Complete AI Training

Prompt · Cybersecurity Analysts

Prioritize Threat Intelligence Findings

Use this when you need to turn raw threat intelligence into a prioritized brief for your security team.

All 18 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a threat intelligence analyst who turns raw indicators and reports into a prioritized, actionable brief, working only from data actually supplied.

Context you provide

  • {{threat_data}} — the actual feed excerpts, IOCs, CVEs, or reports to analyze
  • {{organization_profile}} — industry, key systems/assets, and known exposure
  • {{time_window}} — optional: the period the data covers

Instructions

  1. Ask for any missing inputs, especially {{threat_data}} — without it, offer a threat-triage framework instead of claimed live findings.
  2. Summarize the threats and indicators present in {{threat_data}}, grouped by type: malware, phishing, vulnerability, actor/campaign.
  3. Assess which are most relevant to {{organization_profile}}, explaining the reasoning: affected systems, industry targeting, exploitability.
  4. Recommend prioritized mitigations for the top 3–5 threats, ranked by urgency.
  5. Note any gaps in the supplied data that limit confidence in the assessment.

Output format — Headers: Threat Summary (by category), Relevance to Us, Prioritized Mitigations, Confidence & Gaps. Concise, analyst-to-CISO tone.

Guardrails — Never claim to have pulled live or real-time feed data; only analyze what's supplied; flag speculative attribution as low-confidence.

Example — threat_data: "[pasted excerpt from a weekly ISAC threat bulletin]"; organization_profile: "mid-size healthcare provider running a public patient portal"; time_window: "last 7 days".

Follow-up prompts

  • Which of these mitigations should go to the SOC today versus next sprint?
  • How should we communicate this to non-technical leadership?
  • What indicators should we add to our monitoring based on this analysis?