managing-intelligence-lifecycle

Manages the six-phase cyber threat intelligence lifecycle from PIR definition through feedback.

954|172|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/xalgord/xalgorix --skill managing-intelligence-lifecycle
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: managing-intelligence-lifecycle
Source: https://github.com/xalgord/xalgorix/tree/main/internal/tools/skills/data/threat-intelligence/managing-intelligence-lifecycle
Command: npx skills add https://github.com/xalgord/xalgorix --skill managing-intelligence-lifecycle

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

CTI teams often collect feeds without direction, produce reports nobody acts on, and cannot demonstrate program value. This Skill structures the full intelligence lifecycle so every collection source traces to a Priority Intelligence Requirement (PIR) and every product reaches the right audience with measurable feedback.

Core Features & Use Cases

  • PIR Definition & Collection Mapping: Facilitates stakeholder interviews to define 5-10 quarterly PIRs and maps each to technical, human, and internal collection sources while documenting coverage gaps.
  • Three-Level Intelligence Production: Guides production of strategic (quarterly executive), operational (weekly campaign), and tactical (daily IOC) products using structured analytic techniques like ACH and Key Assumptions Check.
  • Dissemination & Feedback Loops: Matches product formats to audiences (PDFs for executives, Sigma rules and MISP events for SOC), applies TLP classifications, and tracks metrics like PIR coverage rate and IOC true-positive rate.
  • Use Case: A security director establishing a new CTI program uses this Skill to run a quarterly requirements review, align MISP feed ingestion to documented PIRs, and set up a stakeholder satisfaction survey to prove program value.

Quick Start

Help me define Priority Intelligence Requirements for our CTI program and map our existing threat feeds to them.

Frequently Asked Questions about managing-intelligence-lifecycle

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I define Priority Intelligence Requirements for a CTI program?

Define PIRs by interviewing SOC leads, IR teams, the CISO, and risk management, then document them as structured questions about threat actors, critical assets, and techniques. Prioritize 5-10 PIRs per quarter and review them monthly with stakeholders.

What is the threat intelligence lifecycle process?

The intelligence lifecycle is a six-phase iterative process: Planning and Direction, Collection, Processing, Analysis, Dissemination, and Feedback. Each phase feeds the next, with feedback loops ensuring products continuously meet stakeholder requirements.

Which platforms support threat intelligence lifecycle management?

ThreatConnect provides built-in PIR tracking and stakeholder dashboards, while MISP and OpenCTI offer open-source lifecycle management from collection through sharing. Recorded Future delivers structured reports aligned to lifecycle phases.

When should I not use intelligence lifecycle management?

Do not apply lifecycle management to day-to-day IOC triage or incident-specific intelligence tasks, which belong to operational intelligence workflows. Lifecycle management addresses program-level planning, requirements, and feedback, not real-time indicator handling.

How do I measure CTI program effectiveness?

Track PIR coverage rate, IOC true-positive rate, time-to-disseminate, and stakeholder satisfaction scores quarterly. Collect structured feedback within 5 business days of each dissemination to confirm products address the original requirements.