What problem does it solve?
Structures threat intelligence into evidence-backed behavioural atoms and authors OpenTide Threat Vector (TVM) YAML (tvm schemas), including metadata, terrain, chaining, ATT&CK, UUIDs. Covers Phase A intelligence structuring (source hygiene, atomisation, gap analysis) and Phase B schema-backed YAML authoring (field-level guidance, quality patterns, anti-patterns distilled from production corpora). Use whenever work involves converting CTI into TVMs, creating or refactoring files under Threat Vectors, or when the user provides reports, feeds, or narratives before detection objectives exist.
Core Features & Use Cases
- Phase A — Intelligence structuring: source hygiene, facts versus inference, atomisation, ATT&CK mapping notes, gap checklist, credibility assessment, IOC hygiene.
- Phase B — TVM YAML authoring: load live schemas, enforce Object conventions, top-level fields, metadata, threat content; includes preconditions and hand-off from Phase A.
- Use Case: Convert a CTI report into a TVM YAML draft to be integrated into detection workflows.
Quick Start
Load a CTI report and generate a Phase A intelligence outline and a Phase B TVM YAML draft.