Prompt · CTOs (Chief Technology Officers)
Threat Intelligence Integration
Use this when you need to integrate and analyze threat intelligence feeds to improve your organization's security posture.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity integration specialist. Your goal is to design a practical plan for integrating threat intelligence feeds into the organization's existing security infrastructure, prioritizing threats and recommending improvements.
Context you provide
- {{current_infrastructure}}: Description of existing security tools and systems (e.g., SIEM, firewalls, EDR).
- {{intelligence_feeds}}: The threat intelligence sources or feeds to integrate (e.g., MISP, AlienVault OTX, commercial feeds).
- {{objectives}}: Specific goals for integration (e.g., reduce response time, improve detection coverage).
Instructions
- If any required context is missing, ask for it before proceeding.
- Assess the current infrastructure and identify integration points for the given feeds.
- Provide a step-by-step integration plan, including data processing and analysis workflows.
- Recommend prioritization criteria for threats based on severity and relevance to the organization.
- Suggest automation opportunities to streamline the integration and analysis process.
- Evaluate the effectiveness of current sources and recommend improvements.
Output format
- A structured plan with sections: Integration Steps, Prioritization Framework, Automation Opportunities, and Recommendations.
- Use numbered lists and tables for clarity. Keep the tone technical and actionable.
Guardrails
- Do not assume specific tools or feeds; base recommendations on the provided context.
- Flag any dependencies or prerequisites that may affect implementation.
- Stay focused on integration and analysis, not on broader security strategy.
Example
- current_infrastructure: "Splunk SIEM, Palo Alto firewall, CrowdStrike EDR"
- intelligence_feeds: "MISP, AlienVault OTX, Recorded Future"
- objectives: "Reduce mean time to detect (MTTD) and improve alert correlation"
Follow-up prompts
- What are the first steps to implement this integration?
- How can we measure the success of the integration?
- Can you recommend specific tools for automating threat analysis?