threat-intelligence-enrichment

tarafından tavily-ai

Enrich threat intelligence from CVEs, IOCs, malware names, threat actors, vendor advisories, security incidents, exploit reports, vulnerability disclosures,…

npx skills add https://github.com/tavily-ai/use-case-skills --skill threat-intelligence-enrichment

Threat Intelligence Enrichment

Workflow

Use search and extract to enrich security entities with authoritative and recent evidence; use map or crawl for known vendor portals or advisory collections. Keep this skill focused on query construction, source priority, verification, and security synthesis; execution mechanics should come from companion endpoint skills.

Treat the guidance below as base guidance; adapt it to the user's request when appropriate.

  • Identify the input type: CVE, IOC, malware/tool, threat actor, vendor/product, advisory URL, incident, or campaign.
  • Break the task into short subqueries under 400 characters: identifier, affected product, exploit status, vendor advisory, patches, mitigations, exploitation in the wild, and recent reporting.
  • Search first, using exact-match style queries for CVEs, hashes, domains, IPs, advisory IDs, and malware names.
  • Filter sources before extraction. Prioritize NVD/CVE records, vendor advisories, CISA/agency alerts, security research blogs, reputable incident reports, and official patch notes.
  • Extract selected pages that can support exploit status, impact, affected versions, mitigations, timeline, or confidence.
  • Use site navigation for vendor advisory portals or documentation sites when the relevant page is hard to find.
  • Collect scoped advisory, changelog, release note, or documentation sections only when the user needs broad coverage.

Research Budget

  • Start with a small focused search set covering the identifier, vendor advisory, exploit status, and mitigation or patch evidence.
  • Extract only the strongest authoritative sources before drafting.
  • Add more searches only for named gaps, such as missing affected versions, missing patch notes, or unclear exploitation status.
  • Do not use map unless a known vendor portal or documentation site has a specific advisory or release note to locate.
  • Do not use crawl unless the user asks for coverage across many related advisories or docs pages.

Capability Guidance

  • Use search for CVEs, IOCs, advisories, exploit status, affected versions, mitigations, and recent incident reporting.
  • Use extract on selected vendor advisories, CVE records, agency alerts, patch notes, and security research pages.
  • Use map when a vendor portal or documentation site is known but the specific advisory is hard to locate.
  • Use crawl for advisory/doc sets only when the user asks for coverage across many related pages.
  • Use research only for threat landscape reports or multi-campaign summaries.

Query And Source Guidance

  • Use exact identifiers in queries: CVE IDs, advisory IDs, product/version names, hashes, domains, IPs, malware names, and actor aliases.
  • Prioritize vendor advisories, NVD/CVE records, CISA or national agency alerts, CERT/CC, official patch notes, and reputable security research.
  • Treat social posts, exploit-db style references, and secondary news as supporting evidence unless confirmed by authoritative sources.
  • Separate "exploited in the wild", "public PoC", "theoretical exploitability", and "patched" as different statuses.
  • Report failed or inaccessible sources when they affect vendor advisories, CVE records, affected-version evidence, or mitigation guidance.

Output Template

Use this markdown structure and label uncertainty:

# Threat Intelligence Brief: <entity>

## Summary
- Current status:
- Confidence:
- Most important source:

## Entity Details
- Type:
- Aliases/identifiers:
- Related products or systems:

## Impact And Exposure
- Affected products/versions:
- Exploit status:
- Evidence quality:

## Mitigation And Detection
- Patches or mitigations:
- Detection or hunting notes:
- Recommended checks:

## Timeline
- <date>: <event> ([source](URL))

## Sources And Gaps
- Sources:
- Gaps or unresolved claims:

Do not overstate attribution, exploitation, or compromise evidence. Label speculation and unverified claims.

tavily-ai tarafından daha fazla skill

research
tavily-ai
Herhangi bir konuda otomatik kaynak toplama, analiz ve alıntılarla kapsamlı araştırma. Açık alıntılarla çoklu kaynak web araştırması yapar; karşılaştırmalar, güncel olaylar, pazar analizi ve detaylı raporlar için idealdir. Üç model seçeneği sunar: hedefli tek konulu araştırma için mini (~30 sn), kapsamlı çok açılı analiz için pro (~60-120 sn) ve API tabanlı karmaşıklık algılama için auto. Tavily MCP sunucusu üzerinden OAuth ile kimlik doğrulama yapar ve otomatik tarayıcı tabanlı giriş ile...
official
search
tavily-ai
LLM için optimize edilmiş sonuçlar, alaka düzeyi puanlaması ve esnek filtreleme ile web araması. Yapılandırılabilir gecikme ve alaka düzeyi dengeleriyle dört arama derinliği modunu (ultra hızlı, hızlı, temel, gelişmiş) destekler. Alan filtresi, zaman aralığı kısıtlamaları, tarih aralıkları, ülke önceliklendirmesi ve ham içerik çıkarma içerir. Başlık, URL, içerik parçacığı ve alaka düzeyi puanı ile sonuçlar döndürür; isteğe bağlı görsel sonuçları ve faviconlar. Tavily MCP sunucusu veya API anahtarı yapılandırması aracılığıyla
official
tavily-best-practices
tavily-ai
We need to translate the given English text into Turkish, preserving the name "tavily-best-practices" but not including it unless it appears in the source. The source text does not include the name, so we just translate the description. We must preserve product names, protocol names, URLs, numbers, technical terms. No extra commentary. The text: "Web search API for LLMs with real-time data access, content extraction, site crawling, and AI-powered research. Five core methods: search() for web results, extract() for URL content, crawl() for site-wide extraction, map() for URL discovery, and research() for end-to-end AI synthesis Supports Python and JavaScript SDKs with async clients for parallel queries and configurable search depth (ultra-fast/fast/basic/advanced) Crawl method accepts semantic instructions to focus extraction on..." Translate to Turkish. Note: "LLMs" should remain as is. "API" remains. Method names like search(), extract(), etc. remain. "SDKs" remains. "async clients" - maybe "asenk
official
tavily-cli
tavily-ai
Web araması, içerik çıkarma, site tarama ve Tavily CLI üzerinden derin araştırma. Arama, çıkarma, URL keşfi, toplu tarama ve alıntılarla çoklu kaynak araştırmasını kapsayan beş komut modu. Tüm komutlar, yapılandırılmış, aracı tabanlı iş akışları için JSON çıktısı ve dosyaya kaydetmeyi destekler. İhtiyaçlarınıza göre basit aramadan çıkarma, haritalama, tarama ve kapsamlı araştırmaya yönlendiren bir yükseltme deseni. tavily-cli kurulumu ve tvly login ile API anahtarı kimlik doğrulaması gerektirir.
official
tavily-crawl
tavily-ai
Çok sayfalı web sitesi tarayıcısı, anlamsal filtreleme ve markdown dışa aktarma ile. Derinlik ve genişlik kontrolü ile tüm site bölümlerini tarayın; sonuçları odaklamak için yol regex'i, alan adı veya doğal dil talimatlarıyla filtreleyin Her sayfayı --output-dir aracılığıyla yerel markdown dosyaları olarak kaydedin veya aracı işleme için yapılandırılmış JSON döndürün Sonuçları LLM'lere beslerken bağlam şişmesini önlemek için parça çıkarma ile anlamsal talimatlar kullanın; çevrimdışı dokümantasyon indirmeleri için tam sayfa çıkarma kullanın Destekler...
official
tavily-dynamic-search
tavily-ai
Web'de arama yap, sonuçları filtrele ve içerik çıkar, böylece ham arama verileri asla bağlam pencerene girmez. Yalnızca düzenlenmiş print() çıktın geri döner.
official
tavily-extract
tavily-ai
20 URL'ye kadar temiz markdown veya metin çıkarır; JavaScript işleme ve sorgu odaklı parçalama desteği sunar. JavaScript ile oluşturulmuş sayfaları, yapılandırılabilir çıkarma derinliğiyle (basit sayfalar için temel, dinamik SPA'lar ve tablolar için gelişmiş) işler. Tam sayfalar yerine yalnızca ilgili içerik parçalarını döndürmek için sorgu odaklı çıkarmayı destekler. Varsayılan olarak LLM için optimize edilmiş markdown döndürür; düz metin biçimi ve yapılandırılmış JSON çıktısı seçenekleri sunar. Tek bir çağrıda 20 URL'ye kadar işler;...
official
tavily-map
tavily-ai
Web sitelerinde içerik çıkarmadan hızlı URL keşfi, büyük sitelerde belirli sayfaları bulmak için idealdir. Yapılandırılabilir derinlik ve genişlik, regex yol filtrelemesi ve anlamsal filtreleme için doğal dil talimatları ile bir alandaki tüm URL'lerin yapılandırılmış listelerini döndürür. Derinlik kontrolünü (1–5 seviye), sayfa başına genişlik sınırlarını, harici bağlantı ekleme/hariç tutma ve regex desenleri aracılığıyla alan filtrelemesini destekler. Bir iş akışında 1. adım olarak tasarlanmıştır: doğru sayfayı bulmak için haritalayın, ardından çıkarma veya...
official