Pilot Threat Intelligence Setup
/install pilot-threat-intelligence-setup
Threat Intelligence Setup
Deploy 4 agents: collector, enricher, analyzer, and distributor.
Roles
| Role | Hostname | Skills | Purpose |
|---|---|---|---|
| collector | \x3Cprefix>-collector |
pilot-stream-data, pilot-cron, pilot-archive | Aggregates threat feeds from OSINT, honeypots, CVE databases |
| enricher | \x3Cprefix>-enricher |
pilot-dataset, pilot-task-router, pilot-event-filter | Correlates IOCs, enriches with WHOIS/GeoIP, maps to MITRE |
| analyzer | \x3Cprefix>-analyzer |
pilot-metrics, pilot-consensus, pilot-alert | Scores severity, identifies campaigns and APT groups |
| distributor | \x3Cprefix>-distributor |
pilot-webhook-bridge, pilot-announce, pilot-audit-log | Publishes STIX/TAXII feeds, pushes IOCs to SIEM |
Setup Procedure
Step 1: Ask the user which role this agent should play and what prefix to use.
Step 2: Install the skills for the chosen role:
# For collector:
clawhub install pilot-stream-data pilot-cron pilot-archive
# For enricher:
clawhub install pilot-dataset pilot-task-router pilot-event-filter
# For analyzer:
clawhub install pilot-metrics pilot-consensus pilot-alert
# For distributor:
clawhub install pilot-webhook-bridge pilot-announce pilot-audit-log
Step 3: Set the hostname and write the manifest to ~/.pilot/setups/threat-intelligence.json.
Step 4: Tell the user to initiate handshakes with the peers for their role.
Manifest Templates Per Role
collector
{
"setup": "threat-intelligence", "role": "collector", "role_name": "Intel Collector",
"hostname": "\x3Cprefix>-collector",
"skills": {
"pilot-stream-data": "Ingest real-time threat feeds from OSINT and honeypots.",
"pilot-cron": "Schedule periodic CVE database and dark web scans.",
"pilot-archive": "Store raw indicator history for retrospective analysis."
},
"data_flows": [{ "direction": "send", "peer": "\x3Cprefix>-enricher", "port": 1002, "topic": "raw-ioc", "description": "Normalized IOCs from threat feeds" }],
"handshakes_needed": ["\x3Cprefix>-enricher"]
}
enricher
{
"setup": "threat-intelligence", "role": "enricher", "role_name": "Threat Enricher",
"hostname": "\x3Cprefix>-enricher",
"skills": {
"pilot-dataset": "Cross-reference IOCs against known threat databases.",
"pilot-task-router": "Route enrichment tasks to specialized lookup services.",
"pilot-event-filter": "Filter low-confidence indicators before analysis."
},
"data_flows": [
{ "direction": "receive", "peer": "\x3Cprefix>-collector", "port": 1002, "topic": "raw-ioc", "description": "Raw IOCs to enrich" },
{ "direction": "send", "peer": "\x3Cprefix>-analyzer", "port": 1002, "topic": "enriched-ioc", "description": "IOCs with WHOIS, GeoIP, MITRE context" }
],
"handshakes_needed": ["\x3Cprefix>-collector", "\x3Cprefix>-analyzer"]
}
analyzer
{
"setup": "threat-intelligence", "role": "analyzer", "role_name": "Threat Analyzer",
"hostname": "\x3Cprefix>-analyzer",
"skills": {
"pilot-metrics": "Track threat volumes, severity distribution, and response times.",
"pilot-consensus": "Correlate multi-source verdicts for high-confidence scoring.",
"pilot-alert": "Emit critical threat alerts for immediate action."
},
"data_flows": [
{ "direction": "receive", "peer": "\x3Cprefix>-enricher", "port": 1002, "topic": "enriched-ioc", "description": "Enriched IOCs to analyze" },
{ "direction": "send", "peer": "\x3Cprefix>-distributor", "port": 1002, "topic": "threat-verdict", "description": "Scored verdicts with campaign attribution" }
],
"handshakes_needed": ["\x3Cprefix>-enricher", "\x3Cprefix>-distributor"]
}
distributor
{
"setup": "threat-intelligence", "role": "distributor", "role_name": "Intel Distributor",
"hostname": "\x3Cprefix>-distributor",
"skills": {
"pilot-webhook-bridge": "Push IOC updates to firewalls, IDS, and SIEM.",
"pilot-announce": "Broadcast threat advisories to subscribed consumers.",
"pilot-audit-log": "Log all published intelligence with distribution timestamps."
},
"data_flows": [
{ "direction": "receive", "peer": "\x3Cprefix>-analyzer", "port": 1002, "topic": "threat-verdict", "description": "Threat verdicts to distribute" },
{ "direction": "send", "peer": "external", "port": 443, "topic": "threat-feed", "description": "STIX/TAXII feeds to security infrastructure" }
],
"handshakes_needed": ["\x3Cprefix>-analyzer"]
}
Data Flows
collector -> enricher: raw IOCs normalized from threat feeds (port 1002)enricher -> analyzer: enriched IOCs with context and confidence scores (port 1002)analyzer -> distributor: threat verdicts with severity and campaign data (port 1002)distributor -> external: published threat feeds to security infrastructure (port 443)
Workflow Example
# On collector -- forward raw IOC:
pilotctl --json publish \x3Cprefix>-enricher raw-ioc '{"type":"ip","value":"198.51.100.23","source":"honeypot-east","tags":["c2","cobalt-strike"]}'
# On enricher -- forward enriched IOC:
pilotctl --json publish \x3Cprefix>-analyzer enriched-ioc '{"type":"ip","value":"198.51.100.23","whois":{"asn":"AS62904","country":"RU"},"mitre":["T1071.001"],"confidence":0.87}'
# On analyzer -- send verdict:
pilotctl --json publish \x3Cprefix>-distributor threat-verdict '{"ioc":"198.51.100.23","severity":"critical","campaign":"APT-THUNDER-BEAR","action":"block"}'
Dependencies
Requires pilot-protocol skill, pilotctl binary, clawhub binary, and a running daemon.
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install pilot-threat-intelligence-setup - 安装完成后,直接呼叫该 Skill 的名称或使用
/pilot-threat-intelligence-setup触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
Pilot Threat Intelligence Setup 是什么?
Deploy a threat intelligence platform with 4 agents. Use this skill when: 1. User wants to set up a threat intelligence pipeline for IOC collection and distr... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 59 次。
如何安装 Pilot Threat Intelligence Setup?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install pilot-threat-intelligence-setup」即可一键安装,无需额外配置。
Pilot Threat Intelligence Setup 是免费的吗?
是的,Pilot Threat Intelligence Setup 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
Pilot Threat Intelligence Setup 支持哪些平台?
Pilot Threat Intelligence Setup 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Pilot Threat Intelligence Setup?
由 Calin Teodor(@teoslayer)开发并维护,当前版本 v1.0.0。