generating-threat-intelligence-reports

Featured

Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts. Use when producing finished intelligence products from raw collection data, creating sector threat briefings, or delivering post-incident intelligence assessments. Activates for requests involving CTI report writing, threat briefings, intelligence products, finished intelligence, or executive security reporting.

AI & Automation 16,326 stars 1981 forks Updated 2 weeks ago Apache-2.0

Install

View on GitHub

Quality Score: 97/100

Stars 20%
100
Recency 20%
90
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Generating Threat Intelligence Reports ## When to Use Use this skill when: - Producing weekly, monthly, or quarterly threat intelligence summaries for security leadership - Creating a rapid intelligence assessment in response to a breaking threat (e.g., new zero-day, active ransomware campaign) - Generating sector-specific threat briefings for executive decision-making on security investments **Do not use** this skill for raw IOC distribution — use TIP/MISP for automated IOC sharing and reserve report generation for analyzed, finished intelligence. ## Prerequisites - Completed analysis from collection and processing phase (PIRs partially or fully answered) - Audience profile: technical level, decision-making authority, information classification clearance - TLP classification decision for the product - Organization-specific reporting template aligned to audience expectations ## Workflow ### Step 1: Determine Report Type and Audience Select the appropriate intelligence product type: **Strategic Intelligence Report**: For C-suite, board, risk committee - Content: Threat landscape trends, adversary intent vs. capability, risk to business objectives - Format: 1–3 pages, minimal jargon, business impact language, recommended decisions - Frequency: Monthly/Quarterly **Operational Intelligence Report**: For CISO, security directors, IR leads - Content: Active campaigns, adversary TTPs, defensive recommendations, sector peer incidents - Format: 3–8 pages, moderate technica...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
2 weeks ago
Language
Python
License
Apache-2.0

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Featured

managing-intelligence-lifecycle

Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve. Use when establishing or maturing a CTI program, defining intelligence requirements with business stakeholders, or building feedback loops between intelligence consumers and producers. Activates for requests involving CTI program maturity, intelligence requirements, PIRs, or intelligence lifecycle management.

16,326 Updated 2 weeks ago
mukul975
AI & Automation Featured

analyzing-threat-intelligence-feeds

Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. Use when ingesting commercial or open-source CTI feeds, evaluating feed quality, normalizing data into STIX 2.1 format, or enriching existing IOCs with campaign attribution. Activates for requests involving ThreatConnect, Recorded Future, Mandiant Advantage, MISP, AlienVault OTX, or automated feed aggregation pipelines.

16,326 Updated 2 weeks ago
mukul975
AI & Automation Featured

profiling-threat-actor-groups

Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints, and attribution indicators from multiple intelligence sources. Use when briefing executives on sector-specific threats, updating threat model assumptions, or prioritizing defensive controls against specific adversaries. Activates for requests involving MITRE ATT&CK Groups, Mandiant APT profiles, CrowdStrike adversary naming, or sector-specific threat briefings.

16,326 Updated 2 weeks ago
mukul975