threat-intelligence-enrichment

โดย tavily-ai

Enrich threat intelligence from CVEs, IOCs, malware names, threat actors, vendor advisories, security incidents, exploit reports, vulnerability disclosures,…

npx skills add https://github.com/tavily-ai/use-case-skills --skill threat-intelligence-enrichment

Threat Intelligence Enrichment

Workflow

Use search and extract to enrich security entities with authoritative and recent evidence; use map or crawl for known vendor portals or advisory collections. Keep this skill focused on query construction, source priority, verification, and security synthesis; execution mechanics should come from companion endpoint skills.

Treat the guidance below as base guidance; adapt it to the user's request when appropriate.

  • Identify the input type: CVE, IOC, malware/tool, threat actor, vendor/product, advisory URL, incident, or campaign.
  • Break the task into short subqueries under 400 characters: identifier, affected product, exploit status, vendor advisory, patches, mitigations, exploitation in the wild, and recent reporting.
  • Search first, using exact-match style queries for CVEs, hashes, domains, IPs, advisory IDs, and malware names.
  • Filter sources before extraction. Prioritize NVD/CVE records, vendor advisories, CISA/agency alerts, security research blogs, reputable incident reports, and official patch notes.
  • Extract selected pages that can support exploit status, impact, affected versions, mitigations, timeline, or confidence.
  • Use site navigation for vendor advisory portals or documentation sites when the relevant page is hard to find.
  • Collect scoped advisory, changelog, release note, or documentation sections only when the user needs broad coverage.

Research Budget

  • Start with a small focused search set covering the identifier, vendor advisory, exploit status, and mitigation or patch evidence.
  • Extract only the strongest authoritative sources before drafting.
  • Add more searches only for named gaps, such as missing affected versions, missing patch notes, or unclear exploitation status.
  • Do not use map unless a known vendor portal or documentation site has a specific advisory or release note to locate.
  • Do not use crawl unless the user asks for coverage across many related advisories or docs pages.

Capability Guidance

  • Use search for CVEs, IOCs, advisories, exploit status, affected versions, mitigations, and recent incident reporting.
  • Use extract on selected vendor advisories, CVE records, agency alerts, patch notes, and security research pages.
  • Use map when a vendor portal or documentation site is known but the specific advisory is hard to locate.
  • Use crawl for advisory/doc sets only when the user asks for coverage across many related pages.
  • Use research only for threat landscape reports or multi-campaign summaries.

Query And Source Guidance

  • Use exact identifiers in queries: CVE IDs, advisory IDs, product/version names, hashes, domains, IPs, malware names, and actor aliases.
  • Prioritize vendor advisories, NVD/CVE records, CISA or national agency alerts, CERT/CC, official patch notes, and reputable security research.
  • Treat social posts, exploit-db style references, and secondary news as supporting evidence unless confirmed by authoritative sources.
  • Separate "exploited in the wild", "public PoC", "theoretical exploitability", and "patched" as different statuses.
  • Report failed or inaccessible sources when they affect vendor advisories, CVE records, affected-version evidence, or mitigation guidance.

Output Template

Use this markdown structure and label uncertainty:

# Threat Intelligence Brief: <entity>

## Summary
- Current status:
- Confidence:
- Most important source:

## Entity Details
- Type:
- Aliases/identifiers:
- Related products or systems:

## Impact And Exposure
- Affected products/versions:
- Exploit status:
- Evidence quality:

## Mitigation And Detection
- Patches or mitigations:
- Detection or hunting notes:
- Recommended checks:

## Timeline
- <date>: <event> ([source](URL))

## Sources And Gaps
- Sources:
- Gaps or unresolved claims:

Do not overstate attribution, exploitation, or compromise evidence. Label speculation and unverified claims.

Skills เพิ่มเติมจาก tavily-ai

research
tavily-ai
การวิจัยเชิงลึกในทุกหัวข้อ พร้อมการรวบรวมแหล่งข้อมูล วิเคราะห์ และอ้างอิงโดยอัตโนมัติ ดำเนินการวิจัยทางเว็บจากหลายแหล่งพร้อมการอ้างอิงที่ชัดเจน เหมาะสำหรับการเปรียบเทียบ เหตุการณ์ปัจจุบัน การวิเคราะห์ตลาด และรายงานโดยละเอียด มีสามตัวเลือกโมเดล: mini สำหรับการวิจัยหัวข้อเดียวแบบเจาะจง (~30 วินาที), pro สำหรับการวิเคราะห์หลายมุมแบบครอบคลุม (~60-120 วินาที) และ auto สำหรับการตรวจจับความซับซ้อนผ่าน API ยืนยันตัวตนผ่าน OAuth ผ่านเซิร์ฟเวอร์ Tavily MCP พร้อมการเข้าสู่ระบบผ่านเบราว์เซอร์อัตโนมัติบน...
official
search
tavily-ai
ค้นหาเว็บด้วยผลลัพธ์ที่ปรับให้เหมาะสมกับ LLM การให้คะแนนความเกี่ยวข้อง และการกรองที่ยืดหยุ่น รองรับโหมดความลึกในการค้นหาสี่โหมด (เร็วพิเศษ เร็ว พื้นฐาน ขั้นสูง) พร้อมการปรับแต่งความหน่วงและความเกี่ยวข้องที่กำหนดค่าได้ รวมถึงการกรองโดเมน ข้อจำกัดช่วงเวลา ช่วงวันที่ การเพิ่มน้ำหนักประเทศ และการดึงเนื้อหาดิบ ส่งคืนผลลัพธ์พร้อมชื่อเรื่อง URL ตัวอย่างเนื้อหา และคะแนนความเกี่ยวข้อง ผลลัพธ์รูปภาพและ favicon แบบเลือกได้ การรับรองความถูกต้อง OAuth อัตโนมัติผ่านเซิร์ฟเวอร์ Tavily MCP หรือการกำหนดค่าคีย์ API...
official
tavily-best-practices
tavily-ai
Web search API สำหรับ LLMs ที่เข้าถึงข้อมูลแบบเรียลไทม์ ดึงเนื้อหา ค้นหาเว็บไซต์ และวิจัยด้วย AI มีห้าวิธีหลัก: search() สำหรับผลลัพธ์เว็บ, extract() สำหรับเนื้อหา URL, crawl() สำหรับดึงข้อมูลทั้งเว็บไซต์, map() สำหรับค้นหา URL, และ research() สำหรับสังเคราะห์ AI แบบครบวงจร รองรับ Python และ JavaScript SDK พร้อม async clients สำหรับการค้นหาแบบขนานและปรับความลึกการค้นหาได้ (ultra-fast/fast/basic/advanced) วิธี crawl รองรับคำสั่งเชิงความหมายเพื่อโฟกัสการดึงข้อมูลที่...
official
tavily-cli
tavily-ai
การค้นหาเว็บ การดึงเนื้อหา การรวบรวมข้อมูลเว็บไซต์ และการวิจัยเชิงลึกผ่าน Tavily CLI มีโหมดคำสั่งห้าโหมดครอบคลุมการค้นหา การดึงข้อมูล การค้นพบ URL การรวบรวมข้อมูลจำนวนมาก และการวิจัยหลายแหล่งพร้อมการอ้างอิง คำสั่งทั้งหมดรองรับเอาต์พุต JSON และการบันทึกไฟล์สำหรับเวิร์กโฟลว์แบบมีโครงสร้างและแบบเอเจนต์ รูปแบบการเพิ่มระดับจะแนะนำคุณจากการค้นหาอย่างง่ายผ่านการดึงข้อมูล การทำแผนที่ การรวบรวมข้อมูล ไปจนถึงการวิจัยที่ครอบคลุมตามความต้องการของคุณ ต้องติดตั้ง tavily-cli และการตรวจสอบสิทธิ์คีย์ API ผ่าน tvly login
official
tavily-crawl
tavily-ai
โปรแกรมรวบรวมข้อมูลเว็บไซต์หลายหน้าที่มีการกรองเชิงความหมายและส่งออกเป็นมาร์กดาวน์ เรียกดูส่วนต่างๆ ของไซต์ทั้งหมดพร้อมควบคุมความลึกและความกว้าง กรองตาม regex ของเส้นทาง โดเมน หรือคำสั่งภาษาธรรมชาติเพื่อเน้นผลลัพธ์ บันทึกแต่ละหน้าเป็นไฟล์มาร์กดาวน์ในเครื่องผ่าน --output-dir หรือส่งคืน JSON ที่มีโครงสร้างสำหรับการประมวลผลแบบเอเจนต์ ใช้คำสั่งเชิงความหมายพร้อมการแยกส่วนเพื่อป้องกันการขยายบริบทเมื่อป้อนผลลัพธ์ให้กับ LLM ใช้การแยกทั้งหน้าสำหรับการดาวน์โหลดเอกสารออฟไลน์ รองรับ...
official
tavily-dynamic-search
tavily-ai
ค้นหาเว็บ กรองผลลัพธ์ และดึงเนื้อหา เพื่อให้ข้อมูลการค้นหาดิบไม่เข้าสู่หน้าต่างบริบทของคุณ มีเพียงผลลัพธ์ print() ที่คุณจัดเตรียมไว้เท่านั้นที่จะถูกส่งกลับมา
official
tavily-extract
tavily-ai
แยกข้อมูลเป็น markdown หรือข้อความที่สะอาดจาก URL สูงสุด 20 รายการ พร้อมรองรับการเรนเดอร์ JavaScript และการแบ่งส่วนตามคำค้นหา จัดการหน้าเว็บที่เรนเดอร์ด้วย JavaScript ได้ โดยปรับระดับการแยกข้อมูลได้ (พื้นฐานสำหรับหน้าเว็บธรรมดา ขั้นสูงสำหรับ SPA และตารางแบบไดนามิก) รองรับการแยกข้อมูลตามคำค้นหาเพื่อส่งคืนเฉพาะเนื้อหาที่เกี่ยวข้อง แทนที่จะส่งคืนทั้งหน้า ส่งคืน markdown ที่ปรับให้เหมาะสมกับ LLM โดยค่าเริ่มต้น พร้อมตัวเลือกรูปแบบข้อความธรรมดาและเอาต์พุต JSON แบบมีโครงสร้าง ประมวลผล URL สูงสุด 20 รายการในการเรียกครั้งเดียว...
official
tavily-map
tavily-ai
การค้นพบ URL อย่างรวดเร็วบนเว็บไซต์โดยไม่ต้องดึงเนื้อหา เหมาะสำหรับการค้นหาหน้าเฉพาะบนเว็บไซต์ขนาดใหญ่ ส่งคืนรายการ URL ที่มีโครงสร้างทั้งหมดบนโดเมน พร้อมการกำหนดความลึกและความกว้าง การกรองเส้นทางด้วย regex และคำสั่งภาษาธรรมชาติสำหรับการกรองเชิงความหมาย รองรับการควบคุมความลึก (1–5 ระดับ) การจำกัดความกว้างต่อหน้า การรวม/ไม่รวมลิงก์ภายนอก และการกรองโดเมนผ่านรูปแบบ regex ออกแบบมาเป็นขั้นตอนที่ 1 ในเวิร์กโฟลว์: แผนที่เพื่อค้นหาหน้าที่ถูกต้อง จากนั้นใช้ extract หรือ...
official