generating-threat-intelligence-reports

Generates structured cyber threat intelligence reports for strategic, operational, and tactical audiences.

1|1|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/Yenn503/Net-Runners --skill generating-threat-intelligence-reports-yenn503
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: generating-threat-intelligence-reports
Source: https://github.com/Yenn503/Net-Runners/tree/main/.netrunner/skills/reporting/generating-threat-intelligence-reports
Command: npx skills add https://github.com/Yenn503/Net-Runners --skill generating-threat-intelligence-reports-yenn503

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Turning raw threat data into finished intelligence products that different stakeholders can act on is slow and inconsistent. This Skill standardizes the production of CTI reports so executives, SOC teams, and analysts each get appropriately scoped, classified, and actionable intelligence. ## Core Features & Use Cases - Audience-Tailored Report Types: Produces strategic, operational, tactical, and flash reports with defined formats, lengths, and distribution frequencies. - Intelligence Writing Standards: Applies ICD 203 confidence language, key judgments, evidence attribution, and TLP classification (RED through CLEAR) to every product. - Quality Control Checklist: Enforces accuracy, clarity, actionability, classification, and timeliness reviews before dissemination. - Use Case: After a new zero-day affecting your sector is disclosed, use this Skill to produce a one-page flash report within two hours, followed by an operational briefing with ATT&CK-mapped TTPs and prioritized mitigations for the security team. ## Quick Start Ask the agent to generate a TLP:AMBER operational threat intelligence report on the latest ransomware campaign targeting your sector, including key judgments, ATT&CK techniques, and prioritized recommended actions.

Frequently Asked Questions about generating-threat-intelligence-reports

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a cyber threat intelligence report for executives?▼

Use the strategic report format: 1-3 pages with minimal jargon, business impact language, and recommended decisions. Lead with a plain-language key judgment, then cover threat landscape trends and adversary intent versus capability.

What is the difference between strategic, operational, and tactical threat intelligence reports?▼

Strategic reports target executives with trends and business risk; operational reports give CISOs and IR leads campaign TTPs and mitigation priorities; tactical bulletins deliver IOCs, YARA rules, and Sigma detections to SOC analysts.

How do I apply TLP classification to threat intelligence reports?▼

Select TLP based on source sensitivity: RED for named recipients only, AMBER for organization and trusted partners, GREEN for community sharing, and CLEAR for public distribution. Watermark the TLP level on every page header and footer.

When should I not use a threat intelligence report for IOC sharing?▼

Do not use report generation for raw IOC distribution. Use a TIP or MISP for automated IOC sharing, and reserve reports for analyzed, finished intelligence that answers priority intelligence requirements.

What confidence language should threat intelligence assessments use?▼

Use ICD 203 standards: 'assess with high confidence' for strong evidence, 'assess' for credible sources with assumptions, and 'suggests' for limited sourcing. Omitting confidence qualifiers makes low-certainty claims appear as established facts.