What problem does it solve? Security teams drown in raw threat data without the analytical rigor to turn indicators into defensive action. This Skill applies structured intelligence tradecraft to track adversaries, attribute campaigns, and produce detection rules that catch real intrusions. ## Core Features & Use Cases - Adversary Tracking & Attribution: Build threat actor profiles with alias mapping, targeting analysis, TTP documentation, and confidence-scored attribution following the Diamond Model and Admiralty Code standards. - Detection Engineering: Write and tune Sigma, YARA, and Snort/Suricata rules mapped to MITRE ATT&CK techniques, with false positive analysis and validation guidance. - IOC Enrichment & STIX Export: Classify, validate, and enrich indicators of compromise, then export them as STIX 2.1 bundles or CSV for SIEM ingestion. - Use Case: A SOC receives a phishing campaign alert. Use this Skill to extract and enrich the IOCs, map the observed behavior to ATT&CK techniques, attribute the campaign to a known actor with a confidence assessment, and deliver a Sigma rule plus blocking recommendations. ## Quick Start Analyze the attached phishing email indicators, map the activity to MITRE ATT&CK, and produce a tactical intelligence report with detection rules.