What problem does it solve? Security teams drown in raw threat data without the analytical rigor to turn indicators into defensive action. This Skill applies structured intelligence tradecraft to track adversaries, map campaigns to MITRE ATT&CK, and produce detection rules and reports with explicit confidence assessments. ## Core Features & Use Cases - Adversary Tracking & Attribution: Build threat actor profiles covering aliases, targeting, TTPs, tooling, and infrastructure, with confidence levels grounded in corroborated evidence. - Detection Engineering: Write and tune Sigma, YARA, and Snort/Suricata rules validated against known samples, with false-positive analysis and MITRE ATT&CK technique tagging. - IOC Enrichment & STIX Export: Classify, validate, and enrich indicators (IPs, domains, hashes, URLs) and export them as STIX 2.1 bundles or CSV for SIEM ingestion. - Use Case: After a phishing campaign hits your sector, ask the analyst to profile the actor, map observed behavior to ATT&CK techniques, and deliver a Sigma rule plus an IOC feed your SOC can deploy the same day. ## Quick Start Analyze these phishing indicators, map the activity to MITRE ATT&CK, and produce a detection rule with a confidence assessment.