
Threat Intelligence Pattern Analysis for Cyber Analysts
Extract, correlate, and attribute cyber threats using pattern analysis
What You Can Do
You can rapidly synthesize disparate threat intelligence sources—malware reports, network logs, SIGINT summaries, and technical indicators—to construct actionable threat narratives. The skill enables you to correlate new indicators (IPs, domains, file hashes) against known APT profiles, map threat actor techniques to the MITRE ATT&CK framework, assess attribution confidence with structured justification, and identify capability evolution patterns across campaigns. Output is formatted as threat profiles, TTP matrices, and indicator relationship maps suitable for leadership briefings and defensive operations.
Features
Cross-reference technical indicators and behavioral patterns against known threat actor profiles with confidence scoring
Map threat actor techniques to MITRE ATT&CK framework and identify capability evolution across campaigns
Automatically link IPs, domains, file hashes, and malware signatures to construct infrastructure reuse patterns
Generate structured justifications for attribution decisions with supporting evidence trails
Synthesize disparate intelligence into cohesive threat profiles including motivation, capability, and targeting patterns
Identify behavioral signatures characteristic of specific threat groups from unstructured data sources
Flag missing data points and recommend collection priorities based on attribution and TTP assessment gaps
Example Output
Example 1: APT Attribution Report
- Threat Actor: APT28 (Fancy Bear)
- Confidence: High (85%)
- Supporting Indicators: 3 infrastructure overlaps with known C2 servers, 2 matching malware signatures from previous campaigns, TTP alignment on 6/8 attack phases
- Key TTPs: Spear-phishing (T1566.002), Living off the Land (T1036.005), Lateral Movement via PsExec (T1570)
- Evidence: Domain registration timing matches 2022 operation; malware beacon pattern identical to GRU-attributed Sofacy toolkit
Example 2: TTP Evolution Timeline
- Campaign A (2021): Exploit CVE-2017-0199, Trickbot dropper → C2 beaconing
- Campaign B (2023): Exploit CVE-2022-1234, Emotet variant → Domain fronting evasion
- Evolution: Shift from exploitation persistence to living-off-the-land evasion; 40% increase in anti-forensics techniques
Example 3: Indicator Correlation Network
- IP 192.0.2.45 → Links to 3 malware samples → Connects to 5 known APT domains → Associates with 2 historical campaigns
What's Included
- SKILL.md instruction file with threat intelligence analysis framework:
- APT Profile Template: Standardized format for threat actor characteristics, motivation, capability assessment
- TTP Mapping Checklist: MITRE ATT&CK alignment guide with evidence requirements per technique
- Attribution Confidence Matrix: Scoring rubric and justification framework for confidence levels
- Indicator Correlation Worksheet: Structured format for linking technical indicators across campaigns
Who It's For
- Cyber Threat Intelligence Analysts — Synthesizing raw intelligence into structured threat assessments and attribution reports
- Incident Response Specialists — Correlating incident indicators to known threat actors and identifying TTP patterns
- Security Operations Managers — Generating threat briefings and attribution confidence assessments for leadership decision-making
- Intelligence Fusion Center Analysts — Correlating SIGINT, HUMINT, and technical indicators across compartmented sources
- Defensive Operations Planners — Identifying capability evolution patterns to inform defensive prioritization and hardening strategies
Best For
- APT attribution and confidence assessment for incident investigations
- Bulk malware/network artifact analysis requiring rapid pattern extraction
- TTP mapping and MITRE ATT&CK framework alignment for threat actor profiles
- Indicator correlation across historical campaigns to identify infrastructure reuse
- Threat actor capability evolution analysis and targeting pattern identification
- Intelligence gap analysis and collection prioritization recommendations






