building-ioc-defanging-and-sharing-pipeline
mukul975/Anthropic-Cybersecurity-Skills
This pipeline provides an automated solution for processing raw Indicators of Compromise (IOCs) from various sources, including IPs, domains, URLs, and emails. It performs crucial steps such as normalization, deduplication, and defanging (modifying indicators to prevent accidental execution while preserving readability). The final, processed data is converted into the standardized STIX 2.1 format and can be securely distributed via TAXII servers or MISP instances, streamlining threat intelligence sharing.