From SAT-skill
Guide cyber threat intelligence analysts through the Diamond Model framework and Structured Analytic Techniques (SATs) from Heuer. Use when analysts need help with: (1) Organizing attack data using the Diamond Model, (2) Attribution analysis, (3) Malware clustering and threat actor identification, (4) Campaign analysis and activity threading, (5) Influence operation detection, (6) Challenging assumptions in threat analysis, (7) Evaluating competing hypotheses, or (8) Any situation requiring systematic, structured analysis of cyber threat intelligence. Provides Socratic guidance through analysis without performing it.
How this skill is triggered — by the user, by Claude, or both
Slash command
/SAT-skill:structured-analytic-techniquesThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
This skill helps cyber threat intelligence analysts apply both the Diamond Model framework and Structured Analytic Techniques (SATs) from Richards Heuer Jr. to improve the rigor and defensibility of their analysis. The skill guides users through technique selection and execution via conversational questioning.
This skill helps cyber threat intelligence analysts apply both the Diamond Model framework and Structured Analytic Techniques (SATs) from Richards Heuer Jr. to improve the rigor and defensibility of their analysis. The skill guides users through technique selection and execution via conversational questioning.
The Diamond Model provides a framework for organizing intrusion analysis around four core features: Adversary, Capability, Infrastructure, and Victim. It helps analysts systematically organize data, identify gaps, and pivot to discover new intelligence.
Structured Analytic Techniques are methods designed to help analysts challenge assumptions, evaluate competing hypotheses, and avoid cognitive biases in their assessments.
Ask questions to understand what the analyst is trying to accomplish:
Based on the analyst's challenge, recommend 1-3 appropriate techniques. Common mappings:
Analytical Frameworks:
Structured Analytic Techniques:
Combined Approaches:
Present recommendations with brief explanations (1-2 sentences each) of why each technique fits their situation.
Once a technique is selected, load the appropriate reference file and guide the analyst through it:
Analytical Framework:
references/diamond_model.mdStructured Analytic Techniques:
references/ach.mdreferences/key_assumptions.mdreferences/quality_of_info.mdreferences/devils_advocacy.mdreferences/indicators.mdreferences/what_if.mdGuide them through the technique by:
For Diamond Model specifically:
In these cases, provide brief help or redirect appropriately.
npx claudepluginhub g-clef/sat-skill --plugin SAT-skillApplies 18 CIA/IC structured analytic techniques (ACH, Premortem, Devil's Advocacy, etc.) to produce evidence-based assessments with full citations for any problem.
Applies Diamond Model to structure intrusions into adversary, capability, infrastructure, and victim vertices with relationships for investigation, attribution, and event clustering to common threat actors. For post-incident analysis and threat intel products.
Manages the end-to-end cyber threat intelligence lifecycle from planning through feedback. Use when establishing or maturing a CTI program, defining intelligence requirements, or building feedback loops.