analyzing-threat-landscape-with-misp skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Query a MISP (Malware Information Sharing Platform) instance via PyMISP Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/analyzing-threat-landscape-with-misp/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-threat-landscape-with-misp, or copy the skill folder into ~/.claude/skills/analyzing-threat-landscape-with-misp/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/analyzing-threat-landscape-with-misp/SKILL.md

SKILL.md (verbatim)

name: analyzing-threat-landscape-with-misp
description: Query a MISP (Malware Information Sharing Platform) instance via PyMISP
  to compute event statistics, IOC type breakdowns, threat actor galaxy clusters,
  and tag trends, and generate threat landscape reports with temporal trends. Use
  when asked to analyze threat intelligence data, summarize top threat actors or
  malware families, or produce a CTI landscape report from MISP events.
domain: cybersecurity
subdomain: threat-intelligence
tags:
- threat-intelligence
- misp
- threat-landscape
- ioc-analysis
- cti
- threat-sharing
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- File Metadata Consistency Validation
- Application Protocol Command Analysis
- Identifier Analysis
- Content Format Conversion
- Message Analysis
nist_csf:
- ID.RA-01
- ID.RA-05
- DE.CM-01
- DE.AE-02
mitre_attack:
- T1566
- T1071.001
- T1568
- T1583.001
- T1102

Analyzing Threat Landscape with MISP

When to Use

  • When investigating security incidents that require analyzing threat landscape with misp
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Familiarity with threat intelligence concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Instructions

  1. Install dependencies: pip install pymisp
  2. Configure MISP URL and API key.
  3. Run the agent to generate threat landscape analysis:
    • Pull event statistics by threat level and date range
    • Analyze attribute type distributions (IP, domain, hash, URL)
    • Identify top MITRE ATT&CK techniques from event tags
    • Track threat actor activity via galaxy clusters
    • Generate temporal trend analysis of IOC submissions
python scripts/agent.py --misp-url https://misp.local --api-key YOUR_KEY --days 90 --output landscape_report.json

Examples

Threat Landscape Summary

Period: Last 90 days
Events analyzed: 1,247
Top threat level: High (43%)
Top attribute type: ip-dst (31%), domain (22%), sha256 (18%)
Top MITRE technique: T1566 Phishing (89 events)
Top threat actor: APT28 (34 events)

Other files in this skill

references/api-reference.md (verbatim)

API Reference: MISP Threat Landscape Analysis

PyMISP Connection

from pymisp import PyMISP
misp = PyMISP(url, api_key, ssl=True)
events = misp.search(date_from="2025-01-01", pythonify=True)
Parameter Description
date_from Start date (YYYY-MM-DD)
date_to End date
tags Filter by tags
threat_level_id 1=High, 2=Medium, 3=Low, 4=Undefined
published True/False
pythonify Return MISPEvent objects

Event Object Fields

Field Description
id Event ID
date Event date
threat_level_id 1-4 severity level
analysis 0=Initial, 1=Ongoing, 2=Completed
info Event description
Attribute List of IOC attributes
Tag List of tags
Orgc Contributing organization

Attribute Types

Type Example
ip-dst Destination IP address
ip-src Source IP address
domain Domain name
hostname FQDN
url Full URL
md5 / sha1 / sha256 File hashes
email-src Sender email
filename Malicious filename
mutex Mutex name
regkey Registry key

Galaxy Tag Prefixes

Prefix Content
misp-galaxy:mitre-attack-pattern= MITRE ATT&CK techniques
misp-galaxy:threat-actor= Threat actor groups
misp-galaxy:malpedia= Malware families
misp-galaxy:sector= Target sectors
misp-galaxy:country= Target countries

Statistics API

misp.get_community_id()
misp.user_statistics()
misp.attributes_statistics(context="type")
misp.attributes_statistics(context="category")
misp.tags_statistics()

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.