供。1回の呼び出しで最大20件のURLを処理。
official
tavily-map
tavily-ai
ウェブサイトからコンテンツを抽出せずに高速なURL発見が可能で、大規模サイト上の特定ページを見つけるのに最適です。設定可能な深さと幅、正規表現によるパスフィルタリング、セマンティックフィルタリングのための自然言語指示を用いて、ドメイン上の全URLの構造化リストを返します。深さ制御(1~5レベル)、ページごとの幅制限、外部リンクの包含/除外、正規表現パターンによるドメインフィルタリングをサポートします。ワークフローのステップ1として設計されており、マッピングで目的のページを見つけ、その後抽出や...を使用します。
official