Mission Domains

⚠️ Threat Analysis

Mission domain · code threat

Catalog sources

7
6 no-auth

Disciplines

4
mapped

Data points

7
covered

Skills

automation

Intelligence Disciplines

CYBINT (4) MALINT (3) ACTORINT (3) GOVINT (1)

Sources for this domain (7)

NameCategoryAuthFormat
abuse.ch ThreatFox
Family-labelled IoC exchange.
Threat Analysis NONE json home↗ api↗
CISA Automated Indicator Sharing
US-CERT indicator sharing / advisories.
Threat Analysis NONE xml home↗
MITRE ATT&CK Software/Actors
Adversary tooling & group knowledge base.
ACTORINT NONE json home↗ api↗
ORKL Threat Report Library
Full-text CTI report library API.
APT NONE json home↗ api↗
SANS Internet Storm Center
Internet threat telemetry & handler diary.
CYBINT NONE json home↗ api↗
YARA / Sigma / Detection Rules
Open detection-signature repositories.
MALINT NONE text home↗ api↗
AlienVault OTX Pulses
Community threat-intel pulses (free key).
Threat Analysis KEY json home↗ api↗

🔍 Lookup

📜 Playbook — Threat Analysis operations

  1. Direction — frame the requirement for Threat Analysis: what decision does this support, by when?
  2. Collection — collect from the 7 mapped domain sources and enabled feeds; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🔄 Data Feeds & Datasets

FeedCategoryFormatStatus
abuse.ch ThreatFoxCatalog: Threat Analysisjsonoff
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php