Threat Intelligence (CTI) Lifecycle & IOC Reporting
Run the full CTI lifecycle, enrich IOCs, profile adversaries against MITRE ATT&CK, prioritize CVEs, and produce TLP-marked reports with graded confidence.
$12
Works with the AI tools you already use
Threat Intelligence (CTI) Lifecycle & IOC Reporting
Example session with this skill installed
Perform an initial analysis on CVE-2023-3519. Identify if it is in CISA KEV, its EPSS score, and provide a threat hunting hypothesis for a web server environment.
- Read your context and instructions
- Compiled the threat intelligence cti
- Generated the document
I have analyzed CVE-2023-3519, focusing on its current exploitation status and defensive posture. The analysis prioritizes immediate detection and remediation based on its known presence in active exploitation catalogs.
Vulnerability Intelligence & Hunt Hypothesis: CVE-2023-3519
| Metric | Value | Rationale |
|---|---|---|
| CISA KEV Status | Yes | Added July 2023; confirmed active exploitation in the wild. |
| EPSS Score | 0.97482 | Top 0.1% of vulnerabilities; extremely high probability of exploitation. |
| Confidence Grade | High | Based on verified CISA KEV status and multiple vendor advisories. |
| Source Grade | A (Reliable) | Data sourced from CISA KEV and FIRST.org EPSS feeds. |
| TLP Marking | TLP:CLEAR | Publicly available vulnerability information. |
Analysis of Threat Actor Activity
This vulnerability, a code injection flaw in Citrix NetScaler ADC and Gateway, has been utilized by multiple APT clusters for initial access. High-confidence reporting indicates that attackers use this to execute arbitrary code without authentication, typically followed by credential dumping (LSASS) and lateral movement via RDP.
Threat Hunting Hypothesis
Hypothesis: Adversaries are maintaining persistence on NetScaler appliances by exploiting CVE-2023-3519 to drop webshells in the /var/netscaler/gui/ or /netscaler/ns_gui/ directories.
Detection Logic:
- File Integrity: Monitor for new
.phpor.jspfiles created in web-accessible directories on the appliance.
Process Anomalies: Audit for the nspappe process spawning shell commands (sh, bash) or network utilities (curl, wget).
3.
Log Analysis: Search httpaccess.log for POST requests to unusual URI paths with 200 OK responses followed by high outbound byte counts.
Next steps
- Immediately patch NetScaler instances to the latest firmware version as per vendor guidance.
- Execute the file integrity search across all Gateway appliances to check for existing webshells.
- Review NetScaler AAA logs for anomalous login volumes following successful exploits.
threat-intelligence-cti-lifecycle-ioc-re.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
A cyber threat intelligence engine for analysts, SOC and detection teams, incident responders, and security leaders who need analyst-grade intelligence products rather than raw data. It enriches indicators, profiles adversaries and campaigns, generates threat-hunting hypotheses, prioritizes vulnerabilities, and produces briefings and reports, every assessment carrying an explicit confidence level and its sourcing.
Use it when writing an intelligence report, enriching IOCs into shareable STIX objects, mapping observed behavior to MITRE ATT&CK and the Diamond Model, deciding which CVEs to patch first (combining CVSS, EPSS, and CISA KEV), or turning a messy signal into a BLUF-structured, TLP-marked product for the right audience. It runs on real analytic tradecraft, analysis of competing hypotheses, source grading, and a clean separation of likelihood from analytic confidence.
Lawful and ethical by design: it works only on data you lawfully supply, uses open-source methodology, and refuses collection by intrusion or from stolen-data markets. It enforces attribution discipline, clustering evidence and qualifying with confidence rather than naming an actor on a single match. It's advisory and not a live feed, it calls no external APIs for you, so enrichment quality depends on the data you provide, and it hands finished detection-rule authoring to a detection or forensics workflow.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 9 days ago
- Passed all security checks, Safe to install