GE

generating-threat-intelligence-reports

Creates actionable cyber threat intelligence reports from raw data. Use for briefings, post-incident assessments, and sector-specific analysis.

Install

mkdir -p .claude/skills/generating-threat-intelligence-reports && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/17456" && unzip -o skill.zip -d .claude/skills/generating-threat-intelligence-reports && rm skill.zip

Installs to .claude/skills/generating-threat-intelligence-reports

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Generates structured cyber threat intelligence reports at strategic,
68 charsno explicit “when” trigger
Intermediate

Key capabilities

  • Produce weekly, monthly, or quarterly threat intelligence summaries for security leadership.
  • Create rapid intelligence assessments in response to breaking threats.
  • Generate sector-specific threat briefings for executive decision-making.
  • Structure reports using intelligence writing standards.
  • Apply Traffic Light Protocol (TLP) for distribution controls.
  • Review reports for accuracy, clarity, actionability, classification, and timeliness.

How it works

This skill guides the user through determining report type and audience, structuring the report using intelligence standards, writing the report body, applying TLP and distribution controls, and reviewing for quality control.

Inputs & outputs

You give it
raw collection data, audience profile, TLP classification, reporting template
You get back
structured cyber threat intelligence report

When to use generating-threat-intelligence-reports

  • Creating weekly security threat summaries
  • Drafting intelligence assessments after a zero-day incident
  • Generating executive-level sector threat briefings

About this skill

Generating Threat Intelligence Reports

When to Use

Use this skill when:

  • Producing weekly, monthly, or quarterly threat intelligence summaries for security leadership
  • Creating a rapid intelligence assessment in response to a breaking threat (e.g., new zero-day, active ransomware campaign)
  • Generating sector-specific threat briefings for executive decision-making on security investments

Do not use this skill for raw IOC distribution — use TIP/MISP for automated IOC sharing and reserve report generation for analyzed, finished intelligence.

Prerequisites

  • Completed analysis from collection and processing phase (PIRs partially or fully answered)
  • Audience profile: technical level, decision-making authority, information classification clearance
  • TLP classification decision for the product
  • Organization-specific reporting template aligned to audience expectations

Workflow

Step 1: Determine Report Type and Audience

Select the appropriate intelligence product type:

Strategic Intelligence Report: For C-suite, board, risk committee

  • Content: Threat landscape trends, adversary intent vs. capability, risk to business objectives
  • Format: 1–3 pages, minimal jargon, business impact language, recommended decisions
  • Frequency: Monthly/Quarterly

Operational Intelligence Report: For CISO, security directors, IR leads

  • Content: Active campaigns, adversary TTPs, defensive recommendations, sector peer incidents
  • Format: 3–8 pages, moderate technical detail, mitigation priority list
  • Frequency: Weekly

Tactical Intelligence Bulletin: For SOC analysts, threat hunters, vulnerability management

  • Content: Specific IOCs, YARA rules, Sigma detections, CVEs, patching guidance
  • Format: Structured tables, code blocks, 1–2 pages
  • Frequency: Daily or as-needed

Flash Report: Urgent notification for imminent or active threats

  • Content: What is happening, immediate risk, what to do right now
  • Format: 1 page maximum, distributed within 2 hours of threat identification
  • Frequency: As-needed (zero-day, active campaign targeting sector)

Step 2: Structure Report Using Intelligence Standards

Apply intelligence writing standards from government and professional practice:

Headline/Key Judgment: Lead with the most important finding in plain language.

  • Bad: "This report examines threat actor TTPs associated with Cl0p ransomware"
  • Good: "Cl0p ransomware group is actively exploiting CVE-2024-20353 in Cisco ASA devices to gain initial access; organizations using unpatched ASA appliances face imminent ransomware risk"

Confidence Qualifiers (use language from DNI ICD 203):

  • High confidence: "assess with high confidence" — strong evidence, few assumptions
  • Medium confidence: "assess" — credible sources but analytical assumptions required
  • Low confidence: "suggests" — limited sources, significant uncertainty

Evidence Attribution: Cite sources using reference numbers [1], [2]; maintain source anonymization in TLP:AMBER/RED products.

Step 3: Write Report Body

Use structured format:

Executive Summary (3–5 bullet points): Key findings, immediate business risk, top recommended action

Threat Overview: Who is the adversary? What is their objective? Why does this matter to us?

Technical Analysis: TTPs with ATT&CK technique IDs, IOCs, observed campaign behavior

Impact Assessment: Potential operational, financial, reputational impact if attack succeeds

Recommended Actions: Prioritized, time-bound defensive measures with owner assignment

Appendices: Full IOC lists, YARA rules, Sigma detections, raw source references

Step 4: Apply TLP and Distribution Controls

Select TLP based on source sensitivity and sharing agreements:

  • TLP:RED: Named recipients only; cannot be shared outside briefing room
  • TLP:AMBER+STRICT: Organization only; no sharing with subsidiaries or partners
  • TLP:AMBER: Organization and trusted partners with need-to-know
  • TLP:GREEN: Community-wide sharing (ISAC members, sector peers)
  • TLP:WHITE/CLEAR: Public distribution; no restrictions

Include TLP watermark on every page header and footer.

Step 5: Review and Quality Control

Before dissemination, apply these checks:

  • Accuracy: Are all facts sourced and cited? No unsubstantiated claims.
  • Clarity: Can the target audience understand this without additional context?
  • Actionability: Does every report section drive a decision or action?
  • Classification: Is TLP correctly applied? No source identification in AMBER/RED products?
  • Timeliness: Is this intelligence still current? Events older than 48 hours require freshness assessment.

Key Concepts

TermDefinition
Finished IntelligenceAnalyzed, contextualized intelligence product ready for consumption by decision-makers; distinct from raw collected data
Key JudgmentPrimary analytical conclusion of a report; clearly stated in opening paragraph
TLPTraffic Light Protocol — FIRST-standard classification system for controlling intelligence sharing scope
ICD 203Intelligence Community Directive 203 — US government standard for analytic standards including confidence language
Flash ReportUrgent, time-sensitive intelligence notification for imminent threats; prioritizes speed over depth
Intelligence GapArea where collection is insufficient to answer a PIR; should be explicitly documented in reports

Tools & Systems

  • ThreatConnect Reports: Built-in report templates with ATT&CK mapping, IOC tables, and stakeholder distribution controls
  • Recorded Future: Pre-built intelligence report templates with automated sourcing from proprietary datasets
  • OpenCTI Reports: STIX-based report objects with linked entities for structured finished intelligence
  • Microsoft Word/Confluence: Common report delivery formats; use organization-approved templates with TLP headers

Common Pitfalls

  • Writing for analysts instead of the audience: Technical detail appropriate for SOC analysts overwhelms executives. Maintain strict audience segmentation.
  • Omitting confidence levels: Statements presented without confidence qualifiers appear as established facts when they may be low-confidence assessments.
  • Intelligence without recommendations: Reports that describe threats without prescribing actions leave stakeholders without direction.
  • Stale intelligence: Publishing a report on a threat campaign that was resolved 2 weeks ago creates alarm without utility. Include freshness dating on all claims.
  • Over-classification: Applying TLP:RED to information that could be TLP:GREEN impedes community sharing and limits defensive value across the sector.

When not to use it

  • Do not use this skill for raw IOC distribution.

Prerequisites

Completed analysis from collection and processing phase (PIRs partially or fully answered)Audience profile: technical level, decision-making authority, information classification clearanceTLP classification decision for the productOrganization-specific reporting template aligned to audience expectations

Limitations

  • This skill does not perform raw IOC distribution.
  • It does not generate intelligence without completed analysis from collection and processing phases.
  • It requires an audience profile, TLP classification, and an organizational reporting template.

How it compares

This skill provides a structured, multi-step workflow for generating intelligence reports, unlike manually compiling information without defined standards or review processes.

Compared to similar skills

generating-threat-intelligence-reports side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
generating-threat-intelligence-reports (this skill)025dReviewIntermediate
red-team-tools-and-methodology76moReviewAdvanced
hunt-focus-definition16moNo flagsIntermediate
hunt-research-system-and-tradecraft16moNo flagsIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

You might also like

red-team-tools-and-methodology

davila7

This skill should be used when the user asks to "follow red team methodology", "perform bug bounty hunting", "automate reconnaissance", "hunt for XSS vulnerabilities", "enumerate subdomains", or needs security researcher techniques and tool configurations from top bug bounty hunters.

759

hunt-focus-definition

OTRF

Define a focused hunt hypothesis by synthesizing completed system internals and adversary tradecraft research. Use this skill after research has been completed to narrow a high-level hunt topic into a single, concrete attack pattern with clear investigative intent. This skill produces a structured, testable hypothesis and should be used before selecting data sources, defining environment scope, or developing analytics.

13

hunt-research-system-and-tradecraft

OTRF

Research system internals and adversary tradecraft to ground a threat hunt in real system behavior and realistic abuse patterns. Use this skill at the start of hunt planning, when you are given a high-level hunt topic but lack a clear understanding of how the system normally operates or how adversaries are known to abuse it. This skill informs early hunt direction by producing candidate abuse patterns, key assumptions, and cited sources, and should be used before defining a concrete hunt hypothesis or selecting data sources.

13

security-research

protoLabsAI

Run a multi-step security intelligence workflow: scan CVE feeds, check Exploit-DB, aggregate security RSS, correlate with target intel, generate threat brief.

00

code-understanding

gadievron

Provides adversarial code comprehension for security research, mapping architecture, tracing data flows, and hunting vulnerability variants to build ground-truth understanding before or alongside static analysis.

00

anti-reversing-techniques

T-Sunm

Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Use when analyzing protected binaries, bypassing anti-debugging for authorized analysis, or u...

00

Search skills

Search the agent skills registry