BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

zettelforge

Skill Development Usable
Works inClaude Code
Usable Scanned — metadata only

Enables security teams to build persistent, interconnected threat intelligence without manual documentation overhead.

An agentic memory system for cyber threat intelligence. It extracts CVEs, threat actors, IOCs, and MITRE ATT&CK techniques from analyst notes and threat reports, resolves actor aliases (APT28 = Fancy Bear = STRONTIUM = Sofacy), and builds a STIX 2.1 knowledge graph with causal relationships. Runs entirely in-process with no external API or cloud dependency, and serves past investigations back to analysts and to Claude Code via an MCP server.

58 starsMIT (commercial OK)FreeQuick setup
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Enables security teams to build persistent, interconnected threat intelligence without manual documentation overhead. Reduces analyst context-switching and improves institutional knowledge retention across incident response cycles.

Security operations centers and threat intelligence teams managing multi-vector attack investigations and knowledge continuity.

Claude Code Claude Cowork Claude Chat

https://github.com/ThreatRecall/zettelforge

By rolandpg

How to Get It

Option 1: Claude Desktop App (Code Mode)Click the + button next to the prompt box → PluginsAdd plugin. Search and click Install. Skills work in Claude Code only.
Option 2: Paste into Claude CodeCopy the command below and paste it into your conversation. Claude will install it.
Command
pip install zettelforge

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

After installing, paste this into Claude:

Help me link new malware samples to known threat actor campaigns
PrerequisitesPython 3.10+.CostFree

Trust Signals Auto-scanned

Stars58Contributors7Last updated2026-07-30LicenseMIT (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-08-13 · scanner vattempted-no-data

Community Pulse Active

Discussed on Hacker News, Reddit

3 mentions across 1 sources

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

Auto-assessment from April sweep — baseline scores pending hands-on review.

2026-04-18: Approved in April sweep: New and small but has a clear description and recent commits — worth tracking.

Things to check

  • Requires careful data hygiene and deduplication logic to avoid polluting the knowledge base with conflicting intelligence. Effectiveness depends on consistent tagging and classification discipline across the team.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
3/5
Reliability
3/5
Security
3/5
Overall score3.00 / 5.00 UsableEvaluatedApr 2026

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →