Threat Intelligence Report Synthesizer
Turns raw threat intel into an actionable, audience-tailored brief with IOCs, TTPs, and defensive guidance.
Prompt
ROLE: You are a cyber threat intelligence (CTI) analyst producing a finished intelligence product for defenders. CONTEXT: - Raw inputs (reports, feeds, blog posts, sandbox results): [PASTE_SOURCE_MATERIAL] - Our environment / relevant tech stack: [OUR_ASSETS_AND_SECTOR] - Audience: [SOC_ANALYSTS_OR_EXECUTIVES] TASK: 1. Summarize the threat: actor/campaign, motivation, targeting, and confidence level. 2. Map adversary behavior to MITRE ATT&CK tactics and techniques. 3. Extract and structure IOCs (hashes, domains, IPs, URLs) with type and context; defang them. 4. Assess relevance to OUR environment specifically — which of our assets/tech are exposed. 5. Provide prioritized defensive recommendations: detections to deploy, hunting hypotheses, and patches. OUTPUT FORMAT: - Executive summary (3-4 sentences, plain language) - Threat detail (actor, TTPs with ATT&CK IDs) - IOC table (type | indicator (defanged) | context | confidence) - 'So what for us' relevance assessment - Recommended detections & hunts (with suggested logic) CONSTRAINTS: Apply intelligence confidence language (high/moderate/low) and cite which source supports each claim. Defang all indicators. Do not present a single-source rumor as confirmed. Tailor depth to the stated audience.
How to use this prompt
- 1
Copy the prompt above and paste it into ChatGPT, Claude, or Gemini — or open it in the visual Studio to edit each part on a canvas and run it with your own key.
- 2
Replace any bracketed placeholders with your specifics. The more concrete your context and constraints, the sharper the result — see the 5-part prompt structure.
- 3
Run it, then refine. Ask the model to critique and improve its own answer with self-critique prompting.
Techniques in this prompt
Assigns the model an expert persona so it adopts the right vocabulary, depth, and standards for the task.
Learn this techniqueA rag technique used to shape and strengthen the model's response.
Pins the response to a defined structure so it drops straight into your workflow.
Learn this techniqueRecommended models
Build on this prompt
Open it in the visual Studio to wire it into a full workflow with your own API key — or learn the craft behind prompts like this.
More in Cybersecurity & Risk
STRIDE Threat Model For A New Service
Builds a structured STRIDE threat model for a system with trust boundaries, ranked threats, and concrete mitigations.
Security Incident Postmortem Author
Drafts a blameless post-incident review with timeline, root cause, and corrective actions ready for leadership.
CVE Triage And Prioritization Analyst
Triages a list of CVEs by exploitability and business context to produce an actionable patch priority queue.
Phishing Email Forensic Examiner
Analyzes a suspicious email's headers, URLs, and payload to classify intent and recommend SOC response.