transilienceai/communitytools

ti-ingest

Threat-intel signal ingest — converts a CVE + affected-asset + claim payload into a queued engagement-scope row for the validation pipeline.

Quelltext ansehen
Originales Skill-Dokument

Aus dem Quell-Repository gerendert; Überschriften, Beispiele, Code, Tabellen, Links und Bilder bleiben erhalten.

Threat-Intel Signal Ingest

Convert a threat-intel signal into a queued engagement-scope row that the Exploitability Validation Run (cloud-agent task #3) consumes.

Trigger

Two modes:

  • Prompt-invoked: an analyst runs the skill against a signal.json they have on hand.
  • Scheduled poll: the cloud-agent runtime polls {OUTPUT_DIR}/inbox/ on a cron (default every 15 minutes) and processes any new signal files it finds.

Workflow

  1. Read the payloadtools/ti-ingest.py --in <path-or-stdin>.
  2. Validate schema — required keys: signal_id, cve (one or more), assets (one or more), claim. Optional: confidence, source, references.
  3. Enrich with NVD — for every CVE in the payload, run tools/nvd-lookup.py <CVE> and attach {score, severity, cwe} to the row.
  4. De-dup — skip rows whose (asset, cve) pair already exists in queue/scope-*.json. Re-queue only if the prior row's status is REJECTED AND the TI signal carries a higher confidence than the last attempt.
  5. Write queue row — one JSON file per (asset, cve) pair at queue/scope-{ts}-{asset_id}-{cve}.json. The Validation Run task picks these up.

Output

{OUTPUT_DIR}/
  inbox/
    signal-{ts}.json        # raw payload, kept for audit
  queue/
    scope-{ts}-{asset}-{cve}.json

Per scope row:

json
{
  "scope_id": "scope-20260513-asset42-CVE-2024-12345",
  "signal_id": "ti-2026-0042",
  "asset": {"id": "asset42", "url": "https://app.example.com", "tier": "revenue"},
  "cve": "CVE-2024-12345",
  "nvd": {"score": 9.8, "severity": "CRITICAL", "cwe": "CWE-79"},
  "claim": "Reflected XSS via search parameter",
  "confidence": "high",
  "source": "vendor-advisory",
  "references": ["https://..."],
  "queued_at": "2026-05-13T10:00:00Z",
  "status": "queued"
}

Rules

  1. Idempotent. Re-running on the same payload must not produce duplicate queue rows.
  2. No execution. Ingest never runs PoCs. It only queues scope for downstream tasks.
  3. Audit trail. Raw payload is always copied to inbox/ before any transformation.
  4. NVD failures are non-blocking. If nvd-lookup errors, write the row with nvd: null and nvd_error: "..."; do not drop the signal.
  5. Asset must be in inventory. Cross-check asset.id against artifacts/org-surface.json (from Org Recon Refresh task). Unknown assets get a row but flagged unknown_asset: true so the validator skips them.

References

  • reference/ingest-schema.md — full input/output JSON schemas.
aus demselben Repository

Weitere Skills

Alle Skills
transilienceai
Community

attack-path-stitcher

Stitches confirmed single-asset findings into multi-hop attack paths across the organization. Builds a graph where nodes are assets and edges are confirmed exploit hops citing the findings that enable them.

Installationen
5
GitHub Stars
534
Aktualisiert
29. Juli
transilienceai
Community

authenticated-session-acquisition

Acquire an authenticated session THROUGH MFA/OTP on an in-scope target and emit a reusable session artifact (Playwright storageState + Bearer) so executors can test the post-auth attack surface. Use when the highest-value authenticated classes (BOLA/IDOR/mass-assignment/injection on the real data APIs) are blocked because login is gated by SMS-OTP or TOTP MFA. Distinct from the authentication skill (which ATTACKS auth); this one legitimately authenticates and hands the session to the rest of the engagement.

Installationen
1
GitHub Stars
534
Aktualisiert
29. Juli
transilienceai
Community

blockchain-security

Smart contract security testing and blockchain CTF exploitation. Covers Solidity vulnerability analysis, EVM storage manipulation, delegatecall attacks, CREATE/CREATE2 address prediction, and common DeFi exploit patterns. Use when analyzing Solidity contracts, solving blockchain challenges, or testing smart contract security.

Installationen
1
GitHub Stars
534
Aktualisiert
29. Juli
transilienceai
Community

client-side

Client-side vulnerability testing - XSS (reflected/stored/DOM), CSRF, CORS misconfiguration, Clickjacking, DOM-based attacks, and Prototype Pollution.

Installationen
1
GitHub Stars
534
Aktualisiert
29. Juli