Threat Intelligence (CTI) Lifecycle & IOC Reporting

    1

    Run the full CTI lifecycle, enrich IOCs, profile adversaries against MITRE ATT&CK, prioritize CVEs, and produce TLP-marked reports with graded confidence.

    $12

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Threat Intelligence (CTI) Lifecycle & IOC Reporting

    Example session with this skill installed

    Perform an initial analysis on CVE-2023-3519. Identify if it is in CISA KEV, its EPSS score, and provide a threat hunting hypothesis for a web server environment.

    • Read your context and instructions
    • Compiled the threat intelligence cti
    • Generated the document

    I have analyzed CVE-2023-3519, focusing on its current exploitation status and defensive posture. The analysis prioritizes immediate detection and remediation based on its known presence in active exploitation catalogs.

    Vulnerability Intelligence & Hunt Hypothesis: CVE-2023-3519

    MetricValueRationale
    CISA KEV StatusYesAdded July 2023; confirmed active exploitation in the wild.
    EPSS Score0.97482Top 0.1% of vulnerabilities; extremely high probability of exploitation.
    Confidence GradeHighBased on verified CISA KEV status and multiple vendor advisories.
    Source GradeA (Reliable)Data sourced from CISA KEV and FIRST.org EPSS feeds.
    TLP MarkingTLP:CLEARPublicly available vulnerability information.

    Analysis of Threat Actor Activity

    This vulnerability, a code injection flaw in Citrix NetScaler ADC and Gateway, has been utilized by multiple APT clusters for initial access. High-confidence reporting indicates that attackers use this to execute arbitrary code without authentication, typically followed by credential dumping (LSASS) and lateral movement via RDP.

    Threat Hunting Hypothesis

    Hypothesis: Adversaries are maintaining persistence on NetScaler appliances by exploiting CVE-2023-3519 to drop webshells in the /var/netscaler/gui/ or /netscaler/ns_gui/ directories.

    Detection Logic:

    1. File Integrity: Monitor for new .php or .jsp files created in web-accessible directories on the appliance.

    Process Anomalies: Audit for the nspappe process spawning shell commands (sh, bash) or network utilities (curl, wget).
    3.

    Log Analysis: Search httpaccess.log for POST requests to unusual URI paths with 200 OK responses followed by high outbound byte counts.

    Next steps

    • Immediately patch NetScaler instances to the latest firmware version as per vendor guidance.
    • Execute the file integrity search across all Gateway appliances to check for existing webshells.
    • Review NetScaler AAA logs for anomalous login volumes following successful exploits.

    threat-intelligence-cti-lifecycle-ioc-re.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Create professional TLP-marked threat intelligence reports.Prioritize patching by analyzing CVEs against CISA KEV and EPSS data.Build detection-ready threat hunting hypotheses from raw IOCs.Map adversary behaviors to the Diamond Model for campaign tracking.

    About this skill

    A cyber threat intelligence engine for analysts, SOC and detection teams, incident responders, and security leaders who need analyst-grade intelligence products rather than raw data. It enriches indicators, profiles adversaries and campaigns, generates threat-hunting hypotheses, prioritizes vulnerabilities, and produces briefings and reports, every assessment carrying an explicit confidence level and its sourcing.

    Use it when writing an intelligence report, enriching IOCs into shareable STIX objects, mapping observed behavior to MITRE ATT&CK and the Diamond Model, deciding which CVEs to patch first (combining CVSS, EPSS, and CISA KEV), or turning a messy signal into a BLUF-structured, TLP-marked product for the right audience. It runs on real analytic tradecraft, analysis of competing hypotheses, source grading, and a clean separation of likelihood from analytic confidence.

    Lawful and ethical by design: it works only on data you lawfully supply, uses open-source methodology, and refuses collection by intrusion or from stolen-data markets. It enforces attribution discipline, clustering evidence and qualifying with confidence rather than naming an actor on a single match. It's advisory and not a live feed, it calls no external APIs for you, so enrichment quality depends on the data you provide, and it hands finished detection-rule authoring to a detection or forensics workflow.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 9 days ago

    • Passed all security checks, Safe to install

    Listed9 days ago

    What's inside

    Frequently Asked Questions