From threat-intelligence
Profile a threat actor or campaign — their TTPs (mapped to MITRE ATT&CK), targeting, tooling, infrastructure, and likely intent — to support threat-informed defense. Use to understand who might target you and how, and to prioritize defenses.
How this skill is triggered — by the user, by Claude, or both
Slash command
/threat-intelligence:threat-actor-profilingThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
An actor/campaign profile that informs defense: what they do (TTPs), who they target,
An actor/campaign profile that informs defense: what they do (TTPs), who they target, how they operate, and what that means for your detection and control priorities.
ioc-enrichment).dfir); reconcile aliases.detection-engineering:detection-coverage-review)
and control/hardening recommendations.An actor profile: aliases · motivation · targeting · ATT&CK TTP set · tooling/
infrastructure · relevance-to-us · confidence/gaps · recommended detections &
controls. Use security-reporting; visualize the ATT&CK profile with
security-diagramming.
The deliverable isn't a biography — it's what their TTPs mean for your defenses. Reconcile vendor aliases (the same group has many names) and be explicit about confidence and intelligence gaps. Prioritize defending the techniques they actually use and that you currently can't detect.
Creates, edits, and optimizes skills for Claude Code, including drafting, evaluating with test prompts, iterating on performance, and improving skill descriptions for better triggering accuracy.
npx claudepluginhub jassics/awesome-claude-security --plugin threat-intelligence