CTI Hyperloop Framework

SkillDev tools

Use when the user asks about the CTI Hyperloop framework, the intelligence lifecycle as a high-tempo loop, or how to map intelligence work across strategic / operational / tactical levels with bidirectional feedback. Liberty91's operational doctrine.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the CTI Hyperloop Framework skill

What this skill tells your AI

The instructions your AI receives, as published by liberty91ltd/cti-skills in skills/cti-hyperloop/SKILL.md and read by ahel’s review.

The CTI Hyperloop (based on Google/Mandiant's practical implementation framework) extends the traditional intelligence cycle by running it at three levels simultaneously with continuous bidirectional feedback.

Core Concept

Traditional intelligence cycle: linear, single-track, often stuck at the tactical level. Hyperloop: three parallel tracks (strategic, operational, tactical) feeding each other continuously.

STRATEGIC  ←→  OPERATIONAL  ←→  TACTICAL
    ↓              ↓               ↓
Direction → Collection → Processing → Analysis → Dissemination → Feedback
    ↑                                                              |
    └──────────────────────────────────────────────────────────────┘

Intelligence Levels

Strategic Intelligence

  • Time horizon: 6-24 months
  • Consumers: CISO, Board, Risk Management, Security Architecture
  • Focus: Threat landscape trends, emerging threats, geopolitical developments, sector risk posture
  • Products: Threat landscape reports, strategic assessments, horizon scanning reports, maturity assessments
  • Example PIR: "How will the ransomware threat landscape evolve over the next 12 months and what are the implications for our risk posture?"

Operational Intelligence

  • Time horizon: Weeks to months
  • Consumers: SOC Manager, IR Lead, Security Operations
  • Focus: Active campaigns, threat actor profiling, TTP analysis, vulnerability exploitation trends
  • Products: Campaign reports, threat actor profiles, operational assessments, hunt packages
  • Example PIR: "What TTPs are currently being used by groups targeting our sector?"

Tactical Intelligence

  • Time horizon: Hours to days
  • Consumers: SOC Analysts, Detection Engineers, IR Analysts
  • Focus: IOCs, detection rules, immediate response support, indicator enrichment
  • Products: IOC packages, SIGMA/YARA/KQL rules, flash reports, enrichment reports
  • Example PIR: "What IOCs are associated with the current wave of attacks targeting our VPN appliances?"

Phase Mapping to Platform

Phase 1: Planning & Direction

What: Define what intelligence is needed and set priorities.

LevelActivityAgentSkills
StrategicSet/review PIRs, horizon scanning briefsorchestratorpir-management, stakeholder-management
OperationalDefine collection priorities for active investigationsorchestratorpir-management, sops
TacticalIdentify IOC collection gaps, detection coverage gapsorchestratorsops

Phase 2: Collection

What: Gather raw data from relevant sources.

LevelActivityAgentSkills
StrategicTrend monitoring, landscape researchosint-researcherosint-methodology
OperationalThreat actor tracking, campaign research, dark web monitoringosint-researcher, tool agentsosint-methodology, darkweb-collection
TacticalIOC lookups, bulk enrichmenttool agents, ioc-processortool-api skills, ioc-enrichment-workflow

Phase 3: Processing

What: Normalise, deduplicate, and structure collected data.

LevelActivityAgentSkills
AllIOC deduplication, format normalisation, source assessment taggingioc-processorioc-enrichment-workflow, source-assessment

Phase 4: Analysis

What: Apply human judgment to produce assessed intelligence.

LevelActivityAgentSkills
StrategicHorizon scanning, maturity assessment, trend analysisanalysthorizon-scanning, threat-assessment, maturity-assessment
OperationalACH, threat actor profiling, campaign trackinganalystach, threat-actor-profiling, campaign-tracking, key-assumptions-check
TacticalIOC correlation, detection gap analysis, indicator pivotinganalystindicator-pivoting, vulnerability-intelligence

Phase 5: Dissemination

What: Deliver finished intelligence to stakeholders.

LevelActivityAgentSkills
StrategicLandscape reports, annual assessments, board briefingsreport-writerintelligence-writing, writing-assessments, stakeholder-management
OperationalActor profiles, campaign reports, operational assessmentsreport-writerintelligence-writing, writing-assessments
TacticalIOC packages, detection rules, flash reportsdetection-engineer, ioc-processor, report-writersigma/yara/kql-writing, ioc-export, stix-bundle

Phase 6: Feedback

What: Assess effectiveness and refine direction.

LevelActivityAgentSkills
AllConsumer feedback, source quality tracking, PIR refinementorchestratorfeedback-loops, pir-management

Bidirectional Flow Examples

Tactical → Operational: IOC enrichment reveals infrastructure pattern shared across multiple incidents → triggers campaign tracking investigation.

Operational → Strategic: Campaign analysis identifies new nation-state actor shifting targeting to a new sector → feeds into strategic landscape assessment and PIR update.

Strategic → Operational: Horizon scanning identifies AI-augmented social engineering as emerging threat → creates operational collection tasking for specific TTP monitoring.

Operational → Tactical: Threat actor profiling reveals preferred exploitation technique → drives creation of specific SIGMA detection rules.

Strategic → Tactical: Risk assessment identifies unpatched VPN as critical exposure → prioritises vulnerability intelligence and IOC monitoring for VPN exploits.

Tactical → Strategic: Spike in credential-stuffing alerts → informs strategic assessment of the underground economy and infostealer trend.

Orchestrator Workflow Mapping

When the orchestrator receives a task, it maps it to the Hyperloop:

User RequestPrimary LevelHyperloop PhasesKey Agents
"Investigate this IP"Tactical2→3→4→5Tool agents → IOC processor → Analyst → Detection engineer
"Profile this threat actor"Operational2→3→4→5→6OSINT researcher → IOC processor → Analyst → Report writer → Update knowledge cell
"Write a threat assessment on X"Strategic/Operational1→2→3→4→5→6Orchestrator (PIRs) → OSINT researcher → Analyst (SATs) → Report writer → Quality reviewer
"Enrich this IOC list"Tactical2→3→5Tool agents → IOC processor → Export
"What's the current ransomware landscape?"Strategic2→4→5OSINT researcher → Analyst (knowledge cell) → Report writer
"Create detection rules for APT28 TTPs"Tactical4→5Analyst (knowledge cell) → Detection engineer
"Review our PIRs"Management1→6Orchestrator (PIR management, feedback loops)

Signals

GitHub stars
22
Forks
9
Last commit
Aug 2026
Advanced
Catalog kind
skill
Gateway key
cti-hyperloop
Source
github.com/liberty91ltd/cti-skills