⚡AgentSkills
🔐 Cybersecurity · Detection Operations

Operationalize threat intel instead of hoarding it

Relevance filtering, indicator decay, and hunt/detection integration converting feeds into actions.

advanced~40 minSecurity EngineersAppSecDevSecOps

Steps

  1. 1Score sources by relevance to YOUR stack; unsubscribe from noise
  2. 2Auto-expire indicators by type-typical lifetimes (domains days, hashes years)
  3. 3Route intel to consumers: IOCs→matching, TTPs→hunting, actors→risk registers
  4. 4Measure operationalized percentage — intel touched within SLA
  5. 5Close loop: false-positive-heavy sources get demoted automatically
  6. 6Feed confirmed hits back to sharing communities you consume from

Common Pitfalls

  • ▲Ten thousand stale IPs blocking nothing but log space
  • ▲Intel reports read and archived without any detection change

Commands

Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill detection-operations-threat-intel-operationalization
Install globally
$ npx skills add aniruddhaadak80/skills --skill detection-operations-threat-intel-operationalization -g

Tags

#threat-intel#cti#workflow#cybersecurity#detection-operations

Related skills

Atomic test fixtures, expected-fire assertions, and regression packs keeping detection debt visible.

🔐 Cybersecurity·~45m