threat-intel-analyst

Profile threat actors and produce intelligence with MITRE ATT&CK mappings.

1|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/coreymaypray/sloth-skill-tree --skill threat-intel-analyst
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: threat-intel-analyst
Source: https://github.com/coreymaypray/sloth-skill-tree/tree/main/plugins/maycrest-secure/skills/threat-intel-analyst
Command: npx skills add https://github.com/coreymaypray/sloth-skill-tree --skill threat-intel-analyst

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Profiles threat actors and produces actionable intelligence for security teams, turning scattered indicators into decision-grade insights that guide detection and response.

Core Features & Use Cases

  • Threat actor profiling and campaign analysis to map adversaries, motivations, and infrastructure.
  • Indicator lifecycle management including collection, enrichment, scoring, and retirement, with clear prioritization for detection and response.
  • MITRE ATT&CK mapping, STIX/TAXII integration, and intelligence production workflows for leadership and SOC teams.
  • Development of intelligence requirements documents aligned to business and security operations needs.
  • Industry-specific threat landscape assessments and quarterly trend reporting to inform budgets and controls.

Quick Start

Provide a concise threat intelligence brief for leadership.

Frequently Asked Questions about threat-intel-analyst

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map threat actor profiles to MITRE ATT&CK techniques?

Threat actor profiling maps adversary behaviors to MITRE ATT&CK techniques to identify tactics and procedures. This mapping transforms scattered indicators into structured intelligence, enabling targeted detection rules and actionable response guidance for SOC teams.

What is the best way to generate leadership briefings from threat intelligence data?

Leadership briefings are generated by applying structured analytic techniques to threat intelligence data with explicit confidence levels. This intelligence production workflow turns raw indicators into decision-grade insights, supporting strategic assessments and quarterly trend reporting.

How does STIX TAXII integration work for IOC management?

STIX TAXII integration structures indicator of compromise lifecycle management by standardizing collection, enrichment, and retirement. This integration supports clear indicator scoring and prioritization, guiding detection and response operations across security teams.

Can I use the Diamond Model for threat actor campaign analysis?

The Diamond Model supports threat actor campaign analysis by mapping adversaries, motivations, and infrastructure. Applying this structured analytic technique clarifies adversary capabilities and infrastructure, producing actionable intelligence for security operations.

Does threat intelligence production support industry-specific threat landscape assessments?

Threat intelligence production supports industry-specific threat landscape assessments to inform budgets and controls. It aligns intelligence requirements documents to business needs, delivering quarterly trend reporting and tailored adversary insights.