external/anthropic-cybersecurity-skills/skills/evaluating-threat-intelligence-platforms/SKILL.md
Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP procurement, migrating between TIP solutions, or assessing whether the current TIP meets program maturity requirements. Activates for requests involving ThreatConnect, MISP, OpenCTI, Anomali, EclecticIQ, or TIP procurement decisions.
npx skillsauth add seikaikyo/dash-skills evaluating-threat-intelligence-platformsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill when:
Do not use this skill for evaluating feed quality independently of the TIP — feed evaluation is a separate workflow focused on data quality rather than platform capabilities.
Structure requirements into mandatory (M) and desired (D) categories:
Core TIP Functions:
Integrations:
Operational:
MISP (Open Source):
OpenCTI (Open Source):
ThreatConnect (Commercial):
Anomali ThreatStream (Commercial):
EclecticIQ Platform (Commercial):
Request 30-day PoC from finalists. Test:
Use weighted scoring matrix (weight each criterion by organizational priority):
Criterion Weight Vendor A Vendor B
STIX 2.1 compliance 20% 95 85
SIEM integration 25% 90 70
ATT&CK mapping 15% 85 95
Cost (inverse) 20% 60 90
UI/analyst experience 10% 80 75
Vendor support quality 10% 85 80
TOTAL 100% 82.0 81.5
Plan 90-day implementation:
| Term | Definition | |------|-----------| | TIP | Threat Intelligence Platform — software for collecting, processing, analyzing, and disseminating cyber threat intelligence | | TAXII Server | Component of a TIP that serves STIX bundles to consuming systems on request | | TC Exchange | ThreatConnect's commercial marketplace for pre-built feed integrations and app connectors | | Multi-tenancy | TIP capability to serve multiple organizational units or customers with isolated data environments | | Deduplication | Process of identifying and merging duplicate indicators within a TIP to reduce analyst noise |
tools
Zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private key) without revealing the secret itself. This skill implements the Schnorr identificati
development
Configure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false positives, analyze audit logs for attack detection, and implement custom SecRules for application-specific threats. The analyst configures SecRuleEngine, SecAuditEngine, and CRS paranoia levels to balance security coverage with operational stability. Activates for requests involving WAF configuration, ModSecurity rule tuning, web application audit logging, or CRS deployment.
development
Build automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation workflows, and compliance reporting dashboards.
testing
Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities based on severity, asset criticality, and exploit availability. Effective SLA programs