threat-intelligence-enrichment

작성자: tavily-ai

CVE, IOC, 악성코드 이름, 위협 행위자, 공급업체 권고, 보안 인시던트, 익스플로잇 보고서, 취약점 공개 등으로부터 위협 인텔리전스를 강화합니다.

npx skills add https://github.com/tavily-ai/use-case-skills --skill threat-intelligence-enrichment

Threat Intelligence Enrichment

Workflow

Use search and extract to enrich security entities with authoritative and recent evidence; use map or crawl for known vendor portals or advisory collections. Keep this skill focused on query construction, source priority, verification, and security synthesis; execution mechanics should come from companion endpoint skills.

Treat the guidance below as base guidance; adapt it to the user's request when appropriate.

  • Identify the input type: CVE, IOC, malware/tool, threat actor, vendor/product, advisory URL, incident, or campaign.
  • Break the task into short subqueries under 400 characters: identifier, affected product, exploit status, vendor advisory, patches, mitigations, exploitation in the wild, and recent reporting.
  • Search first, using exact-match style queries for CVEs, hashes, domains, IPs, advisory IDs, and malware names.
  • Filter sources before extraction. Prioritize NVD/CVE records, vendor advisories, CISA/agency alerts, security research blogs, reputable incident reports, and official patch notes.
  • Extract selected pages that can support exploit status, impact, affected versions, mitigations, timeline, or confidence.
  • Use site navigation for vendor advisory portals or documentation sites when the relevant page is hard to find.
  • Collect scoped advisory, changelog, release note, or documentation sections only when the user needs broad coverage.

Research Budget

  • Start with a small focused search set covering the identifier, vendor advisory, exploit status, and mitigation or patch evidence.
  • Extract only the strongest authoritative sources before drafting.
  • Add more searches only for named gaps, such as missing affected versions, missing patch notes, or unclear exploitation status.
  • Do not use map unless a known vendor portal or documentation site has a specific advisory or release note to locate.
  • Do not use crawl unless the user asks for coverage across many related advisories or docs pages.

Capability Guidance

  • Use search for CVEs, IOCs, advisories, exploit status, affected versions, mitigations, and recent incident reporting.
  • Use extract on selected vendor advisories, CVE records, agency alerts, patch notes, and security research pages.
  • Use map when a vendor portal or documentation site is known but the specific advisory is hard to locate.
  • Use crawl for advisory/doc sets only when the user asks for coverage across many related pages.
  • Use research only for threat landscape reports or multi-campaign summaries.

Query And Source Guidance

  • Use exact identifiers in queries: CVE IDs, advisory IDs, product/version names, hashes, domains, IPs, malware names, and actor aliases.
  • Prioritize vendor advisories, NVD/CVE records, CISA or national agency alerts, CERT/CC, official patch notes, and reputable security research.
  • Treat social posts, exploit-db style references, and secondary news as supporting evidence unless confirmed by authoritative sources.
  • Separate "exploited in the wild", "public PoC", "theoretical exploitability", and "patched" as different statuses.
  • Report failed or inaccessible sources when they affect vendor advisories, CVE records, affected-version evidence, or mitigation guidance.

Output Template

Use this markdown structure and label uncertainty:

# Threat Intelligence Brief: <entity>

## Summary
- Current status:
- Confidence:
- Most important source:

## Entity Details
- Type:
- Aliases/identifiers:
- Related products or systems:

## Impact And Exposure
- Affected products/versions:
- Exploit status:
- Evidence quality:

## Mitigation And Detection
- Patches or mitigations:
- Detection or hunting notes:
- Recommended checks:

## Timeline
- <date>: <event> ([source](URL))

## Sources And Gaps
- Sources:
- Gaps or unresolved claims:

Do not overstate attribution, exploitation, or compromise evidence. Label speculation and unverified claims.

tavily-ai의 다른 스킬

research
tavily-ai
모든 주제에 대해 자동 소스 수집, 분석 및 인용을 포함한 포괄적 연구를 수행합니다. 명확한 인용과 함께 다중 소스 웹 연구를 진행하며, 비교 분석, 최신 이슈, 시장 분석 및 상세 보고서에 적합합니다. 세 가지 모델 옵션을 제공합니다: 미니(단일 주제 집중 연구, 약 30초), 프로(포괄적 다각도 분석, 약 60-120초), 오토(API 기반 복잡도 자동 감지). Tavily MCP 서버를 통해 OAuth 인증을 하며, 자동 브라우저 기반 로그인을 지원합니다.
official
search
tavily-ai
LLM 최적화 결과, 관련성 점수, 유연한 필터링을 갖춘 웹 검색. 네 가지 검색 심도 모드(초고속, 빠름, 기본, 고급)를 지원하며 지연 시간과 관련성 간의 균형을 설정 가능. 도메인 필터링, 시간 범위 제약, 날짜 범위, 국가 가중치 부여, 원본 콘텐츠 추출 포함. 제목, URL, 콘텐츠 스니펫, 관련성 점수와 함께 결과 반환; 선택적 이미지 결과 및 파비콘. Tavily MCP 서버 또는 API 키 구성을 통한 자동 OAuth 인증;...
official
tavily-best-practices
tavily-ai
LLM을 위한 웹 검색 API로, 실시간 데이터 접근, 콘텐츠 추출, 사이트 크롤링, AI 기반 리서치를 제공합니다. 다섯 가지 핵심 메서드: 웹 결과 검색을 위한 search(), URL 콘텐츠 추출을 위한 extract(), 사이트 전체 추출을 위한 crawl(), URL 발견을 위한 map(), 종단 간 AI 합성을 위한 research()를 지원합니다. Python 및 JavaScript SDK를 제공하며, 병렬 쿼리와 설정 가능한 검색 심도(초고속/고속/기본/고급)를 위한 비동기 클라이언트를 포함합니다. Crawl 메서드는 추출 대상을 집중시키기 위해 의미론적 지시를 받아들입니다...
official
tavily-cli
tavily-ai
Tavily CLI를 통한 웹 검색, 콘텐츠 추출, 사이트 크롤링 및 심층 리서치. 검색, 추출, URL 발견, 대량 크롤링, 인용 포함 다중 소스 리서치를 아우르는 다섯 가지 명령 모드. 모든 명령은 JSON 출력 및 파일 저장을 지원하여 구조화된 에이전트 워크플로우에 적합. 에스컬레이션 패턴은 단순 검색에서 추출, 매핑, 크롤링, 필요에 따른 종합 리서치까지 안내. tavily-cli 설치 및 tvly login을 통한 API 키 인증 필요.
official
tavily-crawl
tavily-ai
다중 페이지 웹사이트 크롤러로, 의미론적 필터링과 마크다운 내보내기 기능을 제공합니다. 깊이와 범위를 제어하여 사이트 전체 섹션을 크롤링하고, 경로 정규식, 도메인 또는 자연어 명령어로 필터링하여 결과를 집중시킬 수 있습니다. --output-dir 옵션을 통해 각 페이지를 로컬 마크다운 파일로 저장하거나, 구조화된 JSON을 반환하여 에이전트 처리에 활용할 수 있습니다. 결과를 LLM에 전달할 때 컨텍스트 팽창을 방지하기 위해 청크 추출과 함께 의미론적 명령어를 사용하고, 오프라인 문서 다운로드를 위해 전체 페이지 추출을 지원합니다.
official
tavily-dynamic-search
tavily-ai
웹을 검색하고, 결과를 필터링하며, 콘텐츠를 추출하여 원시 검색 데이터가 컨텍스트 창에 들어오지 않도록 합니다. 선별된 print() 출력만 반환됩니다.
official
tavily-extract
tavily-ai
최대 20개의 URL에서 깨끗한 마크다운 또는 텍스트를 추출하며, JavaScript 렌더링 및 쿼리 중심 청킹을 지원합니다. JavaScript로 렌더링된 페이지를 처리하며, 추출 깊이를 구성할 수 있습니다(기본 페이지는 기본, 동적 SPA 및 테이블은 고급). 쿼리 중심 추출을 지원하여 전체 페이지 대신 관련 콘텐츠 청크만 반환합니다. 기본적으로 LLM에 최적화된 마크다운을 반환하며, 일반 텍스트 형식 및 구조화된 JSON 출력 옵션을 제공합니다. 단일 호출에서 최대 20개의 URL을 처리합니다.
official
tavily-map
tavily-ai
웹사이트에서 콘텐츠를 추출하지 않고 빠르게 URL을 발견하여 대규모 사이트에서 특정 페이지를 찾는 데 이상적입니다. 도메인의 모든 URL을 구조화된 목록으로 반환하며, 깊이와 너비를 설정 가능하고, 정규식 경로 필터링 및 자연어 명령어를 통한 의미론적 필터링을 지원합니다. 깊이 제어(1~5단계), 페이지당 너비 제한, 외부 링크 포함/제외, 정규식 패턴을 통한 도메인 필터링을 지원합니다. 워크플로우의 1단계로 설계되어 올바른 페이지를 찾은 후 추출 또는...
official