From threat-intelligence
Run the cyber threat intelligence lifecycle for a question or dataset — direction, collection, processing, analysis with structured techniques, and dissemination — to produce an assessed, actionable intelligence product. Use to turn raw threat data into decision-useful intelligence for a defined audience.
How this skill is triggered — by the user, by Claude, or both
Slash command
/threat-intelligence:cti-analysisThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
An intelligence product that answers a specific requirement, states assessments with
An intelligence product that answers a specific requirement, states assessments with calibrated confidence, and tells the consumer what to do — not just a pile of data.
dfir, OSINT,
feeds, ISAC/sharing, vendor reports). Track source reliability.ioc-enrichment).An intelligence product: requirement · key judgments (with confidence) · supporting
evidence · ATT&CK/Diamond framing · recommendations · sources (with reliability).
Use security-reporting; tactical output feeds detection-engineering.
Intelligence is requirement-driven and decision-oriented — data without a consumer and a recommendation isn't intelligence. State confidence explicitly and separate fact from assessment from assumption. Match altitude to audience: leadership wants strategic implications, the SOC wants tactical TTPs/IOCs.
Creates, edits, and optimizes skills for Claude Code, including drafting, evaluating with test prompts, iterating on performance, and improving skill descriptions for better triggering accuracy.
npx claudepluginhub jassics/awesome-claude-security --plugin threat-intelligence