Threat Assessment Methodology

SkillSecurity

Structured threat assessment methodology. Intent + Capability + Opportunity = Threat Level. Use when formally evaluating a threat.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Threat Assessment Methodology skill

What this skill tells your AI

The instructions your AI receives, as published by liberty91ltd/cti-skills in skills/threat-assessment/SKILL.md and read by ahel’s review.

A threat assessment evaluates the threat posed by a specific actor or scenario to a specific target. It combines Intent, Capability, and Opportunity into an overall Threat Level.

Formula

Threat = Intent + Capability + Opportunity

All three must be present for a credible threat. A highly capable actor with no intent poses minimal threat. A motivated actor with no capability poses minimal threat.

Assessment Components

Intent — What does the adversary want?

RatingCriteria
DemonstratedActive targeting observed, stated objectives, ongoing operations against similar targets
ProbableHistorical targeting of similar organisations/sectors, geopolitical alignment, inferred from capability development
PossibleGeneral capability exists, sector/geography falls within known interests, no direct indicators
UnlikelyNo known interest in sector/geography, no historical targeting of similar targets

Evidence to assess intent:

  • Direct targeting of the organisation or sector
  • Stated objectives (manifestos, claims, leaked documents)
  • Historical targeting patterns
  • Geopolitical/economic motivations
  • Reconnaissance activity observed

Capability — What can the adversary do?

RatingCriteria
AdvancedZero-day exploitation, custom tooling, state-level resources, proven track record of complex operations
SignificantSophisticated TTPs, modified tools, professional operations, ability to adapt
ModerateKnown exploits and commodity tools, some custom capability, competent operations
BasicScript-kiddie level, publicly available tools only, limited operational security

Evidence to assess capability:

  • Known tools and malware sophistication
  • Historical operations and their complexity
  • Resources (financial, human, infrastructure)
  • Ability to develop or acquire zero-days
  • Operational security and counter-intelligence capability

Opportunity — What attack surface exists?

RatingCriteria
SignificantLarge internet-facing footprint, known unpatched vulnerabilities, supply chain exposure, limited security controls
ModerateSome internet exposure, generally patched but gaps exist, reasonable security controls
LimitedMinimal attack surface, strong security controls, rapid patching, limited supply chain exposure
MinimalAir-gapped or highly restricted, advanced security controls, comprehensive monitoring

Evidence to assess opportunity:

  • Internet-facing services and known vulnerabilities
  • Supply chain relationships and third-party access
  • Security control maturity (detection, response)
  • Employee exposure (social media, conferences)
  • Historical incidents and near-misses

Combining into Threat Level

LevelCriteria
CRITICALDemonstrated intent + Advanced capability + Significant opportunity. Attack is imminent or ongoing.
HIGHStrong intent indicators + Significant capability + Exploitable opportunity. Attack is highly likely.
MODERATESome intent indicators + Moderate capability + Some opportunity. Attack is a realistic possibility.
LOWLimited intent indicators + Basic/Moderate capability + Limited opportunity. Attack is unlikely.
NEGLIGIBLENo credible intent OR minimal capability OR no meaningful opportunity.

Output Template

## Threat Assessment: [Subject]
**Date**: YYYY-MM-DD | **Confidence**: [Level] | **TLP**: [Level]

### Threat Level: [CRITICAL/HIGH/MODERATE/LOW/NEGLIGIBLE]

### Intent: [Rating]
[Assessment with evidence and confidence]

### Capability: [Rating]
[Assessment with evidence and confidence]

### Opportunity: [Rating]
[Assessment with evidence and confidence]

### Combined Assessment
[Synthesis of intent + capability + opportunity into overall threat level. Use likelihood language for forward-looking statements.]

### Key Assumptions
[Per key-assumptions-check]

### Recommended Mitigations
1. [Prioritised by impact on reducing threat level]

### Sources
[With Admiralty Scale ratings]

Signals

GitHub stars
22
Forks
9
Last commit
Aug 2026
Advanced
Catalog kind
skill
Gateway key
threat-assessment
Source
github.com/liberty91ltd/cti-skills