sops

Standardize CTI operational workflows with modular SOPs for triage and reporting.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill sops
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: sops
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/sops
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill sops

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

CTI operations often suffer from inconsistency and delays due to ad-hoc procedures. This Skill provides a standardized set of SOPs to guide daily triage, data handling, reporting, and stakeholder communications, reducing drift and improving response times.

Core Features & Use Cases

  • Standardized SOPs covering Daily Intelligence Triage, IOC Processing, Flash Reports, Threat Actor Profile Updates, Stakeholder Briefing, and Knowledge Cell Maintenance.
  • Consistent ownership, triggers, and output artifacts across CTI workflows.
  • Use Case: A CSIRT team adopts these SOPs to align triage speed, IOC validation, and reporting cadence across a large organization.

Quick Start

Run SOP-001 daily to begin the intelligence triage workflow and ensure PIRs are up to date.

Frequently Asked Questions about sops

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are standard operating procedures for cyber threat intelligence operations?

Standard operating procedures for CTI operations coordinate daily intelligence triage, IOC processing, flash reports, and threat actor profile updates to reduce process drift and improve response times across CSIRT teams.

How do I standardize CSIRT daily triage and IOC processing workflows?

You can standardize CSIRT workflows by applying modular SOP steps that define specific owner roles, execution triggers, and output artifacts for daily triage and IOC validation.

How do I start the daily intelligence triage workflow?

To start the daily intelligence triage workflow, run SOP-001 to initiate the triage process and ensure your Priority Intelligence Requirements are kept consistently up to date.

Can I use these SOPs for stakeholder briefings and risk assessments?

Yes, these SOPs are explicitly applicable for CSIRT teams performing routine threat intel operations, risk assessments, and executive stakeholder briefings through standardized reporting cadences.

What is the best way to maintain threat intelligence knowledge management?

The best way to maintain threat intelligence knowledge management is to execute dedicated SOP steps for Knowledge Cell Maintenance, ensuring consistent ownership and standardized output artifacts.

Why do CTI teams experience delays and inconsistency in threat intel operations?

CTI teams experience delays and inconsistency due to ad-hoc procedures; implementing standardized SOPs for data handling and reporting reduces drift and improves overall response times.