Managing Intelligence Lifecycle
Overview
Cybersecurity skill for managing intelligence lifecycle. Follows industry best practices and security standards.
When to Use
Trigger phrases:
- "managing intelligence lifecycle"
- "Establishing a formal CTI program and defining its operational model"
- "Conducting quarterly intelligence requirements reviews with business stakeholder"
- "Evaluating CTI program maturity against established frameworks (FIRST CTI-SIG ma"
Use this skill when:
- Establishing a formal CTI program and defining its operational model
- Conducting quarterly intelligence requirements reviews with business stakeholders
- Evaluating CTI program maturity against established frameworks (FIRST CTI-SIG maturity model)
Do not use this skill for day-to-day IOC triage or incident-specific intelligence tasks — those use operational intelligence workflows, not lifecycle management.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Executive sponsorship and defined CTI team structure (1+ dedicated analysts)
- Stakeholder map identifying intelligence consumers (SOC, IR, executive team, vulnerability management)
- Existing feed subscriptions or ISAC memberships for collection baseline
- CTI platform (MISP, ThreatConnect, OpenCTI) for lifecycle management
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Define Objectives — Clarify the goals and scope for intelligence lifecycle.
- Gather Resources — Collect tools, data, and access needed for intelligence lifecycle.
- Execute Process — Carry out intelligence lifecycle operations methodically.
- Verify Quality — Check results against acceptance criteria.
- Document Outcomes — Record findings, decisions, and next steps.
Tools
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Scope — Define research questions, identify data sources, set time boundaries
- Gather — Collect data from primary sources, APIs, and public records
- Synthesize — Analyze findings, identify patterns, produce actionable report
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: managing-intelligence-lifecycle3description: Use when manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve. Use when establishing or maturing a CTI program, defining intelligence requirements with business stakeholders, or building feedback loops between intelligence consumers and producers.4license: Apache-2.05---67# Managing Intelligence Lifecycle89## Overview1011Cybersecurity skill for managing intelligence lifecycle. Follows industry best practices and security standards.1213## When to Use1415**Trigger phrases:**16- "managing intelligence lifecycle"17- "Establishing a formal CTI program and defining its operational model"18- "Conducting quarterly intelligence requirements reviews with business stakeholder"19- "Evaluating CTI program maturity against established frameworks (FIRST CTI-SIG ma"202122Use this skill when:23- Establishing a formal CTI program and defining its operational model24- Conducting quarterly intelligence requirements reviews with business stakeholders25- Evaluating CTI program maturity against established frameworks (FIRST CTI-SIG maturity model)2627**Do not use** this skill for day-to-day IOC triage or incident-specific intelligence tasks — those use operational intelligence workflows, not lifecycle management.282930## When NOT to Use3132- When you lack proper authorization for testing33- For production systems without change management34- When the task requires legal or compliance expertise beyond technical scope353637## Prerequisites3839- Executive sponsorship and defined CTI team structure (1+ dedicated analysts)40- Stakeholder map identifying intelligence consumers (SOC, IR, executive team, vulnerability management)41- Existing feed subscriptions or ISAC memberships for collection baseline42- CTI platform (MISP, ThreatConnect, OpenCTI) for lifecycle management4344## Workflow4546```python47# Example: IOC detection48import re4950IOC_PATTERNS = {51 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",52 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",53 "hash_md5": r"\b[a-f0-9]{32}\b",54 "hash_sha256": r"\b[a-f0-9]{64}\b",55}5657def extract_iocs(text: str) -> dict:58 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}59```60611. **Define Objectives** — Clarify the goals and scope for intelligence lifecycle.622. **Gather Resources** — Collect tools, data, and access needed for intelligence lifecycle.633. **Execute Process** — Carry out intelligence lifecycle operations methodically.644. **Verify Quality** — Check results against acceptance criteria.655. **Document Outcomes** — Record findings, decisions, and next steps.6667## Tools6869- **Analysis Platform** — Data processing and visualization70- **Collaboration Tools** — Team coordination and knowledge sharing717273## Process74751. **Scope** — Define research questions, identify data sources, set time boundaries761. **Gather** — Collect data from primary sources, APIs, and public records771. **Synthesize** — Analyze findings, identify patterns, produce actionable report7879## Verification8081- [ ] All intelligence lifecycle procedures executed completely and documented82- [ ] Findings validated against multiple data sources83- [ ] False positives identified and filtered84- [ ] Results documented with evidence and timestamps85- [ ] Recommendations provided with risk-based prioritization8687## Anti-Rationalization Table8889| Rationalization | Reality |90|---|---|91| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |92| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |93| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |