Threat Intelligence

Profile threat actors and manage IOCs using the Diamond Model and Cyber Kill Chain.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/defconxt/CIPHER --skill threat-intelligence-defconxt
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Threat Intelligence
Source: https://github.com/defconxt/CIPHER/tree/main/skills/threat-intelligence
Command: npx skills add https://github.com/defconxt/CIPHER --skill threat-intelligence-defconxt

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps security professionals understand and combat cyber threats by providing tools and frameworks for analyzing threat actors, their tactics, techniques, and procedures (TTPs), and indicators of compromise (IOCs).

Core Features & Use Cases

  • Threat Actor Profiling: Analyze motivations, capabilities, and TTPs of known APT groups and cybercriminal organizations.
  • IOC Management: Ingest, enrich, and manage Indicators of Compromise (IOCs) for detection and hunting.
  • Framework Application: Utilize established frameworks like the Diamond Model and Cyber Kill Chain for structured analysis.
  • Use Case: A security analyst can use this Skill to quickly profile a newly identified threat actor, understand their common TTPs, and generate detection rules based on their known IOCs.

Quick Start

Use the threat intelligence skill to profile the APT29 threat actor.

Frequently Asked Questions about Threat Intelligence

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I profile an APT threat actor and analyze their TTPs?

Threat actor profiling analyzes the motivations, capabilities, and tactics of known APT groups. It applies analytical frameworks like the Diamond Model and Cyber Kill Chain to structure threat intelligence analysis for strategic, operational, and tactical audiences.

Does threat intelligence analysis support STIX and TAXII for data exchange?

Yes, threat intelligence analysis supports data exchange using STIX and TAXII protocols. It integrates with platforms like MISP to facilitate structured intelligence production and sharing across security systems.

Can I use the Diamond Model and Cyber Kill Chain frameworks together for threat analysis?

Yes, you can apply both the Diamond Model and Cyber Kill Chain frameworks together. This structured analysis approach helps map threat actor capabilities and track their progression through attack phases.

How do I generate detection rules from IOCs for threat hunting?

You can ingest and enrich Indicators of Compromise to generate detection rules. This IOC management capability supports threat hunting by translating structured intelligence into actionable detection logic.