Threat Intelligence & CTI
Installation
SKILL.md
Threat Intelligence & CTI
Purpose
Enable Claude to turn raw observations into finished intelligence — assessments a defender can act on and decision-makers can trust. This skill governs the whole intelligence cycle: framing requirements, collecting and normalizing indicators, applying structured analytic models, scoring sources and confidence, tracking actors and campaigns, and disseminating in machine-readable (STIX/MISP) and human-readable (report) form.
This is distinct from Skill 06 (Threat Hunting): hunting uses intelligence to search an environment for adversary activity; this skill produces and manages the intelligence itself. It is also distinct from Skill 05 (Malware Analysis), which produces the technical facts this skill contextualizes and disseminates.