Threat Intel Daily Brief
intel_daily_briefGenerates a localized threat brief by correlating inventory packages, telemetry indicators, campaign data, and ransomware claims against governed intelligence sources.
Instructions
Return a local analyst threat brief from governed intel sources.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| packages | No | Optional inventory packages with purl or ecosystem/name/version objects for local matching. | |
| telemetry_indicators | No | Optional governed IoC observations with indicator, hit_count, source_url, license, fetched_at, and content_hash. | |
| campaign_activity | No | Optional governed campaign activity items with sectors/geos and provenance for tenant-profile matching. | |
| ransomware_claims | No | Optional governed ransomware claim items with sectors/geos and provenance for tenant-profile matching. | |
| tenant_profile | No | Optional tenant profile with sectors and geos used to match campaign/ransomware inputs. | |
| epss_threshold | No | Minimum EPSS probability for inventory-prioritized CVEs, 0-1. | |
| kev_window_hours | No | KEV date_added lookback window, 1-168 hours. | |
| limit | No | Maximum packages/advisories to inspect, 1-500. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |