agentsclimarketplace

Cti hyperloop

Skill Liberty91LTD/cti-skills/skills/cti-hyperloop

Cyber Threat Intelligence Skills for each stage of the CTI Lifecycle.

Install
npx -y skills add Liberty91LTD/cti-skills --skill cti-hyperloop

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 8 stars8 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Use when the user asks about the CTI Hyperloop framework, the intelligence lifecycle as a high-tempo loop, or how to map intelligence work across strategic / operational / tactical levels with bidirectional feedback. Liberty91's operational doctrine.

SKILL.md

7.4 KB, as published. Nobody here has run it

CTI Hyperloop Framework

The CTI Hyperloop (based on Google/Mandiant's practical implementation framework) extends the traditional intelligence cycle by running it at three levels simultaneously with continuous bidirectional feedback.

Core Concept

Traditional intelligence cycle: linear, single-track, often stuck at the tactical level. Hyperloop: three parallel tracks (strategic, operational, tactical) feeding each other continuously.

STRATEGIC  ←→  OPERATIONAL  ←→  TACTICAL
    ↓              ↓               ↓
Direction → Collection → Processing → Analysis → Dissemination → Feedback
    ↑                                                              |
    └──────────────────────────────────────────────────────────────┘

Intelligence Levels

Strategic Intelligence

  • Time horizon: 6-24 months
  • Consumers: CISO, Board, Risk Management, Security Architecture
  • Focus: Threat landscape trends, emerging threats, geopolitical developments, sector risk posture
  • Products: Threat landscape reports, strategic assessments, horizon scanning reports, maturity assessments
  • Example PIR: "How will the ransomware threat landscape evolve over the next 12 months and what are the implications for our risk posture?"

Operational Intelligence

  • Time horizon: Weeks to months
  • Consumers: SOC Manager, IR Lead, Security Operations
  • Focus: Active campaigns, threat actor profiling, TTP analysis, vulnerability exploitation trends
  • Products: Campaign reports, threat actor profiles, operational assessments, hunt packages
  • Example PIR: "What TTPs are currently being used by groups targeting our sector?"

Tactical Intelligence

  • Time horizon: Hours to days
  • Consumers: SOC Analysts, Detection Engineers, IR Analysts
  • Focus: IOCs, detection rules, immediate response support, indicator enrichment
  • Products: IOC packages, SIGMA/YARA/KQL rules, flash reports, enrichment reports
  • Example PIR: "What IOCs are associated with the current wave of attacks targeting our VPN appliances?"

Phase Mapping to Platform

Phase 1: Planning & Direction

What: Define what intelligence is needed and set priorities.

LevelActivityAgentSkills
StrategicSet/review PIRs, horizon scanning briefsorchestratorpir-management, stakeholder-management
OperationalDefine collection priorities for active investigationsorchestratorpir-management, sops
TacticalIdentify IOC collection gaps, detection coverage gapsorchestratorsops

Phase 2: Collection

What: Gather raw data from relevant sources.

LevelActivityAgentSkills
StrategicTrend monitoring, landscape researchosint-researcherosint-methodology
OperationalThreat actor tracking, campaign research, dark web monitoringosint-researcher, tool agentsosint-methodology, darkweb-collection
TacticalIOC lookups, bulk enrichmenttool agents, ioc-processortool-api skills, ioc-enrichment-workflow

Phase 3: Processing

What: Normalise, deduplicate, and structure collected data.

LevelActivityAgentSkills
AllIOC deduplication, format normalisation, source assessment taggingioc-processorioc-enrichment-workflow, source-assessment

Phase 4: Analysis

What: Apply human judgment to produce assessed intelligence.

LevelActivityAgentSkills
StrategicHorizon scanning, maturity assessment, trend analysisanalysthorizon-scanning, threat-assessment, maturity-assessment
OperationalACH, threat actor profiling, campaign trackinganalystach, threat-actor-profiling, campaign-tracking, key-assumptions-check
TacticalIOC correlation, detection gap analysis, indicator pivotinganalystindicator-pivoting, vulnerability-intelligence

Phase 5: Dissemination

What: Deliver finished intelligence to stakeholders.

LevelActivityAgentSkills
StrategicLandscape reports, annual assessments, board briefingsreport-writerintelligence-writing, writing-assessments, stakeholder-management
OperationalActor profiles, campaign reports, operational assessmentsreport-writerintelligence-writing, writing-assessments
TacticalIOC packages, detection rules, flash reportsdetection-engineer, ioc-processor, report-writersigma/yara/kql-writing, ioc-export, stix-bundle

Phase 6: Feedback

What: Assess effectiveness and refine direction.

LevelActivityAgentSkills
AllConsumer feedback, source quality tracking, PIR refinementorchestratorfeedback-loops, pir-management

Bidirectional Flow Examples

Tactical → Operational: IOC enrichment reveals infrastructure pattern shared across multiple incidents → triggers campaign tracking investigation.

Operational → Strategic: Campaign analysis identifies new nation-state actor shifting targeting to a new sector → feeds into strategic landscape assessment and PIR update.

Strategic → Operational: Horizon scanning identifies AI-augmented social engineering as emerging threat → creates operational collection tasking for specific TTP monitoring.

Operational → Tactical: Threat actor profiling reveals preferred exploitation technique → drives creation of specific SIGMA detection rules.

Strategic → Tactical: Risk assessment identifies unpatched VPN as critical exposure → prioritises vulnerability intelligence and IOC monitoring for VPN exploits.

Tactical → Strategic: Spike in credential-stuffing alerts → informs strategic assessment of the underground economy and infostealer trend.

Orchestrator Workflow Mapping

When the orchestrator receives a task, it maps it to the Hyperloop:

User RequestPrimary LevelHyperloop PhasesKey Agents
"Investigate this IP"Tactical2→3→4→5Tool agents → IOC processor → Analyst → Detection engineer
"Profile this threat actor"Operational2→3→4→5→6OSINT researcher → IOC processor → Analyst → Report writer → Update knowledge cell
"Write a threat assessment on X"Strategic/Operational1→2→3→4→5→6Orchestrator (PIRs) → OSINT researcher → Analyst (SATs) → Report writer → Quality reviewer
"Enrich this IOC list"Tactical2→3→5Tool agents → IOC processor → Export
"What's the current ransomware landscape?"Strategic2→4→5OSINT researcher → Analyst (knowledge cell) → Report writer
"Create detection rules for APT28 TTPs"Tactical4→5Analyst (knowledge cell) → Detection engineer
"Review our PIRs"Management1→6Orchestrator (PIR management, feedback loops)

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.