building-threat-intelligence-feed-integration
mukul975/Anthropic-Cybersecurity-Skills
This skill provides a comprehensive framework for building automated pipelines that ingest, normalize, and operationalize threat intelligence (TI). It connects diverse sources—including STIX/TAXII feeds, open-source feeds (e.g., Abuse.ch), and commercial TI platforms—into SIEM and security tools. Use this when SOC teams need to automate the entire lifecycle of IOC ingestion, scoring, and real-time matching against network telemetry.