From cybersecurity-skills
Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels for executives, SOC teams, and analysts. Activates for CTI report writing, threat briefings, and finished intelligence products.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cybersecurity-skills:generating-threat-intelligence-reportsThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Use this skill when:
Use this skill when:
Do not use this skill for raw IOC distribution — use TIP/MISP for automated IOC sharing and reserve report generation for analyzed, finished intelligence.
Select the appropriate intelligence product type:
Strategic Intelligence Report: For C-suite, board, risk committee
Operational Intelligence Report: For CISO, security directors, IR leads
Tactical Intelligence Bulletin: For SOC analysts, threat hunters, vulnerability management
Flash Report: Urgent notification for imminent or active threats
Apply intelligence writing standards from government and professional practice:
Headline/Key Judgment: Lead with the most important finding in plain language.
Confidence Qualifiers (use language from DNI ICD 203):
Evidence Attribution: Cite sources using reference numbers [1], [2]; maintain source anonymization in TLP:AMBER/RED products.
Use structured format:
Executive Summary (3–5 bullet points): Key findings, immediate business risk, top recommended action
Threat Overview: Who is the adversary? What is their objective? Why does this matter to us?
Technical Analysis: TTPs with ATT&CK technique IDs, IOCs, observed campaign behavior
Impact Assessment: Potential operational, financial, reputational impact if attack succeeds
Recommended Actions: Prioritized, time-bound defensive measures with owner assignment
Appendices: Full IOC lists, YARA rules, Sigma detections, raw source references
Select TLP based on source sensitivity and sharing agreements:
Include TLP watermark on every page header and footer.
Before dissemination, apply these checks:
| Term | Definition |
|---|---|
| Finished Intelligence | Analyzed, contextualized intelligence product ready for consumption by decision-makers; distinct from raw collected data |
| Key Judgment | Primary analytical conclusion of a report; clearly stated in opening paragraph |
| TLP | Traffic Light Protocol — FIRST-standard classification system for controlling intelligence sharing scope |
| ICD 203 | Intelligence Community Directive 203 — US government standard for analytic standards including confidence language |
| Flash Report | Urgent, time-sensitive intelligence notification for imminent threats; prioritizes speed over depth |
| Intelligence Gap | Area where collection is insufficient to answer a PIR; should be explicitly documented in reports |
npx claudepluginhub mukul975/anthropic-cybersecurity-skills --plugin cybersecurity-skillsGenerates structured cyber threat intelligence reports at strategic, operational, and tactical levels for executives, SOC teams, and analysts. Activates for CTI report writing, threat briefings, and finished intelligence products.
Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels for executives, SOC teams, or technical analysts. Activates for CTI report writing, threat briefings, or post-incident assessments.
Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels for executives, SOC teams, and analysts from raw data.