Skip to content
Security
Skill

/correlating-threat-campaigns

Correlates disparate security incidents, IOCs, and adversary behaviors

From plugin
cybersecurity-skills
28k200 skills
Install
$ npx -y skills add mukul975/Anthropic-Cybersecurity-Skills --skill correlating-threat-campaigns --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/correlating-threat-campaigns

Context preview

The summary Claude sees to decide when to auto-load this skill.

Correlates disparate security incidents, IOCs, and adversary behaviors

SKILL.md

correlating-threat-campaigns.SKILL.md
name: correlating-threat-campaigns
description: 'Correlates disparate security incidents, IOCs, and adversary behaviors
  across time and organizations to identify unified threat campaigns, attribute them
  to common threat actors, and extract shared indicators for improved detection. Use
  when multiple incidents exhibit overlapping indicators, when sector-wide attack
  campaigns require cross-organizational analysis, or when building campaign-level
  intelligence products. Activates for requests involving campaign analysis, incident
  clustering, cross-organizational IOC correlation, or MISP correlation engine.

  '
domain: cybersecurity
subdomain: threat-intelligence
tags:
- campaign-analysis
- correlation
- MISP
- ATT&CK
- threat-actor
- intrusion-set
- clustering
- CTI
version: 1.0.0
author: team-cybersecurity
license: Apache-2.0
nist_csf:
- ID.RA-01
- ID.RA-05
- DE.CM-01
- DE.AE-02
mitre_attack:
- T1566
- T1071.001
- T1587.001
- T1583.001
- T1588.002

Correlating Threat Campaigns

When to Use

Use this skill when:

  • Multiple unrelated-appearing incidents share IOCs (same C2 IP, same malware hash, similar TTPs)
  • An ISAC partner shares indicators from an incident that match your own historical events
  • Building a campaign report linking adversary activity over weeks or months to a single operation

**Do not use** this skill to force correlation based on weak signals — false campaign attribution misleads defenders and wastes resources on incorrect threat models.

Prerequisites

  • TIP or SIEM with historical indicator and event data (90+ days recommended)
  • MISP correlation engine enabled with event sharing configured
  • Graph analysis tool (Maltego, Neo4j, or OpenCTI) for relationship visualization
  • Reference to MITRE ATT&CK intrusion set and campaign objects for structuring output

Workflow

Step 1: Collect and Normalize Events

Gather all candidate events for correlation from:

  • Internal SIEM (raw events, alert history)
  • TIP (historical indicators and events)
  • ISAC sharing (partner-submitted events in MISP or TAXII)
  • Commercial intelligence (Recorded Future, Mandiant, CrowdStrike reports)

Normalize all events to STIX 2.1 schema with consistent timestamp (UTC), indicator types, and confidence scores. Ensure all indicators have source attribution and collection date.

Step 2: Identify Correlation Pivot Points

Apply systematic pivot analysis across four dimensions:

**Infrastructure pivots**:

  • Same IP address or /24 subnet across events
  • Same domain registrant email or WHOIS organization
  • Same ASN or hosting provider with same account fingerprint
  • Same SSL certificate fingerprint or serial number across C2 domains

**Capability pivots**:

  • Same malware hash or YARA signature match
  • Same C2 communication protocol (Cobalt Strike beacon config, Sliver implant parameters)
  • Same exploit code or weaponized document template
  • Same obfuscation method or packer fingerprint

**Temporal pivots**:

  • Events occurring within same time window (operational hours suggesting same timezone)
  • Sequential events with logical kill chain progression
  • Malware compilation timestamps clustering in same date range

**Victimology pivots**:

  • Same target sector (healthcare, energy, financial)
  • Same target geography
  • Same targeted technology (specific ERP vendor, VPN appliance brand)

Step 3: Calculate Correlation Confidence

Apply weighted scoring for campaign attribution:

def calculate_campaign_confidence(events: list) -> float:
    scores = []

    # Infrastructure overlap (highest weight — most discriminating)
    infra_overlap = count_shared_infra(events) / len(events)
    scores.append(infra_overlap * 40)

    # Capability overlap (high weight — TTPs are durable)
    capability_overlap = count_shared_ttps(events) / len(events)
    scores.append(capability_overlap * 35)

    # Temporal proximity (moderate weight)
    temporal_score = assess_temporal_clustering(events)
    scores.append(temporal_score * 15)

    # Victimology alignment (lower weight — many actors target same sector)
    victim_score = assess_victim_pattern(events)
    scores.append(victim_score * 10)

    total = sum(scores)
    if total >= 70: return "HIGH"
    elif total >= 45: return "MEDIUM"
    else: return "LOW"

Step 4: Build Campaign Graph

In OpenCTI or Maltego, construct campaign graph:

  • Campaign object (STIX) as central node
  • Intrusion Set → uses → Malware objects
  • Intrusion Set → uses → Infrastructure objects
  • Intrusion Set → targets → Identity objects (victim organizations/sectors)
  • Campaign → attributed-to → Threat Actor (if attribution achieved)
  • Indicators → indicates → Malware (linking technical observables to capabilities)

Label each relationship with evidence reference and confidence.

Step 5: Produce Campaign Intelligence Report

Structure the campaign report: 1. **Campaign name**: Assign descriptive codename based on targeting theme or tooling 2. **Timeline**: First/last observed dates with activity phases 3. **Attribution**: Suspected threat actor with confidence level 4. **Target profile**: Industry verticals, geographies, organization sizes 5. **TTPs summary**: ATT&CK Navigator heatmap for campaign-specific techniques 6. **Shared indicators**: IOCs that span multiple incidents (highest confidence for blocking) 7. **Detection guidance**: Sigma/YARA rules specific to this campaign

Key Concepts

| Term | Definition | |------|-----------| | **Campaign** | STIX object representing a grouping of adversarial behaviors with common objectives over a defined time period | | **Intrusion Set** | STIX object grouping related intrusion activity by common objectives, even when actor identity is uncertain | | **Pivot** | Using a single data point (IOC, infrastructure, TTP) to discover related events or adversary artifacts | | **Clustering** | Machine learning or manual grouping of incidents based on feature similarity to identify campaign boundaries | | **Fal

Read more
Ships withcybersecurity-skills

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

Get the whole plugin

Other skills on cybersecurity-skills.