Generating Threat Intelligence Reports
Overview
Cybersecurity skill for generating threat intelligence reports. Follows industry best practices and security standards.
When to Use
Trigger phrases:
- "generating threat intelligence reports"
- "Producing weekly, monthly, or quarterly threat intelligence summaries for securi"
- "Creating a rapid intelligence assessment in response to a breaking threat (e"
- "Generating sector-specific threat briefings for executive decision-making on sec"
Use this skill when:
- Producing weekly, monthly, or quarterly threat intelligence summaries for security leadership
- Creating a rapid intelligence assessment in response to a breaking threat (e.g., new zero-day, active ransomware campaign)
- Generating sector-specific threat briefings for executive decision-making on security investments
Do not use this skill for raw IOC distribution — use TIP/MISP for automated IOC sharing and reserve report generation for analyzed, finished intelligence.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Completed analysis from collection and processing phase (PIRs partially or fully answered)
- Audience profile: technical level, decision-making authority, information classification clearance
- TLP classification decision for the product
- Organization-specific reporting template aligned to audience expectations
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Define Objectives — Clarify the goals and scope for threat intelligence reports.
- Gather Resources — Collect tools, data, and access needed for threat intelligence reports.
- Execute Process — Carry out threat intelligence reports operations methodically.
- Verify Quality — Check results against acceptance criteria.
- Document Outcomes — Record findings, decisions, and next steps.
Tools
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Scope — Define research questions, identify data sources, set time boundaries
- Gather — Collect data from primary sources, APIs, and public records
- Synthesize — Analyze findings, identify patterns, produce actionable report
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: generating-threat-intelligence-reports3description: Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts. Use when producing finished intelligence products from raw collection data, creating sector threat briefings, or delivering post-incident intelligence assessments.4license: Apache-2.05---67# Generating Threat Intelligence Reports89## Overview1011Cybersecurity skill for generating threat intelligence reports. Follows industry best practices and security standards.1213## When to Use1415**Trigger phrases:**16- "generating threat intelligence reports"17- "Producing weekly, monthly, or quarterly threat intelligence summaries for securi"18- "Creating a rapid intelligence assessment in response to a breaking threat (e"19- "Generating sector-specific threat briefings for executive decision-making on sec"202122Use this skill when:23- Producing weekly, monthly, or quarterly threat intelligence summaries for security leadership24- Creating a rapid intelligence assessment in response to a breaking threat (e.g., new zero-day, active ransomware campaign)25- Generating sector-specific threat briefings for executive decision-making on security investments2627**Do not use** this skill for raw IOC distribution — use TIP/MISP for automated IOC sharing and reserve report generation for analyzed, finished intelligence.282930## When NOT to Use3132- When you lack proper authorization for testing33- For production systems without change management34- When the task requires legal or compliance expertise beyond technical scope353637## Prerequisites3839- Completed analysis from collection and processing phase (PIRs partially or fully answered)40- Audience profile: technical level, decision-making authority, information classification clearance41- TLP classification decision for the product42- Organization-specific reporting template aligned to audience expectations4344## Workflow4546```python47# Example: IOC detection48import re4950IOC_PATTERNS = {51 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",52 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",53 "hash_md5": r"\b[a-f0-9]{32}\b",54 "hash_sha256": r"\b[a-f0-9]{64}\b",55}5657def extract_iocs(text: str) -> dict:58 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}59```60611. **Define Objectives** — Clarify the goals and scope for threat intelligence reports.622. **Gather Resources** — Collect tools, data, and access needed for threat intelligence reports.633. **Execute Process** — Carry out threat intelligence reports operations methodically.644. **Verify Quality** — Check results against acceptance criteria.655. **Document Outcomes** — Record findings, decisions, and next steps.6667## Tools6869- **Analysis Platform** — Data processing and visualization70- **Collaboration Tools** — Team coordination and knowledge sharing717273## Process74751. **Scope** — Define research questions, identify data sources, set time boundaries761. **Gather** — Collect data from primary sources, APIs, and public records771. **Synthesize** — Analyze findings, identify patterns, produce actionable report7879## Verification8081- [ ] All threat intelligence reports procedures executed completely and documented82- [ ] Findings validated against multiple data sources83- [ ] False positives identified and filtered84- [ ] Results documented with evidence and timestamps85- [ ] Recommendations provided with risk-based prioritization8687## Anti-Rationalization Table8889| Rationalization | Reality |90|---|---|91| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |92| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |93| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |