Threat Intelligence Templates
Stand up and run a CTI program on open-source tooling — a scored maturity assessment, the build workbook, feed and scoring tools, analyst runbooks, and the policy pack that governs it
CTI Program Maturity Assessment
Nine domains, forty-five statements, and two ceiling rules that stop you scoring yourself a three. The front door to the line — find out where the program actually is before spending anything.
CTI Maturity Assessment — Auto-Scoring
The same forty-five statements as a spreadsheet that applies both ceiling rules and ranks your gaps for you — six tabs, 98 formulas, nothing hardcoded.
Build Your Own Threat Intelligence Program
The anchor. Ten sections taking a small team from no capability to a running CTI program in ninety days, on MISP and the open-source CIRCL stack — with an honest ceiling on what a DIY program can ever do.
Feed Selection Matrix
Sixty-two open sources pre-scored on the six criteria that are the same for everyone — you supply the two that are not. Six tabs, 411 formulas, an eight-criterion rubric and a cut line at 18 of 40.
CTI Analyst Runbook Library
Eighteen procedures for the things that actually land in an analyst queue. One page each, each ending in a decision rather than a suggestion — with an escalation matrix and an execution log.
Threat Intel Policy & Governance Pack
Six adoptable documents covering marking, handling, sharing, retention, membership, and machine access — with DORA Article 45, NIS2 Article 29 and ISO 27001 mappings. The governance a sharing programme is required to have and almost never does.