performing-indicator-lifecycle-management
mukul975/Anthropic-Cybersecurity-Skills
This skill provides a systematic framework for managing Indicators of Compromise (IOCs) throughout their entire life cycle—from initial discovery and validation to enrichment, deployment, monitoring, and eventual retirement. It emphasizes implementing confidence decay functions, tracking hit rates, and managing false positives to maintain a high-quality, actionable threat intelligence database, thereby minimizing analyst fatigue and maximizing detection efficacy.