Cybersecurity & Risk5.0 · 0 ratings

Threat Intelligence Report Synthesizer

Turns raw threat intel into an actionable, audience-tailored brief with IOCs, TTPs, and defensive guidance.

Role-BasedRAGStructured-Output

Prompt

ROLE: You are a cyber threat intelligence (CTI) analyst producing a finished intelligence product for defenders.

CONTEXT:
- Raw inputs (reports, feeds, blog posts, sandbox results): [PASTE_SOURCE_MATERIAL]
- Our environment / relevant tech stack: [OUR_ASSETS_AND_SECTOR]
- Audience: [SOC_ANALYSTS_OR_EXECUTIVES]

TASK:
1. Summarize the threat: actor/campaign, motivation, targeting, and confidence level.
2. Map adversary behavior to MITRE ATT&CK tactics and techniques.
3. Extract and structure IOCs (hashes, domains, IPs, URLs) with type and context; defang them.
4. Assess relevance to OUR environment specifically — which of our assets/tech are exposed.
5. Provide prioritized defensive recommendations: detections to deploy, hunting hypotheses, and patches.

OUTPUT FORMAT:
- Executive summary (3-4 sentences, plain language)
- Threat detail (actor, TTPs with ATT&CK IDs)
- IOC table (type | indicator (defanged) | context | confidence)
- 'So what for us' relevance assessment
- Recommended detections & hunts (with suggested logic)

CONSTRAINTS: Apply intelligence confidence language (high/moderate/low) and cite which source supports each claim. Defang all indicators. Do not present a single-source rumor as confirmed. Tailor depth to the stated audience.

How to use this prompt

  1. 1

    Copy the prompt above and paste it into ChatGPT, Claude, or Gemini — or open it in the visual Studio to edit each part on a canvas and run it with your own key.

  2. 2

    Replace any bracketed placeholders with your specifics. The more concrete your context and constraints, the sharper the result — see the 5-part prompt structure.

  3. 3

    Run it, then refine. Ask the model to critique and improve its own answer with self-critique prompting.

Techniques in this prompt

Role-Based

Assigns the model an expert persona so it adopts the right vocabulary, depth, and standards for the task.

Learn this technique
RAG

A rag technique used to shape and strengthen the model's response.

Structured Output

Pins the response to a defined structure so it drops straight into your workflow.

Learn this technique

Recommended models

claudegpt-4ogemini

Build on this prompt

Open it in the visual Studio to wire it into a full workflow with your own API key — or learn the craft behind prompts like this.

More in Cybersecurity & Risk