stixtaxii-intelligence-skill

Solid

STIX/TAXII threat intelligence format and sharing

AI & Automation 1,160 stars 71 forks Updated today MIT

Install

View on GitHub

Quality Score: 92/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
47
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# STIX/TAXII Intelligence Skill ## Overview This skill provides STIX/TAXII threat intelligence format creation, querying, and sharing capabilities. ## Capabilities - Create STIX 2.1 bundles - Query TAXII servers - Generate threat reports - Create indicator relationships - Map to MITRE ATT&CK - Support OpenIOC format - Validate STIX syntax - Share intelligence feeds ## Target Processes - threat-intelligence-research.js - malware-analysis.js - security-advisory-writing.js ## Dependencies - stix2 library (Python) - taxii2-client - Python 3.x - TAXII server access (optional) ## Usage Context This skill is essential for: - Threat intelligence sharing - IOC standardization - Intelligence feed management - Threat report generation - Intelligence correlation ## Integration Notes - Supports STIX 2.0 and 2.1 - Can publish to TAXII servers - Integrates with MISP - Supports multiple IOC formats - Can generate human-readable reports

Details

Author
a5c-ai
Repository
a5c-ai/babysitter
Created
4 months ago
Last Updated
today
Language
JavaScript
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Featured

implementing-security-information-sharing-with-stix2

Create, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators, malware, campaigns, relationships, bundles, and TAXII 2.1 publishing.

13,115 Updated today
mukul975
AI & Automation Featured

processing-stix-taxii-feeds

Processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to appropriate consuming systems. Use when onboarding new TAXII collection endpoints, automating bi-directional intelligence sharing with ISACs, or building pipeline validation for malformed STIX bundles. Activates for requests involving OASIS STIX, TAXII server configuration, MISP TAXII, or Cortex XSOAR feed integrations.

13,115 Updated today
mukul975
AI & Automation Featured

implementing-stix-taxii-feed-integration

STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) are OASIS open standards for representing and transporting cyber threat intelligence.

13,115 Updated today
mukul975
AI & Automation Featured

building-threat-intelligence-feed-integration

Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need to operationalize threat intelligence by automating feed ingestion, normalization, scoring, and distribution to detection systems.

13,115 Updated today
mukul975
DevOps & Infrastructure Featured

implementing-taxii-server-with-opentaxii

Deploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using the TAXII 2.1 protocol for automated indicator exchange between organizations.

13,115 Updated today
mukul975