managing-intelligence-lifecycle

Featured

Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve. Use when establishing or maturing a CTI program, defining intelligence requirements with business stakeholders, or building feedback loops between intelligence consumers and producers. Activates for requests involving CTI program maturity, intelligence requirements, PIRs, or intelligence lifecycle management.

AI & Automation 16,326 stars 1981 forks Updated 2 weeks ago Apache-2.0

Install

View on GitHub

Quality Score: 97/100

Stars 20%
100
Recency 20%
90
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Managing Intelligence Lifecycle ## When to Use Use this skill when: - Establishing a formal CTI program and defining its operational model - Conducting quarterly intelligence requirements reviews with business stakeholders - Evaluating CTI program maturity against established frameworks (FIRST CTI-SIG maturity model) **Do not use** this skill for day-to-day IOC triage or incident-specific intelligence tasks — those use operational intelligence workflows, not lifecycle management. ## Prerequisites - Executive sponsorship and defined CTI team structure (1+ dedicated analysts) - Stakeholder map identifying intelligence consumers (SOC, IR, executive team, vulnerability management) - Existing feed subscriptions or ISAC memberships for collection baseline - CTI platform (MISP, ThreatConnect, OpenCTI) for lifecycle management ## Workflow ### Step 1: Planning and Direction Define Priority Intelligence Requirements (PIRs) with stakeholders: - Interview SOC leads, IR team, CISO, risk management, and product security - Document PIRs in structured format: "What is the current capability and intent of [threat actor] to attack [critical asset] using [technique]?" - Prioritize 5–10 PIRs for the quarter, reviewed monthly Example PIR: "Is ransomware group Cl0p currently targeting organizations in our sector using MoveIT or GoAnywhere vulnerabilities?" ### Step 2: Collection Planning Map PIRs to required collection sources: - Technical sources: commercial feeds, TAXII, ISAC data, ...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
2 weeks ago
Language
Python
License
Apache-2.0

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Featured

generating-threat-intelligence-reports

Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts. Use when producing finished intelligence products from raw collection data, creating sector threat briefings, or delivering post-incident intelligence assessments. Activates for requests involving CTI report writing, threat briefings, intelligence products, finished intelligence, or executive security reporting.

16,326 Updated 2 weeks ago
mukul975
AI & Automation Featured

analyzing-threat-intelligence-feeds

Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. Use when ingesting commercial or open-source CTI feeds, evaluating feed quality, normalizing data into STIX 2.1 format, or enriching existing IOCs with campaign attribution. Activates for requests involving ThreatConnect, Recorded Future, Mandiant Advantage, MISP, AlienVault OTX, or automated feed aggregation pipelines.

16,326 Updated 2 weeks ago
mukul975
AI & Automation Featured

evaluating-threat-intelligence-platforms

Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP procurement, migrating between TIP solutions, or assessing whether the current TIP meets program maturity requirements. Activates for requests involving ThreatConnect, MISP, OpenCTI, Anomali, EclecticIQ, or TIP procurement decisions.

16,326 Updated 2 weeks ago
mukul975