Agent skill

Managing Intelligence Lifecycle

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet…

Apache-2.0Auto-check passedSecurity

Install Managing Intelligence Lifecycle

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill managing-intelligence-lifecycle -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills managing-intelligence-lifecycle --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/managing-intelligence-lifecycle .claude/skills/managing-intelligence-lifecycle && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
managing-intelligence-lifecycle
GitHub stars
34k
Token cost
~1.6k tokens
SKILL.md length
630 words
Files
4 (incl. scripts, references)
Skills in repo
639
Repo updated
First seen
Licence
Apache-2.0

At a glance

Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet…

  • Works in 6 steps: Planning and Direction → Collection Planning → Processing and Normalization → …
  • Maturing a CTI program
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Managing Intelligence Lifecycle is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve. Use when establishing or maturing a CTI program, defining intelligence requirements with business stakeholders, or building feedback loops between intelligence consumers and producers. Activates for requests involving CTI program maturity, intelligence requirements, PIRs…

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering OSINT. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Maturing a CTI program
  • Defining intelligence requirements with business stakeholders
  • Building feedback loops between intelligence consumers and producers

Example prompts

  • “Use the managing-intelligence-lifecycle skill to manage the end-to-end cyber threat intelligence lifecycle from planning and direction through…”
  • “/managing-intelligence-lifecycle”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Planning and Direction
  2. Collection Planning
  3. Processing and Normalization
  4. Analysis and Production
  5. Dissemination
  6. Feedback and Evaluation

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Managing Intelligence Lifecycle loads about 1.6k tokens when it runs, and up to ~2.1k if it reads all its reference files. Until then it costs about 147 tokens; SKILL.md has 630 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~147
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 630 words, ~1,576 tokens.

Download SKILL.mdSave it as .claude/skills/managing-intelligence-lifecycle/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
managing-intelligence-lifecycle
description
Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve. Use when establishing or maturing a CTI program, defining intelligence requirements with business stakeholders, or building feedback loops between intelligence consumers and producers. Activates for requests involving CTI program maturity, intelligence requirements, PIRs, or intelligence lifecycle management.
domain
cybersecurity
subdomain
threat-intelligence
tags
CTI, intelligence-lifecycle, PIR, NIST-SP-800-150, threat-intelligence-program, NIST-CSF
version
1.0.0
author
team-cybersecurity
license
Apache-2.0
nist_csf
ID.RA-01, ID.RA-05, DE.CM-01, DE.AE-02
mitre_attack
T1591, T1592, T1593, T1589

Managing Intelligence Lifecycle

When to Use

Use this skill when:

  • Establishing a formal CTI program and defining its operational model
  • Conducting quarterly intelligence requirements reviews with business stakeholders
  • Evaluating CTI program maturity against established frameworks (FIRST CTI-SIG maturity model)

Do not use this skill for day-to-day IOC triage or incident-specific intelligence tasks — those use operational intelligence workflows, not lifecycle management.

Prerequisites

  • Executive sponsorship and defined CTI team structure (1+ dedicated analysts)
  • Stakeholder map identifying intelligence consumers (SOC, IR, executive team, vulnerability management)
  • Existing feed subscriptions or ISAC memberships for collection baseline
  • CTI platform (MISP, ThreatConnect, OpenCTI) for lifecycle management

Workflow

Step 1: Planning and Direction

Define Priority Intelligence Requirements (PIRs) with stakeholders:

  • Interview SOC leads, IR team, CISO, risk management, and product security
  • Document PIRs in structured format: "What is the current capability and intent of [threat actor] to attack [critical asset] using [technique]?"
  • Prioritize 5–10 PIRs for the quarter, reviewed monthly

Example PIR: "Is ransomware group Cl0p currently targeting organizations in our sector using MoveIT or GoAnywhere vulnerabilities?"

Step 2: Collection Planning

Map PIRs to required collection sources:

  • Technical sources: commercial feeds, TAXII, ISAC data, honeypot telemetry, darkweb monitoring
  • Human sources: vendor threat briefings, industry working groups, law enforcement partnerships
  • Internal sources: SIEM logs, EDR telemetry, phishing submission mailbox

Document collection gaps and associated costs to fill them.

Step 3: Processing and Normalization

Implement automated processing pipeline:

  • Ingest → normalize to STIX 2.1 → deduplicate → enrich → score confidence
  • Reject unverifiable or duplicate indicators before analysis
  • Tag all processed data with source, collection date, and expiration
Step 4: Analysis and Production

Produce intelligence at three levels:

  • Strategic: Quarterly threat landscape report for executives; sector trends, geopolitical context
  • Operational: Weekly campaign reports for security leadership; active campaigns, adversary activity
  • Tactical: Daily IOC bulletins for SOC; actionable indicators with block/monitor recommendations

Apply structured analytic techniques: Analysis of Competing Hypotheses (ACH), Key Assumptions Check, Devil's Advocacy.

Step 5: Dissemination

Match product format to audience:

  • Executives: 1-page PDF with risk ratings, business impact, recommended decisions
  • SOC analysts: SIEM-ready IOC list, Sigma rules, MISP events
  • Vulnerability management: CVE lists with EPSS scores and exploitation likelihood
  • IT/Security leadership: Full intelligence report with technical appendix

Apply TLP classifications and distribution lists per product type.

Show full SKILL.md (265 more words)Show less
Step 6: Feedback and Evaluation

Collect feedback within 5 business days of dissemination:

  • Did the product address the PIR?
  • Was actionability sufficient?
  • What data was missing?

Track metrics quarterly: PIR coverage rate, IOC true positive rate, time-to-disseminate, stakeholder satisfaction score (NPS or structured survey).

Key Concepts

TermDefinition
PIRPriority Intelligence Requirement — specific, actionable question driving intelligence collection and analysis
Intelligence LifecycleSix-phase iterative process: Planning → Collection → Processing → Analysis → Dissemination → Feedback
Strategic IntelligenceLong-term threat trend analysis for executive decision-making; time horizon 6–24 months
Operational IntelligenceCampaign-level analysis for security program decisions; time horizon 1–6 months
Tactical IntelligenceSpecific IOCs and TTPs for immediate detection and blocking; time horizon hours to days
FIRST CTI-SIGForum of Incident Response and Security Teams — CTI Special Interest Group maturity model

Tools & Systems

  • ThreatConnect: TIP with built-in intelligence lifecycle workflows, PIR tracking, and stakeholder reporting dashboards
  • MISP: Open-source TIP supporting intelligence lifecycle from collection through sharing
  • OpenCTI: Graph-based CTI platform with workflow management for intelligence products
  • Recorded Future: Commercial platform with structured intelligence reports aligned to the intelligence lifecycle

Common Pitfalls

  • Collection without direction: Ingesting every available feed without PIRs produces data overload and no actionable intelligence.
  • Missing feedback loops: Without structured feedback, CTI teams produce reports that don't meet stakeholder needs and lose organizational relevance.
  • Tactical-only focus: Overemphasis on IOC sharing neglects strategic intelligence that informs security investment and risk decisions.
  • No metrics program: Cannot demonstrate CTI program value without tracking detection contributions, true positive rates, and stakeholder satisfaction.
  • Underfunded collection: PIRs cannot be answered without appropriate collection sources; document and escalate gaps rather than producing low-confidence estimates.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/managing-intelligence-lifecycle of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Managing Intelligence Lifecycle next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Managing Intelligence Lifecycle compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Managing Intelligence Lifecycle this skillmukul975/Anthropic-Cybersecurity-Skills34k—~1.6kAutomated safety check: PassApache-2.0
Metabigor OSINT Reconj3ssie/metabigor1.8k—~2.4kAutomated safety check: PassMIT
Ctf Osintljagiello/ctf-skills3.4k2 repos~2.3kAutomated safety check: NotesMIT
ShadowBroker Intelligence ClientBigBodyCobain/Shadowbroker11k—~8.9kAutomated safety check: WarnAGPL-3.0
Awesome Osint Operatorshoyann/RZK-The-Hunter140—~4.8kAutomated safety check: PassCC-BY-SA-4.0
Run Claude Osintelementalsouls/Claude-OSINT2.8k—~1.2kAutomated safety check: PassMIT

Similar skills

  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.8k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Ctf Osint

    ljagiello/ctf-skills

    Provides open source intelligence techniques for CTF challenges.

    3.4k GitHub starsUsed in 2 repos~2.3k tokens
    SecurityAuto-check: notes
  • ShadowBroker Intelligence Client

    BigBodyCobain/Shadowbroker

    Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins.

    11k GitHub stars~8.9k tokensUpdated today
    SecurityAuto-check: warnings
  • Awesome Osint Operator

    shoyann/RZK-The-Hunter

    Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…

    140 GitHub stars~4.8k tokensUpdated 16 days ago
    SecurityAuto-check passed
  • Run Claude Osint

    elementalsouls/Claude-OSINT

    Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test.

    2.8k GitHub stars~1.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Osint

    smixs/osint-skill

    Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill.

    140 GitHub stars~5.5k tokensUpdated 7 mo ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 639 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Managing Intelligence Lifecycle

What does Managing Intelligence Lifecycle do?

Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet…. Managing Intelligence Lifecycle is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve.

When should I use Managing Intelligence Lifecycle?

Managing Intelligence Lifecycle fits situations like: maturing a CTI program; defining intelligence requirements with business stakeholders; building feedback loops between intelligence consumers and producers.

How do I install Managing Intelligence Lifecycle in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill managing-intelligence-lifecycle -a claude-code`. Or copy the skill folder (skills/managing-intelligence-lifecycle in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/managing-intelligence-lifecycle in your project. Claude Code loads it when a task matches its description.

How do I install Managing Intelligence Lifecycle in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill managing-intelligence-lifecycle -a codex`. Or copy the skill folder (skills/managing-intelligence-lifecycle in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/managing-intelligence-lifecycle in your project. Codex loads it when a task matches its description.

Can I use Managing Intelligence Lifecycle in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill managing-intelligence-lifecycle -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/managing-intelligence-lifecycle, .gemini/skills/managing-intelligence-lifecycle, .github/skills/managing-intelligence-lifecycle and .opencode/skills/managing-intelligence-lifecycle in your project.

What does Managing Intelligence Lifecycle need to run?

Going by SKILL.md and its folder, Managing Intelligence Lifecycle needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Managing Intelligence Lifecycle access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Managing Intelligence Lifecycle safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Managing Intelligence Lifecycle use?

Managing Intelligence Lifecycle is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Managing Intelligence Lifecycle use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 514 tokens, read only when the agent opens those files.

What are the alternatives to Managing Intelligence Lifecycle?

Skills that share tags, products or a category with Managing Intelligence Lifecycle: Metabigor OSINT Recon (j3ssie/metabigor, 1.8k stars), Ctf Osint (ljagiello/ctf-skills, 3.4k stars), ShadowBroker Intelligence Client (BigBodyCobain/Shadowbroker, 11k stars) and Awesome Osint Operator (shoyann/RZK-The-Hunter, 140 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Managing Intelligence Lifecycle?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,870 GitHub stars. The repository holds 639 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.