Agent skill

Evaluating Threat Intelligence Platforms

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst…

Apache-2.0Auto-check passedSecurity

Install Evaluating Threat Intelligence Platforms

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill evaluating-threat-intelligence-platforms -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills evaluating-threat-intelligence-platforms --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/evaluating-threat-intelligence-platforms .claude/skills/evaluating-threat-intelligence-platforms && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
evaluating-threat-intelligence-platforms
GitHub stars
34k
Token cost
~1.9k tokens
SKILL.md length
759 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst…

  • Works in 5 steps: Define Evaluation Criteria → Evaluate Major TIP Options → Conduct Proof of Concept → …
  • Conducting a TIP procurement
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Evaluating Threat Intelligence Platforms is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP procurement, migrating between TIP solutions, or assessing whether the current TIP meets program maturity requirements. Activates for requests involving ThreatConnect, MISP, OpenCTI, Anomali, EclecticIQ, or TIP procurement decisions.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering OSINT, Vendor and procurement management and Workflow automation. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Conducting a TIP procurement
  • Migrating between TIP solutions
  • Assessing whether the current TIP meets program maturity requirements

Example prompts

  • “Use the evaluating-threat-intelligence-platforms skill to evaluate and selects Threat Intelligence Platform (TIP) products based on organizational…”
  • “/evaluating-threat-intelligence-platforms”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Define Evaluation Criteria
  2. Evaluate Major TIP Options
  3. Conduct Proof of Concept
  4. Score and Select
  5. Implementation and Onboarding Planning

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Evaluating Threat Intelligence Platforms loads about 1.9k tokens when it runs, and up to ~2.5k if it reads all its reference files. Until then it costs about 133 tokens; SKILL.md has 759 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~133
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 759 words, ~1,854 tokens.

Download SKILL.mdSave it as .claude/skills/evaluating-threat-intelligence-platforms/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
evaluating-threat-intelligence-platforms
description
Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP procurement, migrating between TIP solutions, or assessing whether the current TIP meets program maturity requirements. Activates for requests involving ThreatConnect, MISP, OpenCTI, Anomali, EclecticIQ, or TIP procurement decisions.
domain
cybersecurity
subdomain
threat-intelligence
tags
TIP, ThreatConnect, MISP, OpenCTI, Anomali, EclecticIQ, STIX-TAXII, CTI-program, procurement
version
1.0.0
author
team-cybersecurity
license
Apache-2.0
nist_csf
ID.RA-01, ID.RA-05, DE.CM-01, DE.AE-02
mitre_attack
T1591, T1592, T1593, T1589

Evaluating Threat Intelligence Platforms

When to Use

Use this skill when:

  • Conducting a formal RFP or vendor evaluation for a TIP solution
  • Assessing whether the current TIP (e.g., MISP) needs to be replaced or augmented as the CTI program scales
  • Establishing evaluation criteria aligned to organizational maturity and budget

Do not use this skill for evaluating feed quality independently of the TIP — feed evaluation is a separate workflow focused on data quality rather than platform capabilities.

Prerequisites

  • Documented CTI program requirements: team size, feed sources, integration targets, use cases
  • Budget range and procurement timeline
  • Technical staff who will administer the platform (Python/API experience for open-source TIPs)
  • List of current and planned integrations (SIEM, SOAR, EDR, firewalls)

Workflow

Step 1: Define Evaluation Criteria

Structure requirements into mandatory (M) and desired (D) categories:

Core TIP Functions:

  • M: STIX 2.1 import/export with TAXII 2.1 server
  • M: REST API for automated IOC ingestion and export
  • M: Indicator deduplication and TTL management
  • M: TLP classification enforcement
  • D: Built-in MITRE ATT&CK integration and technique tagging
  • D: Graph visualization of indicator relationships
  • D: Workflow automation for analyst triage

Integrations:

  • M: SIEM integration (Splunk, Sentinel, QRadar) via syslog, API, or native connector
  • M: EDR integration for IOC push (CrowdStrike, Defender, SentinelOne)
  • D: SOAR integration (XSOAR, Splunk SOAR) for playbook triggers
  • D: Ticketing system (ServiceNow, Jira) for intelligence task tracking

Operational:

  • M: Role-based access control with TLP-aware data segregation
  • M: Audit logging for all analyst actions
  • D: Multi-tenancy for MSSP use cases
Step 2: Evaluate Major TIP Options

MISP (Open Source):

  • Cost: Free (self-hosted infrastructure cost only)
  • Strengths: Largest community, 250+ modules, extensive ISAC usage, STIX 2.0 native
  • Weaknesses: Requires dedicated admin, limited visualization, UI dated
  • Best for: Budget-constrained teams with technical staff; government/ISAC sharing programs

OpenCTI (Open Source):

  • Cost: Free (self-hosted); paid SaaS at ~$3,000–$15,000/year
  • Strengths: Native STIX 2.1, graph visualization, ATT&CK integration, modern API
  • Weaknesses: Resource-intensive deployment (Elasticsearch, MinIO required)
  • Best for: Teams wanting open source with modern UX; SOC/CTI integration focus

ThreatConnect (Commercial):

  • Cost: $50,000–$500,000/year depending on scale
  • Strengths: End-to-end CTI lifecycle, playbook automation, TC Exchange marketplace, analyst workflow
  • Weaknesses: High cost; complex implementation; best value at larger scale
  • Best for: Mature enterprise CTI programs; MSSPs; red team/blue team integration

Anomali ThreatStream (Commercial):

  • Cost: $30,000–$200,000/year
  • Strengths: Strong feed aggregation, Splunk-native integration, extensive pre-built connectors
  • Weaknesses: Graph visualization weaker than OpenCTI; UI refresh lagging
  • Best for: Splunk-heavy environments; teams prioritizing feed volume over analysis workflows

EclecticIQ Platform (Commercial):

  • Cost: $40,000–$300,000/year
  • Strengths: STIX 2.1 native, collaborative intelligence workbench, strong European customer base
  • Weaknesses: Smaller partner ecosystem than ThreatConnect
  • Best for: Teams with MITRE ATT&CK-centric workflows; EMEA-focused organizations
Show full SKILL.md (330 more words)Show less
Step 3: Conduct Proof of Concept

Request 30-day PoC from finalists. Test:

  1. Feed onboarding: Can your top 5 feeds be ingested within 4 hours?
  2. SIEM integration: Can enriched IOCs push to your SIEM in <5 minutes?
  3. ATT&CK mapping: Can analysts tag indicators with ATT&CK techniques efficiently?
  4. Report generation: Can the platform produce a tactical IOC bulletin with one click?
  5. API performance: Can the REST API handle 10,000 indicator queries per day?
Step 4: Score and Select

Use weighted scoring matrix (weight each criterion by organizational priority):

Criterion                 Weight   Vendor A   Vendor B
STIX 2.1 compliance       20%      95         85
SIEM integration          25%      90         70
ATT&CK mapping            15%      85         95
Cost (inverse)            20%      60         90
UI/analyst experience     10%      80         75
Vendor support quality    10%      85         80
TOTAL                     100%     82.0       81.5
Step 5: Implementation and Onboarding Planning

Plan 90-day implementation:

  • Week 1–2: Infrastructure deployment (cloud or on-prem)
  • Week 3–4: Feed onboarding and deduplication tuning
  • Week 5–6: SIEM/SOAR integration and testing
  • Week 7–8: Analyst workflow configuration and training
  • Week 9–12: Operational validation and go-live

Key Concepts

TermDefinition
TIPThreat Intelligence Platform — software for collecting, processing, analyzing, and disseminating cyber threat intelligence
TAXII ServerComponent of a TIP that serves STIX bundles to consuming systems on request
TC ExchangeThreatConnect's commercial marketplace for pre-built feed integrations and app connectors
Multi-tenancyTIP capability to serve multiple organizational units or customers with isolated data environments
DeduplicationProcess of identifying and merging duplicate indicators within a TIP to reduce analyst noise

Tools & Systems

  • MISP: Open-source TIP used by 6,000+ organizations; strongest ISAC/government community integration
  • OpenCTI: Modern open-source TIP with native STIX 2.1 and graph-based analysis
  • ThreatConnect: Enterprise commercial TIP with lifecycle management and SOAR playbook integration
  • Anomali ThreatStream: Commercial TIP with strong Splunk ecosystem integration
  • EclecticIQ: Commercial TIP with ATT&CK-centric workflow design

Common Pitfalls

  • Selecting TIP before defining requirements: Technology selection before use case definition leads to expensive mismatches.
  • Underestimating administration burden: MISP and OpenCTI require dedicated admin time (minimum 0.25 FTE); budget accordingly.
  • Ignoring data migration costs: Moving historical intelligence from one TIP to another is costly and often impractical for legacy systems.
  • Not testing SIEM integration in PoC: TIP value depends heavily on downstream integration quality; always test SIEM/SOAR connectivity during evaluation.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/evaluating-threat-intelligence-platforms of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Evaluating Threat Intelligence Platforms next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Evaluating Threat Intelligence Platforms compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Evaluating Threat Intelligence Platforms this skillmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0
Operationstravisjneuman/.claude101—~3.4kAutomated safety check: PassMIT
CLI Anything IntelwatchHKUDS/CLI-Anything52k—~360Automated safety check: PassApache-2.0
ApocdataApocData/ApocData-skill104—~1.9kAutomated safety check: PassApache-2.0
Serenity Alphahaskaomni/serenity-skill633—~2.6kAutomated safety check: PassMIT
Scorecard Matrixpnp/sharepoint-skills132—~1.9kAutomated safety check: PassMIT

Similar skills

  • Operations

    travisjneuman/.claude

    Operations excellence expertise for supply chain optimization, process improvement (Lean, Six Sigma), capacity planning, vendor management, quality assurance, and operational efficiency.

    101 GitHub stars~3.4k tokensUpdated today
    SecurityAuto-check passed
  • CLI Anything Intelwatch

    HKUDS/CLI-Anything

    Zero friction. An agent skill from HKUDS/CLI-Anything.

    52k GitHub stars~360 tokensUpdated 17 days ago
    SecurityAuto-check passed
  • Apocdata

    ApocData/ApocData-skill

    A-share data service with structured announcement parsing: every announcement carries an AI summary, category, importance level and sentiment, fully traceable to source.

    104 GitHub stars~1.9k tokensUpdated 23 days ago
    Business, Finance & HRAuto-check passed
  • Serenity Alpha

    haskaomni/serenity-skill

    Translate market-moving news into investable alpha hypotheses by mapping observed demand changes to revenue lines, supply chains, small-cap financial elasticity, market misclassification, validation…

    633 GitHub stars~2.6k tokensUpdated 2 mo ago
    Business, Finance & HRAuto-check passed
  • Scorecard Matrix

    pnp/sharepoint-skills

    Generates a polished, self-contained HTML heatmap scorecard — a weighted comparison matrix where entities (rows) are scored across dimensions (columns), with computed totals, rank badges, and a…

    132 GitHub stars~1.9k tokensUpdated 2 days ago
    Business, Finance & HRAuto-check passed
  • Recover source-bound buyer jobs, struggling moments, desired progress, forces, workarounds, information acts, journey states, criteria, constraints, roles, locales, and authentic language.

    1.5k GitHub stars~1.4k tokensUpdated 2 days ago
    Business, Finance & HRAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Evaluating Threat Intelligence Platforms

What does Evaluating Threat Intelligence Platforms do?

Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst…. Evaluating Threat Intelligence Platforms is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership.

When should I use Evaluating Threat Intelligence Platforms?

Evaluating Threat Intelligence Platforms fits situations like: conducting a TIP procurement; migrating between TIP solutions; assessing whether the current TIP meets program maturity requirements.

How do I install Evaluating Threat Intelligence Platforms in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill evaluating-threat-intelligence-platforms -a claude-code`. Or copy the skill folder (skills/evaluating-threat-intelligence-platforms in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/evaluating-threat-intelligence-platforms in your project. Claude Code loads it when a task matches its description.

How do I install Evaluating Threat Intelligence Platforms in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill evaluating-threat-intelligence-platforms -a codex`. Or copy the skill folder (skills/evaluating-threat-intelligence-platforms in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/evaluating-threat-intelligence-platforms in your project. Codex loads it when a task matches its description.

Can I use Evaluating Threat Intelligence Platforms in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill evaluating-threat-intelligence-platforms -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/evaluating-threat-intelligence-platforms, .gemini/skills/evaluating-threat-intelligence-platforms, .github/skills/evaluating-threat-intelligence-platforms and .opencode/skills/evaluating-threat-intelligence-platforms in your project.

What does Evaluating Threat Intelligence Platforms need to run?

Going by SKILL.md and its folder, Evaluating Threat Intelligence Platforms needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Evaluating Threat Intelligence Platforms access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Evaluating Threat Intelligence Platforms safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Evaluating Threat Intelligence Platforms use?

Evaluating Threat Intelligence Platforms is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Evaluating Threat Intelligence Platforms use?

About 1.9k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 695 tokens, read only when the agent opens those files.

What are the alternatives to Evaluating Threat Intelligence Platforms?

Skills that share tags, products or a category with Evaluating Threat Intelligence Platforms: Operations (travisjneuman/.claude, 101 stars), CLI Anything Intelwatch (HKUDS/CLI-Anything, 52k stars), Apocdata (ApocData/ApocData-skill, 104 stars) and Serenity Alpha (haskaomni/serenity-skill, 633 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Evaluating Threat Intelligence Platforms?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.