agentsclimarketplace

Horizon scanning

Skill Liberty91LTD/cti-skills/skills/horizon-scanning

Cyber Threat Intelligence Skills for each stage of the CTI Lifecycle.

Install
npx -y skills add Liberty91LTD/cti-skills --skill horizon-scanning

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 8 stars8 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Use when the user asks "what is coming next?", wants strategic forecasting, or is hunting weak signals of emerging threats before they materialise. Covers signal identification, trend analysis, and scenario development.

SKILL.md

3.7 KB, as published. Nobody here has run it

Horizon Scanning

Horizon scanning identifies emerging threats, opportunities, and developments that could impact the organisation's security posture in the medium to long term (6-24 months).

Process

1. Define Scope

  • Time horizon (6 months? 12 months? 24 months?)
  • Focus areas (specific sectors, threat types, geographies)
  • Stakeholder needs (what decisions will this inform?)

2. Identify Weak Signals

Weak signals are early indicators of emerging trends. Sources:

  • Academic research and conference papers (BlackHat, DEF CON, CCC, academic journals)
  • Underground forum discussions (new tools, techniques being discussed)
  • Patent filings and startup activity (indicators of new capabilities)
  • Geopolitical developments (sanctions, conflicts, elections)
  • Regulatory changes (new compliance requirements creating new attack surfaces)
  • Technology adoption trends (new tech = new attack surface)

3. Categorise Signals

CategoryExamples
Emerging TTPsNew exploitation techniques, novel social engineering methods, AI-augmented attacks
Technology shiftsNew platforms widely adopted, legacy tech being deprecated, cloud migration patterns
Threat actor evolutionNew groups emerging, existing groups changing targets, capability development
Geopolitical driversConflicts, sanctions, elections, diplomatic shifts
Regulatory/legalNew laws, enforcement actions, liability changes
Underground economyNew services, market shifts, ecosystem changes

4. Develop Scenarios

For each significant signal, develop three scenarios:

  • Best case: Signal does not materialise or is mitigated
  • Worst case: Signal materialises with maximum impact
  • Most likely: Balanced assessment based on available evidence

5. Assess Impact and Likelihood

For each scenario:

  • Likelihood (using probability yardstick from likelihood-language skill)
  • Impact on organisation (Critical/High/Moderate/Low/Negligible)
  • Time to materialise
  • Confidence in assessment

6. Identify Early Warning Indicators

For each high-impact scenario, define:

  • What observable indicators would suggest this is materialising?
  • Where would we see these indicators? (collection sources)
  • How frequently should we monitor?

Output Template

## Horizon Scanning Report: [Focus Area]
**Period**: [Time horizon]
**Date**: YYYY-MM-DD

### Executive Summary
[Key emerging threats and their implications]

### Emerging Threats

#### [Threat 1]: [Title]
- **Signal strength**: Weak / Emerging / Established
- **Time horizon**: [When could this materialise?]
- **Likelihood**: [Probability yardstick term]
- **Potential impact**: [Critical/High/Moderate/Low]
- **Confidence**: [Level with rationale]
- **Description**: [What is this threat and why does it matter?]
- **Early warning indicators**: [What to watch for]
- **Recommended action**: [Proactive steps]

### Scenario Analysis
[For top 2-3 threats, develop best/worst/most likely scenarios]

### Collection Gaps
[What we need to monitor but currently can't]

Common Signals to Monitor (CTI)

  • AI-powered phishing/deepfakes maturation
  • Quantum computing impact on cryptography
  • Supply chain security tooling gaps
  • Cloud-native attack technique evolution
  • Ransomware business model evolution
  • Nation-state cyber capability proliferation
  • Infostealer-to-ransomware pipeline evolution
  • Edge device/IoT exploitation trends

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.