cti-analyst

Vet and package cyber threat intelligence with STIX/TAXII exports and ATT&CK mappings.

7|1|Updated May 19, 2026
One-click install
npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill cti-analyst
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cti-analyst
Source: https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill/tree/main/cti-analyst
Command: npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill cti-analyst

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Guides cyber threat intelligence (CTI)—collection and vetting of intel from OSINT, commercial feeds, and ISACs; threat actor and campaign analysis; IOC/TTP production with MITRE ATT&CK mapping; STIX/TAXII and sharing concepts; strategic, tactical, and operational intel briefs; fusion with hunts and incident response; confidence scoring and source handling. Use for CTI, threat intelligence, threat actor profiling, IOC production, TTP analysis, intel briefs, STIX, ISAC reporting, campaign analysis, APT reporting—not proactive hunt execution (threat-hunter), SOC alert triage (soc-analyst), adversary simulation ops (red-team-specialist), incident command (incident-responder), or legal conclusions.

Core Features & Use Cases

  • Intelligence collection & vetting: standardizes sources, evaluates reliability, documents handling constraints, and flags circular reporting.
  • Actor & campaign analysis: clusters activity, timelines, infrastructure, malware context, and ATT&CK mappings.
  • IOC/TP production & sharing: packages indicators with context, urgency, confidence, expiration, and export formats (STIX/TAXII).
  • Intel briefs & handoffs: crafts strategic, tactical, and operational briefs with explicit confidence and dissent notes.
  • Use Case: Supports leadership risk discussions, SOC enrichment, and hunt hypothesis formulation.

Quick Start

Produce a vetted CTI briefing for leadership using STIX/TAXII artifacts and ATT&CK mappings.

Frequently Asked Questions about cti-analyst

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I package cyber threat intelligence with STIX exports and MITRE ATT&CK mappings?

Package cyber threat intelligence by vetting OSINT and commercial feeds, clustering threat actor activity, and mapping TTPs to MITRE ATT&CK. This produces structured STIX/TAXII sharing bundles with explicit confidence scores and governance constraints for defenders.

What is the best way to produce a threat actor campaign analysis for a leadership intel brief?

Threat actor campaign analysis clusters activity timelines, infrastructure, and malware context into structured intel briefs. It crafts strategic, tactical, and operational narratives with explicit confidence and dissent notes tailored for leadership risk discussions.

Does this threat intelligence vetting process handle collection planning from ISACs and OSINT feeds?

Yes, threat intelligence vetting handles collection planning by standardizing sources from OSINT, commercial feeds, and ISACs. It evaluates reliability, documents handling constraints, and flags circular reporting to ensure source governance.

How do threat intelligence outputs hand off to threat hunting and incident response teams?

Threat intelligence outputs hand off to threat hunting and incident response by producing structured briefs and sharing bundles with explicit confidence. These artifacts formulate hunt hypotheses and provide SOC enrichment for downstream fusion.

When should I not use CTI analysis for security operations?

Avoid using CTI analysis for proactive hunt execution, SOC alert triage, adversary simulation operations, incident command, or legal conclusions. It is strictly designed for intelligence collection, vetting, actor profiling, and briefing tasks.