Mission Domains

🦠 Malware

Mission domain · code mal

Catalog sources

0
0 no-auth

Disciplines

0
mapped

Data points

0
covered

Skills

automation

🔍 Lookup

📜 Playbook — Malware operations

  1. Direction — frame the requirement for Malware: what decision does this support, by when?
  2. Collection — collect from the 0 mapped domain sources and enabled feeds; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🔄 Data Feeds & Datasets

FeedCategoryFormatStatus
MISP Galaxy Tools/MalwareMalware Familiesjsonenabled
Malpedia families (key)Malware Familiesjsonenabled
URLhaus FullMalware URLscsvenabled
URLhaus (tags/family)Malware URLscsvenabled
MalwareBazaar Recent (hash→family)Malware Attributioncsvenabled
ThreatFox SHA256Malware Hashestextenabled
ThreatFox MD5Malware Hashestextenabled
ThreatFox DomainsMalware Domainscsvenabled
MalwareWorld IPsIP Blockliststextenabled
Maltrail MalwareDomains/URLstextenabled
ThreatView MD5Malware Hashestextenabled
ThreatView DomainMalware Domainstextenabled
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php