What problem does it solve? Security analysts often lack structured guidance when building a cyber threat intelligence program, managing indicators of compromise, or running hypothesis-driven threat hunts. This Skill provides the frameworks, standards, and tradecraft needed to perform intelligence-driven analysis without prior CTI experience. ## Core Features & Use Cases - CTI Lifecycle & Frameworks: Covers the 6-phase intelligence cycle, PIRs, Cyber Kill Chain, MITRE ATT&CK, Diamond Model, and Structured Analytic Techniques for bias mitigation. - IOC Management Standards: Explains STIX 2.1, TAXII 2.1, MISP event-attribute model, TLP 2.0 markings, YARA rules, and Sigma detection rules. - Threat Hunting Methodology: Details the PEAK framework, ABLE hypothesis model, Hunting Maturity Model, and ready-to-use query examples for Splunk, Elastic, and Sentinel. - Use Case: A SOC analyst needs to build a threat hunting program. The Skill guides them from defining PIRs, selecting data sources, writing KQL/SPL queries, to converting successful hunts into automated Sigma detection rules. ## Quick Start Ask the agent to explain how to build a hypothesis-driven threat hunt for Kerberoasting using the PEAK framework and ATT&CK mapping.