external/anthropic-cybersecurity-skills/skills/generating-threat-intelligence-reports/SKILL.md
Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts. Use when producing finished intelligence products from raw collection data, creating sector threat briefings, or delivering post-incident intelligence assessments. Activates for requests involving CTI report writing, threat briefings, intelligence products, finished intelligence, or executive security reporting.
npx skillsauth add seikaikyo/dash-skills generating-threat-intelligence-reportsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill when:
Do not use this skill for raw IOC distribution — use TIP/MISP for automated IOC sharing and reserve report generation for analyzed, finished intelligence.
Select the appropriate intelligence product type:
Strategic Intelligence Report: For C-suite, board, risk committee
Operational Intelligence Report: For CISO, security directors, IR leads
Tactical Intelligence Bulletin: For SOC analysts, threat hunters, vulnerability management
Flash Report: Urgent notification for imminent or active threats
Apply intelligence writing standards from government and professional practice:
Headline/Key Judgment: Lead with the most important finding in plain language.
Confidence Qualifiers (use language from DNI ICD 203):
Evidence Attribution: Cite sources using reference numbers [1], [2]; maintain source anonymization in TLP:AMBER/RED products.
Use structured format:
Executive Summary (3–5 bullet points): Key findings, immediate business risk, top recommended action
Threat Overview: Who is the adversary? What is their objective? Why does this matter to us?
Technical Analysis: TTPs with ATT&CK technique IDs, IOCs, observed campaign behavior
Impact Assessment: Potential operational, financial, reputational impact if attack succeeds
Recommended Actions: Prioritized, time-bound defensive measures with owner assignment
Appendices: Full IOC lists, YARA rules, Sigma detections, raw source references
Select TLP based on source sensitivity and sharing agreements:
Include TLP watermark on every page header and footer.
Before dissemination, apply these checks:
| Term | Definition | |------|-----------| | Finished Intelligence | Analyzed, contextualized intelligence product ready for consumption by decision-makers; distinct from raw collected data | | Key Judgment | Primary analytical conclusion of a report; clearly stated in opening paragraph | | TLP | Traffic Light Protocol — FIRST-standard classification system for controlling intelligence sharing scope | | ICD 203 | Intelligence Community Directive 203 — US government standard for analytic standards including confidence language | | Flash Report | Urgent, time-sensitive intelligence notification for imminent threats; prioritizes speed over depth | | Intelligence Gap | Area where collection is insufficient to answer a PIR; should be explicitly documented in reports |
development
Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing validation, remediation tracking, and continuous compliance monitoring. Covers all five TSC categories (Security, Availability, Processing Integrity, Confidentiality, Privacy) with automated evidence gathering from AWS, Azure, GCP, Okta, GitHub, and Jira. Use when preparing for or maintaining SOC 2 Type II certification.
testing
Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems. Use when organizations need to validate IR playbooks, train analysts, or meet compliance requirements for incident response testing.
development
Perform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE, WS-Security bypass, and SOAPAction spoofing.
devops
Automate credential rotation for service accounts across Active Directory, cloud platforms, and application databases to eliminate stale secrets and reduce compromise risk.