generating-threat-intelligence-reports

Generate finished threat intelligence reports from structured JSON data using templates.

Updated Apr 23, 2026
One-click install
npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill generating-threat-intelligence-reports-yukiito1999
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: generating-threat-intelligence-reports
Source: https://github.com/YukiIto1999/ctf-sleuth/tree/main/.claude/skills/generating-threat-intelligence-reports
Command: npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill generating-threat-intelligence-reports-yukiito1999

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires jinja2, and includes scripts (resource) and references (resource) components.

What problem does it solve?

Disparate threat data and analyses require manual, time-consuming synthesis into executive-ready intelligence products. This Skill automates the generation of finished threat intelligence reports from structured inputs and standardized templates.

Core Features & Use Cases

  • Template-driven reporting across strategic, operational, tactical, and flash levels for executives, SOC teams, IR, and technical analysts.
  • MITRE ATT&CK mappings, IOCs, confidence qualifiers, and TLP controls to ensure standardized, actionable outputs.
  • End-to-end workflow with data validation, quality checks, and machine-readable metadata suitable for automation and reporting.

Quick Start

Provide a structured JSON data file and run the agent to render a finished intelligence report.

Frequently Asked Questions about generating-threat-intelligence-reports

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate structured threat intelligence reports from raw data?

To generate threat intelligence reports, provide structured JSON data to an automated template-driven workflow that validates inputs, renders the final document, and enforces quality checks. This process outputs executive-ready intelligence products with MITRE ATT&CK mappings and IOCs.

Can I create different threat intelligence report types for executives and SOC teams?

Yes, you can generate strategic, operational, tactical, and flash threat intelligence reports tailored for distinct audiences. Template-driven rendering adapts the output for executives, SOC teams, IR leads, and technical analysts from the same structured data.

How does template-driven threat intelligence reporting handle TLP controls and confidence qualifiers?

Template-driven threat intelligence reporting handles TLP controls and confidence qualifiers by enforcing them during the rendering workflow. The system automatically applies Traffic Light Protocol designations and confidence levels to ensure standardized, actionable intelligence outputs.

What is the best way to automate threat intelligence product creation with MITRE ATT&CK mappings?

The best way to automate threat intelligence product creation is using template-driven workflows that process structured data. This method automatically integrates MITRE ATT&CK mappings, produces machine-readable metadata, and validates required fields for automated reporting pipelines.

Do I need structured JSON data to generate finished intelligence products?

Yes, you need to provide a structured JSON data file as input to generate finished intelligence products. The reporting workflow validates required fields within the JSON before rendering templates to ensure quality and accuracy across strategic and tactical outputs.

What are the limitations of using Jinja2 templates for threat intelligence reporting?

When using Jinja2 templates for threat intelligence reporting, outputs are strictly bound to the structure of your input data and predefined template schemas. Complex or unstructured narrative analyses may require manual synthesis before rendering through the template-driven workflow.